Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 7 additions & 10 deletions .github/actionlint.yaml
Original file line number Diff line number Diff line change
@@ -1,24 +1,21 @@
# This is the actionlint config.
# The paths.<glob>.ignore key filters specific error messages by regex, scoped to the file that needs it, rather than disabling the rule fleet-wide.
#
# The job.workflow_sha and job.workflow_repository properties are documented GitHub Actions context fields (GitHub Docs, "Contexts", the job context).
# They exist specifically so a reusable workflow can check out its own repository at the exact commit its caller pinned.
# The actionlint context schema has not caught up to them yet, so it reports a false property-not-defined finding here.
# Drop this entry once a released actionlint recognizes both properties.
# GitHub's documented $/ self-repository syntax is not recognized by actionlint yet.
# Remove each scoped ignore when actionlint accepts that form.
paths:
'.github/workflows/build-release-task.yml':
ignore:
- 'property "workflow_repository" is not defined in object type'
- 'property "workflow_sha" is not defined in object type'
- 'reusable workflow call "\$/\.github/workflows/'
- 'specifying action "\$/\.github/actions/'
'.github/workflows/build-docker-task.yml':
ignore:
- 'property "workflow_repository" is not defined in object type'
- 'property "workflow_sha" is not defined in object type'
- 'specifying action "\$/\.github/actions/'
'.github/workflows/publish-docker-readme-task.yml':
ignore:
- 'property "workflow_repository" is not defined in object type'
- 'property "workflow_sha" is not defined in object type'
- 'specifying action "\$/\.github/actions/'
'.github/workflows/validate-task.yml':
ignore:
- 'property "workflow_repository" is not defined in object type'
- 'property "workflow_sha" is not defined in object type'
- 'specifying action "\$/\.github/actions/'
Original file line number Diff line number Diff line change
@@ -1,10 +1,6 @@
# Hub default for the build-executable hook, run when a caller carries no .github/actions/build-executable/action.yml of its own.
# It publishes a .NET console project across the runtime matrix and zips every runtime into one archive.
# This matches the vanilla project layout catalog/snippets/workflows/build-executable-task.yml once carried (./Console/Console.csproj).
# A caller whose project lives elsewhere sets project-file rather than carrying a hook.
# A composite action runs in one job, so the matrix is a sequential bash loop here rather than a job-level strategy.
name: Build executable default
description: Publish the console project across the runtime matrix and upload the release asset.
name: Publish .NET project default
description: Publish a .NET project across the runtime matrix and upload the release asset.

inputs:
branch:
Expand All @@ -24,9 +20,8 @@ inputs:
assembly-informational-version:
required: true
project-file:
description: Path to the console project file.
required: false
default: ./Console/Console.csproj
description: Path to the .NET project file.
required: true
asset-name:
description: Name of the release archive without its .7z extension, so Widget produces Widget.7z. Empty derives it from the project file's stem, so ./Widget/Widget.csproj also produces Widget.7z. Letters, digits, dot, underscore and hyphen only, given or derived, and anything else fails the step.
required: false
Expand All @@ -41,7 +36,7 @@ runs:
with:
dotnet-version: 10.x

- name: Build executable project step
- name: Publish .NET project step
shell: bash
env:
BRANCH: ${{ inputs.branch }}
Expand Down Expand Up @@ -74,7 +69,7 @@ runs:
-property:PackageVersion="$SEMVER2"
done

# The archive is named for the project unless the caller names it, since a release asset called Console.7z tells a downloader nothing.
# The archive is named for the project unless the caller names it.
- name: Zip build output step
id: zip
if: ${{ inputs.smoke != 'true' }}
Expand Down
Original file line number Diff line number Diff line change
@@ -1,11 +1,5 @@
# Hub default for the build-nuget hook, run when a caller carries no .github/actions/build-nuget/action.yml of its own.
# It builds a NuGet library project and publishes it to NuGet.org through OIDC trusted publishing, so there is no stored API key.
# See spec/secrets.json "nuget-oidc" for the mechanism this matches.
# It also uploads the release asset.
# A caller whose project lives elsewhere sets project-file rather than carrying a hook.
# Every live NuGet repo today carries its own hook for that reason.
name: Build NuGet library default
description: Build, OIDC-publish, and upload the release asset for a NuGet library project.
name: Push NuGet package default
description: Build, OIDC-publish, and upload the release asset for a .NET project.

inputs:
branch:
Expand All @@ -28,9 +22,8 @@ inputs:
assembly-informational-version:
required: true
project-file:
description: Path to the library project file.
required: false
default: ./NuGetLibrary/NuGetLibrary.csproj
description: Path to the .NET project file.
required: true
nuget-username:
description: nuget.org profile name for OIDC trusted publishing. Empty when push is false.
required: false
Expand Down
Original file line number Diff line number Diff line change
@@ -1,11 +1,5 @@
# Hub default for the build-pypi hook, run when a caller carries no .github/actions/build-pypi/action.yml of its own.
# It builds the wheel and sdist and uploads the build artifact.
# Publishing is a separate publish-pypi job at the caller stub, since id-token: write belongs at one entry point.
# This hook contributes no release-asset-*.
# It matches the vanilla project layout catalog/snippets/workflows/build-pypilibrary-task.yml once carried
# (./PyPiLibrary, hatchling reading src/ptr727_projecttemplate_library/_version.py).
name: Build PyPI library default
description: Build the PyPI wheel and sdist and upload the build artifact for the publish-pypi job.
name: Build PyPI package default
description: Build a wheel and source distribution for the publish-pypi job.

inputs:
branch:
Expand All @@ -20,12 +14,10 @@ inputs:
required: true
project-dir:
description: Working directory of the PyPI project.
required: false
default: ./PyPiLibrary
required: true
version-file:
description: Repo-relative path of the file carrying the hardcoded __version__ hatchling reads.
required: false
default: PyPiLibrary/src/ptr727_projecttemplate_library/_version.py
required: true
uv-version:
description: uv version, pinned in lockstep with the devcontainer's UV_VERSION.
required: false
Expand Down
14 changes: 1 addition & 13 deletions .github/workflows/build-docker-task.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,10 +5,6 @@ name: Build Docker image task
# Multi-arch (amd64+arm64) applies only to a non-smoke main build, and every other build is amd64 only.
# The cache policy and the platform selection are decided once here, per docs/reusable-workflows.md "The Docker Family", never per caller.
#
# This file exists both as a hub task in its own right, for a caller that wants only the Docker leg with no NBGV release/version chain, and as the source build-release-task.yml duplicates into its own build-docker job.
# A hub task cannot call a sibling hub task by a ./ path, since that path resolves against the caller's repository, not the hub.
# The two carry the same job body rather than one calling the other, so keep them in lockstep by hand.
#
# The in-job Docker Hub description push that earlier per-repo copies carried is dropped here in favor of publish-docker-readme-task.yml, per docs/reusable-workflows.md "The Docker Family" (stage 5).
# The overview then publishes once per release rather than once per image build.
#
Expand Down Expand Up @@ -100,14 +96,6 @@ jobs:
with:
ref: ${{ inputs.ref }}

- name: Checkout hub for hook default step
if: ${{ inputs.matrix == '' && hashFiles('.github/actions/docker-prepare/action.yml') == '' }}
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
repository: ${{ job.workflow_repository }}
ref: ${{ job.workflow_sha }}
path: .hub

- name: Run caller docker-prepare hook step
if: ${{ inputs.matrix == '' && hashFiles('.github/actions/docker-prepare/action.yml') != '' }}
id: hook
Expand All @@ -120,7 +108,7 @@ jobs:
- name: Run hub docker-prepare default step
if: ${{ inputs.matrix == '' && hashFiles('.github/actions/docker-prepare/action.yml') == '' }}
id: default
uses: ./.hub/.github/actions/docker-prepare-default
uses: $/.github/actions/docker-prepare-default
with:
image: ${{ inputs.image }}
branch: ${{ inputs.branch }}
Expand Down
Loading