diff --git a/.github/CONTRIBUTING.md b/.github/CONTRIBUTING.md index 9759964..b7b730b 100644 --- a/.github/CONTRIBUTING.md +++ b/.github/CONTRIBUTING.md @@ -147,6 +147,19 @@ default tmux server or sweep another port's temporary files. Record the actual tmux version when behavior depends on it. A passing subset does not establish support for an entire version range. +## Documentation publisher updates + +[`renovate.json`](../renovate.json) groups the docs checkout and reusable +publisher in one update. Enable Renovate for this repository to open those +pull requests. Both references remain full commit hashes; their `# main` +comments tell Renovate which branch to check for updates. + +Review the selected `libtmux/docs` revision before authorizing it in the +publisher's IAM trust policy. Automatic merging is disabled. The ordinary +workflow tests reject different build and publisher pins, and the docs +workflow validates the generated artifact before publication. A new pin +cannot publish until its exact workflow revision is approved in IAM. + ## Pull requests Keep one subject per pull request and one logical change per commit. Review diff --git a/.github/workflows/docs.yml b/.github/workflows/docs.yml index f6abe6d..597ae8f 100644 --- a/.github/workflows/docs.yml +++ b/.github/workflows/docs.yml @@ -219,7 +219,7 @@ jobs: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: repository: libtmux/docs - ref: 99532a7ec07ae3af3ef399941e81a1d6424720cb + ref: bc037e77a78977a32de7a18890dcaed2188826e1 # main path: docs persist-credentials: false @@ -309,7 +309,7 @@ jobs: permissions: contents: read id-token: write - uses: libtmux/docs/.github/workflows/reusable-deploy.yml@99532a7ec07ae3af3ef399941e81a1d6424720cb + uses: libtmux/docs/.github/workflows/reusable-deploy.yml@bc037e77a78977a32de7a18890dcaed2188826e1 # main with: path-prefix: ruby/${{ matrix.version }} artifact: docs-ruby-${{ matrix.version }} diff --git a/renovate.json b/renovate.json new file mode 100644 index 0000000..08bc5a6 --- /dev/null +++ b/renovate.json @@ -0,0 +1,28 @@ +{ + "$schema": "https://docs.renovatebot.com/renovate-schema.json", + "extends": ["config:recommended", "helpers:pinGitHubActionDigests"], + "enabledManagers": ["github-actions", "custom.regex"], + "dependencyDashboard": false, + "automerge": false, + "customManagers": [ + { + "customType": "regex", + "description": "Keep the docs checkout and reusable publisher on the same commit.", + "managerFilePatterns": ["/^\\.github/workflows/[^/]+\\.ya?ml$/"], + "matchStrings": [ + "repository: libtmux/docs\\s+ref: (?[a-f0-9]{40}) # (?main)" + ], + "depNameTemplate": "libtmux/docs", + "datasourceTemplate": "github-digest", + "versioningTemplate": "exact" + } + ], + "packageRules": [ + { + "matchPackageNames": ["libtmux/docs"], + "groupName": "docs publisher", + "groupSlug": "docs-publisher", + "automerge": false + } + ] +}