Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat(github-actions): support ratchet comments #27846

Merged
merged 8 commits into from Mar 12, 2024
Expand Up @@ -17,3 +17,5 @@ jobs:
- uses: actions/checkout@01aecc#v2.1.0
- uses: actions/checkout@689fcce700ae7ffc576f2b029b51b2ffb66d3abd # comment containing 2.1.0
- uses: actions/checkout@689fcce700ae7ffc576f2b029b51b2ffb66d3abd # v2.1.0 additional comment
- uses: actions/checkout@689fcce700ae7ffc576f2b029b51b2ffb66d3abd # ratchet:actions/checkout@v2.1.0
- uses: actions/checkout@689fcce700ae7ffc576f2b029b51b2ffb66d3abd # ratchet:exclude
12 changes: 12 additions & 0 deletions lib/modules/manager/github-actions/extract.spec.ts
Expand Up @@ -385,6 +385,18 @@ describe('modules/manager/github-actions/extract', () => {
replaceString:
'actions/checkout@689fcce700ae7ffc576f2b029b51b2ffb66d3abd # v2.1.0',
},
{
currentDigest: '689fcce700ae7ffc576f2b029b51b2ffb66d3abd',
currentValue: 'v2.1.0',
replaceString:
'actions/checkout@689fcce700ae7ffc576f2b029b51b2ffb66d3abd # ratchet:actions/checkout@v2.1.0',
},
{
currentDigest: '689fcce700ae7ffc576f2b029b51b2ffb66d3abd',
currentValue: undefined,
replaceString:
'actions/checkout@689fcce700ae7ffc576f2b029b51b2ffb66d3abd # ratchet:exclude',
},
]);
});

Expand Down
2 changes: 1 addition & 1 deletion lib/modules/manager/github-actions/extract.ts
Expand Up @@ -15,7 +15,7 @@ import type { Workflow } from './types';

const dockerActionRe = regEx(/^\s+uses\s*: ['"]?docker:\/\/([^'"]+)\s*$/);
const actionRe = regEx(
/^\s+-?\s+?uses\s*: (?<replaceString>['"]?(?<registryUrl>https:\/\/[.\w-]+\/)?(?<depName>[\w-]+\/[.\w-]+)(?<path>\/.*)?@(?<currentValue>[^\s'"]+)['"]?(?:\s+#\s*(?:renovate\s*:\s*)?(?:pin\s+|tag\s*=\s*)?@?(?<tag>v?\d+(?:\.\d+(?:\.\d+)?)?))?)/,
/^\s+-?\s+?uses\s*: (?<replaceString>['"]?(?<registryUrl>https:\/\/[.\w-]+\/)?(?<depName>[\w-]+\/[.\w-]+)(?<path>\/.*)?@(?<currentValue>[^\s'"]+)['"]?(?:\s+#\s*(((?:renovate\s*:\s*)?(?:pin\s+|tag\s*=\s*)?|(?:ratchet:[\w-]+\/[.\w-]+)?)@?(?<tag>v?\d+(?:\.\d+(?:\.\d+)?)?)|(?:ratchet:exclude)))?)/,
rarkins marked this conversation as resolved.
Show resolved Hide resolved
);

// SHA1 or SHA256, see https://github.blog/2020-10-19-git-2-29-released/
Expand Down
3 changes: 3 additions & 0 deletions lib/modules/manager/github-actions/readme.md
Expand Up @@ -40,3 +40,6 @@ jobs:
build:
runs-on: ${{ env.RUNNER }}
```

The `github-action` manager also supports `ratchet` comments, like `# ratchet:actions/checkout@v2.1.0`.
rarkins marked this conversation as resolved.
Show resolved Hide resolved
Please read the [ratchet documentation](https://github.com/sethvargo/ratchet/blob/main/README.md) for more information.