diff --git a/.github/workflows/dependabot-bun-lock.yml b/.github/workflows/dependabot-bun-lock.yml new file mode 100644 index 0000000..bb13ea7 --- /dev/null +++ b/.github/workflows/dependabot-bun-lock.yml @@ -0,0 +1,60 @@ +name: dependabot bun.lock + +# Dependabot's npm updater rewrites package.json and package-lock.json but never bun.lock, so `bun install +# --frozen-lockfile` in ci.yml fails on every npm bump before a test runs. This refreshes bun.lock on Dependabot's +# branches and re-runs CI on the new commit (a commit pushed with GITHUB_TOKEN starts no workflow by itself). + +on: + push: + branches: ["dependabot/npm_and_yarn/**"] + +permissions: + contents: read + +jobs: + refresh: + name: refresh bun.lock + if: github.actor == 'dependabot[bot]' + runs-on: ubuntu-latest + timeout-minutes: 10 + # Job-level, so a skipped run from someone else's push cannot cancel a refresh between its push and the CI dispatch. + concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true + permissions: + contents: write + actions: write + steps: + - name: Checkout + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + with: + persist-credentials: false + + - name: Setup Bun + uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2.2.0 + with: + bun-version: 1.4.2 + + # Pinned by SHA and run without dependency lifecycle scripts: this job holds a write token. + - name: Refresh bun.lock + run: bun install --ignore-scripts + + - name: Commit and re-run CI + env: + GH_TOKEN: ${{ github.token }} + BRANCH: ${{ github.ref_name }} + run: | + if git diff --quiet -- bun.lock; then + echo "bun.lock is already current" + exit 0 + fi + if [ -n "$(git status --porcelain -- . ':!bun.lock')" ]; then + git status --porcelain + echo "::error::bun install changed files other than bun.lock; not committing" + exit 1 + fi + git config user.name "github-actions[bot]" + git config user.email "41898282+github-actions[bot]@users.noreply.github.com" + git commit -m "build(deps): refresh bun.lock" -- bun.lock + git push "https://x-access-token:${GH_TOKEN}@github.com/${GITHUB_REPOSITORY}.git" "HEAD:refs/heads/${BRANCH}" + gh workflow run ci.yml --ref "$BRANCH"