From 25686c94f8eef6777faa6392d09d29902ecf2450 Mon Sep 17 00:00:00 2001 From: Matthias Dellweg Date: Thu, 24 Sep 2026 15:40:38 +0200 Subject: [PATCH 1/2] Update cookiecutter templates to remove RELEASE_TOKEN Also consolidate all checkouts of the repository into the same subdirectory. --- cookiecutter/ci/templates/macros | 26 +++++++- .../.ci/scripts/release.sh | 2 +- .../.github/workflows/build.yml | 8 ++- .../.github/workflows/codeql.yml | 7 ++- .../.github/workflows/collect_changes.yml | 26 +++----- .../.github/workflows/cookiecutter.yml | 60 +++---------------- .../.github/workflows/lint.yml | 4 ++ .../.github/workflows/nightly.yml | 6 +- .../.github/workflows/pr.yml | 7 ++- .../.github/workflows/pr_checks.yml | 10 +++- .../.github/workflows/publish.yml | 6 +- .../.github/workflows/release.yml | 14 +++-- .../.github/workflows/release_branch.yml | 37 ++++-------- .../.github/workflows/test.yml | 8 ++- 14 files changed, 102 insertions(+), 119 deletions(-) diff --git a/cookiecutter/ci/templates/macros b/cookiecutter/ci/templates/macros index b951972b5..ae3b5feb6 100644 --- a/cookiecutter/ci/templates/macros +++ b/cookiecutter/ci/templates/macros @@ -9,10 +9,11 @@ concurrency: {%- macro checkout(deep=false) -%} - name: "Checkout" uses: "actions/checkout@v6" - {%- if deep %} with: + path: "pulp-cli{{ cookiecutter.__app_label_suffix }}" + {%- if deep %} fetch-depth: 0 - {%- endif %} + {%- endif %} {%- endmacro -%} {%- macro download_wheels() -%} @@ -43,3 +44,24 @@ concurrency: git config user.name pulpbot git config user.email pulp-infra@redhat.com {%- endmacro -%} + +{%- macro create_pr(branch, title) -%} +- name: "Create Pull Request" + uses: "peter-evans/create-pull-request@v8" + id: "create_pr" + with: + title: "{{ title }}" + body: "" + branch: "{{ branch }}" + delete-branch: true + path: "pulp-cli{{ cookiecutter.__app_label_suffix }}" +{%- raw %} +- name: "Mark PR automerge" + run: | + gh pr merge --rebase --auto "${{ steps.create_pr.outputs.pull-request-number }}" + if: "steps.create_pr.outputs.pull-request-number" + env: + GH_TOKEN: "${{ secrets.GITHUB_TOKEN }}" + continue-on-error: true +{%- endraw %} +{%- endmacro -%} diff --git a/cookiecutter/ci/{{ cookiecutter.__project_name }}/.ci/scripts/release.sh b/cookiecutter/ci/{{ cookiecutter.__project_name }}/.ci/scripts/release.sh index a9c3644a9..41d26774f 100755 --- a/cookiecutter/ci/{{ cookiecutter.__project_name }}/.ci/scripts/release.sh +++ b/cookiecutter/ci/{{ cookiecutter.__project_name }}/.ci/scripts/release.sh @@ -23,4 +23,4 @@ towncrier build --yes --version "${NEW_VERSION}" bump-my-version bump release --commit --message "Release {new_version}" --tag --tag-name "{new_version}" --tag-message "Release {new_version}" --allow-dirty bump-my-version bump patch --commit -git push origin "${BRANCH}" "${NEW_VERSION}" +git push --atomic origin "${BRANCH}" "${NEW_VERSION}" diff --git a/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/build.yml b/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/build.yml index 310c1a8d7..930bfeee0 100644 --- a/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/build.yml +++ b/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/build.yml @@ -5,6 +5,10 @@ name: "Build" on: workflow_call: +defaults: + run: + working-directory: "pulp-cli{{ cookiecutter.__app_label_suffix }}" + jobs: build: runs-on: "ubuntu-latest" @@ -21,8 +25,8 @@ jobs: with: name: "pulp_cli_packages" path: | - .root - dist/ + pulp-cli{{ cookiecutter.__app_label_suffix }}/.root + pulp-cli{{ cookiecutter.__app_label_suffix }}/dist/ if-no-files-found: "error" retention-days: 5 ... diff --git a/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/codeql.yml b/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/codeql.yml index 08b77fe2c..0dd24bef1 100644 --- a/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/codeql.yml +++ b/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/codeql.yml @@ -3,11 +3,12 @@ name: "CodeQL" on: - push: - branches: - - "main" workflow_call: +defaults: + run: + working-directory: "pulp-cli{{ cookiecutter.__app_label_suffix }}" + jobs: analyze: name: "Analyze" diff --git a/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/collect_changes.yml b/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/collect_changes.yml index 93f2b8d5a..f3452ccfd 100644 --- a/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/collect_changes.yml +++ b/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/collect_changes.yml @@ -5,8 +5,15 @@ on: workflow_call: workflow_dispatch: +defaults: + run: + working-directory: "pulp-cli{{ cookiecutter.__app_label_suffix }}" + jobs: collect-changes: + permissions: + contents: "write" + pull-requests: "write" runs-on: "ubuntu-latest" steps: {{ macros.checkout(deep=true) | indent(6) }} @@ -16,22 +23,5 @@ jobs: - name: "Collect changes" run: | uv run --script .ci/scripts/collect_changes.py - {%- raw %} - - name: "Create Pull Request" - uses: "peter-evans/create-pull-request@v8" - id: "create_pr" - with: - token: "${{ secrets.RELEASE_TOKEN }}" - title: "Update Changelog" - body: "" - branch: "update_changes" - delete-branch: true - - name: "Mark PR automerge" - run: | - gh pr merge --rebase --auto "${{ steps.create_pr.outputs.pull-request-number }}" - if: "steps.create_pr.outputs.pull-request-number" - env: - GH_TOKEN: "${{ secrets.RELEASE_TOKEN }}" - continue-on-error: true - {%- endraw %} + {{ macros.create_pr("update_changes", "Update Changelog") | indent(6) }} ... diff --git a/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/cookiecutter.yml b/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/cookiecutter.yml index ea68f9d44..f61be06ec 100644 --- a/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/cookiecutter.yml +++ b/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/cookiecutter.yml @@ -12,18 +12,16 @@ defaults: jobs: update-ci: + permissions: + contents: "write" + pull-requests: "write" runs-on: "ubuntu-latest" steps: - uses: "actions/checkout@v6" with: repository: "pulp/pulp-cli" path: "pulp-cli" - - uses: "actions/checkout@v6" - with: - {%- raw %} - token: "${{ secrets.RELEASE_TOKEN }}" - {%- endraw %} - path: "pulp-cli{{ cookiecutter.__app_label_suffix }}" + {{ macros.checkout() | indent(6) }} {{ macros.setup_python() | indent(6) }} {{ macros.install_uv() | indent(6) }} {{ macros.setup_git() | indent(6) }} @@ -35,29 +33,12 @@ jobs: git add . git commit -m "Update cookiecutter" fi - - name: "Create Pull Request" - uses: "peter-evans/create-pull-request@v8" - id: "create_pr" - with: - {%- raw %} - token: "${{ secrets.RELEASE_TOKEN }}" - {%- endraw %} - title: "Update cookiecutter" - body: "" - branch: "update_cookiecutter" - delete-branch: true - path: "pulp-cli{{ cookiecutter.__app_label_suffix }}" - {%- raw %} - - name: "Mark PR automerge" - run: | - gh pr merge --rebase --auto "${{ steps.create_pr.outputs.pull-request-number }}" - if: "steps.create_pr.outputs.pull-request-number" - env: - GH_TOKEN: "${{ secrets.RELEASE_TOKEN }}" - continue-on-error: true - {%- endraw %} + {{ macros.create_pr("update_cookiecutter", "Update cookiecutter") | indent(6) }} {%- if cookiecutter.app_label %} update-dependencies: + permissions: + contents: "write" + pull-requests: "write" runs-on: "ubuntu-latest" steps: - uses: "actions/checkout@v6" @@ -66,9 +47,6 @@ jobs: path: "pulp-cli" - uses: "actions/checkout@v6" with: - {%- raw %} - token: "${{ secrets.RELEASE_TOKEN }}" - {%- endraw %} path: "pulp-cli{{ cookiecutter.__app_label_suffix }}" {{ macros.setup_python() | indent(6) }} {{ macros.install_uv() | indent(6) }} @@ -81,26 +59,6 @@ jobs: git add . git commit -m "Update CLI and GLUE" fi - - name: "Create Pull Request" - uses: "peter-evans/create-pull-request@v8" - id: "create_pr" - with: - {%- raw %} - token: "${{ secrets.RELEASE_TOKEN }}" - {%- endraw %} - title: "Update CLI and GLUE" - body: "" - branch: "update_cli" - delete-branch: true - path: "pulp-cli{{ cookiecutter.__app_label_suffix }}" - {%- raw %} - - name: "Mark PR automerge" - run: | - gh pr merge --rebase --auto "${{ steps.create_pr.outputs.pull-request-number }}" - if: "steps.create_pr.outputs.pull-request-number" - env: - GH_TOKEN: "${{ secrets.RELEASE_TOKEN }}" - continue-on-error: true - {%- endraw %} + {{ macros.create_pr("update_cli", "Update CLI and GLUE") | indent(6) }} {%- endif %} ... diff --git a/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/lint.yml b/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/lint.yml index 30c85e8bc..37633416d 100644 --- a/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/lint.yml +++ b/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/lint.yml @@ -5,6 +5,10 @@ name: "Lint" on: workflow_call: +defaults: + run: + working-directory: "pulp-cli{{ cookiecutter.__app_label_suffix }}" + jobs: lint: runs-on: "ubuntu-latest" diff --git a/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/nightly.yml b/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/nightly.yml index cf39225a1..6c7d01800 100644 --- a/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/nightly.yml +++ b/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/nightly.yml @@ -1,5 +1,5 @@ --- -name: "pulp-cli Nightly" +name: "Nightly" on: schedule: @@ -14,6 +14,10 @@ jobs: - "build" uses: "./.github/workflows/test.yml" codeql: + permissions: + actions: "read" + contents: "read" + security-events: "write" uses: "./.github/workflows/codeql.yml" collect_changes: uses: "./.github/workflows/collect_changes.yml" diff --git a/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/pr.yml b/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/pr.yml index 35281832b..a139e5ddd 100644 --- a/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/pr.yml +++ b/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/pr.yml @@ -1,6 +1,6 @@ {%- import 'macros' as macros with context -%} --- -name: "pulp-cli CI" +name: "Pull Request" on: pull_request: @@ -30,6 +30,10 @@ jobs: codeql: needs: - "lint" + permissions: + actions: "read" + contents: "read" + security-events: "write" uses: "./.github/workflows/codeql.yml" check-commits: runs-on: "ubuntu-latest" @@ -53,6 +57,7 @@ jobs: fi done shell: "bash" + working-directory: "pulp-cli{{ cookiecutter.__app_label_suffix }}" ready-to-ship: # This is a dummy dependent task to have a single entry for the branch protection rules. runs-on: "ubuntu-latest" diff --git a/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/pr_checks.yml b/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/pr_checks.yml index 718c7eb37..5d386c6f2 100644 --- a/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/pr_checks.yml +++ b/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/pr_checks.yml @@ -1,6 +1,6 @@ {%- import 'macros' as macros with context -%} --- -name: "Pulp CLI PR static checks" +name: "PR static checks" on: pull_request_target: types: ["opened", "synchronize", "reopened"] @@ -15,12 +15,16 @@ concurrency: {%- endraw %} cancel-in-progress: true +defaults: + run: + working-directory: "pulp-cli{{ cookiecutter.__app_label_suffix }}" + jobs: apply_labels: - runs-on: "ubuntu-latest" - name: "Label PR" permissions: pull-requests: "write" + runs-on: "ubuntu-latest" + name: "Label PR" steps: {{ macros.checkout(deep=true) | indent(6) }} {{ macros.setup_python() | indent(6) }} diff --git a/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/publish.yml b/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/publish.yml index 7a02da183..f5575ff4d 100644 --- a/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/publish.yml +++ b/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/publish.yml @@ -1,6 +1,6 @@ {%- import 'macros' as macros with context -%} --- -name: "pulp-cli Publish" +name: "Publish" on: push: @@ -10,11 +10,13 @@ on: jobs: build: uses: "./.github/workflows/build.yml" - environment: "pypi" publish-pypi: name: "Publish to PyPI" needs: "build" runs-on: "ubuntu-latest" + environment: + name: "pypi" + url: "https://pypi.org/p/pulp-cli{{ cookiecutter.__app_label_suffix }}" steps: {{ macros.download_wheels() | indent(6) }} {{ macros.install_uv() | indent(6) }} diff --git a/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/release.yml b/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/release.yml index a0fe39837..f5eacc2b4 100644 --- a/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/release.yml +++ b/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/release.yml @@ -1,20 +1,22 @@ {%- import 'macros' as macros with context -%} --- -name: "pulp-cli Release" +name: "Tag Release" on: workflow_dispatch: +defaults: + run: + working-directory: "pulp-cli{{ cookiecutter.__app_label_suffix }}" + jobs: release: name: "Release" + permissions: + contents: "write" runs-on: "ubuntu-latest" steps: - - uses: "actions/checkout@v6" - with: - {%- raw %} - token: "${{ secrets.RELEASE_TOKEN }}" - {%- endraw %} + {{ macros.checkout() | indent(6) }} {{ macros.setup_python() | indent(6) }} {{ macros.install_uv() | indent(6) }} {{ macros.setup_git() | indent(6) }} diff --git a/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/release_branch.yml b/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/release_branch.yml index 7bc27a416..d7c36ab2c 100644 --- a/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/release_branch.yml +++ b/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/release_branch.yml @@ -4,43 +4,26 @@ name: "Create Release Branch" on: workflow_dispatch: +defaults: + run: + working-directory: "pulp-cli{{ cookiecutter.__app_label_suffix }}" + jobs: create-release-branch: + permissions: + contents: "write" + issues: "write" + pull-requests: "write" runs-on: "ubuntu-latest" steps: - - uses: "actions/checkout@v6" - with: - {%- raw %} - token: "${{ secrets.RELEASE_TOKEN }}" - {%- endraw %} + {{ macros.checkout() | indent(6) }} {{ macros.setup_python() | indent(6) }} {{ macros.install_uv() | indent(6) }} {{ macros.setup_git() | indent(6) }} - name: "Create Release Branch" run: | uv run --with bump-my-version~=0.20.0 .ci/scripts/create_release_branch.sh - - name: "Create Pull Request" - uses: "peter-evans/create-pull-request@v8" - id: "create_pr" - with: - {%- raw %} - token: "${{ secrets.RELEASE_TOKEN }}" - title: "Bump dev-version" - body: "" - branch: "bump_version" - delete-branch: true - {%- endraw %} - - name: "Mark PR automerge" - run: | - {%- raw %} - gh pr merge --rebase --auto "${{ steps.create_pr.outputs.pull-request-number }}" - {%- endraw %} - if: "steps.create_pr.outputs.pull-request-number" - env: - {%- raw %} - GH_TOKEN: "${{ secrets.RELEASE_TOKEN }}" - {%- endraw %} - continue-on-error: true + {{ macros.create_pr("bump_version", "Bump dev-version") | indent(6) }} - name: "Add Backport Label for new Branch" uses: "actions/github-script@v8" with: diff --git a/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/test.yml b/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/test.yml index ae13144e7..a08114cc7 100644 --- a/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/test.yml +++ b/cookiecutter/ci/{{ cookiecutter.__project_name }}/.github/workflows/test.yml @@ -5,6 +5,10 @@ name: "Test" on: workflow_call: +defaults: + run: + working-directory: "pulp-cli{{ cookiecutter.__app_label_suffix }}" + env: COLORTERM: "yes" TERM: "xterm-256color" @@ -22,7 +26,7 @@ jobs: {{ macros.install_uv() | indent(6) }} - name: "Run tests" run: | - uv run --isolated --with dist/pulp_glue*.whl --with dist/pulp_cli*.whl --only-group test make _unittest + uv run --isolated --with ../dist/pulp_glue*.whl --with ../dist/pulp_cli*.whl --only-group test make _unittest {%- endif %} test: runs-on: "ubuntu-24.04" @@ -70,5 +74,5 @@ jobs: fi {%- endraw %} - uv run "${RESOLUTION[@]}" --isolated --with dist/pulp_glue*.whl --with dist/pulp_cli*.whl --only-group test .ci/run_container.sh make _{% if cookiecutter.paralleltests %}parallel{% elif cookiecutter.unittests %}live{% endif %}test + uv run "${RESOLUTION[@]}" --isolated --with ../dist/pulp_glue*.whl --with ../dist/pulp_cli*.whl --only-group test .ci/run_container.sh make _{% if cookiecutter.paralleltests %}parallel{% elif cookiecutter.unittests %}live{% endif %}test ... From e30df91075fc98623e95383490a921968e37541d Mon Sep 17 00:00:00 2001 From: Matthias Dellweg Date: Thu, 24 Sep 2026 15:40:57 +0200 Subject: [PATCH 2/2] Apply cookiecutter --- .ci/scripts/release.sh | 2 +- .github/workflows/build.yml | 10 ++++++++-- .github/workflows/codeql.yml | 9 ++++++--- .github/workflows/collect_changes.yml | 12 ++++++++++-- .github/workflows/cookiecutter.yml | 10 ++++++---- .github/workflows/lint.yml | 6 ++++++ .github/workflows/nightly.yml | 6 +++++- .github/workflows/pr.yml | 8 +++++++- .github/workflows/pr_checks.yml | 11 ++++++++--- .github/workflows/publish.yml | 6 ++++-- .github/workflows/release.yml | 13 ++++++++++--- .github/workflows/release_branch.yml | 17 +++++++++++++---- .github/workflows/test.yml | 12 ++++++++++-- 13 files changed, 94 insertions(+), 28 deletions(-) diff --git a/.ci/scripts/release.sh b/.ci/scripts/release.sh index a9c3644a9..41d26774f 100755 --- a/.ci/scripts/release.sh +++ b/.ci/scripts/release.sh @@ -23,4 +23,4 @@ towncrier build --yes --version "${NEW_VERSION}" bump-my-version bump release --commit --message "Release {new_version}" --tag --tag-name "{new_version}" --tag-message "Release {new_version}" --allow-dirty bump-my-version bump patch --commit -git push origin "${BRANCH}" "${NEW_VERSION}" +git push --atomic origin "${BRANCH}" "${NEW_VERSION}" diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index d7c6a4ba7..b94a8d25a 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -4,12 +4,18 @@ name: "Build" on: workflow_call: +defaults: + run: + working-directory: "pulp-cli" + jobs: build: runs-on: "ubuntu-latest" steps: - name: "Checkout" uses: "actions/checkout@v6" + with: + path: "pulp-cli" - name: "Set up Python" uses: "actions/setup-python@v6" with: @@ -28,8 +34,8 @@ jobs: with: name: "pulp_cli_packages" path: | - .root - dist/ + pulp-cli/.root + pulp-cli/dist/ if-no-files-found: "error" retention-days: 5 ... diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index facb1a8ff..129485d1e 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -2,11 +2,12 @@ name: "CodeQL" on: - push: - branches: - - "main" workflow_call: +defaults: + run: + working-directory: "pulp-cli" + jobs: analyze: name: "Analyze" @@ -19,6 +20,8 @@ jobs: steps: - name: "Checkout" uses: "actions/checkout@v6" + with: + path: "pulp-cli" - name: "Initialize CodeQL" uses: "github/codeql-action/init@v4" with: diff --git a/.github/workflows/collect_changes.yml b/.github/workflows/collect_changes.yml index 5e08242e6..7f8571ce9 100644 --- a/.github/workflows/collect_changes.yml +++ b/.github/workflows/collect_changes.yml @@ -4,13 +4,21 @@ on: workflow_call: workflow_dispatch: +defaults: + run: + working-directory: "pulp-cli" + jobs: collect-changes: + permissions: + contents: "write" + pull-requests: "write" runs-on: "ubuntu-latest" steps: - name: "Checkout" uses: "actions/checkout@v6" with: + path: "pulp-cli" fetch-depth: 0 - name: "Set up Python" uses: "actions/setup-python@v6" @@ -32,16 +40,16 @@ jobs: uses: "peter-evans/create-pull-request@v8" id: "create_pr" with: - token: "${{ secrets.RELEASE_TOKEN }}" title: "Update Changelog" body: "" branch: "update_changes" delete-branch: true + path: "pulp-cli" - name: "Mark PR automerge" run: | gh pr merge --rebase --auto "${{ steps.create_pr.outputs.pull-request-number }}" if: "steps.create_pr.outputs.pull-request-number" env: - GH_TOKEN: "${{ secrets.RELEASE_TOKEN }}" + GH_TOKEN: "${{ secrets.GITHUB_TOKEN }}" continue-on-error: true ... diff --git a/.github/workflows/cookiecutter.yml b/.github/workflows/cookiecutter.yml index 64dd8e1df..fa150df2d 100644 --- a/.github/workflows/cookiecutter.yml +++ b/.github/workflows/cookiecutter.yml @@ -11,15 +11,18 @@ defaults: jobs: update-ci: + permissions: + contents: "write" + pull-requests: "write" runs-on: "ubuntu-latest" steps: - uses: "actions/checkout@v6" with: repository: "pulp/pulp-cli" path: "pulp-cli" - - uses: "actions/checkout@v6" + - name: "Checkout" + uses: "actions/checkout@v6" with: - token: "${{ secrets.RELEASE_TOKEN }}" path: "pulp-cli" - name: "Set up Python" uses: "actions/setup-python@v6" @@ -46,7 +49,6 @@ jobs: uses: "peter-evans/create-pull-request@v8" id: "create_pr" with: - token: "${{ secrets.RELEASE_TOKEN }}" title: "Update cookiecutter" body: "" branch: "update_cookiecutter" @@ -57,6 +59,6 @@ jobs: gh pr merge --rebase --auto "${{ steps.create_pr.outputs.pull-request-number }}" if: "steps.create_pr.outputs.pull-request-number" env: - GH_TOKEN: "${{ secrets.RELEASE_TOKEN }}" + GH_TOKEN: "${{ secrets.GITHUB_TOKEN }}" continue-on-error: true ... diff --git a/.github/workflows/lint.yml b/.github/workflows/lint.yml index fee95cdb1..e21a5df2d 100644 --- a/.github/workflows/lint.yml +++ b/.github/workflows/lint.yml @@ -4,6 +4,10 @@ name: "Lint" on: workflow_call: +defaults: + run: + working-directory: "pulp-cli" + jobs: lint: runs-on: "ubuntu-latest" @@ -16,6 +20,8 @@ jobs: steps: - name: "Checkout" uses: "actions/checkout@v6" + with: + path: "pulp-cli" - name: "Set up Python" uses: "actions/setup-python@v6" with: diff --git a/.github/workflows/nightly.yml b/.github/workflows/nightly.yml index cf39225a1..6c7d01800 100644 --- a/.github/workflows/nightly.yml +++ b/.github/workflows/nightly.yml @@ -1,5 +1,5 @@ --- -name: "pulp-cli Nightly" +name: "Nightly" on: schedule: @@ -14,6 +14,10 @@ jobs: - "build" uses: "./.github/workflows/test.yml" codeql: + permissions: + actions: "read" + contents: "read" + security-events: "write" uses: "./.github/workflows/codeql.yml" collect_changes: uses: "./.github/workflows/collect_changes.yml" diff --git a/.github/workflows/pr.yml b/.github/workflows/pr.yml index 742e2457f..209eb8f55 100644 --- a/.github/workflows/pr.yml +++ b/.github/workflows/pr.yml @@ -1,5 +1,5 @@ --- -name: "pulp-cli CI" +name: "Pull Request" on: pull_request: @@ -29,6 +29,10 @@ jobs: codeql: needs: - "lint" + permissions: + actions: "read" + contents: "read" + security-events: "write" uses: "./.github/workflows/codeql.yml" check-commits: runs-on: "ubuntu-latest" @@ -36,6 +40,7 @@ jobs: - name: "Checkout" uses: "actions/checkout@v6" with: + path: "pulp-cli" fetch-depth: 0 - name: "Set up Python" uses: "actions/setup-python@v6" @@ -60,6 +65,7 @@ jobs: fi done shell: "bash" + working-directory: "pulp-cli" ready-to-ship: # This is a dummy dependent task to have a single entry for the branch protection rules. runs-on: "ubuntu-latest" diff --git a/.github/workflows/pr_checks.yml b/.github/workflows/pr_checks.yml index c0317567f..f2d8d1c63 100644 --- a/.github/workflows/pr_checks.yml +++ b/.github/workflows/pr_checks.yml @@ -1,5 +1,5 @@ --- -name: "Pulp CLI PR static checks" +name: "PR static checks" on: pull_request_target: types: ["opened", "synchronize", "reopened"] @@ -12,16 +12,21 @@ concurrency: group: "${{ github.event.pull_request.number }}-${{ github.workflow }}" cancel-in-progress: true +defaults: + run: + working-directory: "pulp-cli" + jobs: apply_labels: - runs-on: "ubuntu-latest" - name: "Label PR" permissions: pull-requests: "write" + runs-on: "ubuntu-latest" + name: "Label PR" steps: - name: "Checkout" uses: "actions/checkout@v6" with: + path: "pulp-cli" fetch-depth: 0 - name: "Set up Python" uses: "actions/setup-python@v6" diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 04fd8ace7..9307abaed 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -1,5 +1,5 @@ --- -name: "pulp-cli Publish" +name: "Publish" on: push: @@ -9,11 +9,13 @@ on: jobs: build: uses: "./.github/workflows/build.yml" - environment: "pypi" publish-pypi: name: "Publish to PyPI" needs: "build" runs-on: "ubuntu-latest" + environment: + name: "pypi" + url: "https://pypi.org/p/pulp-cli" steps: - name: "Download wheels" uses: "actions/download-artifact@v8" diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index bda570851..97ecbb715 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -1,17 +1,24 @@ --- -name: "pulp-cli Release" +name: "Tag Release" on: workflow_dispatch: +defaults: + run: + working-directory: "pulp-cli" + jobs: release: name: "Release" + permissions: + contents: "write" runs-on: "ubuntu-latest" steps: - - uses: "actions/checkout@v6" + - name: "Checkout" + uses: "actions/checkout@v6" with: - token: "${{ secrets.RELEASE_TOKEN }}" + path: "pulp-cli" - name: "Set up Python" uses: "actions/setup-python@v6" with: diff --git a/.github/workflows/release_branch.yml b/.github/workflows/release_branch.yml index f20a5ef3e..8a51fcf3c 100644 --- a/.github/workflows/release_branch.yml +++ b/.github/workflows/release_branch.yml @@ -3,13 +3,22 @@ name: "Create Release Branch" on: workflow_dispatch: +defaults: + run: + working-directory: "pulp-cli" + jobs: create-release-branch: + permissions: + contents: "write" + issues: "write" + pull-requests: "write" runs-on: "ubuntu-latest" steps: - - uses: "actions/checkout@v6" + - name: "Checkout" + uses: "actions/checkout@v6" with: - token: "${{ secrets.RELEASE_TOKEN }}" + path: "pulp-cli" - name: "Set up Python" uses: "actions/setup-python@v6" with: @@ -30,17 +39,17 @@ jobs: uses: "peter-evans/create-pull-request@v8" id: "create_pr" with: - token: "${{ secrets.RELEASE_TOKEN }}" title: "Bump dev-version" body: "" branch: "bump_version" delete-branch: true + path: "pulp-cli" - name: "Mark PR automerge" run: | gh pr merge --rebase --auto "${{ steps.create_pr.outputs.pull-request-number }}" if: "steps.create_pr.outputs.pull-request-number" env: - GH_TOKEN: "${{ secrets.RELEASE_TOKEN }}" + GH_TOKEN: "${{ secrets.GITHUB_TOKEN }}" continue-on-error: true - name: "Add Backport Label for new Branch" uses: "actions/github-script@v8" diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 7b7d697e1..240ddb34c 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -4,6 +4,10 @@ name: "Test" on: workflow_call: +defaults: + run: + working-directory: "pulp-cli" + env: COLORTERM: "yes" TERM: "xterm-256color" @@ -16,6 +20,8 @@ jobs: steps: - name: "Checkout" uses: "actions/checkout@v6" + with: + path: "pulp-cli" - name: "Download wheels" uses: "actions/download-artifact@v8" with: @@ -31,7 +37,7 @@ jobs: enable-cache: true - name: "Run tests" run: | - uv run --isolated --with dist/pulp_glue*.whl --with dist/pulp_cli*.whl --only-group test make _unittest + uv run --isolated --with ../dist/pulp_glue*.whl --with ../dist/pulp_cli*.whl --only-group test make _unittest test: runs-on: "ubuntu-24.04" needs: @@ -69,6 +75,8 @@ jobs: steps: - name: "Checkout" uses: "actions/checkout@v6" + with: + path: "pulp-cli" - name: "Download wheels" uses: "actions/download-artifact@v8" with: @@ -105,5 +113,5 @@ jobs: RESOLUTION=() fi - uv run "${RESOLUTION[@]}" --isolated --with dist/pulp_glue*.whl --with dist/pulp_cli*.whl --only-group test .ci/run_container.sh make _paralleltest + uv run "${RESOLUTION[@]}" --isolated --with ../dist/pulp_glue*.whl --with ../dist/pulp_cli*.whl --only-group test .ci/run_container.sh make _paralleltest ...