Skip to content

fix(ci): grant the secret-scanner reusable its required job permissio… #217

fix(ci): grant the secret-scanner reusable its required job permissio…

fix(ci): grant the secret-scanner reusable its required job permissio… #217

Workflow file for this run

# SPDX-License-Identifier: MPL-2.0
# Finishingbot - Release readiness validation
# Part of gitbot-fleet (hyperpolymath/gitbot-fleet :: bots/finishingbot)
name: Finishingbot Release Check
permissions:
contents: read
on:
push:
branches: [main, develop]
pull_request:
branches: [main]
workflow_dispatch:
env:
# Pinned gitbot-fleet commit. Bump in lockstep when the fleet changes.
GITBOT_FLEET_REF: 2e0ea3ca67821a91e650f51bf48a6cfd1c7aae1c
jobs:
release-readiness:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4
- name: Setup Rust toolchain
uses: dtolnay/rust-toolchain@6d9817901c499d6b02debbb57edb38d33daa680b # stable
with:
toolchain: stable
# Clone BEFORE the rust-cache step: rust-cache needs the workspace
# (Cargo.lock) to exist to key the cache, and cloning into a
# cache-created directory fails with `destination path ... already
# exists and is not an empty directory` (exit 128).
- name: Fetch gitbot-fleet at pinned ref
run: |
rm -rf "$RUNNER_TEMP/gitbot-fleet"
git clone --no-checkout --filter=tree:0 \
https://github.com/hyperpolymath/gitbot-fleet.git \
"$RUNNER_TEMP/gitbot-fleet"
git -C "$RUNNER_TEMP/gitbot-fleet" checkout "$GITBOT_FLEET_REF"
- name: Cache dependencies
uses: Swatinem/rust-cache@9d47c6ad4b02e050fd481d890b2ea34778fd09d6 # v2
with:
workspaces: ${{ runner.temp }}/gitbot-fleet/bots/finishingbot
- name: Build finishingbot
working-directory: ${{ runner.temp }}/gitbot-fleet/bots/finishingbot
env:
OPENSSL_NO_VENDOR: 1
run: cargo build --release
- name: Run finishingbot audit
id: finishingbot
continue-on-error: true
run: |
# The finishingbot crate's binary is `finishing-bot` (hyphenated).
# A non-zero audit is the intended gating signal. Capture it
# without letting `set -e` abort the step before the exit-code
# file is written, then re-exit with it so this step's outcome
# is `failure` and the "Fail on …findings" step below triggers.
rc=0
"$RUNNER_TEMP/gitbot-fleet/bots/finishingbot/target/release/finishing-bot" \
--path "$GITHUB_WORKSPACE" audit > finishingbot-results.txt 2>&1 || rc=$?
echo "$rc" > finishingbot-exit-code.txt
exit "$rc"
- name: Display results
if: always()
run: |
if [ -f finishingbot-results.txt ]; then
echo "## Finishingbot Release Readiness Results" >> $GITHUB_STEP_SUMMARY
echo '```' >> $GITHUB_STEP_SUMMARY
cat finishingbot-results.txt >> $GITHUB_STEP_SUMMARY
echo '```' >> $GITHUB_STEP_SUMMARY
exit_code=$(cat finishingbot-exit-code.txt 2>/dev/null || echo unknown)
if [ "$exit_code" = "0" ]; then
echo "✅ Release readiness checks passed" >> $GITHUB_STEP_SUMMARY
else
echo "❌ Release readiness checks failed (exit code: $exit_code)" >> $GITHUB_STEP_SUMMARY
fi
fi
- name: Upload results
if: always()
uses: actions/upload-artifact@1eb3cb2b3e0f29609092a73eb033bb759a334595 # v4
with:
name: finishingbot-results
path: finishingbot-results.txt
if-no-files-found: ignore
- name: Fail on high-severity findings
if: steps.finishingbot.outcome == 'failure'
run: exit 1