Skip to content
Closed
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
82 changes: 21 additions & 61 deletions .github/workflows/update-readme.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,34 +4,20 @@ name: Update README
# scripts/update-readme.mjs): the repository table (from the GitHub API) and
# the software tools tables (imported from robotiq/robotiq.github.io's
# docs/intro.mdx). Opens a PR only when the regenerated content actually
# differs, then auto-merges it — mirroring
# robotiq.github.io's .github/workflows/dependabot-auto-merge.yml.
# differs — a human merges it.
#
# Why this needs a PAT instead of just GITHUB_TOKEN: the prToMain ruleset's
# required-review rule blocks a PR's *author* from approving its own PR. In
# dependabot-auto-merge.yml, Dependabot (a distinct actor) opens the PR and
# GITHUB_TOKEN (github-actions[bot]) approves it — two different actors, so
# it's not self-approval. Here there's no Dependabot; this workflow itself
# generates the content. So the "open PR" step authenticates as
# README_BOT_PAT (a fine-grained PAT scoped to just this repo, Contents +
# Pull requests: write) instead of GITHUB_TOKEN, making its author a
# distinct actor from the github-actions[bot] identity that then approves
# and merges it in the next step.
#
# Why this is safe to merge without further human review: the generated
# content is either the GitHub API's own repo descriptions or
# robotiq.github.io's own published docs/intro.mdx — both already public and
# already reviewed upstream. What actually gates the merge is the "Test"
# workflow (.github/workflows/test.yml) as a required status check on the
# prToMain ruleset: `gh pr merge --auto` waits on it, so a change that breaks
# update-readme.mjs sits as an open, failing PR instead of reaching the org's
# public landing page. Without that required check, `--auto` has nothing to
# wait on and errors out instead of merging — see the review on PR #2.
#
# Also requires: `allow_auto_merge` enabled on this repo (Settings → General
# → Pull Requests), and the commit's author email resolving to a real GitHub
# account (below) so prToMain's require_extra_approval_for_unattributed_changes
# rule doesn't kick in and demand a second approval nothing here can produce.
# Why this doesn't auto-merge: the prToMain ruleset requires 1 approving
# review, and blocks a PR's *author* from approving its own PR. GITHUB_TOKEN
# always acts as github-actions[bot], and this workflow both generates the
# content and would be the one opening the PR — so the author and the only
# available approver would be the same identity. Getting a truly separate
# identity to approve needs either a PAT for a second bot/human account, or
# a ruleset bypass actor for GitHub Actions (which would exempt every
# GITHUB_TOKEN-authored PR in this repo from review, not just this one) —
# both trade one problem for another. Stopping at "PR opens automatically,
# a human clicks merge" needs neither: GITHUB_TOKEN is enough to open the
# PR, and the required `test` check (.github/workflows/test.yml) still
# gates it before that merge is possible.

on:
schedule:
Expand All @@ -46,10 +32,7 @@ jobs:
update-readme:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
with:
token: ${{ secrets.README_BOT_PAT }}
- uses: actions/checkout@v4

- uses: actions/setup-node@v4
with:
Expand All @@ -61,51 +44,28 @@ jobs:
run: node scripts/update-readme.mjs

- name: Open PR if content changed
id: pr
env:
GH_TOKEN: ${{ secrets.README_BOT_PAT }}
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
if git diff --quiet -- profile/README.md; then
echo "changed=false" >> "$GITHUB_OUTPUT"
exit 0
fi

# Fixed name rather than one timestamped per run: a run that lands
# before yesterday's PR merged (still waiting on the required
# check) force-pushes onto the same branch/PR instead of piling up
# a new branch and a new unmergeable PR each day.
# before yesterday's PR merged force-pushes onto the same
# branch/PR instead of piling up a new branch and PR each day.
BRANCH="auto/update-readme"
git config user.name "robotiq-readme-bot"
# This must resolve to a real GitHub account (github-actions[bot]'s
# own noreply address) or the prToMain ruleset's
# require_extra_approval_for_unattributed_changes rule treats the
# commit as unattributed and demands a second approval this
# workflow has no way to produce.
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git checkout -b "$BRANCH"
git add profile/README.md
git commit -m "chore: update README repository table and software tools section"
git push --force origin "$BRANCH"

EXISTING_PR=$(gh pr list --base main --head "$BRANCH" --state open --json url --jq '.[0].url')
if [ -n "$EXISTING_PR" ]; then
PR_URL="$EXISTING_PR"
else
PR_URL=$(gh pr create \
if [ -z "$(gh pr list --base main --head "$BRANCH" --state open --json url --jq '.[0].url')" ]; then
gh pr create \
--base main \
--head "$BRANCH" \
--title "chore: update README repository table" \
--body "Automated daily refresh of the repository table (GitHub API) and software tools section (robotiq.github.io docs/intro.mdx) — see \`scripts/update-readme.mjs\`.")
--body "Automated daily refresh of the repository table (GitHub API) and software tools section (robotiq.github.io docs/intro.mdx) — see \`scripts/update-readme.mjs\`. Merge once the \`test\` check passes."
fi

echo "changed=true" >> "$GITHUB_OUTPUT"
echo "url=$PR_URL" >> "$GITHUB_OUTPUT"

- name: Approve and auto-merge
if: steps.pr.outputs.changed == 'true'
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
PR_URL: ${{ steps.pr.outputs.url }}
run: |
gh pr review --approve "$PR_URL"
gh pr merge --auto --squash --delete-branch "$PR_URL"
Loading