Reconciles develop to master's latest renovate values for deps bumped on the 2.7 line but never back-merged, so the develop->master 2.8 promotion (#10777) doesn't regress them. Done as a value reconcile, not a cherry-pick: several master commits are superseded (5 device-ui bumps, 2 ststm32 bumps), and develop's stale archive/refs/tags/ URL form actually blocked renovate from bumping these (the regex expects archive/<version>.zip). GitHub Actions: - actions/checkout v6 -> v7 (35 refs) - actions/cache v5 -> v6 - actions/github-script v8 -> v9 (3 refs) - actions/stale v10.2.0 -> v10.3.0 Build / platform: - alpine 3.23 -> 3.24 (alpine.Dockerfile) - platformio/ststm32 19.5.0 -> 19.7.0 - platformio/nordicnrf52 10.11.0 -> 10.12.0 Libraries: - Adafruit SSD1306 2.5.16 -> 2.5.17 - SparkFun MMC5983MA v1.1.4 -> v1.1.5 - Sensirion I2C SCD30 1.0.0 -> 1.1.1 - meshtastic esp8266-oled-ssd1306 6bfd1f1 -> 2e26010 Deliberately excluded: - meshtastic/device-ui digest: coupled to firmware protobuf/API and develop has diverged hard (NodeDB v25); left for a separate maintainer bump + visual check. - libpax: develop uses the mverch67 fork (pinned by Arduino-3.x migration #9122), master uses dbinfrago -- a fork divergence, not a version bump; not reconciled. - platform-native digest: develop already at 61067ac (equal to master).
63 lines
2.5 KiB
YAML
63 lines
2.5 KiB
YAML
name: Post Web Flasher Build Placeholder
|
|
|
|
# Drops an immediate "build in progress" comment when a PR opens, so the web
|
|
# flasher entry shows up right away. The real CI-driven workflow
|
|
# (flasher-link-comment.yml) later replaces it in place via the shared marker.
|
|
#
|
|
# SECURITY: this uses pull_request_target (write token, runs for fork PRs) but is
|
|
# safe because it never checks out or runs PR code and posts a fully static body
|
|
# — no PR title, branch name, or other untrusted input is used anywhere.
|
|
|
|
on:
|
|
pull_request_target:
|
|
types: [opened, reopened]
|
|
|
|
permissions:
|
|
pull-requests: write
|
|
|
|
jobs:
|
|
post-placeholder:
|
|
if: github.repository == 'meshtastic/firmware'
|
|
continue-on-error: true
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Post web flasher build-in-progress placeholder
|
|
uses: actions/github-script@v9
|
|
with:
|
|
script: |
|
|
const marker = '<!-- web-flasher-link -->';
|
|
const { owner, repo } = context.repo;
|
|
const pr = context.payload.pull_request;
|
|
|
|
// Trusted authors only (matches the real workflow). author_association
|
|
// can't reflect private org membership for the token, so concealed
|
|
// members appear as CONTRIBUTOR — include it, or maintainers are excluded.
|
|
const allowedAssociations = ['OWNER', 'MEMBER', 'COLLABORATOR', 'CONTRIBUTOR'];
|
|
if (!allowedAssociations.includes(pr.author_association)) {
|
|
core.info(`Author association ${pr.author_association} is not trusted; skipping.`);
|
|
return;
|
|
}
|
|
|
|
// Only seed a placeholder when no flasher comment exists yet — never
|
|
// overwrite a real (or existing placeholder) comment.
|
|
const comments = await github.paginate(github.rest.issues.listComments, {
|
|
owner, repo, issue_number: pr.number, per_page: 100,
|
|
});
|
|
if (comments.some((c) => c.body?.includes(marker))) {
|
|
core.info('Flasher comment already exists; nothing to do.');
|
|
return;
|
|
}
|
|
|
|
const body = [
|
|
marker,
|
|
'## ⚡ Try this PR in the Web Flasher',
|
|
'',
|
|
'> [!NOTE]',
|
|
'> Building this pull request… the flash button, badges and supported-board',
|
|
'> list will appear here automatically once CI finishes.',
|
|
].join('\n');
|
|
|
|
await github.rest.issues.createComment({
|
|
owner, repo, issue_number: pr.number, body,
|
|
});
|