diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 79c64413d..c6d92ddd7 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -31,6 +31,14 @@ updates: - dependency-name: better-auth versions: - ">= 1.7.0" + # eslint 10 is outside eslint-plugin-react's peer range, so npm install + # fails with ERESOLVE. Drop these entries once the plugin supports 10. + - dependency-name: eslint + versions: + - ">= 10.0.0" + - dependency-name: "@eslint/js" + versions: + - ">= 10.0.0" - package-ecosystem: github-actions directory: / @@ -45,12 +53,15 @@ updates: - "*" # Python — every packages/* dir with a pyproject.toml + uv.lock. The - # sandbox-images/locks/python-tools project is left out: `sandbox:images lock` - # generates it from the image tool manifest, so edits to it fail the - # freshness check. + # sandbox-images/locks tree is left out: `sandbox:images lock` generates it + # from the image tool manifest and the runtime uv.lock, so edits to it fail + # the freshness check. The dependabot-image-locks workflow regenerates it on + # each Dependabot PR instead. - package-ecosystem: uv directories: - /packages/* + exclude-paths: + - "packages/sandbox-images/locks/**" schedule: interval: weekly day: monday diff --git a/.github/workflows/dependabot-image-locks.yml b/.github/workflows/dependabot-image-locks.yml new file mode 100644 index 000000000..1db09af2c --- /dev/null +++ b/.github/workflows/dependabot-image-locks.yml @@ -0,0 +1,57 @@ +name: Dependabot image locks + +# Dependabot bumps packages/sandbox-runtime/uv.lock but cannot run +# `sandbox:images lock`, so the exported image locks go stale and the +# Sandbox Images freshness check fails. This regenerates them on the PR branch. +# +# The push uses a GitHub App token so the new commit triggers CI; a +# GITHUB_TOKEN push would not. Dependabot-triggered runs only see Dependabot +# secrets, so GH_APP_ID and GH_APP_PRIVATE_KEY must be set there. + +on: + pull_request: + paths: + - "packages/sandbox-runtime/uv.lock" + - ".nvmrc" + +permissions: + contents: read + +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true + +jobs: + regenerate: + if: github.event.pull_request.user.login == 'dependabot[bot]' + runs-on: ubuntu-latest + timeout-minutes: 10 + steps: + - uses: actions/create-github-app-token@v3 + id: app-token + with: + app-id: ${{ secrets.GH_APP_ID }} + private-key: ${{ secrets.GH_APP_PRIVATE_KEY }} + - uses: actions/checkout@v7 + with: + ref: ${{ github.head_ref }} + token: ${{ steps.app-token.outputs.token }} + - uses: actions/setup-node@v7 + with: + node-version-file: .nvmrc + - uses: astral-sh/setup-uv@v7 + with: + version: "0.9.7" + - name: Regenerate image locks + run: python3 packages/sandbox-images/cli.py lock + - name: Commit and push + run: | + if git diff --quiet -- packages/sandbox-images/locks; then + echo "Image locks already fresh." + exit 0 + fi + git config user.name "github-actions[bot]" + git config user.email "41898282+github-actions[bot]@users.noreply.github.com" + git add packages/sandbox-images/locks + git commit -m "chore: regenerate sandbox image locks" + git push