Files
bot-bottle/.gitea/workflows/refresh-image-locks.yml
T
didericis-codex 432a2573eb
prd-number-check / require-numbered-prds (pull_request) Successful in 14s
refresh-image-locks / refresh (push) Failing after 1m17s
tracker-policy-pr / check-pr (pull_request) Successful in 8s
test / unit (pull_request) Successful in 1m46s
test / coverage (pull_request) Has been skipped
test / integration-docker (pull_request) Failing after 1m30s
test / image-input-builds (pull_request) Failing after 46s
ci: pin compatible gateway lock tooling
2026-07-26 09:38:35 +00:00

81 lines
2.5 KiB
YAML

# Manually refresh the committed package locks and the pinned Codex installer
# checksum after deliberately changing a direct version in the source files.
#
# The job uploads the generated files for review; it never commits or pushes.
name: refresh-image-locks
on:
workflow_dispatch:
push:
paths:
- 'requirements.gateway.in'
- 'bot_bottle/contrib/claude/package.json'
- 'bot_bottle/contrib/pi/package.json'
- 'bot_bottle/contrib/codex/Dockerfile'
- '.gitea/workflows/refresh-image-locks.yml'
permissions:
code: read
jobs:
refresh:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Use the image Python version
uses: actions/setup-python@v5
with:
python-version: '3.12.13'
- name: Use the image Node version
uses: actions/setup-node@v4
with:
node-version: '22.23.1'
- name: Compile gateway Python lock
run: |
python3 -m pip install pip==25.2 pip-tools==7.5.1
python3 -m piptools compile \
--generate-hashes \
--output-file requirements.gateway.lock \
requirements.gateway.in
- name: Resolve provider npm locks
run: |
for provider in claude pi; do
(
cd "bot_bottle/contrib/$provider"
npm install --package-lock-only --ignore-scripts --no-audit --no-fund
)
done
python3 scripts/complete_npm_lock_integrity.py \
bot_bottle/contrib/claude/package-lock.json \
bot_bottle/contrib/pi/package-lock.json
- name: Refresh pinned Codex installer checksum
run: |
CODEX_VERSION=$(
sed -n 's/^ARG CODEX_VERSION=//p' bot_bottle/contrib/codex/Dockerfile
)
test -n "$CODEX_VERSION"
curl -fsSL \
"https://raw.githubusercontent.com/openai/codex/rust-v${CODEX_VERSION}/scripts/install/install.sh" \
-o bot_bottle/contrib/codex/install.sh
(
cd bot_bottle/contrib/codex
sha256sum install.sh > install.sh.sha256
)
- name: Upload refreshed inputs
uses: actions/upload-artifact@v3
with:
name: image-input-locks
path: |
requirements.gateway.lock
bot_bottle/contrib/claude/package-lock.json
bot_bottle/contrib/pi/package-lock.json
bot_bottle/contrib/codex/install.sh.sha256