diff --git a/.github/labeler.yml b/.github/labeler.yml index 28edfa8a..91593fdb 100644 --- a/.github/labeler.yml +++ b/.github/labeler.yml @@ -1,15 +1,20 @@ data-update: -- '_data/**' +- changed-files: + - any-glob-to-any-file: '_data/**' text-update: -- '**/*.md' +- changed-files: + - any-glob-to-any-file: '**/*.md' tool-update: -- '_tools/**' +- changed-files: + - any-glob-to-any-file: '_tools/**' code-update: -- '**/*.rb' -- 'Gemfile' -- 'Rakefile' -- '_config.yml' -- '.*' +- changed-files: + - any-glob-to-any-file: + - '**/*.rb' + - 'Gemfile' + - 'Rakefile' + - '_config.yml' + - '.*' diff --git a/.github/workflows/build-ci.yml b/.github/workflows/build-ci.yml index 23daf5ec..7d7222e3 100644 --- a/.github/workflows/build-ci.yml +++ b/.github/workflows/build-ci.yml @@ -7,24 +7,24 @@ on: jobs: ci-test: name: "Root Project" - uses: hack-different/apple-knowledge/.github/workflows/build-test.yml@main + uses: ./.github/workflows/build-test.yml ci-build-jekyll: name: "Jekyll" needs: ci-test - uses: hack-different/apple-knowledge/.github/workflows/build-jekyll.yml@main + uses: ./.github/workflows/build-jekyll.yml ci-build-python: name: "Python" needs: ci-test - uses: hack-different/apple-knowledge/.github/workflows/build-python.yml@main + uses: ./.github/workflows/build-python.yml ci-build-ruby: name: "Ruby" needs: ci-test - uses: hack-different/apple-knowledge/.github/workflows/build-ruby.yml@main + uses: ./.github/workflows/build-ruby.yml ci-build-node: name: "Node" needs: ci-test - uses: hack-different/apple-knowledge/.github/workflows/build-node.yml@main + uses: ./.github/workflows/build-node.yml diff --git a/.github/workflows/build-jekyll.yml b/.github/workflows/build-jekyll.yml index 441f4016..bfd82859 100644 --- a/.github/workflows/build-jekyll.yml +++ b/.github/workflows/build-jekyll.yml @@ -15,18 +15,12 @@ jobs: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v3 - with: - fetch-depth: ${{ inputs.fetch-depth }} + - name: Install OS Packages + run: sudo apt-get update && sudo apt-get install -y libidn-dev cmake - - name: Cache Ruby Gems and Bundle - id: cache-gems - uses: actions/cache@v4 + - uses: actions/checkout@v5 with: - path: vendor/bundle - key: ${{ runner.os }}-build-ruby-${{ hashFiles('Gemfile.lock') }} - restore-keys: | - ${{ runner.os }}-build-ruby- + fetch-depth: ${{ inputs.fetch-depth }} - name: Setup Ruby 4.0.5 uses: ruby/setup-ruby@v1 @@ -36,9 +30,13 @@ jobs: - name: Build Jekyll Site run: bundle exec jekyll build + env: + JEKYLL_ENV: production + JEKYLL_GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - name: Archive Site Artifacts - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v5 with: name: data-ci-site path: _site + include-hidden-files: true diff --git a/.github/workflows/build-node.yml b/.github/workflows/build-node.yml index c262ecc5..48b74a11 100644 --- a/.github/workflows/build-node.yml +++ b/.github/workflows/build-node.yml @@ -19,44 +19,41 @@ jobs: matrix: node-version: ["22", "24"] + defaults: + run: + working-directory: ./_packages/node + steps: - - uses: actions/checkout@v3 + - uses: actions/checkout@v5 with: fetch-depth: ${{ inputs.fetch-depth }} - uses: oven-sh/setup-bun@v2 - - name: Cache Node Packages - id: cache-node - uses: actions/cache@v4 + - uses: actions/setup-node@v5 with: - path: _packages/node/node_modules - key: ${{ runner.os }}-build-ci-node-yarn-${{ matrix.node-version }}-${{ hashFiles('_packages/node/yarn.lock') }} + node-version: ${{ matrix.node-version }} - - uses: actions/setup-node@v3 + - name: Cache Node Packages + uses: actions/cache@v5 with: - node-version: ${{ matrix.node-version }} - cache-dependency-path: _packages/node/yarn.lock - registry-url: https://registry.npmjs.org/ + path: _packages/node/node_modules + key: ${{ runner.os }}-build-ci-node-${{ matrix.node-version }}-${{ hashFiles('_packages/node/bun.lock') }} - name: Install dependencies - working-directory: ./_packages/node run: bun install - name: Perform a Build - working-directory: ./_packages/node run: bun run build - name: Run Package Tests - working-directory: ./_packages/node run: bun run test - name: Package Node Artifact - working-directory: ./_packages/node run: bun pm pack - name: Archive Node Package Artifacts - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v5 with: name: package-node-${{ matrix.node-version }} - path: _packages/node/*.tgz \ No newline at end of file + path: _packages/node/*.tgz diff --git a/.github/workflows/build-python.yml b/.github/workflows/build-python.yml index 2bd7c086..51c430f9 100644 --- a/.github/workflows/build-python.yml +++ b/.github/workflows/build-python.yml @@ -23,12 +23,13 @@ jobs: python-version: ["3.10", "3.11", "3.12"] steps: - - uses: actions/checkout@v3 + - uses: actions/checkout@v5 with: fetch-depth: ${{ inputs.fetch-depth }} - - name: Set up Python with Poetry Caching - uses: actions/setup-python@v4 + - name: Set up Python + id: setup-python + uses: actions/setup-python@v6 with: python-version: ${{ matrix.python-version }} @@ -40,15 +41,11 @@ jobs: - name: Load cached venv id: cached-poetry-dependencies - uses: actions/cache@v4 + uses: actions/cache@v5 with: path: ./_packages/python/.venv key: venv-${{ runner.os }}-${{ steps.setup-python.outputs.python-version }}-${{ hashFiles('_packages/python/poetry.lock') }} - - name: Install dependencies - if: steps.cached-poetry-dependencies.outputs.cache-hit != 'true' - run: poetry install --no-interaction --no-root - - name: Update Version String run: python ./update_version.py @@ -62,4 +59,10 @@ jobs: run: poetry run pytest - name: Build package - run: poetry build \ No newline at end of file + run: poetry build + + - name: Archive Python Package Artifacts + uses: actions/upload-artifact@v5 + with: + name: package-python-${{ matrix.python-version }} + path: _packages/python/dist/* diff --git a/.github/workflows/build-ruby.yml b/.github/workflows/build-ruby.yml index 5e5bdda1..1157f029 100644 --- a/.github/workflows/build-ruby.yml +++ b/.github/workflows/build-ruby.yml @@ -24,17 +24,10 @@ jobs: working-directory: ./_packages/ruby steps: - - uses: actions/checkout@v3 + - uses: actions/checkout@v5 with: fetch-depth: ${{ inputs.fetch-depth }} - - name: Cache Ruby Gems and Bundle - id: cache-gems - uses: actions/cache@v4 - with: - path: _packages/ruby/vendor/bundle - key: ${{ runner.os }}-build-ci-ruby-${{ matrix.ruby-version }}-gem-${{ hashFiles('_packages/ruby/Gemfile.lock') }} - - name: Setup Ruby uses: ruby/setup-ruby@v1 with: @@ -52,7 +45,7 @@ jobs: run: gem build *.gemspec - name: Archive Gem Artifacts - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v5 with: name: package-gem-${{ matrix.ruby-version }} - path: _packages/ruby/*.gem \ No newline at end of file + path: _packages/ruby/*.gem diff --git a/.github/workflows/build-test.yml b/.github/workflows/build-test.yml index 693c3352..ae87b9ea 100644 --- a/.github/workflows/build-test.yml +++ b/.github/workflows/build-test.yml @@ -16,20 +16,13 @@ jobs: steps: - name: Install OS Packages - run: sudo apt-get install -y libidn-dev + run: sudo apt-get update && sudo apt-get install -y libidn-dev cmake - name: Checkout Repository with History - uses: actions/checkout@v3 + uses: actions/checkout@v5 with: fetch-depth: ${{ inputs.fetch-depth }} - - name: Cache Ruby Gems and Bundle - id: cache-gems - uses: actions/cache@v4 - with: - path: vendor/bundle - key: ${{ runner.os }}-build-ci-ruby-${{ hashFiles('Gemfile.lock') }} - - name: Setup Ruby 4.0.5 uses: ruby/setup-ruby@v1 with: @@ -40,7 +33,7 @@ jobs: run: bundle exec rake - name: Archive Data Artifacts - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v5 with: name: data-artifacts path: _data diff --git a/.github/workflows/label.yml b/.github/workflows/label.yml index 7fa0627f..5d3f5c34 100644 --- a/.github/workflows/label.yml +++ b/.github/workflows/label.yml @@ -11,6 +11,6 @@ jobs: pull-requests: write steps: - - uses: actions/labeler@v2 + - uses: actions/labeler@v5 with: repo-token: "${{ secrets.GITHUB_TOKEN }}" diff --git a/.github/workflows/publish-gem.yml b/.github/workflows/publish-gem.yml index fac857f7..7f56fb93 100644 --- a/.github/workflows/publish-gem.yml +++ b/.github/workflows/publish-gem.yml @@ -6,7 +6,7 @@ on: jobs: ci-build-ruby: - uses: hack-different/apple-knowledge/.github/workflows/build-ruby.yml@main + uses: ./.github/workflows/build-ruby.yml publish-gem: name: Publish to RubyGems @@ -15,7 +15,6 @@ jobs: environment: gem-push permissions: contents: read - packages: write steps: - name: Setup Ruby 4.0.5 @@ -23,7 +22,7 @@ jobs: with: ruby-version: 4.0.5 - - uses: actions/download-artifact@v4 + - uses: actions/download-artifact@v5 name: Download Ruby Package Artifacts with: name: package-gem-4.0 @@ -31,9 +30,4 @@ jobs: - name: Publish to RubyGems env: GEM_HOST_API_KEY: "${{secrets.RUBYGEMS_AUTH_TOKEN}}" - run: | - mkdir -p $HOME/.gem - touch $HOME/.gem/credentials - chmod 0600 $HOME/.gem/credentials - printf -- "---\n:rubygems_api_key: ${GEM_HOST_API_KEY}\n" > $HOME/.gem/credentials - gem push *.gem + run: gem push *.gem diff --git a/.github/workflows/publish-npm.yml b/.github/workflows/publish-npm.yml index 18cc677d..c35e71d7 100644 --- a/.github/workflows/publish-npm.yml +++ b/.github/workflows/publish-npm.yml @@ -1,6 +1,3 @@ -# This workflow will run tests using node and then publish a package to GitHub Packages when a release is created -# For more information see: https://help.github.com/actions/language-and-framework-guides/publishing-nodejs-packages - name: Publish Package - Node / NPM on: @@ -9,39 +6,32 @@ on: jobs: ci-build-node: - uses: hack-different/apple-knowledge/.github/workflows/build-node.yml@main + uses: ./.github/workflows/build-node.yml publish-npm: name: Publish to NPM runs-on: ubuntu-latest needs: ci-build-node environment: node-push + permissions: + contents: read + # Required for npm trusted publishing (OIDC) and provenance + id-token: write steps: - - uses: actions/checkout@v3 - with: - fetch-depth: 0 - - - name: Cache Node Packages - id: cache-node - uses: actions/cache@v4 - with: - path: _packages/node/node_modules - key: ${{ runner.os }}-publish-npm-${{ hashFiles('_packages/node/yarn.lock') }} - - - uses: actions/setup-node@v3 + - uses: actions/setup-node@v5 with: node-version: 24 - cache: bun registry-url: https://registry.npmjs.org/ - name: Download Node Package Artifacts - uses: actions/download-artifact@v4 + uses: actions/download-artifact@v5 with: name: package-node-24 - path: _packages/node/dist/ + path: dist - name: Publish to NPM Registry - run: yarn publish _packages/node/ + # Uses npm trusted publishing (OIDC) when configured on npmjs.com, otherwise falls back to NPM_TOKEN + run: npm publish dist/*.tgz --access public --provenance env: - NODE_AUTH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} diff --git a/.github/workflows/publish-pypi.yml b/.github/workflows/publish-pypi.yml index 635db984..03ff020d 100644 --- a/.github/workflows/publish-pypi.yml +++ b/.github/workflows/publish-pypi.yml @@ -1,11 +1,3 @@ -# This workflow will upload a Python Package using Twine when a release is created -# For more information see: https://help.github.com/en/actions/language-and-framework-guides/using-python-with-github-actions#publishing-to-package-registries - -# This workflow uses actions that are not certified by GitHub. -# They are provided by a third-party and are governed by -# separate terms of service, privacy policy, and support -# documentation. - name: Publish Package - Python / PyPI on: @@ -14,49 +6,27 @@ on: jobs: ci-build-python: - uses: hack-different/apple-knowledge/.github/workflows/build-python.yml@main + uses: ./.github/workflows/build-python.yml publish-pypi: name: Publish to PyPI runs-on: ubuntu-latest + needs: ci-build-python environment: pypi-push + permissions: + contents: read + # Required for PyPI trusted publishing (OIDC) + id-token: write steps: - - uses: actions/checkout@v3 - with: - fetch-depth: 0 - - - uses: actions/setup-python@v5 - id: setup-python - with: - python-version: '3.12' - - - name: Install Poetry - uses: snok/install-poetry@v1 - with: - virtualenvs-create: true - virtualenvs-in-project: true - installer-parallel: true - - - name: Load cached venv - id: cached-poetry-dependencies - uses: actions/cache@v4 - with: - path: .venv - key: venv-${{ runner.os }}-${{ steps.setup-python.outputs.python-version }}-${{ hashFiles('**/poetry.lock') }} - - - name: Install dependencies - if: steps.cached-poetry-dependencies.outputs.cache-hit != 'true' - run: poetry install --no-interaction --no-root - - name: Download Python Package Artifacts - uses: actions/download-artifact@v4 + uses: actions/download-artifact@v5 with: - name: package-python - path: ./_packages/python/dist/ + name: package-python-3.12 + path: dist - name: Publish to PyPI - # Note: No "password" or "api-token" secret is referenced here + # Note: No "password" or "api-token" secret is referenced here, this uses trusted publishing uses: pypa/gh-action-pypi-publish@release/v1 with: - packages-dir: ./_packages/python/dist/ \ No newline at end of file + packages-dir: dist/ diff --git a/.github/workflows/publish-site.yml b/.github/workflows/publish-site.yml index a511916f..45e1dcbe 100644 --- a/.github/workflows/publish-site.yml +++ b/.github/workflows/publish-site.yml @@ -5,34 +5,35 @@ on: branches: - main + workflow_dispatch: + +concurrency: + group: publish-site + cancel-in-progress: false + jobs: + ci-build-jekyll: + uses: ./.github/workflows/build-jekyll.yml + github-pages: name: Publish Static Website runs-on: ubuntu-latest + needs: ci-build-jekyll environment: gh-pages - steps: - - name: Install Dependencies - run: sudo apt install libidn-dev - - - uses: actions/checkout@v3 + permissions: + contents: write - - id: gem-cache - uses: actions/cache@v4 - with: - path: vendor/bundle - key: ${{ runner.os }}-gems-${{ hashFiles('Gemfile.lock') }} - restore-keys: | - ${{ runner.os }}-gems- - - - uses: hack-different/jekyll-action@master + steps: + - name: Download Site Artifacts + uses: actions/download-artifact@v5 with: - token: ${{ secrets.GITHUB_TOKEN }} - debug: true - target_branch: gh-pages - target_path: / + name: data-ci-site + path: _site - - name: Archive Data Artifacts - uses: actions/upload-artifact@v4 + - name: Publish to gh-pages Branch + uses: peaceiris/actions-gh-pages@v4 with: - name: data-site - path: _site + github_token: ${{ secrets.GITHUB_TOKEN }} + publish_branch: gh-pages + publish_dir: ./_site + cname: docs.hackdiffe.rent diff --git a/.github/workflows/update.yml b/.github/workflows/update.yml index 3b4ba6d9..a9046026 100644 --- a/.github/workflows/update.yml +++ b/.github/workflows/update.yml @@ -2,7 +2,7 @@ name: Periodic Updates on: schedule: - - cron: '* 8 * * *' + - cron: '17 8 * * *' workflow_dispatch: inputs: @@ -11,41 +11,43 @@ on: required: false type: string +concurrency: + group: periodic-update + cancel-in-progress: false + +env: + UPDATE_BRANCH: ${{ inputs.ref || 'auto-update-bot' }} + jobs: periodic-update: runs-on: ubuntu-latest timeout-minutes: 120 + permissions: + contents: write + pull-requests: write steps: + - name: Install OS Packages + run: sudo apt-get update && sudo apt-get install -y libidn-dev cmake + # This allows us to continue to update an existing auto-update branch if it has yet to be merged, but if one # does not exist we will create a new one from the main branch. - id: repo shell: bash run: | - if git ls-remote --heads --quiet --exit-code https://github.com/${{ github.repository }}.git ${{ inputs.ref }} + if git ls-remote --heads --quiet --exit-code "https://github.com/${{ github.repository }}.git" "${UPDATE_BRANCH}" then - echo "::notice::Checkout: ${{ github.repository }} using ${{ inputs.ref }}" - echo "name=ref-exists::true" >> $GITHUB_OUTPUT + echo "::notice::Checkout: ${{ github.repository }} using ${UPDATE_BRANCH}" + echo "checkout-ref=${UPDATE_BRANCH}" >> "$GITHUB_OUTPUT" else - USING="main" - echo "::notice::Checkout: ${{ github.repository }} does not have ref ${{ inputs.ref }} (fallback to ${USING})" - echo "name=ref-exists::false" >> $GITHUB_OUTPUT - echo "name=default-branch::${USING}" >> $GITHUB_OUTPUT + echo "::notice::Checkout: ${{ github.repository }} does not have ref ${UPDATE_BRANCH} (fallback to main)" + echo "checkout-ref=main" >> "$GITHUB_OUTPUT" fi - - uses: actions/checkout@v3 + - uses: actions/checkout@v5 with: fetch-depth: 0 - ref: ${{ inputs.ref }} - - - name: Cache Ruby Gems and Bundle - id: cache-gems - uses: actions/cache@v4 - with: - path: vendor/bundle - key: ${{ runner.os }}-build-ruby-${{ hashFiles('Gemfile.lock') }} - restore-keys: | - ${{ runner.os }}-build-ruby- + ref: ${{ steps.repo.outputs.checkout-ref }} - name: Set up Ruby 4.0.5 uses: ruby/setup-ruby@v1 @@ -54,54 +56,32 @@ jobs: bundler-cache: true - name: Cache Temporary Data - id: cache-tmp - uses: actions/cache@v4 + uses: actions/cache@v5 with: path: tmp - key: data-update-cache + key: data-update-cache-${{ github.run_id }} + restore-keys: | + data-update-cache- - - name: Perform Default Rake Task + - name: Perform Update Rake Task run: bundle exec rake update - name: Archive Data Artifacts - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v5 with: name: data-update-artifacts path: _data - - uses: stefanzweifel/git-auto-commit-action@v4 + - name: Create or Update Pull Request + uses: peter-evans/create-pull-request@v7 with: - commit_message: Apply data updates - create_branch: true - branch: ${{ inputs.ref }} - commit_user_name: The Hack Different fully sentient AI - file_pattern: _data/** - push_options: '--force' - - - name: pull-request - uses: repo-sync/pull-request@v2 - with: - destination_branch: main - source_branch: ${{ inputs.ref }} - github_token: ${{ secrets.GITHUB_TOKEN }} - pr_title: "Automated Data Update: ${{ github.run_number }}" - - ci-test: - needs: periodic-update - uses: hack-different/apple-knowledge/.github/workflows/build-test.yml@main - - ci-build-jekyll: - needs: ci-test - uses: hack-different/apple-knowledge/.github/workflows/build-jekyll.yml@main - - ci-build-python: - needs: ci-test - uses: hack-different/apple-knowledge/.github/workflows/build-python.yml@main - - ci-build-ruby: - needs: ci-test - uses: hack-different/apple-knowledge/.github/workflows/build-ruby.yml@main - - ci-build-node: - needs: ci-test - uses: hack-different/apple-knowledge/.github/workflows/build-node.yml@main + token: ${{ secrets.GITHUB_TOKEN }} + branch: ${{ env.UPDATE_BRANCH }} + base: main + add-paths: _data/** + commit-message: Apply data updates + committer: The Hack Different fully sentient AI <41898282+github-actions[bot]@users.noreply.github.com> + author: The Hack Different fully sentient AI <41898282+github-actions[bot]@users.noreply.github.com> + title: "Automated Data Update" + body: "Automated data update from run ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}" + labels: data-update diff --git a/_packages/python/pyproject.toml b/_packages/python/pyproject.toml index b06372b4..e88e8449 100644 --- a/_packages/python/pyproject.toml +++ b/_packages/python/pyproject.toml @@ -9,8 +9,7 @@ description = "Static data from https://docs.hackdiffe.rent" readme = "README.md" authors = ["Rick Mark "] -include = ['share/**/*'] -build = "build.py" +include = [{ path = "share/**/*", format = ["sdist", "wheel"] }] [tool.poetry.dependencies] python = "^3.10"