Files
mlpack/.github/workflows/update-cli11.yaml
T
naveen a47e4359ba chore: Set permissions for GitHub actions
Restrict the GitHub token permissions only to the required ones; this way, even if the attackers will succeed in compromising your workflow, they won’t be able to do much.

- Included permissions for the action. https://github.com/ossf/scorecard/blob/main/docs/checks.md#token-permissions

https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#permissions

https://docs.github.com/en/actions/using-jobs/assigning-permissions-to-jobs

[Keeping your GitHub Actions and workflows secure Part 1: Preventing pwn requests](https://securitylab.github.com/research/github-actions-preventing-pwn-requests/)

Signed-off-by: naveen <172697+naveensrinivasan@users.noreply.github.com>
2022-06-14 00:30:10 +00:00

52 lines
2.4 KiB
YAML

name: Update CLI11
on:
workflow_dispatch:
schedule:
- cron: '0 10 1/16 * *'
permissions:
contents: read
jobs:
updateCLI11:
permissions:
contents: write # for peter-evans/create-pull-request to create branch
pull-requests: write # for peter-evans/create-pull-request to create a PR
if: ${{ github.repository == 'mlpack/mlpack' }}
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v2
- name: Get Latest CLI11 Tagged Release
id: cli11-header
run: |
# Ping version information upstream.
CLI11_RELEASE_JSON=$(curl -sL https://api.github.com/repos/CLIUtils/CLI11/releases/latest)
CLI11_RELEASE_VERSION=$(jq -r ".tag_name" <<< "$CLI11_RELEASE_JSON" | tr -d v)
echo ::set-output name=release_tag::$(echo $CLI11_RELEASE_VERSION)
# Extract out version information from git repository.
CLI11_VERSION_VALUE=$(grep -i ".*#define CLI11_VERSION.*" src/mlpack/bindings/cli/third_party/CLI/CLI11.hpp | grep -Po "(\d+\.)+\d+")
# Set the current release tag.
echo ::set-output name=current_tag::$(echo $CLI11_VERSION_VALUE)
- name: Update CLI11
if: steps.cli11-header.outputs.current_tag != steps.cli11-header.outputs.release_tag
env:
CURRENT_TAG: ${{ steps.cli11-header.outputs.current_tag }}
RELEASE_TAG: ${{ steps.cli11-header.outputs.release_tag }}
run: |
# Delete the CLI11.hpp.
rm -f src/mlpack/bindings/cli/third_party/CLI/CLI11.hpp
# Download the release.
curl -sL https://github.com/CLIUtils/CLI11/releases/latest/download/CLI11.hpp -o src/mlpack/bindings/cli/third_party/CLI/CLI11.hpp
- name: Create Pull Request For CLI11
if: steps.cli11-header.outputs.current_tag != steps.cli11-header.outputs.release_tag
uses: peter-evans/create-pull-request@v3
with:
commit-message: Upgrade CLI11 to ${{ steps.cli11-header.outputs.release_tag }}
title: Upgrade CLI11 to ${{ steps.cli11-header.outputs.release_tag }}
body: |
Updates [CLIUtils/CLI11](https://github.com/CLIUtils/CLI11) to ${{ steps.cli11-header.outputs.release_tag }}.
Auto-generated by [create-pull-request](https://github.com/peter-evans/create-pull-request).
labels: update dependencies, automated PR
branch: cli11-header-updates-${{ steps.cli11-header.outputs.release_tag }}