Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
31 changes: 11 additions & 20 deletions .github/actions/setup-node/action.yml
Original file line number Diff line number Diff line change
@@ -1,24 +1,15 @@
name: Setup node
description: Local node setup for runners
name: Set up Node.js
description: Install Node.js and the project's npm dependencies

runs:
using: "composite"
using: composite
steps:
- name: Cache npm and node_modules
uses: actions/cache@v6
with:
path: |
~/.npm
node_modules
key: ${{ runner.os }}-npm-${{ hashFiles('**/package-lock.json') }}
restore-keys: |
${{ runner.os }}-npm-
- name: Set up Node.js
uses: actions/setup-node@v7
with:
node-version: "24"
cache: npm

- name: Set up Node.js
uses: actions/setup-node@v7
with:
node-version: '24'

- name: Install dependencies
shell: bash
run: npm install
- name: Install dependencies
shell: bash
run: npm ci
36 changes: 27 additions & 9 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -1,16 +1,34 @@
version: 2
updates:
- package-ecosystem: "docker"
directory: "/"
- package-ecosystem: npm
directory: /
schedule:
interval: "daily"
interval: weekly
groups:
npm:
patterns: ["*"]

- package-ecosystem: "bundler"
directory: "/"
- package-ecosystem: bundler
directory: /
schedule:
interval: "daily"
interval: weekly
groups:
bundler:
patterns: ["*"]

- package-ecosystem: "github-actions"
directory: "/"
- package-ecosystem: docker
directory: /
schedule:
interval: "daily"
interval: weekly
groups:
docker:
patterns: ["*"]

- package-ecosystem: github-actions
# "/" only covers .github/workflows, so the local composite actions are listed too
directories: ["/", "/.github/actions/*"]
schedule:
interval: weekly
groups:
github-actions:
patterns: ["*"]
54 changes: 21 additions & 33 deletions .github/workflows/codeql-analysis.yml
Original file line number Diff line number Diff line change
@@ -1,52 +1,40 @@
name: "CodeQL"
name: CodeQL

on:
push:
branches: [ "main" ]
branches: [main]
pull_request:
branches: [ "main" ]
branches: [main]
schedule:
- cron: '39 7 * * 6'
- cron: "39 7 * * 6"

permissions:
contents: read

concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}

jobs:
analyze:
name: Analyze
runs-on: ubuntu-latest
permissions:
actions: read
contents: read
security-events: write

strategy:
fail-fast: false
matrix:
language: [ 'javascript', 'ruby' ]

language: [actions, javascript]
steps:
- name: Checkout repository
uses: actions/checkout@v7

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@v4
with:
languages: ${{ matrix.language }}


# Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
# If this step fails, then you should remove it and run the build manually (see below)
- name: Autobuild
uses: github/codeql-action/autobuild@v4

# ℹ️ Command-line programs to run using the OS shell.
# 📚 See https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#jobsjob_idstepsrun

# If the Autobuild fails above, remove it and uncomment the following three lines.
# modify them (or add more) to build your code if your project, please refer to the EXAMPLE below for guidance.
- name: Checkout repository
uses: actions/checkout@v7

# - run: |
# echo "Run, Build Application using script"
# ./location_of_script_within_repo/buildscript.sh
- name: Initialize CodeQL
uses: github/codeql-action/init@v4
with:
languages: ${{ matrix.language }}
build-mode: none

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v4
- name: Perform CodeQL analysis
uses: github/codeql-action/analyze@v4
28 changes: 0 additions & 28 deletions .github/workflows/pr-auto-label.yml

This file was deleted.

23 changes: 0 additions & 23 deletions .github/workflows/pr-auto-merge.yml

This file was deleted.

41 changes: 41 additions & 0 deletions .github/workflows/pr-auto-setup.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,41 @@
name: PR auto-setup

# pull_request_target gives fork PRs access to the App secrets. This is safe only
# because no step checks out or runs code from the PR.
on:
pull_request_target:
types: [opened, ready_for_review]
branches: [main]

# The job uses the GitHub App token, not GITHUB_TOKEN
permissions: {}

jobs:
pr-auto-setup:
name: Label and enable auto-merge
runs-on: ubuntu-latest
steps:
- name: Generate App token
id: app-token
uses: actions/create-github-app-token@v3
with:
client-id: ${{ vars.PR_AUTO_UPDATE_CLIENT_ID }}
private-key: ${{ secrets.PR_AUTO_UPDATE_PRIVATE_KEY }}

# Only for branches in this repo; bots such as Dependabot rebase their own PRs
- name: Add sync label
if: >-
github.event.action == 'opened'
&& github.event.pull_request.head.repo.full_name == github.repository
&& github.event.pull_request.user.type != 'Bot'
run: gh pr edit "$PR_URL" --add-label sync
env:
GH_TOKEN: ${{ steps.app-token.outputs.token }}
PR_URL: ${{ github.event.pull_request.html_url }}

- name: Enable auto-merge
if: ${{ !github.event.pull_request.draft }}
run: gh pr merge "$PR_URL" --auto --squash
env:
GH_TOKEN: ${{ steps.app-token.outputs.token }}
PR_URL: ${{ github.event.pull_request.html_url }}
39 changes: 24 additions & 15 deletions .github/workflows/pr-auto-update.yml
Original file line number Diff line number Diff line change
@@ -1,27 +1,36 @@
name: pr-auto-update
name: PR auto-update

on:
push: {}
push:
branches: [main]

# The job uses the GitHub App token, not GITHUB_TOKEN
permissions: {}

# Queue rather than cancel, so an update is never stopped part way through
concurrency:
group: ${{ github.workflow }}
cancel-in-progress: false

jobs:
pr-auto-update:
name: Automatic PR Updater
name: Update PRs labelled sync
runs-on: ubuntu-latest
# Dependabot-triggered runs can't read the App secrets
if: github.repository == 'CSSUoB/cssuob.github.io' && github.actor != 'dependabot[bot]'
permissions:
pull-requests: write
contents: write
steps:
- name: Generate Access Token
- name: Generate App token
id: app-token
uses: actions/create-github-app-token@v3
id: generate-token
with:
app-id: ${{ vars.PR_AUTO_UPDATE_CLIENT_ID }}
client-id: ${{ vars.PR_AUTO_UPDATE_CLIENT_ID }}
private-key: ${{ secrets.PR_AUTO_UPDATE_PRIVATE_KEY }}

- uses: CSSUoB/pr-auto-updater@v4.0.0
- name: Update PRs labelled sync
uses: CSSUoB/pr-auto-updater@v4.0.0
env:
GITHUB_TOKEN: ${{ steps.generate-token.outputs.token }}
PR_FILTER: 'labelled'
PR_LABELS: 'sync'
MERGE_CONFLICT_ACTION: 'label'
MERGE_CONFLICT_LABEL: 'conflict'
GITHUB_TOKEN: ${{ steps.app-token.outputs.token }}
PR_FILTER: labelled
PR_LABELS: sync
MERGE_CONFLICT_ACTION: label
MERGE_CONFLICT_LABEL: conflict
50 changes: 50 additions & 0 deletions .github/workflows/static-analysis.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,50 @@
name: Static analysis

on:
push:
branches: [main]
pull_request:
branches: [main]

permissions:
contents: read

concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}

jobs:
static-analysis:
name: Format, lint and spellcheck
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v7
with:
# The parent commit is needed to work out which files changed
fetch-depth: 2

- name: Set up Node.js
uses: ./.github/actions/setup-node

# Each check runs even if an earlier one fails, so all problems are reported at once
- name: Check formatting
if: ${{ !cancelled() }}
run: npm run format

- name: Lint JavaScript
if: ${{ !cancelled() }}
run: npm run lint:js

- name: Lint Markdown
if: ${{ !cancelled() }}
run: npm run lint:md

# Advisory only: unknown words are shown as warnings on the PR without failing the check
- name: Spellcheck changed files
if: ${{ !cancelled() }}
continue-on-error: true
run: |
git diff --name-only --diff-filter=d HEAD^ HEAD -- '*.md' '*.html' \
| npx cspell --file-list stdin --no-must-find-files --no-progress \
--issue-template '::warning file=$filename,line=$row,col=$col::Unknown word: $text'
Loading
Loading