-
Notifications
You must be signed in to change notification settings - Fork 2
78 lines (68 loc) · 2.1 KB
/
Copy pathtpip.yml
File metadata and controls
78 lines (68 loc) · 2.1 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
name: TPIP
on:
pull_request:
paths:
- '.github/workflows/tpip.yml'
- docs/third-party-licenses.json
- docs/tpip-header.md
- scripts/tpip-reporter.ts
- package-lock.json
- '!**/*.md'
- '!.github/workflows/markdown.yml'
- '!.github/markdownlint.json'
- '!.github/markdownlint.jsonc'
branches:
- main
workflow_dispatch:
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
update-tpip:
name: Update TPIP Report
permissions:
contents: write
packages: read
actions: read
runs-on: ubuntu-latest
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
with:
egress-policy: audit
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
ref: ${{ github.event.pull_request.head.ref }}
- name: Setup Node
uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6.3.0
env:
NODE_AUTH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
with:
node-version-file: package.json
registry-url: https://npm.pkg.github.com
package-manager-cache: false
- name: Install dependencies
env:
GITHUB_TOKEN: ${{ github.token }}
NODE_OPTIONS: --max-old-space-size=8192
run: npm ci
- name: Generate third-party licenses report
id: report
run: |
npm run tpip:update
npm run tpip:report
if git diff --exit-code TPIP.md > /dev/null; then
echo "update=0" >> $GITHUB_OUTPUT
else
echo "update=1" >> $GITHUB_OUTPUT
fi
- name: Commit changes
if: ${{ steps.report.outputs.update == 1 }}
uses: EndBug/add-and-commit@290ea2c423ad77ca9c62ae0f5b224379612c0321
with:
message: "Update TPIP report [skip ci]"
add: |
docs/third-party-licenses.json
TPIP.md