diff --git a/docs/specs/DEVX-174.md b/docs/specs/DEVX-174.md new file mode 100644 index 0000000..561acba --- /dev/null +++ b/docs/specs/DEVX-174.md @@ -0,0 +1,31 @@ +# DEVX-174: Set git identity in dep-PR target clone + +## Problem + +`create_dependency_pr` commits the manifest bump in a fresh clone of the +target repo. The clone has no `user.name`/`user.email`, so `git commit` +exits 128 ("Please tell me who you are") — observed in sso-bridge +post-merge run 6284 after the digest and manifest bump both succeeded. + +## Approach + +REQ-1: Pass a CI bot identity inline (`git -c user.name=... -c +user.email=... commit`) so the commit works in any environment without +mutating global git config. + +## Test Plan + +- Unit test asserting the commit invocation carries `-c user.name` / + `-c user.email` arguments. + +## Deploy Plan + +devx release; sso-bridge picks it up via its devx pin on next bump. + +## Rollback Plan + +Revert; dep-PR commit fails again in containers without git identity. + +## Acceptance Criteria + +- [x] REQ-1: dep-PR commit supplies explicit identity flags. diff --git a/src/devx/ci/create_dependency_pr.py b/src/devx/ci/create_dependency_pr.py index 70c8156..13f082b 100644 --- a/src/devx/ci/create_dependency_pr.py +++ b/src/devx/ci/create_dependency_pr.py @@ -505,7 +505,22 @@ def cli( add_files.append(spec_rel) subprocess.run(["git", "add", *add_files], check=True, cwd=workdir) # nosec B603 B607 commit_msg = f"deps: bump {package} from {old_version} to {new_version}" - subprocess.run(["git", "commit", "-m", commit_msg], check=True, cwd=workdir) # nosec B603 B607 + # Implements: REQ-1 — the fresh clone has no git identity in CI + # containers; supply it inline (same bot identity as push_badges). + subprocess.run( # nosec B603 B607 + [ + "git", + "-c", + "user.name=gitea-actions-bot", + "-c", + "user.email=actions@oblachno.fyi", + "commit", + "-m", + commit_msg, + ], + check=True, + cwd=workdir, + ) subprocess.run( # nosec B603 B607 ["git", "-c", auth_cfg, "push", "origin", branch_name], check=True, diff --git a/tests/unit/test_create_dependency_pr.py b/tests/unit/test_create_dependency_pr.py index e45b982..135d5b6 100644 --- a/tests/unit/test_create_dependency_pr.py +++ b/tests/unit/test_create_dependency_pr.py @@ -661,6 +661,10 @@ class TestBranchCreation: # PR title carries the task ID assert client.create_pr.call_args.kwargs["title"] == "OBL-INFRA-581: Bump sso_bridge to 0.9.1" mock_task.assert_called_once() + # Commit supplies an explicit identity (fresh clones have none) + commit = next(c for c in subprocess.run.call_args_list if "commit" in c.args[0]) + assert "user.name=gitea-actions-bot" in commit.args[0] + assert "user.email=actions@oblachno.fyi" in commit.args[0] def test_retries_404_until_published(self) -> None: import requests