Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 9 additions & 6 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,13 +5,16 @@ on:
branches: [main, v7]
pull_request:
branches: [main, v7]
# Lets another workflow start this one against a specific ref.
# Re-run CI against a ref by hand. Convenience only.
#
# The spec-drift job opens its PR with GITHUB_TOKEN, and GitHub does not
# start workflow runs from GITHUB_TOKEN-raised events — so the required
# checks never report and the PR is blocked on a report it can never get.
# workflow_dispatch and repository_dispatch are the two documented
# exceptions to that rule, so drift can dispatch this run itself.
# This was added to let the spec-drift job start its own CI, on the reasoning
# that workflow_dispatch is a documented exception to "GITHUB_TOKEN-raised
# events do not start workflow runs". The run does start — but measured
# against a real PR, its check runs do not satisfy branch protection, even
# sitting on the PR head SHA with the exact required names and a check suite
# reporting as linked to the PR. A push-event run on the next commit cleared
# the same PR immediately. Drift therefore pushes as a GitHub App instead;
# see spec-drift.yml. Kept because dispatching CI by hand is still useful.
workflow_dispatch:

jobs:
Expand Down
18 changes: 18 additions & 0 deletions .github/workflows/spec-drift.yml
Original file line number Diff line number Diff line change
Expand Up @@ -37,9 +37,27 @@ jobs:
continue-on-error: true
run: npm run test:live

# The PR must not be opened with GITHUB_TOKEN. GitHub does not start
# workflow runs from GITHUB_TOKEN-raised events, so a PR opened that way
# never gets its required checks and can never be merged, however good
# the diff is. Both drift PRs sat blocked for days on exactly that.
#
# workflow_dispatch is documented as an exception to the no-runs rule and
# does start a run — but measured against a real PR, those check runs do
# not satisfy branch protection even on the right SHA under the right
# names. A push-event run does. So the push has to come from an identity
# that is not GITHUB_TOKEN, and this app is that identity.
- name: Mint an installation token for the drift bot
id: app-token
uses: actions/create-github-app-token@v2
with:
app-id: ${{ secrets.DRIFT_APP_ID }}
private-key: ${{ secrets.DRIFT_APP_PRIVATE_KEY }}

- name: Open PR if schema changed
uses: peter-evans/create-pull-request@v8
with:
token: ${{ steps.app-token.outputs.token }}
add-paths: src/_generated/schema.ts
branch: automated/spec-drift
commit-message: 'chore: regenerate schema from upstream spec'
Expand Down