Skip to content

build(deps-dev): Bump @tanstack/react-virtual from 3.14.12 to 3.14.13… #312

build(deps-dev): Bump @tanstack/react-virtual from 3.14.12 to 3.14.13…

build(deps-dev): Bump @tanstack/react-virtual from 3.14.12 to 3.14.13… #312

name: Bump downstream submodule pointers
# When this repo's main moves, push a matching gitlink bump to every downstream
# repo that carries this one as a `failproofai/oss` submodule, so their pinned
# commits track upstream automatically. Direct push to each downstream `main` —
# no PR.
#
# Both downstreams are governed by the org-level `failproofai-rules` ruleset
# (PR + 1 review required on main), which rejects a plain GITHUB_TOKEN push with
# GH013. We instead mint a token for the version-bot GitHub App — a bypass actor
# on that ruleset — so the push is accepted. The same ruleset object governs both
# repos, so one bypass covers both.
#
# The filename still says `platform` so the Actions run history — which GitHub
# keys by workflow path — survives; the matrix below is the source of truth for
# which repos actually get bumped.
on:
push:
branches: [main]
workflow_dispatch:
jobs:
bump:
runs-on: ubuntu-latest
strategy:
# Independent repos: a failure bumping one must not cancel the other.
fail-fast: false
matrix:
# Every repo carrying this one at `failproofai/oss`. Add a repo here and
# it gets bumped — nothing else in this file is downstream-specific.
repo: [platform, agenteye]
# Serialize per downstream so back-to-back merges produce sequential bumps,
# not a race that loses one of them. Keyed by repo so a slow platform bump
# never delays agenteye's.
concurrency:
group: bump-submodule-${{ matrix.repo }}
cancel-in-progress: false
steps:
# Token for the version-bot GitHub App — a bypass actor on the org
# ruleset, so pushes to the downstream main bypass the PR requirement.
# Scoped to just the one repo this matrix leg touches.
- name: Mint version-bot app token
id: app-token
uses: actions/create-github-app-token@v3
with:
app-id: ${{ secrets.VERSION_BOT_APP_ID }}
private-key: ${{ secrets.VERSION_BOT_PRIVATE_KEY }}
# Without an explicit owner/repository, the action scopes the token
# to this repository, which cannot checkout the private downstream repo.
owner: FailproofAI
repositories: ${{ matrix.repo }}
- name: Checkout FailproofAI/${{ matrix.repo }} main
uses: actions/checkout@v7.0.1
with:
repository: FailproofAI/${{ matrix.repo }}
# Persist the app token so `git push` below bypasses the ruleset.
# The version-bot App is a bypass actor on `failproofai-rules`.
token: ${{ steps.app-token.outputs.token }}
ref: main
fetch-depth: 1
# Don't fetch submodule contents — we only edit the gitlink.
submodules: false
- name: Bump failproofai/oss gitlink and push
env:
NEW_SHA: ${{ github.sha }}
COMMIT_SUBJECT: ${{ github.event.head_commit.message }}
UPSTREAM_REPO: ${{ github.repository }}
DOWNSTREAM_REPO: ${{ matrix.repo }}
run: |
set -euo pipefail
git config user.name "agenteye-bot"
git config user.email "agenteye-bot@users.noreply.github.com"
CURRENT_SHA=$(git ls-tree HEAD failproofai/oss | awk '{print $3}')
if [ -z "$CURRENT_SHA" ]; then
echo "::error::failproofai/oss is not a gitlink in $DOWNSTREAM_REPO main — aborting."
exit 1
fi
if [ "$CURRENT_SHA" = "$NEW_SHA" ]; then
echo "Already at $NEW_SHA — nothing to do."
exit 0
fi
# Rewrite the gitlink (mode 160000 = submodule entry) without
# needing the submodule contents on disk.
git update-index --add --cacheinfo "160000,$NEW_SHA,failproofai/oss"
# Extract the first line via pure bash parameter expansion — piping
# printf into `head -n 1` raced under `set -o pipefail`: head closes
# the pipe after the first line, printf dies with SIGPIPE, and the
# pipeline exits non-zero. The squash-merge commit body that broke
# run 27208748580 was several KB, easily triggering it.
SUBJECT_LINE=${COMMIT_SUBJECT:-Manual trigger}
SUBJECT_LINE=${SUBJECT_LINE%%$'\n'*}
SHORT_SHA=${NEW_SHA:0:7}
git commit -m "Bump failproofai/oss to $SHORT_SHA" \
-m "Upstream: $SUBJECT_LINE" \
-m "https://github.com/$UPSTREAM_REPO/commit/$NEW_SHA"
# Race-safe push: if the downstream main moved between checkout and
# push, rebase the single bump commit on top and try again.
for attempt in 1 2 3; do
if git push origin main; then
echo "Pushed bump on attempt $attempt"
exit 0
fi
echo "Push failed on attempt $attempt — rebasing onto latest main"
git fetch origin main
git rebase origin/main
done
echo "::error::Failed to push submodule bump after 3 attempts"
exit 1