Files
deepagents/.github/workflows/dcode_release_notes.yml
dependabot[bot] 53b3dcd74e chore(deps): bump actions/setup-node from 6.4.0 to 7.0.0 in the major group (#4748)
Bumps the major group with 1 update:
[actions/setup-node](https://github.com/actions/setup-node).

Updates `actions/setup-node` from 6.4.0 to 7.0.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/setup-node/releases">actions/setup-node's
releases</a>.</em></p>
<blockquote>
<h2>v7.0.0</h2>
<h2>What's Changed</h2>
<h3>Enhancements:</h3>
<ul>
<li>Add cache-primary-key and cache-matched-key as outputs by <a
href="https://github.com/gowridurgad"><code>@​gowridurgad</code></a> in
<a
href="https://redirect.github.com/actions/setup-node/pull/1577">actions/setup-node#1577</a></li>
<li>Migrate to ESM and upgrade dependencies by <a
href="https://github.com/gowridurgad"><code>@​gowridurgad</code></a> in
<a
href="https://redirect.github.com/actions/setup-node/pull/1574">actions/setup-node#1574</a></li>
</ul>
<h3>Bug fixes:</h3>
<ul>
<li>Remove dummy NODE_AUTH_TOKEN export by <a
href="https://github.com/gowridurgad"><code>@​gowridurgad</code></a> in
<a
href="https://redirect.github.com/actions/setup-node/pull/1558">actions/setup-node#1558</a></li>
<li>Only use <code>mirrorToken</code> in <code>getManifest</code> if
it's provided by <a
href="https://github.com/deiga"><code>@​deiga</code></a> in <a
href="https://redirect.github.com/actions/setup-node/pull/1548">actions/setup-node#1548</a></li>
</ul>
<h3>Documentation updates:</h3>
<ul>
<li>Add documentation for publishing to npm with Trusted Publisher
(OIDC) by <a
href="https://github.com/chiranjib-swain"><code>@​chiranjib-swain</code></a>
in <a
href="https://redirect.github.com/actions/setup-node/pull/1536">actions/setup-node#1536</a></li>
<li>docs: Update restore-only cache documentation by <a
href="https://github.com/priya-kinthali"><code>@​priya-kinthali</code></a>
in <a
href="https://redirect.github.com/actions/setup-node/pull/1550">actions/setup-node#1550</a></li>
<li>docs: Update caching recommendations to mitigate cache poisoning
risks by <a
href="https://github.com/chiranjib-swain"><code>@​chiranjib-swain</code></a>
in <a
href="https://redirect.github.com/actions/setup-node/pull/1567">actions/setup-node#1567</a></li>
</ul>
<h3>Dependency update:</h3>
<ul>
<li>Upgrade <code>@​actions/cache</code> to 5.1.0, log cache write
denied by <a
href="https://github.com/jasongin"><code>@​jasongin</code></a> in <a
href="https://redirect.github.com/actions/setup-node/pull/1569">actions/setup-node#1569</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a
href="https://github.com/chiranjib-swain"><code>@​chiranjib-swain</code></a>
made their first contribution in <a
href="https://redirect.github.com/actions/setup-node/pull/1536">actions/setup-node#1536</a></li>
<li><a href="https://github.com/deiga"><code>@​deiga</code></a> made
their first contribution in <a
href="https://redirect.github.com/actions/setup-node/pull/1548">actions/setup-node#1548</a></li>
<li><a href="https://github.com/jasongin"><code>@​jasongin</code></a>
made their first contribution in <a
href="https://redirect.github.com/actions/setup-node/pull/1569">actions/setup-node#1569</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/setup-node/compare/v6...v7.0.0">https://github.com/actions/setup-node/compare/v6...v7.0.0</a></p>
<h2>v6.5.0</h2>
<h2>What's Changed</h2>
<ul>
<li>Update <code>@​actions/cache</code> to 5.1.0 and add security
overrides for undici and fast-xml-parser by <a
href="https://github.com/HarithaVattikuti"><code>@​HarithaVattikuti</code></a>
in <a
href="https://redirect.github.com/actions/setup-node/pull/1579">actions/setup-node#1579</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/setup-node/compare/v6.4.0...v6.5.0">https://github.com/actions/setup-node/compare/v6.4.0...v6.5.0</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/actions/setup-node/commit/820762786026740c76f36085b0efc47a31fe5020"><code>8207627</code></a>
Migrate to ESM and upgrade dependencies (<a
href="https://redirect.github.com/actions/setup-node/issues/1574">#1574</a>)</li>
<li><a
href="https://github.com/actions/setup-node/commit/04be95cf3511ea51ebf9f224ddfb99cc7ab87cd4"><code>04be95c</code></a>
Add cache-primary-key and cache-matched-key as outputs (<a
href="https://redirect.github.com/actions/setup-node/issues/1577">#1577</a>)</li>
<li><a
href="https://github.com/actions/setup-node/commit/7c2c68d20d402ed6a201ada70a81341941093140"><code>7c2c68d</code></a>
docs: Update caching recommendations to mitigate cache poisoning risks
(<a
href="https://redirect.github.com/actions/setup-node/issues/1567">#1567</a>)</li>
<li><a
href="https://github.com/actions/setup-node/commit/6a61c0375d66246de94630495909f12cf8dac84d"><code>6a61c03</code></a>
Merge pull request <a
href="https://redirect.github.com/actions/setup-node/issues/1569">#1569</a>
from jasongin/update-actions-cache-5.1.0</li>
<li><a
href="https://github.com/actions/setup-node/commit/30eb73b41ded577900c1ebf968ef95cdf8f7434f"><code>30eb73b</code></a>
Resolve high-severity audit issues</li>
<li><a
href="https://github.com/actions/setup-node/commit/4e1a87a501d0302f99e30e2748568adcb388d09f"><code>4e1a87a</code></a>
Update dist</li>
<li><a
href="https://github.com/actions/setup-node/commit/360237f0c01778d0c17291f75c56d6feae4f7574"><code>360237f</code></a>
Strict equality</li>
<li><a
href="https://github.com/actions/setup-node/commit/4f8aac5beb2f0854bc79651567a18c67eb0b9de3"><code>4f8aac5</code></a>
Bump <code>@​actions/cache</code> to 5.1.0, log cache write denied</li>
<li><a
href="https://github.com/actions/setup-node/commit/f4a67bbeca970f103397d3d2b9462cf787cd2980"><code>f4a67bb</code></a>
Only use <code>mirrorToken</code> in <code>getManifest</code> if it's
provided (<a
href="https://redirect.github.com/actions/setup-node/issues/1548">#1548</a>)</li>
<li><a
href="https://github.com/actions/setup-node/commit/0355742c943ddb13ca8a6b700f824231caa91e75"><code>0355742</code></a>
Remove dummy NODE_AUTH_TOKEN export (<a
href="https://redirect.github.com/actions/setup-node/issues/1558">#1558</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/actions/setup-node/compare/48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e...820762786026740c76f36085b0efc47a31fe5020">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/setup-node&package-manager=github_actions&previous-version=6.4.0&new-version=7.0.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-15 06:56:53 -04:00

441 lines
20 KiB
YAML

# Draft and apply curated release notes for ready deepagents-code release PRs.
# All automation runs from a trusted `main` checkout (`trusted-source`); the ambient
# GITHUB_TOKEN is read-only for contents. Release PR content is read only through
# GitHub's API at the validated commit SHA and treated as untrusted data; it is
# never checked out or executed. Drafting is a single request to a fixed model API:
# untrusted text is never given filesystem, shell, or network tools, and only the
# selected provider key is present in that process. Repository mutations —
# curated-notes comments, PR-body updates, and a
# non-force Git Data API update to the release-please branch — are performed only by
# specific helper steps that receive a short-lived GitHub App token. (The validate job's
# permission/readiness feedback comments use the default GITHUB_TOKEN.)
name: "📝 Curate dcode release notes"
on:
pull_request_target:
types: [ready_for_review]
issue_comment:
types: [created]
permissions:
contents: read
concurrency:
group: dcode-release-notes-${{ github.event.pull_request.number || github.event.issue.number }}
cancel-in-progress: false
jobs:
validate:
name: Validate release-notes command
# Skip the noise: run only for ready_for_review PR events, or PR comments that
# mention the bot AND come from a repo insider. The author_association filter
# stops an external drive-by mention from spawning a run (Actions-minute burn)
# and mirrors the in-script FEEDBACK_ASSOCIATIONS gate; validateTrigger still
# re-checks the exact command and write permission, so this only drops comments
# that could never have triggered an action.
if: >-
github.event_name == 'pull_request_target' ||
(github.event.issue.pull_request &&
contains(github.event.comment.body, '@dcode-release-bot') &&
contains(fromJSON('["OWNER","MEMBER","COLLABORATOR"]'), github.event.comment.author_association))
runs-on: ubuntu-latest
timeout-minutes: 5
permissions:
contents: read
issues: write
pull-requests: read
outputs:
should-run: ${{ steps.validate.outputs.should-run }}
command: ${{ steps.validate.outputs.command }}
number: ${{ steps.validate.outputs.number }}
version: ${{ steps.validate.outputs.version }}
head: ${{ steps.validate.outputs.head }}
branch: ${{ steps.validate.outputs.branch }}
steps:
- name: Checkout trusted automation
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
ref: main
path: trusted-source
persist-credentials: false
- name: Validate event, PR, and maintainer permission
id: validate
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
env:
BOT_LOGIN: ${{ vars.DCODE_RELEASE_BOT_LOGIN }}
BOT_ID: ${{ vars.DCODE_RELEASE_BOT_ID }}
with:
script: |
const { validateTrigger } = require('./trusted-source/.github/scripts/dcode-release-notes.js');
const result = await validateTrigger({
github,
context,
core,
botLogin: process.env.BOT_LOGIN,
botId: process.env.BOT_ID,
});
core.setOutput('should-run', String(result.shouldRun === true));
for (const key of ['command', 'number', 'version', 'head', 'branch']) {
core.setOutput(key, result[key] ?? '');
}
# A transient error while validating an insider's manual @dcode-release-bot
# command would otherwise leave only a red job in the Actions tab; surface it
# on the PR so the maintainer who ran the command knows to retry. Scoped to the
# manual (issue_comment) path so a transient failure on an unrelated
# ready_for_review PR does not draw a comment, and best-effort so it can never
# mask the underlying failure that already reds the job.
- name: Comment on validation failure
if: ${{ failure() && github.event_name == 'issue_comment' }}
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
with:
script: |
try {
await github.rest.issues.createComment({
...context.repo,
issue_number: context.payload.issue.number,
body: 'Could not validate the `@dcode-release-bot` command because of a workflow error; see the run logs and try the command again.',
});
} catch (error) {
core.warning(`Could not post the validation-failure comment: ${error instanceof Error ? error.message : String(error)}`);
}
draft:
name: Draft curated release notes
needs: validate
if: needs.validate.outputs.should-run == 'true' && needs.validate.outputs.command == 'draft'
runs-on: ubuntu-latest
timeout-minutes: 30
environment: release-dcode
permissions:
contents: read
steps:
- name: Generate release bot token
id: app-token
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3
with:
client-id: ${{ secrets.ORG_MEMBERSHIP_APP_CLIENT_ID }}
private-key: ${{ secrets.ORG_MEMBERSHIP_APP_PRIVATE_KEY }}
permission-contents: write
permission-issues: write
permission-pull-requests: write
- name: Checkout trusted automation
id: checkout-trusted
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
ref: main
path: trusted-source
persist-credentials: false
- name: Prepare isolated drafting input
id: prepare
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
env:
PR_NUMBER: ${{ needs.validate.outputs.number }}
PR_HEAD: ${{ needs.validate.outputs.head }}
with:
script: |
const { prepareDraft } = require('./trusted-source/.github/scripts/dcode-release-notes.js');
try {
const result = await prepareDraft({
github,
...context.repo,
number: Number(process.env.PR_NUMBER),
expectedHead: process.env.PR_HEAD,
runnerTemp: process.env.RUNNER_TEMP,
});
for (const [key, value] of Object.entries(result)) core.setOutput(key, value);
} catch (error) {
// Record the reason so the failure-comment step can surface it on the
// PR instead of the maintainer having to open the Actions logs.
core.setOutput('error', error instanceof Error ? error.message : String(error));
throw error;
}
# Pin Node so the drafting helper (which relies on global fetch and
# AbortSignal.timeout) doesn't depend on whatever the runner image
# preinstalls; matches the version the helper tests run under in ci.yml.
- name: Set up Node
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v6
with:
node-version: "24"
- name: Draft polished release notes without model tools
id: draft-model
continue-on-error: true
env:
MODEL_SPEC: ${{ vars.DCODE_RELEASE_MODEL }}
# Put only the configured provider's credential in this process. The
# deterministic helper sends one request to a fixed provider endpoint;
# model output is never interpreted as a tool call or URL.
MODEL_API_KEY: >-
${{ startsWith(vars.DCODE_RELEASE_MODEL, 'openai:') && secrets.OPENAI_API_KEY ||
startsWith(vars.DCODE_RELEASE_MODEL, 'anthropic:') && secrets.ANTHROPIC_API_KEY ||
startsWith(vars.DCODE_RELEASE_MODEL, 'google_genai:') && secrets.GOOGLE_API_KEY ||
'' }}
INPUT_FILE: ${{ steps.prepare.outputs.input }}
OUTPUT_FILE: ${{ steps.prepare.outputs.output }}
run: node ./trusted-source/.github/scripts/draft-dcode-release-notes.js
- name: Post bot-authored curated draft
id: post
if: steps.draft-model.outcome == 'success'
continue-on-error: true
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
env:
DRAFT_STATE: ${{ steps.prepare.outputs.state }}
DRAFT_OUTPUT: ${{ steps.prepare.outputs.output }}
APP_SLUG: ${{ steps.app-token.outputs.app-slug }}
BOT_LOGIN: ${{ vars.DCODE_RELEASE_BOT_LOGIN }}
BOT_ID: ${{ vars.DCODE_RELEASE_BOT_ID }}
with:
github-token: ${{ steps.app-token.outputs.token }}
script: |
const { postDraft } = require('./trusted-source/.github/scripts/dcode-release-notes.js');
try {
await postDraft({
github,
...context.repo,
stateFile: process.env.DRAFT_STATE,
outputFile: process.env.DRAFT_OUTPUT,
appSlug: process.env.APP_SLUG,
login: process.env.BOT_LOGIN,
id: process.env.BOT_ID,
});
} catch (error) {
core.setOutput('error', error instanceof Error ? error.message : String(error));
throw error;
}
# Runs for any non-success in prepare/agent/post, including a hard failure in
# `prepare` (which would otherwise skip a plain `success()`-gated step and
# leave the maintainer with no PR feedback). `!cancelled()` keeps it firing
# after an earlier step failed the job.
- name: Comment on drafting failure
if: ${{ !cancelled() && (steps.prepare.outcome != 'success' || steps.draft-model.outcome != 'success' || steps.post.outcome != 'success') }}
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
env:
PR_NUMBER: ${{ needs.validate.outputs.number }}
PR_HEAD: ${{ needs.validate.outputs.head }}
APP_SLUG: ${{ steps.app-token.outputs.app-slug }}
BOT_LOGIN: ${{ vars.DCODE_RELEASE_BOT_LOGIN }}
BOT_ID: ${{ vars.DCODE_RELEASE_BOT_ID }}
PREPARE_ERROR: ${{ steps.prepare.outputs.error }}
POST_ERROR: ${{ steps.post.outputs.error }}
DRAFT_OUTCOME: ${{ steps.draft-model.outcome }}
CHECKOUT_TRUSTED_OUTCOME: ${{ steps.checkout-trusted.outcome }}
with:
github-token: ${{ steps.app-token.outputs.token }}
script: |
const number = Number(process.env.PR_NUMBER);
const details = process.env.PREPARE_ERROR
|| process.env.POST_ERROR
|| (process.env.CHECKOUT_TRUSTED_OUTCOME !== 'success'
? 'Checking out the trusted automation failed; see the workflow logs.'
: `The drafting step did not succeed (outcome: ${process.env.DRAFT_OUTCOME || 'skipped'}); see the workflow logs.`);
try {
const { postDraftFailure } = require('./trusted-source/.github/scripts/dcode-release-notes.js');
await postDraftFailure({
github,
...context.repo,
number,
head: process.env.PR_HEAD,
appSlug: process.env.APP_SLUG,
login: process.env.BOT_LOGIN,
id: process.env.BOT_ID,
message: details,
});
} catch (error) {
// The trusted checkout can itself fail, leaving trusted-source/ (and the
// helper module) absent so the require above throws — exactly the case
// the CHECKOUT_TRUSTED_OUTCOME branch above is written to report. Fall
// back to a direct comment (no bot-identity check or per-head dedup) so
// the maintainer still gets PR feedback instead of only a red run.
core.warning(`Falling back to a direct drafting-failure comment: ${error instanceof Error ? error.message : String(error)}`);
await github.rest.issues.createComment({
...context.repo,
issue_number: number,
body: `Automatic release-note drafting failed.\n\n${details}\n\nAfter resolving the issue, a maintainer should run \`@dcode-release-bot draft\` again.`,
});
}
- name: Fail when drafting or comment publication failed
if: ${{ !cancelled() && (steps.prepare.outcome != 'success' || steps.draft-model.outcome != 'success' || steps.post.outcome != 'success') }}
run: |
echo "::error::Curated release-note drafting failed; see the PR comment and earlier step logs."
exit 1
apply:
name: Apply curated release notes
needs: validate
if: needs.validate.outputs.should-run == 'true' && needs.validate.outputs.command == 'apply'
runs-on: ubuntu-latest
timeout-minutes: 10
environment: release-dcode
permissions:
contents: read
steps:
- name: Generate release bot token
id: app-token
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3
with:
client-id: ${{ secrets.ORG_MEMBERSHIP_APP_CLIENT_ID }}
private-key: ${{ secrets.ORG_MEMBERSHIP_APP_PRIVATE_KEY }}
permission-contents: write
permission-issues: write
permission-pull-requests: write
- name: Checkout trusted automation
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
ref: main
path: trusted-source
persist-credentials: false
- name: Validate override and prepare changelog/body edits
id: prepare-apply
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
env:
PR_NUMBER: ${{ needs.validate.outputs.number }}
PR_HEAD: ${{ needs.validate.outputs.head }}
APP_SLUG: ${{ steps.app-token.outputs.app-slug }}
BOT_LOGIN: ${{ vars.DCODE_RELEASE_BOT_LOGIN }}
BOT_ID: ${{ vars.DCODE_RELEASE_BOT_ID }}
APPLY_STATE: ${{ runner.temp }}/dcode-release-apply.json
CHANGELOG_FILE: ${{ runner.temp }}/dcode-release-changelog.md
with:
github-token: ${{ steps.app-token.outputs.token }}
script: |
const { prepareApply } = require('./trusted-source/.github/scripts/dcode-release-notes.js');
try {
await prepareApply({
github,
...context.repo,
number: Number(process.env.PR_NUMBER),
expectedHead: process.env.PR_HEAD,
changelogFile: process.env.CHANGELOG_FILE,
stateFile: process.env.APPLY_STATE,
appSlug: process.env.APP_SLUG,
login: process.env.BOT_LOGIN,
id: process.env.BOT_ID,
});
core.setOutput('state', process.env.APPLY_STATE);
core.setOutput('changelog', process.env.CHANGELOG_FILE);
} catch (error) {
core.setOutput('error', error instanceof Error ? error.message : String(error));
throw error;
}
- name: Create and publish the apply commit without rewriting history
id: commit
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
env:
APPLY_STATE: ${{ steps.prepare-apply.outputs.state }}
CHANGELOG_FILE: ${{ steps.prepare-apply.outputs.changelog }}
APP_SLUG: ${{ steps.app-token.outputs.app-slug }}
BOT_LOGIN: ${{ vars.DCODE_RELEASE_BOT_LOGIN }}
BOT_ID: ${{ vars.DCODE_RELEASE_BOT_ID }}
with:
github-token: ${{ steps.app-token.outputs.token }}
script: |
const { createApplyCommit } = require('./trusted-source/.github/scripts/dcode-release-notes.js');
try {
const result = await createApplyCommit({
github,
...context.repo,
stateFile: process.env.APPLY_STATE,
changelogFile: process.env.CHANGELOG_FILE,
appSlug: process.env.APP_SLUG,
login: process.env.BOT_LOGIN,
id: process.env.BOT_ID,
});
core.setOutput('applied-head', result.appliedHead);
} catch (error) {
// Record the reason so the failure-comment step can surface it on the
// PR instead of the maintainer having to open the Actions logs.
core.setOutput('error', error instanceof Error ? error.message : String(error));
throw error;
}
- name: Update PR preview and publish applied metadata
id: publish
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
env:
APPLY_STATE: ${{ steps.prepare-apply.outputs.state }}
APPLIED_HEAD: ${{ steps.commit.outputs.applied-head }}
APP_SLUG: ${{ steps.app-token.outputs.app-slug }}
BOT_LOGIN: ${{ vars.DCODE_RELEASE_BOT_LOGIN }}
BOT_ID: ${{ vars.DCODE_RELEASE_BOT_ID }}
with:
github-token: ${{ steps.app-token.outputs.token }}
script: |
const { publishAppliedState } = require('./trusted-source/.github/scripts/dcode-release-notes.js');
try {
await publishAppliedState({
github,
...context.repo,
stateFile: process.env.APPLY_STATE,
appliedHead: process.env.APPLIED_HEAD,
appSlug: process.env.APP_SLUG,
login: process.env.BOT_LOGIN,
id: process.env.BOT_ID,
});
} catch (error) {
core.setOutput('error', error instanceof Error ? error.message : String(error));
throw error;
}
# The apply steps have no continue-on-error, so any failure reds the job;
# this mirrors the draft job's failure comment so a maintainer who ran
# `apply` sees the reason on the PR instead of only a red Actions run.
- name: Comment on apply failure
if: failure()
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
env:
PR_NUMBER: ${{ needs.validate.outputs.number }}
PR_HEAD: ${{ needs.validate.outputs.head }}
APP_SLUG: ${{ steps.app-token.outputs.app-slug }}
BOT_LOGIN: ${{ vars.DCODE_RELEASE_BOT_LOGIN }}
BOT_ID: ${{ vars.DCODE_RELEASE_BOT_ID }}
PREPARE_ERROR: ${{ steps.prepare-apply.outputs.error }}
COMMIT_ERROR: ${{ steps.commit.outputs.error }}
PUBLISH_ERROR: ${{ steps.publish.outputs.error }}
COMMIT_OUTCOME: ${{ steps.commit.outcome }}
with:
github-token: ${{ steps.app-token.outputs.token }}
script: |
const number = Number(process.env.PR_NUMBER);
// Steps run prepare-apply -> commit -> publish, each skipping the rest on
// failure, so this precedence surfaces the first (root-cause) failure.
const details = process.env.PREPARE_ERROR
|| process.env.COMMIT_ERROR
|| process.env.PUBLISH_ERROR
|| `commit=${process.env.COMMIT_OUTCOME || 'skipped'}; see the workflow logs.`;
try {
const { postApplyFailure } = require('./trusted-source/.github/scripts/dcode-release-notes.js');
await postApplyFailure({
github,
...context.repo,
number,
head: process.env.PR_HEAD,
appSlug: process.env.APP_SLUG,
login: process.env.BOT_LOGIN,
id: process.env.BOT_ID,
message: details,
});
} catch (error) {
// The trusted checkout can itself fail, leaving the helper module absent
// so the require above throws. Fall back to a direct comment (no
// bot-identity check or per-head dedup) so the maintainer still gets PR
// feedback instead of only a red run.
core.warning(`Falling back to a direct apply-failure comment: ${error instanceof Error ? error.message : String(error)}`);
await github.rest.issues.createComment({
...context.repo,
issue_number: number,
body: `Applying curated release notes failed.\n\n${details}`,
});
}