Merge Data Branch #27
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| --- | |
| name: Merge Data Branch | |
| on: | |
| schedule: | |
| - cron: '0 22 * * 0' # Every Sunday at 22:00 UTC | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| jobs: | |
| merge-data: | |
| name: Merge data into main | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 10 | |
| steps: | |
| - id: get-workflow-app-token | |
| name: Get Workflow Access Token | |
| uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0 | |
| with: | |
| app-id: ${{ secrets.APPLICATION_ID }} | |
| private-key: ${{ secrets.APPLICATION_PRIVATE_KEY }} | |
| - name: ⤵ Checkout Branch | |
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| with: | |
| fetch-depth: 0 # full history needed for three-dot diff in promotion privacy check | |
| - name: 📦 Setup | |
| uses: ./.github/actions/setup | |
| # Two checkouts: scripts live on main, the wiki/metadata being promoted live on data. | |
| # The privacy check below runs from the data subtree to gate the actual merge content. | |
| - name: ⤵ Fetch data branch for privacy check | |
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| with: | |
| ref: data | |
| path: data-branch-check | |
| # Privacy gate: blocks promotion if a private repo's wiki page would leak onto main. | |
| # Design: delta-based public-allowlist inversion — no GraphQL needed. | |
| # - data's own repos.yaml is authoritative (data branch is the writer) | |
| # - publicSlugs built from entries with explicit private===false via computeRepoSlug | |
| # - pages already on main (default checkout = main) are grandfathered to avoid | |
| # re-flagging verifiably-public repos that lack an explicit private===false field | |
| # (e.g. marcusrbrown/copiloting: onboarding_status=lost-access, absent private) | |
| # - dead/node-null orphans are tolerated: if already on main → grandfathered; | |
| # if genuinely new → correctly flagged without any GraphQL call | |
| - name: 🔒 Block private wiki pages | |
| env: | |
| GRANDFATHER_WIKI_REPOS_DIR: ../knowledge/wiki/repos | |
| working-directory: data-branch-check | |
| run: node ../scripts/check-wiki-private-presence.ts | |
| # Promotion privacy gate: blocks merge if a private repo name appears in the data→main diff. | |
| # Design: three-dot diff (origin/main...origin/data) against private node_ids from data's | |
| # repos.yaml — requires full history (fetch-depth: 0 above) and origin/data ref (fetched | |
| # below). The fetch runs under the default checkout GITHUB_TOKEN (sufficient to reach | |
| # origin/data); the broad-scope FRO_BOT_POLL_PAT is confined to the node step that resolves | |
| # private names. Splitting the steps keeps FRO_BOT_POLL_PAT out of every git subprocess — | |
| # the env-stripping in runPromotionCli enforces the same property for the diff git call. | |
| - name: 🔒 Fetch data ref for promotion diff | |
| run: git fetch --no-tags --prune origin data | |
| - name: 🔒 Block private repo names in promotion diff | |
| env: | |
| FRO_BOT_POLL_PAT: ${{ secrets.FRO_BOT_POLL_PAT }} | |
| PROMOTION_REPOS_YAML_PATH: data-branch-check/metadata/repos.yaml | |
| run: node scripts/check-private-leak.ts --promotion | |
| - name: 🔀 Open weekly data merge PR | |
| env: | |
| GITHUB_TOKEN: ${{ steps.get-workflow-app-token.outputs.token }} | |
| run: node scripts/merge-data-pr.ts |