-
-
Notifications
You must be signed in to change notification settings - Fork 20
53 lines (44 loc) · 1.94 KB
/
Copy pathpre-commit-autoupdate.yml
File metadata and controls
53 lines (44 loc) · 1.94 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
name: 'Linuxfabrik: Update pre-commit hooks'
on:
schedule:
- cron: '0 5 * * 5'
workflow_dispatch: {}
permissions: 'read-all'
jobs:
update:
runs-on: 'ubuntu-latest'
steps:
- name: 'Harden the runner (Audit all outbound calls)'
uses: 'step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40' # v2.20.1
with:
egress-policy: 'audit'
# The pull request is created with the automation app's token, not with
# GITHUB_TOKEN. GitHub does not run workflows on a pull request that
# GITHUB_TOKEN opened, so the checks required by the branch ruleset would
# never report and the pull request would sit blocked forever.
- name: 'Generate app token'
id: 'app-token'
uses: 'actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1' # v3.2.0
with:
client-id: '${{ vars.LF_AUTOMATION_CLIENT_ID }}'
private-key: '${{ secrets.LF_AUTOMATION_APP_PRIVATE_KEY }}'
- name: 'Checkout repository'
uses: 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1' # v7.0.1
with:
token: '${{ steps.app-token.outputs.token }}'
- name: 'Set up Python'
uses: 'actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97' # v7.0.0
with:
python-version: '3.12'
- name: 'Install pre-commit'
run: 'pip install --require-hashes --requirement .github/pre-commit/requirements.txt'
- name: 'Run pre-commit autoupdate'
run: 'pre-commit autoupdate'
- name: 'Create Pull Request'
uses: 'peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1' # v8.1.1
with:
token: '${{ steps.app-token.outputs.token }}'
commit-message: 'chore: update pre-commit hooks'
title: 'chore: update pre-commit hooks'
body: 'Automatic pre-commit hook version update.'
branch: 'chore/pre-commit-autoupdate'