Skip to content

Commit 0bedacd

Browse files
authored
chore(deps-dev): Bump frequenz-repo-config from 0.17.0 to 0.18.0 in the repo-config group across 1 directory (#102)
Bumps the repo-config group with 1 update in the / directory: [frequenz-repo-config](https://github.com/frequenz-floss/frequenz-repo-config-python). Updates `frequenz-repo-config` from 0.17.0 to 0.18.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/frequenz-floss/frequenz-repo-config-python/releases">frequenz-repo-config's releases</a>.</em></p> <blockquote> <h2>v0.18.0</h2> <h1>Frequenz Repository Configuration Release Notes</h1> <h2>Summary</h2> <p>This release focuses on finishing the automation of dependabot updates, adding more automated upgrade workflows and fixing some problems with the previous release.</p> <h2>Upgrading</h2> <h3>Cookiecutter template</h3> <p>All upgrading should be done via the migration script or regenerating the templates.</p> <pre lang="bash"><code>curl -sSLf https://raw.githubusercontent.com/frequenz-floss/frequenz-repo-config-python/&lt;tag&gt;/cookiecutter/migrate.py | python3 -I </code></pre> <h2>New Features</h2> <h3>Cookiecutter template</h3> <ul> <li>The cookiecutter now asks whether a repository is private, defaults that answer from the selected license, and uses it to toggle private-repository workflow behavior, public publishing jobs, and the link to GitHub Discussions in the issue template chooser.</li> <li>All dependencies have been updated in the templates.</li> <li>API projects now ship a dedicated <code>grpc-migration.yaml</code> workflow that runs after Dependabot bumps <code>grpcio</code>/<code>grpcio-tools</code>/<code>protobuf</code> and rewrites the matching runtime <code>&gt;=</code> floors in <code>pyproject.toml</code>.</li> <li>API projects now have a better grpcio/protobuf updates grouping in Dependabot, which should make upgrading easier, and plays nicer with the new <code>grpc-migration.yaml</code> workflow.</li> <li>API projects should now use the new API-specific <em>Protect version branches</em> ruleset variant, which includes the required <code>Fix gRPC/protobuf runtime floors</code> check without affecting non-API Python projects.</li> <li>Workflows using the <code>gh-action-dependabot-migrate</code> are upgraded to the latest version, which avoids unnecessary version iterations.</li> <li>Add an <code>isort-migration.yaml</code> workflow that automatically reorders imports when Dependabot upgrades <code>isort</code>.</li> </ul> <h2>Bug Fixes</h2> <h3>Cookiecutter template</h3> <ul> <li>The unused cross-arch QEMU-based testing infrastructure has been removed. The <code>.github/containers/nox-cross-arch/</code> and <code>.github/containers/test-installation/</code> directories, as well as the &quot;Cross-Arch Testing&quot; section in <code>CONTRIBUTING.md</code>.</li> <li>Private repositories now are generated with credentials uncommented and the publishing workflows disabled.</li> <li>The issue template chooser (<code>config.yml</code>) no longer includes the <code>contact_links</code> section for private repositories, since GitHub Discussions are typically disabled for them.</li> <li>Normalized the GitHub Action hashes for <code>gh-action-setup-git</code> and <code>gh-action-setup-python-with-deps</code> to point to the actual commit object, which is what Dependabot expects.</li> <li>API projects now configure black with <code>extend-exclude = '^/submodules/'</code> so the formatting check doesn't descend into external git submodules that don't follow our formatting rules.</li> <li>API projects now configure isort with <code>skip_glob = [&quot;submodules/*&quot;]</code> so the import-sorting check doesn't descend into external git submodules that don't follow our rules.</li> <li><code>CONTRIBUTING.md</code> <ul> <li>Fixed the nox example commands in to use the correct <code>tests/</code> directory instead of the non-existent <code>test/</code> directory.</li> <li>Fixed the wrong mention to PyPI publishing when releasing for private repositories.</li> </ul> </li> </ul> <h2>What's Changed</h2> <ul> <li>Add how to re-trigger a migration to the docs by <a href="https://github.com/llucax"><code>@​llucax</code></a> in <a href="https://redirect.github.com/frequenz-floss/frequenz-repo-config-python/pull/559">frequenz-floss/frequenz-repo-config-python#559</a></li> <li>Remove unused cross-arch files and docs by <a href="https://github.com/llucax"><code>@​llucax</code></a> in <a href="https://redirect.github.com/frequenz-floss/frequenz-repo-config-python/pull/547">frequenz-floss/frequenz-repo-config-python#547</a></li> <li>build(deps): bump frequenz-floss/gh-action-setup-python-with-deps from 0d0d77eac3b54799f31f25a1060ef2c6ebdf9299 to e4d0b2ef8f5a1612d7827f3abaef17c931d2b946 by <a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] in <a href="https://redirect.github.com/frequenz-floss/frequenz-repo-config-python/pull/561">frequenz-floss/frequenz-repo-config-python#561</a></li> <li>build(deps): bump frequenz-floss/gh-action-nox from 1.1.0 to 1.1.1 in the compatible group by <a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] in <a href="https://redirect.github.com/frequenz-floss/frequenz-repo-config-python/pull/560">frequenz-floss/frequenz-repo-config-python#560</a></li> <li>build(deps): bump frequenz-floss/gh-action-setup-git from 16952aac3ccc01d27412fe0dea3ea946530dcace to f9d86a01228ee1cadaac5224d4d7626f1eb23f90 by <a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] in <a href="https://redirect.github.com/frequenz-floss/frequenz-repo-config-python/pull/562">frequenz-floss/frequenz-repo-config-python#562</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/frequenz-floss/frequenz-repo-config-python/commit/953600229a68741824999432b9b49d9a0bc56bec"><code>9536002</code></a> Update template versions and prepare the v0.18.0 release (<a href="https://redirect.github.com/frequenz-floss/frequenz-repo-config-python/issues/590">#590</a>)</li> <li><a href="https://github.com/frequenz-floss/frequenz-repo-config-python/commit/085121516fb788293325e56808edecbd31f564f4"><code>0851215</code></a> Prepare release notes for v0.18.0</li> <li><a href="https://github.com/frequenz-floss/frequenz-repo-config-python/commit/bee542d201b4b66ce71df2f17044dcf76869356a"><code>bee542d</code></a> template: Bump dependencies</li> <li><a href="https://github.com/frequenz-floss/frequenz-repo-config-python/commit/80402d2a3969e3d19d2671eb98b6ac47ca422e2b"><code>80402d2</code></a> build(deps): bump the compatible group with 2 updates (<a href="https://redirect.github.com/frequenz-floss/frequenz-repo-config-python/issues/589">#589</a>)</li> <li><a href="https://github.com/frequenz-floss/frequenz-repo-config-python/commit/df8ba243393801fd97e2b46cddfb68bef00848c7"><code>df8ba24</code></a> build(deps): bump the compatible group with 2 updates</li> <li><a href="https://github.com/frequenz-floss/frequenz-repo-config-python/commit/e5f4e3968e5bc86758c46c41bdca5999dd80746c"><code>e5f4e39</code></a> Add <code>isort</code> dependabot auto-migration workflow (<a href="https://redirect.github.com/frequenz-floss/frequenz-repo-config-python/issues/585">#585</a>)</li> <li><a href="https://github.com/frequenz-floss/frequenz-repo-config-python/commit/3afcb70310b690cc8eef4e631423af8d221b9f21"><code>3afcb70</code></a> Update release notes</li> <li><a href="https://github.com/frequenz-floss/frequenz-repo-config-python/commit/e86009be83504bd3751139775388b0cb078f0c2e"><code>e86009b</code></a> Add isort submodules migration step</li> <li><a href="https://github.com/frequenz-floss/frequenz-repo-config-python/commit/22be0eed5d3b5866dd348b0161de314eca66d5a5"><code>22be0ee</code></a> template: Make isort exclude submodules from API projects</li> <li><a href="https://github.com/frequenz-floss/frequenz-repo-config-python/commit/a45950072bfd4e287dffafb8096c0d42ddff7e47"><code>a459500</code></a> isort: Exclude golden tests</li> <li>Additional commits viewable in <a href="https://github.com/frequenz-floss/frequenz-repo-config-python/compare/v0.17.0...v0.18.0">compare view</a></li> </ul> </details> <br />
2 parents 00dba31 + e57dc7f commit 0bedacd

12 files changed

Lines changed: 121 additions & 103 deletions

.cookiecutter-replay.json

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,7 @@
88
"keywords": "assets, microgrid, gridpools, components",
99
"github_org": "frequenz-floss",
1010
"license": "MIT",
11+
"private_repo": "no",
1112
"author_name": "Frequenz Energy-as-a-Service GmbH",
1213
"author_email": "floss@frequenz.com",
1314
"python_package": "frequenz.api.assets",
@@ -34,6 +35,10 @@
3435
"MIT",
3536
"Proprietary"
3637
],
38+
"private_repo": [
39+
"{{ 'yes' if cookiecutter.license == 'Proprietary' else 'no' }}",
40+
"{{ 'no' if cookiecutter.license == 'Proprietary' else 'yes' }}"
41+
],
3742
"author_name": "Frequenz Energy-as-a-Service GmbH",
3843
"author_email": "floss@frequenz.com",
3944
"python_package": "{{cookiecutter | python_package}}",

.github/containers/nox-cross-arch/arm64-ubuntu-20.04-python-3.11.Dockerfile

Lines changed: 0 additions & 33 deletions
This file was deleted.

.github/containers/nox-cross-arch/entrypoint.bash

Lines changed: 0 additions & 9 deletions
This file was deleted.

.github/containers/test-installation/Dockerfile

Lines changed: 0 additions & 20 deletions
This file was deleted.

.github/dependabot.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -34,6 +34,7 @@ updates:
3434
- "grpcio"
3535
- "grpcio-tools"
3636
- "protobuf"
37+
- "isort"
3738
minor:
3839
update-types:
3940
- "minor"
@@ -55,6 +56,7 @@ updates:
5556
- "grpcio"
5657
- "grpcio-tools"
5758
- "protobuf"
59+
- "isort"
5860
# We group repo-config updates as it uses optional dependencies that are
5961
# considered different dependencies otherwise, and will create one PR for
6062
# each if we don't group them.

.github/workflows/auto-dependabot.yaml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,8 @@ jobs:
2626
!contains(github.event.pull_request.title, 'the grpc-compatible group') &&
2727
!contains(github.event.pull_request.title, 'the grpcio-major group') &&
2828
!contains(github.event.pull_request.title, 'the protobuf-major group') &&
29-
!contains(github.event.pull_request.title, 'Bump black from ')
29+
!contains(github.event.pull_request.title, 'Bump black from ') &&
30+
!contains(github.event.pull_request.title, 'Bump isort from ')
3031
runs-on: ubuntu-slim
3132
steps:
3233
- name: Generate GitHub App token

.github/workflows/black-migration.yaml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -66,7 +66,7 @@ jobs:
6666
# Read/update pull request metadata and labels.
6767
permission-pull-requests: write
6868
- name: Migrate
69-
uses: frequenz-floss/gh-action-dependabot-migrate@e93e3b50930132717c9aabdd09413a6737d4b7ef # v1.3.0
69+
uses: frequenz-floss/gh-action-dependabot-migrate@27763fb5eb56476d91abe00132e8a0614171f92f # v1.2.0
7070
with:
7171
migration-script: |
7272
import os
@@ -81,6 +81,7 @@ jobs:
8181
subprocess.run([sys.executable, "-Im", "black", "."], check=True)
8282
token: ${{ steps.create-app-token.outputs.token }}
8383
auto-merge-on-changes: "false"
84+
version-iteration: "false"
8485
sign-commits: "true"
8586
auto-merged-label: "tool:auto-merged"
8687
migrated-label: "tool:black:migration:executed"

.github/workflows/grpc-migration.yaml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -63,7 +63,7 @@ jobs:
6363
steps:
6464
- name: Generate token
6565
id: create-app-token
66-
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
66+
uses: actions/create-github-app-token@1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1
6767
with:
6868
app-id: ${{ secrets.FREQUENZ_AUTO_DEPENDABOT_APP_ID }}
6969
private-key: ${{ secrets.FREQUENZ_AUTO_DEPENDABOT_APP_PRIVATE_KEY }}
@@ -74,10 +74,10 @@ jobs:
7474
# Read/update pull request metadata and labels.
7575
permission-pull-requests: write
7676
- name: Migrate
77-
uses: frequenz-floss/gh-action-dependabot-migrate@e93e3b50930132717c9aabdd09413a6737d4b7ef # v1.x.x
77+
uses: frequenz-floss/gh-action-dependabot-migrate@27763fb5eb56476d91abe00132e8a0614171f92f # v1.2.0
7878
with:
79-
script-url-template: >-
80-
https://raw.githubusercontent.com/llucax/frequenz-repo-config-python/refs/heads/fix-grpc-group/cookiecutter/scripts/dependabot-grpc-fixer.py
79+
script-url-template: >- # v0.18.0
80+
https://raw.githubusercontent.com/frequenz-floss/frequenz-repo-config-python/529d30b554392e6d8b66e84e92c04ac9cd170da7/cookiecutter/scripts/dependabot-grpc-fixer.py
8181
token: ${{ steps.create-app-token.outputs.token }}
8282
version-iteration: "false"
8383
sign-commits: "true"
Lines changed: 92 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,92 @@
1+
# Automatic isort migration for Dependabot PRs
2+
#
3+
# When Dependabot upgrades isort, this workflow installs the new version and
4+
# runs `isort .` so the PR already contains any import-ordering changes
5+
# introduced by the upgrade, while leaving the PR open for review.
6+
#
7+
# isort follows SemVer but its release policy
8+
# (https://github.com/PyCQA/isort/blob/main/docs/major_releases/release_policy.md)
9+
# explicitly allows intentional formatting changes in minor releases, and
10+
# patch releases may also adjust output in smaller bug-fix ways. Because of
11+
# that, isort is excluded from the regular `patch` and `minor` Dependabot
12+
# groups: every isort bump produces an individual `Bump isort from …` PR and
13+
# is routed through this migration workflow.
14+
#
15+
# The companion auto-dependabot workflow skips those PRs so they're handled
16+
# exclusively by this migration workflow.
17+
#
18+
# XXX: !!! SECURITY WARNING !!!
19+
# pull_request_target has write access to the repo, and can read secrets.
20+
# This is required because Dependabot PRs are treated as fork PRs: the
21+
# GITHUB_TOKEN is read-only and secrets are unavailable with a plain
22+
# pull_request trigger. The action mitigates the risk by:
23+
# - Never executing code from the PR (the migration script is embedded
24+
# in this workflow file on the base branch, not taken from the PR).
25+
# - Gating migration steps on github.actor == 'dependabot[bot]'.
26+
# - Running checkout with persist-credentials: false and isolating
27+
# push credentials from the migration script environment.
28+
# For more details read:
29+
# https://securitylab.github.com/research/github-actions-preventing-pwn-requests/
30+
31+
name: isort Migration
32+
33+
on:
34+
merge_group: # To allow using this as a required check for merging
35+
pull_request_target:
36+
types: [opened, synchronize, reopened, labeled, unlabeled]
37+
38+
permissions:
39+
# Commit reformatted files back to the PR branch.
40+
contents: write
41+
# Create and normalize migration state labels.
42+
issues: write
43+
# Read/update pull request metadata and comments.
44+
pull-requests: write
45+
46+
jobs:
47+
isort-migration:
48+
name: Migrate isort
49+
# Skip if it was triggered by the merge queue. We only need the workflow to
50+
# be executed to meet the "Required check" condition for merging, but we
51+
# don't need to actually run the job, having the job present as Skipped is
52+
# enough.
53+
if: |
54+
github.event_name == 'pull_request_target' &&
55+
github.actor == 'dependabot[bot]' &&
56+
contains(github.event.pull_request.title, 'Bump isort from ')
57+
runs-on: ubuntu-24.04
58+
steps:
59+
- name: Generate token
60+
id: create-app-token
61+
uses: actions/create-github-app-token@1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1
62+
with:
63+
app-id: ${{ secrets.FREQUENZ_AUTO_DEPENDABOT_APP_ID }}
64+
private-key: ${{ secrets.FREQUENZ_AUTO_DEPENDABOT_APP_PRIVATE_KEY }}
65+
# Push reformatted files to the PR branch.
66+
permission-contents: write
67+
# Create and normalize migration state labels.
68+
permission-issues: write
69+
# Read/update pull request metadata and labels.
70+
permission-pull-requests: write
71+
- name: Migrate
72+
uses: frequenz-floss/gh-action-dependabot-migrate@27763fb5eb56476d91abe00132e8a0614171f92f # v1.2.0
73+
with:
74+
migration-script: |
75+
import os
76+
import subprocess
77+
import sys
78+
79+
version = os.environ["MIGRATION_VERSION"].lstrip("v")
80+
subprocess.run(
81+
[sys.executable, "-Im", "pip", "install", f"isort=={version}"],
82+
check=True,
83+
)
84+
subprocess.run([sys.executable, "-Im", "isort", "."], check=True)
85+
token: ${{ steps.create-app-token.outputs.token }}
86+
auto-merge-on-changes: "false"
87+
version-iteration: "false"
88+
sign-commits: "true"
89+
auto-merged-label: "tool:auto-merged"
90+
migrated-label: "tool:isort:migration:executed"
91+
intervention-pending-label: "tool:isort:migration:intervention-pending"
92+
intervention-done-label: "tool:isort:migration:intervention-done"

.github/workflows/repo-config-migration.yaml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -58,12 +58,14 @@ jobs:
5858
# Allow pushes when migration changes workflow files.
5959
permission-workflows: write
6060
- name: Migrate
61-
uses: frequenz-floss/gh-action-dependabot-migrate@e93e3b50930132717c9aabdd09413a6737d4b7ef # v1.3.0
61+
uses: frequenz-floss/gh-action-dependabot-migrate@27763fb5eb56476d91abe00132e8a0614171f92f # v1.2.0
6262
with:
6363
script-url-template: >-
6464
https://raw.githubusercontent.com/frequenz-floss/frequenz-repo-config-python/{version}/cookiecutter/migrate.py
6565
token: ${{ steps.create-app-token.outputs.token }}
6666
migration-token: ${{ secrets.REPO_CONFIG_MIGRATION_TOKEN }}
67+
version-iteration: "minor"
68+
if-no-iterations: "pass"
6769
sign-commits: "true"
6870
auto-merged-label: "tool:auto-merged"
6971
migrated-label: "tool:repo-config:migration:executed"

0 commit comments

Comments
 (0)