mirror of
https://github.com/penpot/penpot.git
synced 2026-10-03 01:06:14 +00:00
👷 Pass explicit secrets to reusable workflows
Replace secrets: inherit with the secrets each reusable workflow actually uses, and declare them under on.workflow_call.secrets in the called workflow. Declared as required: false so behaviour is unchanged if a secret is missing. Signed-off-by: David Barragán Merino <david.barragan@kaleidos.net>
This commit is contained in:
parent
fa3e01f7c7
commit
86fc3dd765
22
.github/workflows/build-adhoc.yml
vendored
22
.github/workflows/build-adhoc.yml
vendored
@ -23,7 +23,12 @@ on:
|
|||||||
jobs:
|
jobs:
|
||||||
build-bundle:
|
build-bundle:
|
||||||
uses: ./.github/workflows/build-bundle.yml
|
uses: ./.github/workflows/build-bundle.yml
|
||||||
secrets: inherit
|
secrets:
|
||||||
|
AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
|
||||||
|
AWS_REGION: ${{ secrets.AWS_REGION }}
|
||||||
|
AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
|
||||||
|
MATTERMOST_WEBHOOK: ${{ secrets.MATTERMOST_WEBHOOK }}
|
||||||
|
S3_BUCKET: ${{ secrets.S3_BUCKET }}
|
||||||
with:
|
with:
|
||||||
gh_ref: ${{ inputs.gh_ref }}
|
gh_ref: ${{ inputs.gh_ref }}
|
||||||
force: ${{ inputs.force }}
|
force: ${{ inputs.force }}
|
||||||
@ -31,7 +36,17 @@ jobs:
|
|||||||
build-docker:
|
build-docker:
|
||||||
needs: build-bundle
|
needs: build-bundle
|
||||||
uses: ./.github/workflows/build-docker.yml
|
uses: ./.github/workflows/build-docker.yml
|
||||||
secrets: inherit
|
secrets:
|
||||||
|
AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
|
||||||
|
AWS_REGION: ${{ secrets.AWS_REGION }}
|
||||||
|
AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
|
||||||
|
DOCKER_PASSWORD: ${{ secrets.DOCKER_PASSWORD }}
|
||||||
|
DOCKER_REGISTRY: ${{ secrets.DOCKER_REGISTRY }}
|
||||||
|
DOCKER_USERNAME: ${{ secrets.DOCKER_USERNAME }}
|
||||||
|
MATTERMOST_WEBHOOK: ${{ secrets.MATTERMOST_WEBHOOK }}
|
||||||
|
PUB_DOCKER_PASSWORD: ${{ secrets.PUB_DOCKER_PASSWORD }}
|
||||||
|
PUB_DOCKER_USERNAME: ${{ secrets.PUB_DOCKER_USERNAME }}
|
||||||
|
S3_BUCKET: ${{ secrets.S3_BUCKET }}
|
||||||
with:
|
with:
|
||||||
gh_ref: ${{ inputs.gh_ref }}
|
gh_ref: ${{ inputs.gh_ref }}
|
||||||
# Pin build-docker to the commit build-bundle actually bundled.
|
# Pin build-docker to the commit build-bundle actually bundled.
|
||||||
@ -40,7 +55,8 @@ jobs:
|
|||||||
|
|
||||||
build-docker-admin-console:
|
build-docker-admin-console:
|
||||||
uses: ./.github/workflows/build-docker-admin-console.yml
|
uses: ./.github/workflows/build-docker-admin-console.yml
|
||||||
secrets: inherit
|
secrets:
|
||||||
|
ORG_WORKFLOW_TOKEN: ${{ secrets.ORG_WORKFLOW_TOKEN }}
|
||||||
with:
|
with:
|
||||||
gh_ref: ${{ inputs.nitrate_ref || inputs.gh_ref }}
|
gh_ref: ${{ inputs.nitrate_ref || inputs.gh_ref }}
|
||||||
force: ${{ inputs.force }}
|
force: ${{ inputs.force }}
|
||||||
|
|||||||
11
.github/workflows/build-bundle.yml
vendored
11
.github/workflows/build-bundle.yml
vendored
@ -29,6 +29,17 @@ on:
|
|||||||
sha:
|
sha:
|
||||||
description: 'Bundled commit, full 40-char SHA.'
|
description: 'Bundled commit, full 40-char SHA.'
|
||||||
value: ${{ jobs.check.outputs.sha }}
|
value: ${{ jobs.check.outputs.sha }}
|
||||||
|
secrets:
|
||||||
|
AWS_ACCESS_KEY_ID:
|
||||||
|
required: false
|
||||||
|
AWS_REGION:
|
||||||
|
required: false
|
||||||
|
AWS_SECRET_ACCESS_KEY:
|
||||||
|
required: false
|
||||||
|
MATTERMOST_WEBHOOK:
|
||||||
|
required: false
|
||||||
|
S3_BUCKET:
|
||||||
|
required: false
|
||||||
|
|
||||||
# Literal group name: under `workflow_call`, `github.workflow` resolves to the
|
# Literal group name: under `workflow_call`, `github.workflow` resolves to the
|
||||||
# caller's workflow, which put this workflow and the other reusable one called
|
# caller's workflow, which put this workflow and the other reusable one called
|
||||||
|
|||||||
22
.github/workflows/build-develop.yml
vendored
22
.github/workflows/build-develop.yml
vendored
@ -21,7 +21,12 @@ concurrency:
|
|||||||
jobs:
|
jobs:
|
||||||
build-bundle:
|
build-bundle:
|
||||||
uses: ./.github/workflows/build-bundle.yml
|
uses: ./.github/workflows/build-bundle.yml
|
||||||
secrets: inherit
|
secrets:
|
||||||
|
AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
|
||||||
|
AWS_REGION: ${{ secrets.AWS_REGION }}
|
||||||
|
AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
|
||||||
|
MATTERMOST_WEBHOOK: ${{ secrets.MATTERMOST_WEBHOOK }}
|
||||||
|
S3_BUCKET: ${{ secrets.S3_BUCKET }}
|
||||||
with:
|
with:
|
||||||
gh_ref: "develop"
|
gh_ref: "develop"
|
||||||
force: ${{ inputs.force || false }}
|
force: ${{ inputs.force || false }}
|
||||||
@ -29,7 +34,17 @@ jobs:
|
|||||||
build-docker:
|
build-docker:
|
||||||
needs: build-bundle
|
needs: build-bundle
|
||||||
uses: ./.github/workflows/build-docker.yml
|
uses: ./.github/workflows/build-docker.yml
|
||||||
secrets: inherit
|
secrets:
|
||||||
|
AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
|
||||||
|
AWS_REGION: ${{ secrets.AWS_REGION }}
|
||||||
|
AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
|
||||||
|
DOCKER_PASSWORD: ${{ secrets.DOCKER_PASSWORD }}
|
||||||
|
DOCKER_REGISTRY: ${{ secrets.DOCKER_REGISTRY }}
|
||||||
|
DOCKER_USERNAME: ${{ secrets.DOCKER_USERNAME }}
|
||||||
|
MATTERMOST_WEBHOOK: ${{ secrets.MATTERMOST_WEBHOOK }}
|
||||||
|
PUB_DOCKER_PASSWORD: ${{ secrets.PUB_DOCKER_PASSWORD }}
|
||||||
|
PUB_DOCKER_USERNAME: ${{ secrets.PUB_DOCKER_USERNAME }}
|
||||||
|
S3_BUCKET: ${{ secrets.S3_BUCKET }}
|
||||||
with:
|
with:
|
||||||
gh_ref: "develop"
|
gh_ref: "develop"
|
||||||
# Pin build-docker to the commit build-bundle actually bundled.
|
# Pin build-docker to the commit build-bundle actually bundled.
|
||||||
@ -38,7 +53,8 @@ jobs:
|
|||||||
|
|
||||||
build-docker-admin-console:
|
build-docker-admin-console:
|
||||||
uses: ./.github/workflows/build-docker-admin-console.yml
|
uses: ./.github/workflows/build-docker-admin-console.yml
|
||||||
secrets: inherit
|
secrets:
|
||||||
|
ORG_WORKFLOW_TOKEN: ${{ secrets.ORG_WORKFLOW_TOKEN }}
|
||||||
with:
|
with:
|
||||||
gh_ref: "develop"
|
gh_ref: "develop"
|
||||||
force: ${{ inputs.force || false }}
|
force: ${{ inputs.force || false }}
|
||||||
|
|||||||
21
.github/workflows/build-docker.yml
vendored
21
.github/workflows/build-docker.yml
vendored
@ -32,6 +32,27 @@ on:
|
|||||||
type: boolean
|
type: boolean
|
||||||
required: false
|
required: false
|
||||||
default: false
|
default: false
|
||||||
|
secrets:
|
||||||
|
AWS_ACCESS_KEY_ID:
|
||||||
|
required: false
|
||||||
|
AWS_REGION:
|
||||||
|
required: false
|
||||||
|
AWS_SECRET_ACCESS_KEY:
|
||||||
|
required: false
|
||||||
|
DOCKER_PASSWORD:
|
||||||
|
required: false
|
||||||
|
DOCKER_REGISTRY:
|
||||||
|
required: false
|
||||||
|
DOCKER_USERNAME:
|
||||||
|
required: false
|
||||||
|
MATTERMOST_WEBHOOK:
|
||||||
|
required: false
|
||||||
|
PUB_DOCKER_PASSWORD:
|
||||||
|
required: false
|
||||||
|
PUB_DOCKER_USERNAME:
|
||||||
|
required: false
|
||||||
|
S3_BUCKET:
|
||||||
|
required: false
|
||||||
|
|
||||||
# Literal group name: under `workflow_call`, `github.workflow` resolves to the
|
# Literal group name: under `workflow_call`, `github.workflow` resolves to the
|
||||||
# caller's workflow, which put this workflow and the other reusable one called
|
# caller's workflow, which put this workflow and the other reusable one called
|
||||||
|
|||||||
22
.github/workflows/build-staging.yml
vendored
22
.github/workflows/build-staging.yml
vendored
@ -21,7 +21,12 @@ concurrency:
|
|||||||
jobs:
|
jobs:
|
||||||
build-bundle:
|
build-bundle:
|
||||||
uses: ./.github/workflows/build-bundle.yml
|
uses: ./.github/workflows/build-bundle.yml
|
||||||
secrets: inherit
|
secrets:
|
||||||
|
AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
|
||||||
|
AWS_REGION: ${{ secrets.AWS_REGION }}
|
||||||
|
AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
|
||||||
|
MATTERMOST_WEBHOOK: ${{ secrets.MATTERMOST_WEBHOOK }}
|
||||||
|
S3_BUCKET: ${{ secrets.S3_BUCKET }}
|
||||||
with:
|
with:
|
||||||
gh_ref: "staging"
|
gh_ref: "staging"
|
||||||
force: ${{ inputs.force || false }}
|
force: ${{ inputs.force || false }}
|
||||||
@ -29,7 +34,17 @@ jobs:
|
|||||||
build-docker:
|
build-docker:
|
||||||
needs: build-bundle
|
needs: build-bundle
|
||||||
uses: ./.github/workflows/build-docker.yml
|
uses: ./.github/workflows/build-docker.yml
|
||||||
secrets: inherit
|
secrets:
|
||||||
|
AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
|
||||||
|
AWS_REGION: ${{ secrets.AWS_REGION }}
|
||||||
|
AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
|
||||||
|
DOCKER_PASSWORD: ${{ secrets.DOCKER_PASSWORD }}
|
||||||
|
DOCKER_REGISTRY: ${{ secrets.DOCKER_REGISTRY }}
|
||||||
|
DOCKER_USERNAME: ${{ secrets.DOCKER_USERNAME }}
|
||||||
|
MATTERMOST_WEBHOOK: ${{ secrets.MATTERMOST_WEBHOOK }}
|
||||||
|
PUB_DOCKER_PASSWORD: ${{ secrets.PUB_DOCKER_PASSWORD }}
|
||||||
|
PUB_DOCKER_USERNAME: ${{ secrets.PUB_DOCKER_USERNAME }}
|
||||||
|
S3_BUCKET: ${{ secrets.S3_BUCKET }}
|
||||||
with:
|
with:
|
||||||
gh_ref: "staging"
|
gh_ref: "staging"
|
||||||
# Pin build-docker to the commit build-bundle actually bundled.
|
# Pin build-docker to the commit build-bundle actually bundled.
|
||||||
@ -38,7 +53,8 @@ jobs:
|
|||||||
|
|
||||||
build-docker-admin-console:
|
build-docker-admin-console:
|
||||||
uses: ./.github/workflows/build-docker-admin-console.yml
|
uses: ./.github/workflows/build-docker-admin-console.yml
|
||||||
secrets: inherit
|
secrets:
|
||||||
|
ORG_WORKFLOW_TOKEN: ${{ secrets.ORG_WORKFLOW_TOKEN }}
|
||||||
with:
|
with:
|
||||||
gh_ref: "staging"
|
gh_ref: "staging"
|
||||||
force: ${{ inputs.force || false }}
|
force: ${{ inputs.force || false }}
|
||||||
|
|||||||
31
.github/workflows/build-tag.yml
vendored
31
.github/workflows/build-tag.yml
vendored
@ -24,7 +24,12 @@ concurrency:
|
|||||||
jobs:
|
jobs:
|
||||||
build-bundle:
|
build-bundle:
|
||||||
uses: ./.github/workflows/build-bundle.yml
|
uses: ./.github/workflows/build-bundle.yml
|
||||||
secrets: inherit
|
secrets:
|
||||||
|
AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
|
||||||
|
AWS_REGION: ${{ secrets.AWS_REGION }}
|
||||||
|
AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
|
||||||
|
MATTERMOST_WEBHOOK: ${{ secrets.MATTERMOST_WEBHOOK }}
|
||||||
|
S3_BUCKET: ${{ secrets.S3_BUCKET }}
|
||||||
with:
|
with:
|
||||||
gh_ref: ${{ github.ref_name }}
|
gh_ref: ${{ github.ref_name }}
|
||||||
force: ${{ inputs.force || false }}
|
force: ${{ inputs.force || false }}
|
||||||
@ -32,14 +37,25 @@ jobs:
|
|||||||
build-docker:
|
build-docker:
|
||||||
needs: build-bundle
|
needs: build-bundle
|
||||||
uses: ./.github/workflows/build-docker.yml
|
uses: ./.github/workflows/build-docker.yml
|
||||||
secrets: inherit
|
secrets:
|
||||||
|
AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
|
||||||
|
AWS_REGION: ${{ secrets.AWS_REGION }}
|
||||||
|
AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
|
||||||
|
DOCKER_PASSWORD: ${{ secrets.DOCKER_PASSWORD }}
|
||||||
|
DOCKER_REGISTRY: ${{ secrets.DOCKER_REGISTRY }}
|
||||||
|
DOCKER_USERNAME: ${{ secrets.DOCKER_USERNAME }}
|
||||||
|
MATTERMOST_WEBHOOK: ${{ secrets.MATTERMOST_WEBHOOK }}
|
||||||
|
PUB_DOCKER_PASSWORD: ${{ secrets.PUB_DOCKER_PASSWORD }}
|
||||||
|
PUB_DOCKER_USERNAME: ${{ secrets.PUB_DOCKER_USERNAME }}
|
||||||
|
S3_BUCKET: ${{ secrets.S3_BUCKET }}
|
||||||
with:
|
with:
|
||||||
gh_ref: ${{ github.ref_name }}
|
gh_ref: ${{ github.ref_name }}
|
||||||
force: ${{ inputs.force || false }}
|
force: ${{ inputs.force || false }}
|
||||||
|
|
||||||
build-docker-admin-console:
|
build-docker-admin-console:
|
||||||
uses: ./.github/workflows/build-docker-admin-console.yml
|
uses: ./.github/workflows/build-docker-admin-console.yml
|
||||||
secrets: inherit
|
secrets:
|
||||||
|
ORG_WORKFLOW_TOKEN: ${{ secrets.ORG_WORKFLOW_TOKEN }}
|
||||||
with:
|
with:
|
||||||
gh_ref: ${{ github.ref_name }}
|
gh_ref: ${{ github.ref_name }}
|
||||||
force: ${{ inputs.force || false }}
|
force: ${{ inputs.force || false }}
|
||||||
@ -67,6 +83,13 @@ jobs:
|
|||||||
- build-docker
|
- build-docker
|
||||||
- build-docker-admin-console
|
- build-docker-admin-console
|
||||||
uses: ./.github/workflows/release.yml
|
uses: ./.github/workflows/release.yml
|
||||||
secrets: inherit
|
secrets:
|
||||||
|
AWS_REGION: ${{ secrets.AWS_REGION }}
|
||||||
|
DOCKER_PASSWORD: ${{ secrets.DOCKER_PASSWORD }}
|
||||||
|
DOCKER_REGISTRY: ${{ secrets.DOCKER_REGISTRY }}
|
||||||
|
DOCKER_USERNAME: ${{ secrets.DOCKER_USERNAME }}
|
||||||
|
MATTERMOST_WEBHOOK: ${{ secrets.MATTERMOST_WEBHOOK }}
|
||||||
|
PUB_DOCKER_PASSWORD: ${{ secrets.PUB_DOCKER_PASSWORD }}
|
||||||
|
PUB_DOCKER_USERNAME: ${{ secrets.PUB_DOCKER_USERNAME }}
|
||||||
with:
|
with:
|
||||||
gh_ref: ${{ github.ref_name }}
|
gh_ref: ${{ github.ref_name }}
|
||||||
|
|||||||
19
.github/workflows/build-tmp-tokens.yml
vendored
19
.github/workflows/build-tmp-tokens.yml
vendored
@ -12,13 +12,28 @@ concurrency:
|
|||||||
jobs:
|
jobs:
|
||||||
build-bundle:
|
build-bundle:
|
||||||
uses: ./.github/workflows/build-bundle.yml
|
uses: ./.github/workflows/build-bundle.yml
|
||||||
secrets: inherit
|
secrets:
|
||||||
|
AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
|
||||||
|
AWS_REGION: ${{ secrets.AWS_REGION }}
|
||||||
|
AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
|
||||||
|
MATTERMOST_WEBHOOK: ${{ secrets.MATTERMOST_WEBHOOK }}
|
||||||
|
S3_BUCKET: ${{ secrets.S3_BUCKET }}
|
||||||
with:
|
with:
|
||||||
gh_ref: "hiru-tokens-in-libs"
|
gh_ref: "hiru-tokens-in-libs"
|
||||||
|
|
||||||
build-docker:
|
build-docker:
|
||||||
needs: build-bundle
|
needs: build-bundle
|
||||||
uses: ./.github/workflows/build-docker.yml
|
uses: ./.github/workflows/build-docker.yml
|
||||||
secrets: inherit
|
secrets:
|
||||||
|
AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
|
||||||
|
AWS_REGION: ${{ secrets.AWS_REGION }}
|
||||||
|
AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
|
||||||
|
DOCKER_PASSWORD: ${{ secrets.DOCKER_PASSWORD }}
|
||||||
|
DOCKER_REGISTRY: ${{ secrets.DOCKER_REGISTRY }}
|
||||||
|
DOCKER_USERNAME: ${{ secrets.DOCKER_USERNAME }}
|
||||||
|
MATTERMOST_WEBHOOK: ${{ secrets.MATTERMOST_WEBHOOK }}
|
||||||
|
PUB_DOCKER_PASSWORD: ${{ secrets.PUB_DOCKER_PASSWORD }}
|
||||||
|
PUB_DOCKER_USERNAME: ${{ secrets.PUB_DOCKER_USERNAME }}
|
||||||
|
S3_BUCKET: ${{ secrets.S3_BUCKET }}
|
||||||
with:
|
with:
|
||||||
gh_ref: "hiru-tokens-in-libs"
|
gh_ref: "hiru-tokens-in-libs"
|
||||||
|
|||||||
7
.github/workflows/plugins-deploy-package.yml
vendored
7
.github/workflows/plugins-deploy-package.yml
vendored
@ -27,6 +27,13 @@ on:
|
|||||||
description: 'Publig name (from plugins/apps/<plugin_name>-plugin)'
|
description: 'Publig name (from plugins/apps/<plugin_name>-plugin)'
|
||||||
type: string
|
type: string
|
||||||
required: true
|
required: true
|
||||||
|
secrets:
|
||||||
|
CLOUDFLARE_ACCOUNT_ID:
|
||||||
|
required: false
|
||||||
|
CLOUDFLARE_API_TOKEN:
|
||||||
|
required: false
|
||||||
|
MATTERMOST_WEBHOOK:
|
||||||
|
required: false
|
||||||
|
|
||||||
permissions:
|
permissions:
|
||||||
contents: read
|
contents: read
|
||||||
|
|||||||
35
.github/workflows/plugins-deploy-packages.yml
vendored
35
.github/workflows/plugins-deploy-packages.yml
vendored
@ -74,7 +74,10 @@ jobs:
|
|||||||
needs: detect-changes
|
needs: detect-changes
|
||||||
if: github.event_name == 'workflow_dispatch' || needs.detect-changes.outputs.colors_to_tokens == 'true'
|
if: github.event_name == 'workflow_dispatch' || needs.detect-changes.outputs.colors_to_tokens == 'true'
|
||||||
uses: ./.github/workflows/plugins-deploy-package.yml
|
uses: ./.github/workflows/plugins-deploy-package.yml
|
||||||
secrets: inherit
|
secrets:
|
||||||
|
CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
|
||||||
|
CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
|
||||||
|
MATTERMOST_WEBHOOK: ${{ secrets.MATTERMOST_WEBHOOK }}
|
||||||
with:
|
with:
|
||||||
gh_ref: "${{ inputs.gh_ref || github.ref_name }}"
|
gh_ref: "${{ inputs.gh_ref || github.ref_name }}"
|
||||||
plugin_name: colors-to-tokens
|
plugin_name: colors-to-tokens
|
||||||
@ -83,7 +86,10 @@ jobs:
|
|||||||
needs: detect-changes
|
needs: detect-changes
|
||||||
if: github.event_name == 'workflow_dispatch' || needs.detect-changes.outputs.contrast == 'true'
|
if: github.event_name == 'workflow_dispatch' || needs.detect-changes.outputs.contrast == 'true'
|
||||||
uses: ./.github/workflows/plugins-deploy-package.yml
|
uses: ./.github/workflows/plugins-deploy-package.yml
|
||||||
secrets: inherit
|
secrets:
|
||||||
|
CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
|
||||||
|
CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
|
||||||
|
MATTERMOST_WEBHOOK: ${{ secrets.MATTERMOST_WEBHOOK }}
|
||||||
with:
|
with:
|
||||||
gh_ref: "${{ inputs.gh_ref || github.ref_name }}"
|
gh_ref: "${{ inputs.gh_ref || github.ref_name }}"
|
||||||
plugin_name: contrast
|
plugin_name: contrast
|
||||||
@ -92,7 +98,10 @@ jobs:
|
|||||||
needs: detect-changes
|
needs: detect-changes
|
||||||
if: github.event_name == 'workflow_dispatch' || needs.detect-changes.outputs.create_palette == 'true'
|
if: github.event_name == 'workflow_dispatch' || needs.detect-changes.outputs.create_palette == 'true'
|
||||||
uses: ./.github/workflows/plugins-deploy-package.yml
|
uses: ./.github/workflows/plugins-deploy-package.yml
|
||||||
secrets: inherit
|
secrets:
|
||||||
|
CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
|
||||||
|
CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
|
||||||
|
MATTERMOST_WEBHOOK: ${{ secrets.MATTERMOST_WEBHOOK }}
|
||||||
with:
|
with:
|
||||||
gh_ref: "${{ inputs.gh_ref || github.ref_name }}"
|
gh_ref: "${{ inputs.gh_ref || github.ref_name }}"
|
||||||
plugin_name: create-palette
|
plugin_name: create-palette
|
||||||
@ -101,7 +110,10 @@ jobs:
|
|||||||
needs: detect-changes
|
needs: detect-changes
|
||||||
if: github.event_name == 'workflow_dispatch' || needs.detect-changes.outputs.icons == 'true'
|
if: github.event_name == 'workflow_dispatch' || needs.detect-changes.outputs.icons == 'true'
|
||||||
uses: ./.github/workflows/plugins-deploy-package.yml
|
uses: ./.github/workflows/plugins-deploy-package.yml
|
||||||
secrets: inherit
|
secrets:
|
||||||
|
CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
|
||||||
|
CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
|
||||||
|
MATTERMOST_WEBHOOK: ${{ secrets.MATTERMOST_WEBHOOK }}
|
||||||
with:
|
with:
|
||||||
gh_ref: "${{ inputs.gh_ref || github.ref_name }}"
|
gh_ref: "${{ inputs.gh_ref || github.ref_name }}"
|
||||||
plugin_name: icons
|
plugin_name: icons
|
||||||
@ -110,7 +122,10 @@ jobs:
|
|||||||
needs: detect-changes
|
needs: detect-changes
|
||||||
if: github.event_name == 'workflow_dispatch' || needs.detect-changes.outputs.lorem_ipsum == 'true'
|
if: github.event_name == 'workflow_dispatch' || needs.detect-changes.outputs.lorem_ipsum == 'true'
|
||||||
uses: ./.github/workflows/plugins-deploy-package.yml
|
uses: ./.github/workflows/plugins-deploy-package.yml
|
||||||
secrets: inherit
|
secrets:
|
||||||
|
CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
|
||||||
|
CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
|
||||||
|
MATTERMOST_WEBHOOK: ${{ secrets.MATTERMOST_WEBHOOK }}
|
||||||
with:
|
with:
|
||||||
gh_ref: "${{ inputs.gh_ref || github.ref_name }}"
|
gh_ref: "${{ inputs.gh_ref || github.ref_name }}"
|
||||||
plugin_name: lorem-ipsum
|
plugin_name: lorem-ipsum
|
||||||
@ -119,7 +134,10 @@ jobs:
|
|||||||
needs: detect-changes
|
needs: detect-changes
|
||||||
if: github.event_name == 'workflow_dispatch' || needs.detect-changes.outputs.rename_layers == 'true'
|
if: github.event_name == 'workflow_dispatch' || needs.detect-changes.outputs.rename_layers == 'true'
|
||||||
uses: ./.github/workflows/plugins-deploy-package.yml
|
uses: ./.github/workflows/plugins-deploy-package.yml
|
||||||
secrets: inherit
|
secrets:
|
||||||
|
CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
|
||||||
|
CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
|
||||||
|
MATTERMOST_WEBHOOK: ${{ secrets.MATTERMOST_WEBHOOK }}
|
||||||
with:
|
with:
|
||||||
gh_ref: "${{ inputs.gh_ref || github.ref_name }}"
|
gh_ref: "${{ inputs.gh_ref || github.ref_name }}"
|
||||||
plugin_name: rename-layers
|
plugin_name: rename-layers
|
||||||
@ -128,7 +146,10 @@ jobs:
|
|||||||
needs: detect-changes
|
needs: detect-changes
|
||||||
if: github.event_name == 'workflow_dispatch' || needs.detect-changes.outputs.table == 'true'
|
if: github.event_name == 'workflow_dispatch' || needs.detect-changes.outputs.table == 'true'
|
||||||
uses: ./.github/workflows/plugins-deploy-package.yml
|
uses: ./.github/workflows/plugins-deploy-package.yml
|
||||||
secrets: inherit
|
secrets:
|
||||||
|
CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
|
||||||
|
CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
|
||||||
|
MATTERMOST_WEBHOOK: ${{ secrets.MATTERMOST_WEBHOOK }}
|
||||||
with:
|
with:
|
||||||
gh_ref: "${{ inputs.gh_ref || github.ref_name }}"
|
gh_ref: "${{ inputs.gh_ref || github.ref_name }}"
|
||||||
plugin_name: table
|
plugin_name: table
|
||||||
|
|||||||
15
.github/workflows/release.yml
vendored
15
.github/workflows/release.yml
vendored
@ -13,6 +13,21 @@ on:
|
|||||||
description: 'Tag to release'
|
description: 'Tag to release'
|
||||||
type: string
|
type: string
|
||||||
required: true
|
required: true
|
||||||
|
secrets:
|
||||||
|
AWS_REGION:
|
||||||
|
required: false
|
||||||
|
DOCKER_PASSWORD:
|
||||||
|
required: false
|
||||||
|
DOCKER_REGISTRY:
|
||||||
|
required: false
|
||||||
|
DOCKER_USERNAME:
|
||||||
|
required: false
|
||||||
|
MATTERMOST_WEBHOOK:
|
||||||
|
required: false
|
||||||
|
PUB_DOCKER_PASSWORD:
|
||||||
|
required: false
|
||||||
|
PUB_DOCKER_USERNAME:
|
||||||
|
required: false
|
||||||
|
|
||||||
permissions:
|
permissions:
|
||||||
contents: write
|
contents: write
|
||||||
|
|||||||
9
.github/zizmor.yml
vendored
9
.github/zizmor.yml
vendored
@ -50,15 +50,6 @@ rules:
|
|||||||
github-app:
|
github-app:
|
||||||
ignore:
|
ignore:
|
||||||
- auto-label.yml
|
- auto-label.yml
|
||||||
# Pass only the secrets each reusable workflow needs.
|
|
||||||
secrets-inherit:
|
|
||||||
ignore:
|
|
||||||
- build-adhoc.yml
|
|
||||||
- build-develop.yml
|
|
||||||
- build-staging.yml
|
|
||||||
- build-tag.yml
|
|
||||||
- build-tmp-tokens.yml
|
|
||||||
- plugins-deploy-packages.yml
|
|
||||||
# Style nudge towards the `$/...` syntax; not worth enforcing.
|
# Style nudge towards the `$/...` syntax; not worth enforcing.
|
||||||
self-repository:
|
self-repository:
|
||||||
disable: true
|
disable: true
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user