Files
winnow/.github/workflows/update-lockfile.yml
T
flan 3296940806 fix: lockfile workflow opens PR on dev instead of direct push
dev is a protected branch requiring PRs. The previous direct push caused
the lockfile update CI job to fail with 'protected branch hook declined'.
When the triggering branch is dev, the workflow now creates a side branch
and opens a PR; all other branches continue to push directly.
2026-06-17 03:12:00 +00:00

64 lines
1.8 KiB
YAML

# .github/workflows/update-lockfile.yml
name: Update lockfile
on:
push:
branches:
- '**'
- '!main'
paths:
- 'pyproject.toml'
workflow_dispatch:
jobs:
update-lockfile:
runs-on: ubuntu-latest
permissions:
contents: write
pull-requests: write
steps:
- name: Checkout repository
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- name: Install uv
uses: astral-sh/setup-uv@fac544c07dec837d0ccb6301d7b5580bf5edae39 # v8.2.0
- name: Set up Python
run: uv python install 3.13
- name: Regenerate lockfile
run: uv lock
- name: Check for changes
id: diff
run: |
if git diff --quiet uv.lock; then
echo "changed=false" >> "$GITHUB_OUTPUT"
else
echo "changed=true" >> "$GITHUB_OUTPUT"
fi
- name: Commit and push updated lockfile
if: steps.diff.outputs.changed == 'true'
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git add uv.lock
git commit -m "chore: update lockfile"
if [ "$GITHUB_REF_NAME" = "dev" ]; then
# dev is protected — open a PR rather than pushing directly
BRANCH="chore/lockfile-$(git rev-parse --short HEAD)"
git checkout -b "$BRANCH"
git push origin "$BRANCH"
gh pr create \
--base dev \
--head "$BRANCH" \
--title "chore: update lockfile" \
--body "Automated lockfile update triggered by a \`pyproject.toml\` change on \`dev\`."
else
git push
fi