mirror of
https://github.com/supabase/supabase.git
synced 2026-10-09 11:25:06 +03:00
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Chore, CI hardening ## Additional context Hardens all GitHub actions to recommendations of [zizmor](https://docs.zizmor.sh/audits/) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Disabled persistence of checkout credentials across many CI workflows to reduce credential exposure. * Upgraded GitHub App token tooling and tightened generated token permissions for automation. * Added cooldown/rate-limiting to dependency update automation to reduce update churn. * Adjusted workflow-level permissions, required secret inputs for workflow callers, and refactored some job step logic. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/46454?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Ali Waseem <waseema393@gmail.com>
63 lines
2.2 KiB
YAML
63 lines
2.2 KiB
YAML
name: '[Docs] Lint v2 (scheduled)'
|
|
on:
|
|
schedule:
|
|
- cron: '0 0 * * *'
|
|
workflow_dispatch:
|
|
|
|
env:
|
|
CARGO_NET_GIT_FETCH_WITH_CLI: true
|
|
|
|
permissions:
|
|
contents: write
|
|
pull-requests: write
|
|
|
|
jobs:
|
|
lint-all:
|
|
runs-on: blacksmith-4vcpu-ubuntu-2404
|
|
steps:
|
|
- uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
|
|
with:
|
|
fetch-depth: 0
|
|
persist-credentials: true
|
|
sparse-checkout: |
|
|
supa-mdx-lint.config.toml
|
|
supa-mdx-lint
|
|
apps/docs/content
|
|
- name: cache cargo
|
|
id: cache-cargo
|
|
uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0
|
|
with:
|
|
path: |
|
|
~/.cargo/bin/
|
|
~/.cargo/registry/index/
|
|
~/.cargo/registry/cache/
|
|
~/.cargo/git/db/
|
|
key: 6b08233ff8bca855f6a38246b2a8049332219188
|
|
- name: install linter
|
|
if: steps.cache-cargo.outputs.cache-hit != 'true'
|
|
run: cargo install --locked --git https://github.com/supabase-community/supa-mdx-lint --rev 6b08233ff8bca855f6a38246b2a8049332219188
|
|
- name: run linter
|
|
env:
|
|
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
run: |
|
|
supa-mdx-lint apps/docs/content || {
|
|
echo "Linter failed, attempting to fix errors..."
|
|
git config --global user.name 'github-docs-bot'
|
|
git config --global user.email 'github-docs-bot@supabase.com'
|
|
BRANCH_NAME="bot/docs-lint-fixes"
|
|
EXISTING_BRANCH=$(git ls-remote --heads origin $BRANCH_NAME)
|
|
if [[ -n "$EXISTING_BRANCH" ]]; then
|
|
git push origin --delete $BRANCH_NAME
|
|
fi
|
|
git checkout -b $BRANCH_NAME
|
|
supa-mdx-lint apps/docs/content --fix || FIX_FAILED=1
|
|
git add .
|
|
git commit -m '[bot] fix lint errors' || true
|
|
git push origin $BRANCH_NAME
|
|
gh pr create --title '[bot] fix lint errors' --body 'This PR fixes lint errors in the documentation.' --head $BRANCH_NAME
|
|
if [ "${FIX_FAILED:-0}" -eq 1 ]; then
|
|
echo "Fix did not correct all errors."
|
|
exit 1
|
|
fi
|
|
}
|