build(deps-dev): Bump @tanstack/react-virtual from 3.14.12 to 3.14.13… #312
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Bump downstream submodule pointers | |
| # When this repo's main moves, push a matching gitlink bump to every downstream | |
| # repo that carries this one as a `failproofai/oss` submodule, so their pinned | |
| # commits track upstream automatically. Direct push to each downstream `main` — | |
| # no PR. | |
| # | |
| # Both downstreams are governed by the org-level `failproofai-rules` ruleset | |
| # (PR + 1 review required on main), which rejects a plain GITHUB_TOKEN push with | |
| # GH013. We instead mint a token for the version-bot GitHub App — a bypass actor | |
| # on that ruleset — so the push is accepted. The same ruleset object governs both | |
| # repos, so one bypass covers both. | |
| # | |
| # The filename still says `platform` so the Actions run history — which GitHub | |
| # keys by workflow path — survives; the matrix below is the source of truth for | |
| # which repos actually get bumped. | |
| on: | |
| push: | |
| branches: [main] | |
| workflow_dispatch: | |
| jobs: | |
| bump: | |
| runs-on: ubuntu-latest | |
| strategy: | |
| # Independent repos: a failure bumping one must not cancel the other. | |
| fail-fast: false | |
| matrix: | |
| # Every repo carrying this one at `failproofai/oss`. Add a repo here and | |
| # it gets bumped — nothing else in this file is downstream-specific. | |
| repo: [platform, agenteye] | |
| # Serialize per downstream so back-to-back merges produce sequential bumps, | |
| # not a race that loses one of them. Keyed by repo so a slow platform bump | |
| # never delays agenteye's. | |
| concurrency: | |
| group: bump-submodule-${{ matrix.repo }} | |
| cancel-in-progress: false | |
| steps: | |
| # Token for the version-bot GitHub App — a bypass actor on the org | |
| # ruleset, so pushes to the downstream main bypass the PR requirement. | |
| # Scoped to just the one repo this matrix leg touches. | |
| - name: Mint version-bot app token | |
| id: app-token | |
| uses: actions/create-github-app-token@v3 | |
| with: | |
| app-id: ${{ secrets.VERSION_BOT_APP_ID }} | |
| private-key: ${{ secrets.VERSION_BOT_PRIVATE_KEY }} | |
| # Without an explicit owner/repository, the action scopes the token | |
| # to this repository, which cannot checkout the private downstream repo. | |
| owner: FailproofAI | |
| repositories: ${{ matrix.repo }} | |
| - name: Checkout FailproofAI/${{ matrix.repo }} main | |
| uses: actions/checkout@v7.0.1 | |
| with: | |
| repository: FailproofAI/${{ matrix.repo }} | |
| # Persist the app token so `git push` below bypasses the ruleset. | |
| # The version-bot App is a bypass actor on `failproofai-rules`. | |
| token: ${{ steps.app-token.outputs.token }} | |
| ref: main | |
| fetch-depth: 1 | |
| # Don't fetch submodule contents — we only edit the gitlink. | |
| submodules: false | |
| - name: Bump failproofai/oss gitlink and push | |
| env: | |
| NEW_SHA: ${{ github.sha }} | |
| COMMIT_SUBJECT: ${{ github.event.head_commit.message }} | |
| UPSTREAM_REPO: ${{ github.repository }} | |
| DOWNSTREAM_REPO: ${{ matrix.repo }} | |
| run: | | |
| set -euo pipefail | |
| git config user.name "agenteye-bot" | |
| git config user.email "agenteye-bot@users.noreply.github.com" | |
| CURRENT_SHA=$(git ls-tree HEAD failproofai/oss | awk '{print $3}') | |
| if [ -z "$CURRENT_SHA" ]; then | |
| echo "::error::failproofai/oss is not a gitlink in $DOWNSTREAM_REPO main — aborting." | |
| exit 1 | |
| fi | |
| if [ "$CURRENT_SHA" = "$NEW_SHA" ]; then | |
| echo "Already at $NEW_SHA — nothing to do." | |
| exit 0 | |
| fi | |
| # Rewrite the gitlink (mode 160000 = submodule entry) without | |
| # needing the submodule contents on disk. | |
| git update-index --add --cacheinfo "160000,$NEW_SHA,failproofai/oss" | |
| # Extract the first line via pure bash parameter expansion — piping | |
| # printf into `head -n 1` raced under `set -o pipefail`: head closes | |
| # the pipe after the first line, printf dies with SIGPIPE, and the | |
| # pipeline exits non-zero. The squash-merge commit body that broke | |
| # run 27208748580 was several KB, easily triggering it. | |
| SUBJECT_LINE=${COMMIT_SUBJECT:-Manual trigger} | |
| SUBJECT_LINE=${SUBJECT_LINE%%$'\n'*} | |
| SHORT_SHA=${NEW_SHA:0:7} | |
| git commit -m "Bump failproofai/oss to $SHORT_SHA" \ | |
| -m "Upstream: $SUBJECT_LINE" \ | |
| -m "https://github.com/$UPSTREAM_REPO/commit/$NEW_SHA" | |
| # Race-safe push: if the downstream main moved between checkout and | |
| # push, rebase the single bump commit on top and try again. | |
| for attempt in 1 2 3; do | |
| if git push origin main; then | |
| echo "Pushed bump on attempt $attempt" | |
| exit 0 | |
| fi | |
| echo "Push failed on attempt $attempt — rebasing onto latest main" | |
| git fetch origin main | |
| git rebase origin/main | |
| done | |
| echo "::error::Failed to push submodule bump after 3 attempts" | |
| exit 1 |