mirror of
https://github.com/openclaw/openclaw.git
synced 2026-07-21 10:16:44 +00:00
Bumps the actions group with 14 updates in the / directory: | Package | From | To | | --- | --- | --- | | [actions/create-github-app-token](https://github.com/actions/create-github-app-token) | `3.1.1` | `3.2.0` | | [actions/attest](https://github.com/actions/attest) | `4.1.1` | `4.2.0` | | [useblacksmith/setup-docker-builder](https://github.com/useblacksmith/setup-docker-builder) | `1.9.0` | `1.11.0` | | [actions/setup-python](https://github.com/actions/setup-python) | `6.2.0` | `6.3.0` | | [actions/setup-java](https://github.com/actions/setup-java) | `5.2.0` | `5.6.0` | | [github/codeql-action/init](https://github.com/github/codeql-action) | `4.36.2` | `4.37.1` | | [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.36.2` | `4.37.1` | | [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) | `4.36.2` | `4.37.1` | | [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `4.1.0` | `4.2.0` | | [docker/login-action](https://github.com/docker/login-action) | `4.2.0` | `4.4.0` | | [docker/build-push-action](https://github.com/docker/build-push-action) | `7.2.0` | `7.3.0` | | [openai/codex-action](https://github.com/openai/codex-action) | `1.8` | `1.11` | | [actions/labeler](https://github.com/actions/labeler) | `6.1.0` | `6.2.0` | | [actions/stale](https://github.com/actions/stale) | `10.3.0` | `10.4.0` | Updates `actions/create-github-app-token` from 3.1.1 to 3.2.0 - [Release notes](https://github.com/actions/create-github-app-token/releases) - [Changelog](https://github.com/actions/create-github-app-token/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/create-github-app-token/compare/v3.1.1...bcd2ba49218906704ab6c1aa796996da409d3eb1) Updates `actions/attest` from 4.1.1 to 4.2.0 - [Release notes](https://github.com/actions/attest/releases) - [Changelog](https://github.com/actions/attest/blob/main/RELEASE.md) - [Commits](https://github.com/actions/attest/compare/a1948c3f048ba23858d222213b7c278aabede763...f7c74d28b9d84cb8768d0b8ca14a4bac6ef463e6) Updates `useblacksmith/setup-docker-builder` from 1.9.0 to 1.11.0 - [Release notes](https://github.com/useblacksmith/setup-docker-builder/releases) - [Commits](https://github.com/useblacksmith/setup-docker-builder/compare/ab5c1da94f53f5cd75c1038092aa276dddfccbba...6ff44f8e5255f9d8aa31ef22f7e57a2d926b7da0) Updates `actions/setup-python` from 6.2.0 to 6.3.0 - [Release notes](https://github.com/actions/setup-python/releases) - [Commits](https://github.com/actions/setup-python/compare/a309ff8b426b58ec0e2a45f0f869d46889d02405...ece7cb06caefa5fff74198d8649806c4678c61a1) Updates `actions/setup-java` from 5.2.0 to 5.6.0 - [Release notes](https://github.com/actions/setup-java/releases) - [Commits](https://github.com/actions/setup-java/compare/be666c2fcd27ec809703dec50e508c2fdc7f6654...03ad4de0992f5dab5e18fcb136590ce7c4a0ac95) Updates `github/codeql-action/init` from 4.36.2 to 4.37.1 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/8aad20d150bbac5944a9f9d289da16a4b0d87c1e...7188fc363630916deb702c7fdcf4e481b751f97a) Updates `github/codeql-action/analyze` from 4.36.2 to 4.37.1 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/8aad20d150bbac5944a9f9d289da16a4b0d87c1e...7188fc363630916deb702c7fdcf4e481b751f97a) Updates `github/codeql-action/upload-sarif` from 4.36.2 to 4.37.1 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/8aad20d150bbac5944a9f9d289da16a4b0d87c1e...7188fc363630916deb702c7fdcf4e481b751f97a) Updates `docker/setup-buildx-action` from 4.1.0 to 4.2.0 - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](https://github.com/docker/setup-buildx-action/compare/d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5...bb05f3f5519dd87d3ba754cc423b652a5edd6d2c) Updates `docker/login-action` from 4.2.0 to 4.4.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](https://github.com/docker/login-action/compare/650006c6eb7dba73a995cc03b0b2d7f5ca915bee...af1e73f918a031802d376d3c8bbc3fe56130a9b0) Updates `docker/build-push-action` from 7.2.0 to 7.3.0 - [Release notes](https://github.com/docker/build-push-action/releases) - [Commits](https://github.com/docker/build-push-action/compare/f9f3042f7e2789586610d6e8b85c8f03e5195baf...53b7df96c91f9c12dcc8a07bcb9ccacbed38856a) Updates `openai/codex-action` from 1.8 to 1.11 - [Changelog](https://github.com/openai/codex-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/openai/codex-action/compare/v1.8...52fe01ec70a42f454c9d2ebd47598f9fd6893d56) Updates `actions/labeler` from 6.1.0 to 6.2.0 - [Release notes](https://github.com/actions/labeler/releases) - [Commits](https://github.com/actions/labeler/compare/f27b608878404679385c85cfa523b85ccb86e213...b8dd2d9be0f68b860e7dae5dae7d772984eacd6d) Updates `actions/stale` from 10.3.0 to 10.4.0 - [Release notes](https://github.com/actions/stale/releases) - [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/stale/compare/eb5cf3af3ac0a1aa4c9c45633dd1ae542a27a899...1e223db275d687790206a7acac4d1a11bd6fe629) --- updated-dependencies: - dependency-name: actions/attest dependency-version: 4.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: actions/create-github-app-token dependency-version: 3.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: actions/labeler dependency-version: 6.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: actions/setup-java dependency-version: 5.6.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: actions/setup-python dependency-version: 6.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: actions/stale dependency-version: 10.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: docker/build-push-action dependency-version: 7.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: docker/login-action dependency-version: 4.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: docker/setup-buildx-action dependency-version: 4.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: github/codeql-action/analyze dependency-version: 4.37.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: github/codeql-action/init dependency-version: 4.37.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: github/codeql-action/upload-sarif dependency-version: 4.37.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: openai/codex-action dependency-version: '1.11' dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: useblacksmith/setup-docker-builder dependency-version: 1.11.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions ... Signed-off-by: dependabot[bot] <support@github.com>
252 lines
9.0 KiB
YAML
252 lines
9.0 KiB
YAML
name: Docs Agent
|
|
|
|
on:
|
|
workflow_run: # zizmor: ignore[dangerous-triggers] main-only docs repair after trusted CI; job gates repository, event, branch, actor, conclusion, exact current main SHA, and hourly cadence before using write token
|
|
workflows:
|
|
- CI
|
|
types:
|
|
- completed
|
|
workflow_dispatch:
|
|
|
|
permissions:
|
|
actions: read
|
|
contents: write
|
|
|
|
concurrency:
|
|
group: docs-agent-main
|
|
cancel-in-progress: false
|
|
|
|
env:
|
|
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true"
|
|
|
|
jobs:
|
|
update-docs:
|
|
if: >
|
|
github.repository == 'openclaw/openclaw' &&
|
|
github.actor != 'github-actions[bot]' &&
|
|
(github.event_name != 'workflow_run' ||
|
|
(github.event.workflow_run.conclusion == 'success' &&
|
|
github.event.workflow_run.event == 'push' &&
|
|
github.event.workflow_run.head_branch == 'main' &&
|
|
github.event.workflow_run.actor.login != 'github-actions[bot]'))
|
|
runs-on: ubuntu-24.04
|
|
timeout-minutes: 30
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
|
|
with:
|
|
ref: main
|
|
fetch-depth: 0
|
|
persist-credentials: false
|
|
submodules: false
|
|
|
|
- name: Gate trusted main activity and hourly cadence
|
|
id: gate
|
|
env:
|
|
EVENT_NAME: ${{ github.event_name }}
|
|
GH_TOKEN: ${{ github.token }}
|
|
WORKFLOW_HEAD_SHA: ${{ github.event.workflow_run.head_sha }}
|
|
run: |
|
|
set -euo pipefail
|
|
|
|
if [ "$EVENT_NAME" != "workflow_run" ]; then
|
|
head_sha="$(git rev-parse HEAD)"
|
|
review_base="$(git rev-parse "${head_sha}^" 2>/dev/null || printf '%s' "$head_sha")"
|
|
{
|
|
echo "run_agent=true"
|
|
echo "base_sha=${head_sha}"
|
|
echo "review_base_sha=${review_base}"
|
|
echo "review_head_sha=${head_sha}"
|
|
} >> "$GITHUB_OUTPUT"
|
|
exit 0
|
|
fi
|
|
|
|
for attempt in 1 2 3 4 5; do
|
|
if timeout --signal=TERM --kill-after=10s 120s git fetch --no-tags origin main; then
|
|
break
|
|
fi
|
|
if [ "$attempt" = "5" ]; then
|
|
echo "Failed to fetch main after retries." >&2
|
|
exit 1
|
|
fi
|
|
echo "Fetch attempt ${attempt} failed; retrying."
|
|
sleep $((attempt * 2))
|
|
done
|
|
remote_main="$(git rev-parse origin/main)"
|
|
if [ "$remote_main" != "$WORKFLOW_HEAD_SHA" ]; then
|
|
echo "CI run is superseded by ${remote_main}; skipping docs agent for ${WORKFLOW_HEAD_SHA}."
|
|
echo "run_agent=false" >> "$GITHUB_OUTPUT"
|
|
exit 0
|
|
fi
|
|
|
|
runs_json="$RUNNER_TEMP/docs-agent-runs.json"
|
|
gh api --method GET "repos/${GITHUB_REPOSITORY}/actions/workflows/docs-agent.yml/runs" \
|
|
-f branch=main \
|
|
-f event=workflow_run \
|
|
-f per_page=100 > "$runs_json"
|
|
|
|
one_hour_ago="$(date -u -d '1 hour ago' +%Y-%m-%dT%H:%M:%SZ)"
|
|
recent_runs="$(
|
|
jq -r \
|
|
--argjson current_run_id "$GITHUB_RUN_ID" \
|
|
--arg one_hour_ago "$one_hour_ago" \
|
|
'.workflow_runs[]
|
|
| select(.database_id != $current_run_id)
|
|
| select(.created_at >= $one_hour_ago)
|
|
| select(.status != "cancelled")
|
|
| select((.conclusion // "") != "skipped")
|
|
| [.database_id, .status, (.conclusion // ""), .created_at, .head_sha]
|
|
| @tsv' "$runs_json"
|
|
)"
|
|
|
|
if [ -n "$recent_runs" ]; then
|
|
echo "Docs agent already ran or is running within the last hour; skipping."
|
|
printf '%s\n' "$recent_runs"
|
|
echo "run_agent=false" >> "$GITHUB_OUTPUT"
|
|
exit 0
|
|
fi
|
|
|
|
review_base="$(
|
|
jq -r \
|
|
--argjson current_run_id "$GITHUB_RUN_ID" \
|
|
--arg remote_main "$remote_main" \
|
|
'.workflow_runs[]
|
|
| select(.database_id != $current_run_id)
|
|
| select(.status != "cancelled")
|
|
| select((.conclusion // "") != "skipped")
|
|
| .head_sha
|
|
| select(. != null and . != "")
|
|
| select(. != $remote_main)
|
|
' "$runs_json" | head -n 1
|
|
)"
|
|
if [ -z "$review_base" ] || ! git cat-file -e "${review_base}^{commit}" 2>/dev/null; then
|
|
review_base="$(git rev-parse "${remote_main}^" 2>/dev/null || printf '%s' "$remote_main")"
|
|
fi
|
|
|
|
{
|
|
echo "run_agent=true"
|
|
echo "base_sha=${remote_main}"
|
|
echo "review_base_sha=${review_base}"
|
|
echo "review_head_sha=${remote_main}"
|
|
} >> "$GITHUB_OUTPUT"
|
|
|
|
- name: Setup Node environment
|
|
if: steps.gate.outputs.run_agent == 'true'
|
|
uses: ./.github/actions/setup-node-env
|
|
with:
|
|
install-bun: "false"
|
|
|
|
- name: Ensure docs agent key exists
|
|
if: steps.gate.outputs.run_agent == 'true'
|
|
env:
|
|
OPENAI_API_KEY: ${{ secrets.OPENCLAW_DOCS_AGENT_OPENAI_API_KEY || secrets.OPENAI_API_KEY }}
|
|
run: |
|
|
set -euo pipefail
|
|
if [ -z "${OPENAI_API_KEY:-}" ]; then
|
|
echo "Missing OPENCLAW_DOCS_AGENT_OPENAI_API_KEY or OPENAI_API_KEY secret." >&2
|
|
exit 1
|
|
fi
|
|
|
|
- name: Run Codex docs agent
|
|
if: steps.gate.outputs.run_agent == 'true'
|
|
uses: openai/codex-action@52fe01ec70a42f454c9d2ebd47598f9fd6893d56
|
|
env:
|
|
DOCS_AGENT_BASE_SHA: ${{ steps.gate.outputs.review_base_sha }}
|
|
DOCS_AGENT_HEAD_SHA: ${{ steps.gate.outputs.review_head_sha }}
|
|
with:
|
|
openai-api-key: ${{ secrets.OPENCLAW_DOCS_AGENT_OPENAI_API_KEY || secrets.OPENAI_API_KEY }}
|
|
prompt-file: .github/codex/prompts/docs-agent.md
|
|
model: ${{ vars.OPENCLAW_CI_OPENAI_MODEL_BARE }}
|
|
effort: medium
|
|
sandbox: workspace-write
|
|
safety-strategy: drop-sudo
|
|
codex-args: '["--full-auto"]'
|
|
|
|
- name: Enforce existing-docs-only patch
|
|
if: steps.gate.outputs.run_agent == 'true'
|
|
run: |
|
|
set -euo pipefail
|
|
|
|
untracked="$(git ls-files --others --exclude-standard)"
|
|
if [ -n "$untracked" ]; then
|
|
echo "Docs agent created untracked files; forbidden:"
|
|
printf '%s\n' "$untracked"
|
|
exit 1
|
|
fi
|
|
|
|
added_or_deleted="$(git diff --name-status --diff-filter=AD)"
|
|
if [ -n "$added_or_deleted" ]; then
|
|
echo "Docs agent added or deleted tracked files; forbidden:"
|
|
printf '%s\n' "$added_or_deleted"
|
|
exit 1
|
|
fi
|
|
|
|
bad_paths="$(
|
|
git diff --name-only | while IFS= read -r path; do
|
|
case "$path" in
|
|
docs/*|README.md|CHANGELOG.md) ;;
|
|
*) printf '%s\n' "$path" ;;
|
|
esac
|
|
done
|
|
)"
|
|
if [ -n "$bad_paths" ]; then
|
|
echo "Docs agent touched non-doc paths; forbidden:"
|
|
printf '%s\n' "$bad_paths"
|
|
exit 1
|
|
fi
|
|
|
|
- name: Restore Node 24 path
|
|
if: steps.gate.outputs.run_agent == 'true'
|
|
run:
|
|
| # zizmor: ignore[github-env] NODE_BIN is set by the trusted local setup-node-env action in this same job
|
|
set -euo pipefail
|
|
export PATH="${NODE_BIN}:${PATH}"
|
|
echo "${NODE_BIN}" >> "$GITHUB_PATH"
|
|
node -v
|
|
corepack enable
|
|
pnpm -v
|
|
|
|
- name: Check docs
|
|
if: steps.gate.outputs.run_agent == 'true'
|
|
run: pnpm check:docs
|
|
|
|
- name: Commit docs updates
|
|
if: steps.gate.outputs.run_agent == 'true'
|
|
env:
|
|
BASE_SHA: ${{ steps.gate.outputs.base_sha }}
|
|
GITHUB_TOKEN: ${{ github.token }}
|
|
TARGET_BRANCH: main
|
|
run: |
|
|
set -euo pipefail
|
|
|
|
if git diff --quiet; then
|
|
echo "No docs changes."
|
|
exit 0
|
|
fi
|
|
|
|
git config user.name "openclaw-docs-agent[bot]"
|
|
git config user.email "openclaw-docs-agent[bot]@users.noreply.github.com"
|
|
git add docs README.md CHANGELOG.md
|
|
git commit --no-verify -m "docs: refresh documentation"
|
|
|
|
for attempt in 1 2 3 4 5; do
|
|
if ! timeout --signal=TERM --kill-after=10s 120s git fetch --no-tags origin "${TARGET_BRANCH}"; then
|
|
echo "Fetch attempt ${attempt} failed; retrying."
|
|
sleep $((attempt * 2))
|
|
continue
|
|
fi
|
|
if git push "https://x-access-token:${GITHUB_TOKEN}@github.com/${GITHUB_REPOSITORY}.git" HEAD:"${TARGET_BRANCH}"; then
|
|
exit 0
|
|
fi
|
|
remote_main="$(git rev-parse "origin/${TARGET_BRANCH}")"
|
|
if [ "$remote_main" != "$BASE_SHA" ]; then
|
|
echo "main advanced from ${BASE_SHA} to ${remote_main}; skipping stale docs update."
|
|
exit 0
|
|
fi
|
|
echo "Docs update attempt ${attempt} failed; retrying."
|
|
sleep $((attempt * 2))
|
|
done
|
|
|
|
echo "Failed to push docs updates after retries." >&2
|
|
exit 1
|