mirror of
https://github.com/penpot/penpot.git
synced 2026-10-03 17:26:16 +00:00
Values coming from `${{ }}` expressions were interpolated directly into
`run:` scripts, so GitHub substituted them into the shell source before
bash parsed it. A commit title containing a double quote broke the
"Write step summary" step of the bundle build with a syntax error, and
the same pattern allowed arbitrary command execution on the
self-hosted runners.
Pass every expression used inside `run:` through step/job `env:` and
reference it as a quoted shell variable instead. Use the runner's
default variables (GITHUB_RUN_ID, GITHUB_REPOSITORY, ...) where the
value comes from the `github` context.
Also validate `plugin_name` in plugins-deploy-package.yml against
`^[a-z0-9][a-z0-9-]*$`, since it is free-form and reaches paths,
worker names, GITHUB_ENV and action inputs.
Affected workflows: build-bundle, build-docker,
build-docker-admin-console, plugins-deploy-package,
plugins-deploy-api-doc, plugins-deploy-styles-doc, release, tests-e2e.
Signed-off-by: David Barragán Merino <david.barragan@kaleidos.net>
109 lines
3.6 KiB
YAML
109 lines
3.6 KiB
YAML
name: Admin Console Docker Builder
|
|
|
|
on:
|
|
workflow_dispatch:
|
|
inputs:
|
|
gh_ref:
|
|
description: 'Name of the branch or ref to build in penpot-nitrate'
|
|
type: string
|
|
required: true
|
|
default: 'develop'
|
|
dispatch_ref:
|
|
description: 'Branch of penpot-nitrate from which the workflow definition is read'
|
|
type: string
|
|
required: false
|
|
default: 'develop'
|
|
force:
|
|
description: 'Rebuild and overwrite even if already built'
|
|
type: boolean
|
|
required: false
|
|
default: false
|
|
workflow_call:
|
|
inputs:
|
|
gh_ref:
|
|
description: 'Name of the branch or ref to build in penpot-nitrate'
|
|
type: string
|
|
required: true
|
|
dispatch_ref:
|
|
description: 'Branch of penpot-nitrate from which the workflow definition is read'
|
|
type: string
|
|
required: false
|
|
default: 'develop'
|
|
force:
|
|
description: 'Rebuild and overwrite even if already built'
|
|
type: boolean
|
|
required: false
|
|
default: false
|
|
secrets:
|
|
ORG_WORKFLOW_TOKEN:
|
|
description: 'Token with Actions write access on penpot-nitrate'
|
|
required: true
|
|
|
|
jobs:
|
|
build-nitrate-docker:
|
|
runs-on: ubuntu-latest
|
|
env:
|
|
GH_TOKEN: ${{ secrets.ORG_WORKFLOW_TOKEN }}
|
|
REPO: penpot/penpot-nitrate
|
|
WORKFLOW: build-docker-admin-console.yml
|
|
GH_REF: ${{ inputs.gh_ref }}
|
|
DISPATCH_REF: ${{ inputs.dispatch_ref }}
|
|
FORCE: ${{ inputs.force }}
|
|
steps:
|
|
- name: Trigger nitrate docker build
|
|
id: dispatch
|
|
run: |
|
|
DISTINCT_ID="${GITHUB_RUN_ID}-${GITHUB_RUN_ATTEMPT}"
|
|
CALLER_URL="${GITHUB_SERVER_URL}/${GITHUB_REPOSITORY}/actions/runs/${GITHUB_RUN_ID}"
|
|
|
|
gh workflow run "$WORKFLOW" --repo "$REPO" --ref "$DISPATCH_REF" \
|
|
-f gh_ref="$GH_REF" \
|
|
-f force="$FORCE" \
|
|
-f caller_run_id="$DISTINCT_ID" \
|
|
-f caller_run_url="$CALLER_URL"
|
|
|
|
# Locate the dispatched run using the correlation id embedded in its run-name
|
|
RUN_ID=""
|
|
for i in $(seq 1 24); do
|
|
sleep 5
|
|
RUN_ID=$(gh run list --repo "$REPO" --workflow "$WORKFLOW" \
|
|
--limit 10 --json databaseId,displayTitle \
|
|
--jq ".[] | select(.displayTitle | contains(\"$DISTINCT_ID\")) | .databaseId" \
|
|
| head -n1)
|
|
[ -n "$RUN_ID" ] && break
|
|
done
|
|
|
|
if [ -z "$RUN_ID" ]; then
|
|
echo "::error::Could not locate the dispatched run in $REPO"
|
|
exit 1
|
|
fi
|
|
|
|
RUN_URL="https://github.com/$REPO/actions/runs/$RUN_ID"
|
|
echo "run_id=$RUN_ID" >> "$GITHUB_OUTPUT"
|
|
echo "run_url=$RUN_URL" >> "$GITHUB_OUTPUT"
|
|
echo "::notice title=Nitrate docker build::$RUN_URL"
|
|
|
|
- name: Wait for nitrate docker build
|
|
env:
|
|
RUN_ID: ${{ steps.dispatch.outputs.run_id }}
|
|
run: |
|
|
gh run watch "$RUN_ID" \
|
|
--repo "$REPO" \
|
|
--interval 30 \
|
|
--exit-status
|
|
|
|
- name: Report result
|
|
if: always() && steps.dispatch.outputs.run_id != ''
|
|
env:
|
|
RUN_ID: ${{ steps.dispatch.outputs.run_id }}
|
|
RUN_URL: ${{ steps.dispatch.outputs.run_url }}
|
|
run: |
|
|
CONCLUSION=$(gh run view "$RUN_ID" \
|
|
--repo "$REPO" --json conclusion --jq '.conclusion')
|
|
{
|
|
echo "### 🐳 Nitrate docker build"
|
|
echo ""
|
|
echo "- Result: \`${CONCLUSION:-in_progress}\`"
|
|
echo "- Run: ${RUN_URL}"
|
|
} >> "$GITHUB_STEP_SUMMARY"
|