mirror of
https://github.com/github/codeql-action.git
synced 2026-10-03 09:14:58 +00:00
Remove regular workflow file updates from sync-back script
Co-authored-by: henrymercer <14129055+henrymercer@users.noreply.github.com>
This commit is contained in:
@@ -36,7 +36,8 @@ python3 pr-checks/sync-back.py
|
||||
The sync-back script automatically updates:
|
||||
- Hardcoded action versions in `pr-checks/sync.py`
|
||||
- Action version references in template files in `pr-checks/checks/`
|
||||
- Action version references in regular workflow files
|
||||
|
||||
Regular workflow files are updated directly by Dependabot and don't need sync-back.
|
||||
|
||||
This ensures that the `verify-pr-checks.sh` test always passes after Dependabot PRs.
|
||||
|
||||
|
||||
@@ -7,13 +7,13 @@ This script scans the generated workflow files (.github/workflows/__*.yml) to fi
|
||||
all external action versions used, then updates:
|
||||
1. Hardcoded action versions in pr-checks/sync.py
|
||||
2. Action version references in template files in pr-checks/checks/
|
||||
3. Action version references in regular workflow files
|
||||
|
||||
The script automatically detects all actions used in generated workflows and
|
||||
preserves version comments (e.g., # v1.2.3) when syncing versions.
|
||||
|
||||
This ensures that when Dependabot updates action versions in generated workflows,
|
||||
those changes are properly synced back to the source templates.
|
||||
those changes are properly synced back to the source templates. Regular workflow
|
||||
files are updated directly by Dependabot and don't need sync-back.
|
||||
"""
|
||||
|
||||
import os
|
||||
@@ -132,45 +132,6 @@ def update_template_files(checks_dir: str, action_versions: Dict[str, str]) -> L
|
||||
return modified_files
|
||||
|
||||
|
||||
def update_regular_workflows(workflow_dir: str, action_versions: Dict[str, str]) -> List[str]:
|
||||
"""
|
||||
Update action versions in regular (non-generated) workflow files
|
||||
|
||||
Args:
|
||||
workflow_dir: Path to .github/workflows directory
|
||||
action_versions: Dictionary of action names to versions (may include comments)
|
||||
|
||||
Returns:
|
||||
List of files that were modified
|
||||
"""
|
||||
modified_files = []
|
||||
|
||||
# Get all workflow files that are NOT generated (don't start with __)
|
||||
all_files = glob.glob(os.path.join(workflow_dir, "*.yml"))
|
||||
regular_files = [f for f in all_files if not os.path.basename(f).startswith("__")]
|
||||
|
||||
for file_path in regular_files:
|
||||
with open(file_path, 'r') as f:
|
||||
content = f.read()
|
||||
|
||||
original_content = content
|
||||
|
||||
# Update action versions
|
||||
for action_name, version_with_comment in action_versions.items():
|
||||
# Look for patterns like 'uses: actions/setup-node@v4' or 'uses: actions/setup-node@sha # comment'
|
||||
pattern = rf"(uses:\s+{re.escape(action_name)})@([^@\n]+)"
|
||||
replacement = rf"\1@{version_with_comment}"
|
||||
content = re.sub(pattern, replacement, content)
|
||||
|
||||
if content != original_content:
|
||||
with open(file_path, 'w') as f:
|
||||
f.write(content)
|
||||
modified_files.append(file_path)
|
||||
print(f"Updated {file_path}")
|
||||
|
||||
return modified_files
|
||||
|
||||
|
||||
def main():
|
||||
parser = argparse.ArgumentParser(description="Sync action versions from generated workflows back to templates")
|
||||
parser.add_argument("--dry-run", action="store_true", help="Show what would be changed without making changes")
|
||||
@@ -214,10 +175,6 @@ def main():
|
||||
template_modified = update_template_files(str(checks_dir), action_versions)
|
||||
modified_files.extend(template_modified)
|
||||
|
||||
# Update regular workflow files
|
||||
workflow_modified = update_regular_workflows(str(workflow_dir), action_versions)
|
||||
modified_files.extend(workflow_modified)
|
||||
|
||||
if modified_files:
|
||||
print(f"\nSync completed. Modified {len(modified_files)} files:")
|
||||
for file_path in modified_files:
|
||||
|
||||
@@ -248,46 +248,6 @@ steps:
|
||||
|
||||
self.assertIn("uses: ruby/setup-ruby@55511735964dcb71245e7e55f72539531f7bc0eb # v1.257.0", updated_content)
|
||||
|
||||
def test_update_regular_workflows(self):
|
||||
"""Test updating regular workflow files"""
|
||||
# Create a regular workflow file
|
||||
workflow_content = """
|
||||
name: Regular Workflow
|
||||
jobs:
|
||||
test:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v3
|
||||
- uses: actions/setup-node@v4
|
||||
"""
|
||||
|
||||
workflow_path = os.path.join(self.workflow_dir, "regular.yml")
|
||||
with open(workflow_path, 'w') as f:
|
||||
f.write(workflow_content)
|
||||
|
||||
# Create a generated workflow file (should be ignored)
|
||||
generated_path = os.path.join(self.workflow_dir, "__generated.yml")
|
||||
with open(generated_path, 'w') as f:
|
||||
f.write(workflow_content)
|
||||
|
||||
action_versions = {
|
||||
'actions/checkout': 'v4',
|
||||
'actions/setup-node': 'v5'
|
||||
}
|
||||
|
||||
result = sync_back.update_regular_workflows(self.workflow_dir, action_versions)
|
||||
|
||||
# Should only update the regular file, not the generated one
|
||||
self.assertEqual(len(result), 1)
|
||||
self.assertIn(workflow_path, result)
|
||||
self.assertNotIn(generated_path, result)
|
||||
|
||||
with open(workflow_path, 'r') as f:
|
||||
updated_content = f.read()
|
||||
|
||||
self.assertIn("uses: actions/checkout@v4", updated_content)
|
||||
self.assertIn("uses: actions/setup-node@v5", updated_content)
|
||||
|
||||
def test_no_changes_needed(self):
|
||||
"""Test that functions return False/empty when no changes are needed"""
|
||||
# Test sync.py with no changes needed
|
||||
|
||||
Reference in New Issue
Block a user