-
Notifications
You must be signed in to change notification settings - Fork 2
99 lines (95 loc) · 5.61 KB
/
Copy pathvalidate.yml
File metadata and controls
99 lines (95 loc) · 5.61 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
name: Validate content
on:
pull_request:
branches: [main]
permissions:
contents: read
concurrency:
group: validate-${{ github.event.pull_request.number }}
cancel-in-progress: true
jobs:
validate:
runs-on: ubuntu-latest
timeout-minutes: 5
env:
BASE_SHA: ${{ github.event.pull_request.base.sha }}
HEAD_SHA: ${{ github.event.pull_request.head.sha }}
MERGE_REF: refs/pull/${{ github.event.pull_request.number }}/merge
MERGE_SHA: ${{ github.sha }}
ASSOCIATION: ${{ github.event.pull_request.author_association }}
HEAD_REPO: ${{ github.event.pull_request.head.repo.full_name }}
REPOSITORY: ${{ github.repository }}
steps:
- name: Check out trusted tooling
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
with:
ref: ${{ env.BASE_SHA }}
path: trusted
persist-credentials: false
- name: Check out submission as data
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
with:
ref: ${{ env.MERGE_REF }}
path: submission
fetch-depth: 0
persist-credentials: false
- name: Use Node.js 20
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020
with:
node-version: 20
cache: npm
cache-dependency-path: trusted/package-lock.json
- name: Install trusted dependencies
working-directory: trusted
run: npm ci --ignore-scripts
- name: Calculate changed files
run: git -C submission diff --name-only "$BASE_SHA...$HEAD_SHA" > changed-files.txt
- name: Enforce contribution scope
shell: bash
run: |
args=(--files changed-files.txt)
if [[ "$HEAD_REPO" == "$REPOSITORY" ]]; then
case "$ASSOCIATION" in OWNER|MEMBER|COLLABORATOR) args+=(--allow-infrastructure) ;; esac
fi
node trusted/scripts/check-contribution-scope.mjs "${args[@]}"
- name: Enforce Demo lifecycle changes with trusted tooling
if: ${{ github.event.pull_request.head.repo.full_name != github.repository || !contains(fromJSON('["OWNER", "MEMBER", "COLLABORATOR"]'), github.event.pull_request.author_association) }}
run: node trusted/scripts/check-demo-changes.mjs --base trusted --candidate submission --files changed-files.txt
- name: Validate Demo source as data with trusted tooling
if: ${{ github.event.pull_request.head.repo.full_name != github.repository || !contains(fromJSON('["OWNER", "MEMBER", "COLLABORATOR"]'), github.event.pull_request.author_association) }}
run: node trusted/scripts/validate-demos.mjs --root submission
- name: Enforce stable published slugs
run: node trusted/scripts/check-stable-slugs.mjs --base trusted --candidate submission
- name: Test trusted tooling
working-directory: trusted
run: npm test
- name: Validate content contribution with trusted tooling
if: ${{ github.event.pull_request.head.repo.full_name != github.repository || !contains(fromJSON('["OWNER", "MEMBER", "COLLABORATOR"]'), github.event.pull_request.author_association) }}
run: node trusted/scripts/validate.mjs --root submission --contract-root trusted
- name: Build content contribution catalog with trusted tooling
if: ${{ github.event.pull_request.head.repo.full_name != github.repository || !contains(fromJSON('["OWNER", "MEMBER", "COLLABORATOR"]'), github.event.pull_request.author_association) }}
run: node trusted/scripts/build-catalog.mjs --root submission --contract-root trusted --out-dir artifacts/catalog --source-commit "$MERGE_SHA"
- name: Install proposed dependencies
if: ${{ github.event.pull_request.head.repo.full_name == github.repository && contains(fromJSON('["OWNER", "MEMBER", "COLLABORATOR"]'), github.event.pull_request.author_association) }}
working-directory: submission
run: npm ci --ignore-scripts
- name: Enforce Demo lifecycle changes with proposed tooling
if: ${{ github.event.pull_request.head.repo.full_name == github.repository && contains(fromJSON('["OWNER", "MEMBER", "COLLABORATOR"]'), github.event.pull_request.author_association) }}
run: node submission/scripts/check-demo-changes.mjs --base trusted --candidate submission --files changed-files.txt
- name: Validate Demo source as data with proposed tooling
if: ${{ github.event.pull_request.head.repo.full_name == github.repository && contains(fromJSON('["OWNER", "MEMBER", "COLLABORATOR"]'), github.event.pull_request.author_association) }}
run: node submission/scripts/validate-demos.mjs --root submission
- name: Check proposed infrastructure
if: ${{ github.event.pull_request.head.repo.full_name == github.repository && contains(fromJSON('["OWNER", "MEMBER", "COLLABORATOR"]'), github.event.pull_request.author_association) }}
working-directory: submission
run: npm run check
- name: Build catalog with proposed infrastructure
if: ${{ github.event.pull_request.head.repo.full_name == github.repository && contains(fromJSON('["OWNER", "MEMBER", "COLLABORATOR"]'), github.event.pull_request.author_association) }}
run: node submission/scripts/build-catalog.mjs --root submission --contract-root submission --out-dir artifacts/catalog --source-commit "$MERGE_SHA"
- name: Upload catalog artifact
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02
with:
name: cookbook-catalog-${{ github.event.pull_request.number }}
path: artifacts/catalog
retention-days: 3
if-no-files-found: error