bump-plugin-shas.yml 3.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384
  1. name: Bump Plugin SHAs
  2. # Nightly sweep: for each external entry whose upstream HEAD has moved past
  3. # its pinned SHA, validate at the new SHA with `claude plugin validate`
  4. # inline, then open one PR per bumped plugin on branch `bump/<slug>`.
  5. # Failing entries stay isolated in their own PR; passing bumps merge
  6. # independently.
  7. #
  8. # Bot-free — uses the default GITHUB_TOKEN. PRs opened with GITHUB_TOKEN don't
  9. # trigger on:pull_request workflows, so the required status checks on main
  10. # (`scan` from Scan Plugins, `check` from Check MCP URLs, `validate` from
  11. # Validate Plugins) would never run and the bump PR could never merge.
  12. # workflow_dispatch is exempt from that recursion guard, so we dispatch all
  13. # three ourselves against each per-entry bump branch after its PR is opened.
  14. # Each check run lands on the branch HEAD — the same SHA as the PR head — and
  15. # satisfies the corresponding required check. (Each of those workflows runs
  16. # its job unconditionally on workflow_dispatch, so a dispatch always reports.)
  17. #
  18. # max-bumps caps the per-night work for cost control. Per-entry scans are
  19. # more expensive than a single batched scan, so the cap is conservative.
  20. # The composite action skips entries that already have an open bump PR, so
  21. # re-dispatches don't pile up duplicate work.
  22. on:
  23. schedule:
  24. - cron: '23 7 * * *' # Daily 07:23 UTC
  25. workflow_dispatch:
  26. inputs:
  27. max_bumps:
  28. description: Cap on plugins bumped this run
  29. required: false
  30. default: '30'
  31. permissions:
  32. contents: write
  33. pull-requests: write
  34. actions: write # gh workflow run {scan-plugins,check-mcp-urls,validate-plugins}.yml per bump branch
  35. concurrency:
  36. group: bump-plugin-shas
  37. jobs:
  38. bump:
  39. runs-on: ubuntu-latest
  40. # Per-bump cost is ~2s (ls-remote + shallow clone + validate); 30 entries
  41. # is ~1-2 min. The 60 min ceiling absorbs slow upstreams without letting a
  42. # pathological run consume the default 360 min budget.
  43. timeout-minutes: 60
  44. steps:
  45. - uses: actions/checkout@v4
  46. # createCommitOnBranch-based bump so commits are signed by GitHub and
  47. # satisfy the org-level required_signatures ruleset on main.
  48. - uses: anthropics/claude-plugins-community/.github/actions/bump-plugin-shas@e2019b2a01f11aa1484c53540b1cfab5eebbc299
  49. id: bump
  50. with:
  51. marketplace-path: .claude-plugin/marketplace.json
  52. max-bumps: ${{ inputs.max_bumps || '30' }}
  53. pr-mode: per-entry
  54. claude-cli-version: latest
  55. # Per-entry fan-out: dispatch the three required checks against each bump
  56. # branch. `pr-urls` is a JSON array of {name, old_sha, new_sha, branch,
  57. # pr_url} entries emitted by the composite action when pr-mode is
  58. # per-entry. All three (scan / check / validate) are required on main and
  59. # none fire on the GITHUB_TOKEN-opened PR, so each must be dispatched.
  60. # A single failed dispatch (transient API error) must not strand the
  61. # remaining branches, so failures are logged as warnings, not fatal.
  62. - name: Dispatch required checks per per-entry PR
  63. if: steps.bump.outputs.pr-urls != '' && steps.bump.outputs.pr-urls != '[]'
  64. env:
  65. GH_TOKEN: ${{ github.token }}
  66. PR_URLS: ${{ steps.bump.outputs.pr-urls }}
  67. run: |
  68. set -euo pipefail
  69. jq -c '.[]' <<<"$PR_URLS" | while read -r entry; do
  70. branch=$(jq -r '.branch' <<<"$entry")
  71. name=$(jq -r '.name' <<<"$entry")
  72. for wf in scan-plugins check-mcp-urls validate-plugins; do
  73. echo "Dispatching ${wf}.yml against $branch ($name)"
  74. gh workflow run "${wf}.yml" --ref "$branch" \
  75. || echo "::warning::Failed to dispatch ${wf}.yml against $branch ($name) — required check may be missing on its PR"
  76. done
  77. done