-
-
Notifications
You must be signed in to change notification settings - Fork 3
73 lines (63 loc) · 2.51 KB
/
nix-update.yml
File metadata and controls
73 lines (63 loc) · 2.51 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
name: Update flake.lock
on:
schedule:
- cron: "30 16 * * FRI" # Every Friday at 16:30 UTC
workflow_dispatch:
permissions:
contents: write
pull-requests: write
actions: write
defaults:
run:
shell: bash -euo pipefail {0}
jobs:
update-lock:
name: Update flake.lock
runs-on: ubuntu-latest
steps:
- name: Generate GitHub App Token
id: generate-token
uses: actions/create-github-app-token@f8d387b68d61c58ab83c6c016672934102569859 # v3.0.0
with:
app-id: ${{ secrets.APP_ID }}
private-key: ${{ secrets.APP_PRIVATE_KEY }}
owner: ${{ github.repository_owner }}
repositories: ${{ github.event.repository.name }}
- name: Generate Auto-Merge GitHub App Token
id: generate-automerge-token
uses: actions/create-github-app-token@f8d387b68d61c58ab83c6c016672934102569859 # v3.0.0
with:
app-id: ${{ secrets.AUTOMERGE_APP_ID }}
private-key: ${{ secrets.AUTOMERGE_APP_PRIVATE_KEY }}
owner: ${{ github.repository_owner }}
repositories: ${{ github.event.repository.name }}
- name: Checkout repository
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
token: ${{ steps.generate-token.outputs.token }}
- name: Install Nix
uses: cachix/install-nix-action@1ca7d21a94afc7c957383a2d217460d980de4934 # v31.10.1
- name: Update flake.lock
run: nix flake update
- name: Create pull request for flake.lock update
id: create-pr
uses: peter-evans/create-pull-request@c0f553fe549906ede9cf27b5156039d195d2ece0 # v8.1.0
with:
token: ${{ steps.generate-token.outputs.token }}
commit-message: "chore(deps): update nix flake dependencies"
branch: update-flake-lock
title: "chore(deps): update flake.lock"
body: "This pull request updates the flake.lock file with the latest flake inputs."
author: "missionis[bot] <234988995+missionis[bot]@users.noreply.github.com>"
committer: "missionis[bot] <234988995+missionis[bot]@users.noreply.github.com>"
labels: |
dependencies
nix
delete-branch: true
- name: Enable auto-merge
id: enable-auto-merge
if: steps.create-pr.outputs.pull-request-number
run: |
gh pr merge --auto -ds ${{ steps.create-pr.outputs.pull-request-number }}
env:
GH_TOKEN: ${{ steps.generate-automerge-token.outputs.token }}