Files
iptvnator/.github/workflows/refresh-windows-embedded-mpv-runtime.yaml
T
4gray e9eca1c386 chore(deps): upgrade Angular to 22.1 and Nx to 23.2 (#1603)
* chore(deps): upgrade Angular to 22.1 and Nx to 23.2

* fix(deps): complete Angular migrations after rebasing on master

* fix(ci): use the Node pin for Windows runtime refresh

* docs(deps): synchronize the workspace-shell Node requirements
2026-09-14 19:02:40 +02:00

109 lines
4.3 KiB
YAML

name: Refresh Windows Embedded MPV Runtime Pin
on:
schedule:
- cron: '17 6 * * 1'
workflow_dispatch:
inputs:
force:
description: Refresh even when the current pin is still young
required: false
default: false
type: boolean
permissions:
contents: read
concurrency:
group: refresh-windows-embedded-mpv-runtime-pin
cancel-in-progress: false
jobs:
refresh:
name: Refresh checked-in runtime pin
if: github.repository == '4gray/iptvnator'
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
with:
fetch-depth: 0
persist-credentials: false
- name: Setup Node.js
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020
with:
node-version-file: '.nvmrc'
- name: Refresh pin when it approaches upstream retention
id: refresh
env:
FORCE_REFRESH: ${{ inputs.force && 'true' || 'false' }}
GITHUB_TOKEN: ${{ github.token }}
shell: bash
run: |
set -euo pipefail
if [ "${FORCE_REFRESH}" = "true" ]; then
node tools/embedded-mpv/update-windows-runtime-pin.mjs --force
else
node tools/embedded-mpv/update-windows-runtime-pin.mjs
fi
- name: Validate updated pin
if: steps.refresh.outputs.changed == 'true'
run: >-
node --test
tools/embedded-mpv/windows-runtime-pin.test.mjs
- name: Create or update refresh pull request
if: steps.refresh.outputs.changed == 'true'
env:
GH_TOKEN: ${{ secrets.PAT }}
BRANCH_NAME: automation/windows-embedded-mpv-runtime-pin
RELEASE_TAG: ${{ steps.refresh.outputs.release-tag }}
shell: bash
run: |
set -euo pipefail
if [ -z "${GH_TOKEN}" ]; then
echo "::error::The PAT secret is required so the bot-created PR triggers normal CI."
exit 1
fi
gh auth setup-git
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git switch -C "${BRANCH_NAME}"
git add -- tools/embedded-mpv/windows-runtime-pin.json
git commit -m "ci(embedded-mpv): refresh Windows runtime pin"
git fetch origin "${BRANCH_NAME}:refs/remotes/origin/${BRANCH_NAME}" || true
git push --force-with-lease origin "HEAD:refs/heads/${BRANCH_NAME}"
PR_BODY="$(printf '%s\n\n%s\n%s\n%s' \
'Automated refresh of the checksum-pinned Windows Embedded MPV CI input.' \
"- Pins upstream release \`${RELEASE_TAG}\` in repository history." \
'- Keeps the binary on its upstream host; IPTVnator does not mirror it.' \
'- Preserves the explicit checksum/layout-only license-verification statement.')"
PR_NUMBER="$(gh pr list \
--base master \
--head "${BRANCH_NAME}" \
--state open \
--json number \
--jq '.[0].number // empty')"
if [ -n "${PR_NUMBER}" ]; then
gh pr edit "${PR_NUMBER}" \
--title "ci(embedded-mpv): refresh Windows runtime pin" \
--body "${PR_BODY}"
gh pr view "${PR_NUMBER}" --json url --jq '.url'
else
gh pr create \
--base master \
--head "${BRANCH_NAME}" \
--title "ci(embedded-mpv): refresh Windows runtime pin" \
--body "${PR_BODY}"
fi