From 0ff8306e93e3567ee79f60fc97f6575e90a910b8 Mon Sep 17 00:00:00 2001 From: Matt Walters Date: Wed, 18 Feb 2026 18:20:08 -0600 Subject: [PATCH] fix(ci): always create sync commit for child repo updates MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Remove the feat/fix gate from on-child-update.yml — all child repo merges now create sync commits in the parent. Release-please still only includes feat/fix in changelogs, so the release PR remains curated. Also hardens both workflows against command injection by moving all ${{ }} expressions into env: blocks, and fixes a stale "Destroy" comment in worktree_cloud.bats. Implements [[tasks/meta-64]] Co-authored-by: Claude Co-Authored-By: Claude Opus 4.6 --- .github/workflows/on-child-update.yml | 85 ++++++++++++++++----------- tests/worktree_cloud.bats | 2 +- 2 files changed, 51 insertions(+), 36 deletions(-) diff --git a/.github/workflows/on-child-update.yml b/.github/workflows/on-child-update.yml index 4483d86..af2586f 100644 --- a/.github/workflows/on-child-update.yml +++ b/.github/workflows/on-child-update.yml @@ -41,45 +41,55 @@ jobs: - name: Extract payload id: payload + env: + EVENT_NAME: ${{ github.event_name }} + DISPATCH_REPO_NAME: ${{ github.event.client_payload.repo_name }} + DISPATCH_SHORT_SHA: ${{ github.event.client_payload.short_sha }} + DISPATCH_MESSAGE: ${{ github.event.client_payload.message }} + DISPATCH_TYPE: ${{ github.event.client_payload.type }} + DISPATCH_ACTOR: ${{ github.event.client_payload.actor }} + INPUT_REPO_NAME: ${{ github.event.inputs.repo_name }} + INPUT_SHORT_SHA: ${{ github.event.inputs.short_sha }} + INPUT_MESSAGE: ${{ github.event.inputs.message }} + INPUT_TYPE: ${{ github.event.inputs.type }} + INPUT_ACTOR: ${{ github.event.inputs.actor }} run: | - # Handle both repository_dispatch and workflow_dispatch - if [ "${{ github.event_name }}" = "repository_dispatch" ]; then - echo "repo_name=${{ github.event.client_payload.repo_name }}" >> $GITHUB_OUTPUT - echo "short_sha=${{ github.event.client_payload.short_sha }}" >> $GITHUB_OUTPUT - echo "message=${{ github.event.client_payload.message }}" >> $GITHUB_OUTPUT - echo "type=${{ github.event.client_payload.type }}" >> $GITHUB_OUTPUT - echo "actor=${{ github.event.client_payload.actor }}" >> $GITHUB_OUTPUT - else - echo "repo_name=${{ github.event.inputs.repo_name }}" >> $GITHUB_OUTPUT - echo "short_sha=${{ github.event.inputs.short_sha }}" >> $GITHUB_OUTPUT - echo "message=${{ github.event.inputs.message }}" >> $GITHUB_OUTPUT - echo "type=${{ github.event.inputs.type }}" >> $GITHUB_OUTPUT - echo "actor=${{ github.event.inputs.actor }}" >> $GITHUB_OUTPUT - fi + write_output() { + local key="$1" value="$2" + local delim="__EOF__$(date +%s%N)_$RANDOM" + { + printf '%s<<%s\n' "$key" "$delim" + printf '%s\n' "$value" + printf '%s\n' "$delim" + } >> "$GITHUB_OUTPUT" + } - - name: Check if release-worthy - id: check - run: | - TYPE="${{ steps.payload.outputs.type }}" - if [ "$TYPE" = "feat" ] || [ "$TYPE" = "fix" ]; then - echo "should_commit=true" >> $GITHUB_OUTPUT + # Handle both repository_dispatch and workflow_dispatch + if [ "$EVENT_NAME" = "repository_dispatch" ]; then + write_output repo_name "$DISPATCH_REPO_NAME" + write_output short_sha "$DISPATCH_SHORT_SHA" + write_output message "$DISPATCH_MESSAGE" + write_output type "$DISPATCH_TYPE" + write_output actor "$DISPATCH_ACTOR" else - echo "should_commit=false" >> $GITHUB_OUTPUT - echo "Skipping: commit type '$TYPE' does not trigger release" + write_output repo_name "$INPUT_REPO_NAME" + write_output short_sha "$INPUT_SHORT_SHA" + write_output message "$INPUT_MESSAGE" + write_output type "$INPUT_TYPE" + write_output actor "$INPUT_ACTOR" fi - name: Create sync commit - if: steps.check.outputs.should_commit == 'true' + env: + REPO_NAME: ${{ steps.payload.outputs.repo_name }} + SHORT_SHA: ${{ steps.payload.outputs.short_sha }} + MESSAGE: ${{ steps.payload.outputs.message }} + TYPE: ${{ steps.payload.outputs.type }} + ACTOR: ${{ steps.payload.outputs.actor }} run: | git config user.name "github-actions[bot]" git config user.email "github-actions[bot]@users.noreply.github.com" - REPO_NAME="${{ steps.payload.outputs.repo_name }}" - SHORT_SHA="${{ steps.payload.outputs.short_sha }}" - MESSAGE="${{ steps.payload.outputs.message }}" - TYPE="${{ steps.payload.outputs.type }}" - ACTOR="${{ steps.payload.outputs.actor }}" - # Strip the "type: " prefix from the message if present CLEAN_MSG="${MESSAGE#*: }" @@ -92,10 +102,15 @@ jobs: git push - name: Log sync + env: + EVENT_NAME: ${{ github.event_name }} + REPO_NAME: ${{ steps.payload.outputs.repo_name }} + SHORT_SHA: ${{ steps.payload.outputs.short_sha }} + TYPE: ${{ steps.payload.outputs.type }} + MESSAGE: ${{ steps.payload.outputs.message }} run: | - echo "Event: ${{ github.event_name }}" - echo "Repo: ${{ steps.payload.outputs.repo_name }}" - echo "SHA: ${{ steps.payload.outputs.short_sha }}" - echo "Type: ${{ steps.payload.outputs.type }}" - echo "Message: ${{ steps.payload.outputs.message }}" - echo "Should commit: ${{ steps.check.outputs.should_commit }}" + echo "Event: $EVENT_NAME" + echo "Repo: $REPO_NAME" + echo "SHA: $SHORT_SHA" + echo "Type: $TYPE" + echo "Message: $MESSAGE" diff --git a/tests/worktree_cloud.bats b/tests/worktree_cloud.bats index 31fd16d..0d4740a 100644 --- a/tests/worktree_cloud.bats +++ b/tests/worktree_cloud.bats @@ -304,7 +304,7 @@ with open('$STORE') as f: assert any(v['name'] == 'store-rm' for v in data['worktrees'].values()) " - # Destroy + # Remove run "$META_BIN" git worktree remove store-rm [ "$status" -eq 0 ]