00759548aa
Merge https://github.com/google/adk-python/pull/6601 This PR resolves 58 security and workflow linting findings identified by zizmor across 13 GitHub Actions workflow files. PiperOrigin-RevId: 962236543
91 lines
3.3 KiB
YAML
91 lines
3.3 KiB
YAML
# Copyright 2026 Google LLC
|
|
#
|
|
# Licensed under the Apache License, Version 2.0 (the "License");
|
|
# you may not use this file except in compliance with the License.
|
|
# You may obtain a copy of the License at
|
|
#
|
|
# http://www.apache.org/licenses/LICENSE-2.0
|
|
#
|
|
# Unless required by applicable law or agreed to in writing, software
|
|
# distributed under the License is distributed on an "AS IS" BASIS,
|
|
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
# See the License for the specific language governing permissions and
|
|
# limitations under the License.
|
|
|
|
# Step 3 (optional): Cherry-picks a commit from a base branch (main or v1) into the active release candidate branch.
|
|
# Use this between step 1 and step 4 to include hotfixes in an in-progress release.
|
|
# Note: Does NOT auto-trigger release-please to preserve manual changelog edits.
|
|
name: "Release: Cherry-pick"
|
|
|
|
on:
|
|
workflow_dispatch:
|
|
inputs:
|
|
branch:
|
|
description: 'Branch line of the release candidate (main or v1)'
|
|
required: true
|
|
default: 'main'
|
|
type: choice
|
|
options:
|
|
- main
|
|
- v1
|
|
commit_sha:
|
|
description: 'Commit SHA to cherry-pick'
|
|
required: true
|
|
|
|
permissions:
|
|
contents: write
|
|
pull-requests: write
|
|
|
|
jobs:
|
|
cherry-pick:
|
|
if: github.repository == 'google/adk-python'
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Determine Branch Configurations
|
|
id: config
|
|
run: |
|
|
BRANCH="${{ inputs.branch }}"
|
|
if [ "$BRANCH" = "v1" ]; then
|
|
echo "candidate_branch=release/v1-candidate" >> $GITHUB_OUTPUT
|
|
else
|
|
echo "candidate_branch=release/candidate" >> $GITHUB_OUTPUT
|
|
fi
|
|
|
|
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
|
|
with:
|
|
ref: ${{ steps.config.outputs.candidate_branch }}
|
|
token: ${{ secrets.RELEASE_PAT }}
|
|
fetch-depth: 0
|
|
|
|
- name: Configure git identity
|
|
env:
|
|
GH_TOKEN: ${{ secrets.RELEASE_PAT }}
|
|
run: |
|
|
USER_JSON=$(gh api user 2>/dev/null || true)
|
|
LOGIN=$(echo "$USER_JSON" | jq -r '.login // empty' 2>/dev/null || true)
|
|
ID=$(echo "$USER_JSON" | jq -r '.id // empty' 2>/dev/null || true)
|
|
if [ -n "$LOGIN" ] && [ -n "$ID" ]; then
|
|
git config user.name "$LOGIN"
|
|
git config user.email "${ID}+${LOGIN}@users.noreply.github.com"
|
|
else
|
|
git config user.name "github-actions[bot]"
|
|
git config user.email "github-actions[bot]@users.noreply.github.com"
|
|
fi
|
|
|
|
- name: Cherry-pick commit
|
|
env:
|
|
CANDIDATE_BRANCH: ${{ steps.config.outputs.candidate_branch }}
|
|
INPUTS_COMMIT_SHA: ${{ inputs.commit_sha }}
|
|
run: |
|
|
echo "Cherry-picking ${INPUTS_COMMIT_SHA} to $CANDIDATE_BRANCH"
|
|
git cherry-pick ${INPUTS_COMMIT_SHA}
|
|
|
|
- name: Push changes
|
|
env:
|
|
CANDIDATE_BRANCH: ${{ steps.config.outputs.candidate_branch }}
|
|
run: |
|
|
git push origin "$CANDIDATE_BRANCH"
|
|
echo "Successfully cherry-picked commit to $CANDIDATE_BRANCH"
|
|
echo "If you want to regenerate the changelog PR, run the 'Release: Cut' workflow manually"
|
|
echo "with action='regenerate' and branch='${{ inputs.branch }}'."
|