ci: auto-merge green dependabot updates

This commit is contained in:
xixu-me committed 2026-05-14 12:53:14 +08:00
1 parent fbeb51b315
commit a94c121009
3 files changed
+251 -1

No files matched your search

+91
View File
@@ -0,0 +1,91 @@
name: CI
on:
pull_request:
branches:
- main
push:
branches:
- main
permissions:
contents: read
jobs:
validate:
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Validate generated JSON
run: |
python3 -m json.tool data/tvbox.json > /dev/null
python3 -m json.tool data/tvbox.meta.json > /dev/null
- name: Test extractor success path
run: |
temp_dir="$(mktemp -d)"
trap 'rm -rf "${temp_dir}"' EXIT
payload_path="${temp_dir}/payload.bin"
PAYLOAD_PATH="${payload_path}" python3 - <<'PY'
import base64
import os
decoded_json = b'{"sites":[{"key":"demo"}]}'
payload = (
b"\xff\xd8\xff\xd9"
+ b"prefix**"
+ base64.b64encode(decoded_json)
)
with open(os.environ["PAYLOAD_PATH"], "wb") as payload_file:
payload_file.write(payload)
PY
payload_url="$(python3 - "${payload_path}" <<'PY'
import sys
from pathlib import Path
print(Path(sys.argv[1]).resolve().as_uri())
PY
)"
TVBOX_URL="${payload_url}" \
OUT_JSON="${temp_dir}/tvbox.json" \
OUT_META="${temp_dir}/tvbox.meta.json" \
python3 scripts/extract_tvbox.py > /dev/null
python3 -m json.tool "${temp_dir}/tvbox.json" > /dev/null
python3 -m json.tool "${temp_dir}/tvbox.meta.json" > /dev/null
- name: Test extractor upstream error path
run: |
temp_dir="$(mktemp -d)"
trap 'rm -rf "${temp_dir}"' EXIT
bad_payload_path="${temp_dir}/bad-payload.bin"
printf 'not-a-tvbox-payload' > "${bad_payload_path}"
bad_payload_url="$(python3 - "${bad_payload_path}" <<'PY'
import sys
from pathlib import Path
print(Path(sys.argv[1]).resolve().as_uri())
PY
)"
set +e
TVBOX_URL="${bad_payload_url}" \
OUT_JSON="${temp_dir}/tvbox.json" \
OUT_META="${temp_dir}/tvbox.meta.json" \
python3 scripts/extract_tvbox.py > /dev/null 2>&1
status="$?"
set -e
if [ "${status}" -ne 75 ]; then
echo "Expected upstream error exit code 75, got ${status}."
exit 1
fi
+147
View File
@@ -0,0 +1,147 @@
name: Dependabot auto-merge
on:
workflow_run:
workflows:
- CI
types:
- completed
permissions:
checks: read
contents: write
pull-requests: write
statuses: read
jobs:
merge:
if: ${{ github.event.workflow_run.event == 'pull_request' }}
runs-on: ubuntu-latest
steps:
- name: Inspect completed PR checks
id: decision
env:
DEFAULT_BRANCH: ${{ github.event.repository.default_branch }}
GH_TOKEN: ${{ github.token }}
PULL_REQUESTS_JSON: ${{ toJson(github.event.workflow_run.pull_requests) }}
REPOSITORY: ${{ github.repository }}
WORKFLOW_CONCLUSION: ${{ github.event.workflow_run.conclusion }}
run: |
if [ "${WORKFLOW_CONCLUSION}" != "success" ]; then
echo "Completed workflow conclusion is ${WORKFLOW_CONCLUSION}; skipping."
echo "merge=false" >> "${GITHUB_OUTPUT}"
exit 0
fi
pr_number="$(python3 - <<'PY'
import json
import os
pull_requests = json.loads(os.environ["PULL_REQUESTS_JSON"])
print(pull_requests[0]["number"] if pull_requests else "")
PY
)"
if [ -z "${pr_number}" ]; then
echo "Completed workflow is not associated with a pull request; skipping."
echo "merge=false" >> "${GITHUB_OUTPUT}"
exit 0
fi
pr_file="${RUNNER_TEMP}/pr.json"
checks_file="${RUNNER_TEMP}/checks.json"
gh api "repos/${REPOSITORY}/pulls/${pr_number}" > "${pr_file}"
gh pr view "${pr_number}" \
--repo "${REPOSITORY}" \
--json statusCheckRollup \
> "${checks_file}"
python3 - "${pr_file}" "${checks_file}" <<'PY'
import json
import os
import sys
GREEN_CHECK_CONCLUSIONS = {"SUCCESS", "NEUTRAL", "SKIPPED"}
GREEN_STATUS_STATES = {"SUCCESS"}
def set_output(name: str, value: str) -> None:
with open(os.environ["GITHUB_OUTPUT"], "a", encoding="utf-8") as output:
output.write(f"{name}={value}\n")
def skip(reason: str) -> None:
print(reason)
set_output("merge", "false")
raise SystemExit(0)
with open(sys.argv[1], encoding="utf-8") as pr_json:
pull_request = json.load(pr_json)
with open(sys.argv[2], encoding="utf-8") as checks_json:
checks = json.load(checks_json)["statusCheckRollup"]
repository = os.environ["REPOSITORY"]
default_branch = os.environ["DEFAULT_BRANCH"]
if pull_request["user"]["login"] != "dependabot[bot]":
skip("Pull request author is not Dependabot; skipping.")
if pull_request["state"] != "open":
skip("Pull request is not open; skipping.")
if pull_request["draft"]:
skip("Pull request is a draft; skipping.")
if pull_request["base"]["repo"]["full_name"] != repository:
skip("Pull request targets a different repository; skipping.")
if pull_request["head"]["repo"]["full_name"] != repository:
skip("Pull request comes from a fork; skipping.")
if pull_request["base"]["ref"] != default_branch:
skip("Pull request does not target the default branch; skipping.")
if not checks:
skip("Pull request has no checks; skipping.")
not_green = []
for check in checks:
check_type = check.get("__typename")
if check_type == "CheckRun":
name = check.get("name", "<unnamed check>")
status = check.get("status")
conclusion = check.get("conclusion")
if status != "COMPLETED" or conclusion not in GREEN_CHECK_CONCLUSIONS:
not_green.append(f"{name}: {status}/{conclusion}")
elif check_type == "StatusContext":
context = check.get("context", "<unnamed status>")
state = check.get("state")
if state not in GREEN_STATUS_STATES:
not_green.append(f"{context}: {state}")
else:
not_green.append(f"Unsupported status item: {check_type}")
if not_green:
skip("Not all pull request checks are green:\n" + "\n".join(not_green))
set_output("merge", "true")
set_output("head_sha", pull_request["head"]["sha"])
set_output("pr_url", pull_request["html_url"])
print(f"Dependabot PR #{pull_request['number']} is green and eligible to merge.")
PY
- name: Squash-merge Dependabot PR
if: ${{ steps.decision.outputs.merge == 'true' }}
env:
GH_TOKEN: ${{ github.token }}
HEAD_SHA: ${{ steps.decision.outputs.head_sha }}
PR_URL: ${{ steps.decision.outputs.pr_url }}
run: |
gh pr merge "${PR_URL}" \
--squash \
--delete-branch \
--match-head-commit "${HEAD_SHA}"