Public Access
DEVX-174: fix(ci): supply git identity for dep-PR manifest commits
This commit was merged in pull request #342.
This commit is contained in:
@@ -0,0 +1,31 @@
|
|||||||
|
# DEVX-174: Set git identity in dep-PR target clone
|
||||||
|
|
||||||
|
## Problem
|
||||||
|
|
||||||
|
`create_dependency_pr` commits the manifest bump in a fresh clone of the
|
||||||
|
target repo. The clone has no `user.name`/`user.email`, so `git commit`
|
||||||
|
exits 128 ("Please tell me who you are") — observed in sso-bridge
|
||||||
|
post-merge run 6284 after the digest and manifest bump both succeeded.
|
||||||
|
|
||||||
|
## Approach
|
||||||
|
|
||||||
|
REQ-1: Pass a CI bot identity inline (`git -c user.name=... -c
|
||||||
|
user.email=... commit`) so the commit works in any environment without
|
||||||
|
mutating global git config.
|
||||||
|
|
||||||
|
## Test Plan
|
||||||
|
|
||||||
|
- Unit test asserting the commit invocation carries `-c user.name` /
|
||||||
|
`-c user.email` arguments.
|
||||||
|
|
||||||
|
## Deploy Plan
|
||||||
|
|
||||||
|
devx release; sso-bridge picks it up via its devx pin on next bump.
|
||||||
|
|
||||||
|
## Rollback Plan
|
||||||
|
|
||||||
|
Revert; dep-PR commit fails again in containers without git identity.
|
||||||
|
|
||||||
|
## Acceptance Criteria
|
||||||
|
|
||||||
|
- [x] REQ-1: dep-PR commit supplies explicit identity flags.
|
||||||
@@ -505,7 +505,22 @@ def cli(
|
|||||||
add_files.append(spec_rel)
|
add_files.append(spec_rel)
|
||||||
subprocess.run(["git", "add", *add_files], check=True, cwd=workdir) # nosec B603 B607
|
subprocess.run(["git", "add", *add_files], check=True, cwd=workdir) # nosec B603 B607
|
||||||
commit_msg = f"deps: bump {package} from {old_version} to {new_version}"
|
commit_msg = f"deps: bump {package} from {old_version} to {new_version}"
|
||||||
subprocess.run(["git", "commit", "-m", commit_msg], check=True, cwd=workdir) # nosec B603 B607
|
# Implements: REQ-1 — the fresh clone has no git identity in CI
|
||||||
|
# containers; supply it inline (same bot identity as push_badges).
|
||||||
|
subprocess.run( # nosec B603 B607
|
||||||
|
[
|
||||||
|
"git",
|
||||||
|
"-c",
|
||||||
|
"user.name=gitea-actions-bot",
|
||||||
|
"-c",
|
||||||
|
"user.email=actions@oblachno.fyi",
|
||||||
|
"commit",
|
||||||
|
"-m",
|
||||||
|
commit_msg,
|
||||||
|
],
|
||||||
|
check=True,
|
||||||
|
cwd=workdir,
|
||||||
|
)
|
||||||
subprocess.run( # nosec B603 B607
|
subprocess.run( # nosec B603 B607
|
||||||
["git", "-c", auth_cfg, "push", "origin", branch_name],
|
["git", "-c", auth_cfg, "push", "origin", branch_name],
|
||||||
check=True,
|
check=True,
|
||||||
|
|||||||
@@ -661,6 +661,10 @@ class TestBranchCreation:
|
|||||||
# PR title carries the task ID
|
# PR title carries the task ID
|
||||||
assert client.create_pr.call_args.kwargs["title"] == "OBL-INFRA-581: Bump sso_bridge to 0.9.1"
|
assert client.create_pr.call_args.kwargs["title"] == "OBL-INFRA-581: Bump sso_bridge to 0.9.1"
|
||||||
mock_task.assert_called_once()
|
mock_task.assert_called_once()
|
||||||
|
# Commit supplies an explicit identity (fresh clones have none)
|
||||||
|
commit = next(c for c in subprocess.run.call_args_list if "commit" in c.args[0])
|
||||||
|
assert "user.name=gitea-actions-bot" in commit.args[0]
|
||||||
|
assert "user.email=actions@oblachno.fyi" in commit.args[0]
|
||||||
|
|
||||||
def test_retries_404_until_published(self) -> None:
|
def test_retries_404_until_published(self) -> None:
|
||||||
import requests
|
import requests
|
||||||
|
|||||||
Reference in New Issue
Block a user