mirror of
https://github.com/penpot/penpot.git
synced 2026-10-03 01:06:14 +00:00
Values coming from `${{ }}` expressions were interpolated directly into
`run:` scripts, so GitHub substituted them into the shell source before
bash parsed it. A commit title containing a double quote broke the
"Write step summary" step of the bundle build with a syntax error, and
the same pattern allowed arbitrary command execution on the
self-hosted runners.
Pass every expression used inside `run:` through step/job `env:` and
reference it as a quoted shell variable instead. Use the runner's
default variables (GITHUB_RUN_ID, GITHUB_REPOSITORY, ...) where the
value comes from the `github` context.
Also validate `plugin_name` in plugins-deploy-package.yml against
`^[a-z0-9][a-z0-9-]*$`, since it is free-form and reaches paths,
worker names, GITHUB_ENV and action inputs.
Affected workflows: build-bundle, build-docker,
build-docker-admin-console, plugins-deploy-package,
plugins-deploy-api-doc, plugins-deploy-styles-doc, release, tests-e2e.
Signed-off-by: David Barragán Merino <david.barragan@kaleidos.net>
135 lines
4.4 KiB
YAML
135 lines
4.4 KiB
YAML
name: Plugins/package deployer
|
|
|
|
on:
|
|
# Deploy package from manual action
|
|
workflow_dispatch:
|
|
inputs:
|
|
gh_ref:
|
|
description: 'Name of the branch'
|
|
type: choice
|
|
required: true
|
|
default: 'develop'
|
|
options:
|
|
- develop
|
|
- staging
|
|
- main
|
|
plugin_name:
|
|
description: 'Pluging name (like plugins/apps/<plugin_name>-plugin)'
|
|
type: string
|
|
required: true
|
|
workflow_call:
|
|
inputs:
|
|
gh_ref:
|
|
description: 'Name of the branch'
|
|
type: string
|
|
required: true
|
|
default: 'develop'
|
|
plugin_name:
|
|
description: 'Publig name (from plugins/apps/<plugin_name>-plugin)'
|
|
type: string
|
|
required: true
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
deploy:
|
|
runs-on: penpot-standar-runner
|
|
env:
|
|
GH_REF: ${{ inputs.gh_ref }}
|
|
PLUGIN_NAME: ${{ inputs.plugin_name }}
|
|
steps:
|
|
# plugin_name is a free-form string that ends up in paths, worker names
|
|
# and GITHUB_ENV; reject anything that is not a plain slug before it is
|
|
# used anywhere.
|
|
- name: Validate inputs
|
|
run: |
|
|
if ! [[ "$PLUGIN_NAME" =~ ^[a-z0-9][a-z0-9-]*$ ]]; then
|
|
echo "::error::Invalid plugin_name: must match ^[a-z0-9][a-z0-9-]*$"
|
|
exit 1
|
|
fi
|
|
|
|
- name: Checkout
|
|
uses: actions/checkout@v6
|
|
with:
|
|
fetch-depth: 0
|
|
ref: ${{ inputs.gh_ref }}
|
|
|
|
# START: Setup Node and PNPM enabling cache
|
|
- name: Setup pnpm + Node.js
|
|
uses: pnpm/setup@v2
|
|
with:
|
|
working-directory: plugins
|
|
runtime: node@24.21.0
|
|
install: false
|
|
|
|
- name: Get pnpm store path
|
|
id: pnpm-store
|
|
working-directory: ./plugins
|
|
shell: bash
|
|
run: echo "STORE_PATH=$(pnpm store path --silent)" >> $GITHUB_OUTPUT
|
|
|
|
- name: Cache pnpm store
|
|
uses: actions/cache@v5
|
|
with:
|
|
path: ${{ steps.pnpm-store.outputs.STORE_PATH }}
|
|
key: ${{ runner.os }}-pnpm-${{ hashFiles('plugins/pnpm-lock.yaml') }}
|
|
restore-keys: |
|
|
${{ runner.os }}-pnpm-
|
|
# END: Setup Node and PNPM enabling cache
|
|
|
|
- name: Install deps
|
|
working-directory: ./plugins
|
|
shell: bash
|
|
run: |
|
|
pnpm install --no-frozen-lockfile;
|
|
pnpm add -D -w wrangler@latest;
|
|
|
|
- name: "Build package for ${{ inputs.plugin_name }}-plugin"
|
|
working-directory: plugins
|
|
shell: bash
|
|
run: pnpm --filter "${PLUGIN_NAME}-plugin" build
|
|
|
|
- name: Select Worker name
|
|
run: |
|
|
case "$GH_REF" in
|
|
main)
|
|
echo "WORKER_NAME=${PLUGIN_NAME}-plugin-pro" >> $GITHUB_ENV
|
|
echo "WORKER_URI=${PLUGIN_NAME}.plugins.penpot.app" >> $GITHUB_ENV ;;
|
|
staging)
|
|
echo "WORKER_NAME=${PLUGIN_NAME}-plugin-pre" >> $GITHUB_ENV
|
|
echo "WORKER_URI=${PLUGIN_NAME}.plugins.penpot.dev" >> $GITHUB_ENV ;;
|
|
develop)
|
|
echo "WORKER_NAME=${PLUGIN_NAME}-plugin-hourly" >> $GITHUB_ENV
|
|
echo "WORKER_URI=${PLUGIN_NAME}.plugins.hourly.penpot.dev" >> $GITHUB_ENV ;;
|
|
*) echo "Unsupported branch ${GH_REF}" && exit 1 ;;
|
|
esac
|
|
|
|
- name: Set the custom url
|
|
working-directory: plugins
|
|
shell: bash
|
|
run: |
|
|
sed -i "s/WORKER_URI/${WORKER_URI}/g" "apps/${PLUGIN_NAME}-plugin/wrangler.toml"
|
|
|
|
- name: Deploy to Cloudflare Workers
|
|
uses: cloudflare/wrangler-action@v3
|
|
with:
|
|
workingDirectory: plugins
|
|
apiToken: ${{ secrets.CLOUDFLARE_API_TOKEN }}
|
|
accountId: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
|
|
command: deploy --config apps/${{ inputs.plugin_name }}-plugin/wrangler.toml --name ${{ env.WORKER_NAME }}
|
|
|
|
- name: Notify Mattermost
|
|
if: failure()
|
|
uses: mattermost/action-mattermost-notify@ae31bb6f9e26a54336e79696f108a2c91cf55b4e # v2.1.0
|
|
with:
|
|
MATTERMOST_WEBHOOK_URL: ${{ secrets.MATTERMOST_WEBHOOK }}
|
|
MATTERMOST_CHANNEL: bot-alerts-cicd
|
|
TEXT: |
|
|
❌ 🧩📦 *[PENPOT PLUGINS] Error deploying ${{ env.WORKER_NAME }}.*
|
|
📄 Triggered from ref: `${{ inputs.gh_ref }}`
|
|
Plugin name: `${{ inputs.plugin_name }}-plugin`
|
|
Cloudflare worker name: `${{ env.WORKER_NAME }}`
|
|
🔗 Run: https://github.com/${{ github.repository }}/actions/runs/${{ github.run_id }}
|
|
@infra
|