From b51a3867c8d0855fdc989cf5dd1409d6d434f0a6 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Rados=C5=82aw?= <54472480+radoslaw-sz@users.noreply.github.com> Date: Thu, 24 Oct 2024 19:39:47 +0200 Subject: [PATCH 1/4] Delete microsite/data/plugins/changelog.yaml MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Due to different plans, I need to remove plugin from plugins. Signed-off-by: Radosław <54472480+radoslaw-sz@users.noreply.github.com> --- microsite/data/plugins/changelog.yaml | 12 ------------ 1 file changed, 12 deletions(-) delete mode 100644 microsite/data/plugins/changelog.yaml diff --git a/microsite/data/plugins/changelog.yaml b/microsite/data/plugins/changelog.yaml deleted file mode 100644 index a1ee12feea..0000000000 --- a/microsite/data/plugins/changelog.yaml +++ /dev/null @@ -1,12 +0,0 @@ ---- -title: Changelog viewer -author: RSC Labs -authorUrl: https://rsoftcon.com/ -category: Discovery -description: View changelogs for your components in Backstage. Built-in support of "Keep the changelog" and "Semver" formats. -documentation: https://github.com/RSC-Labs/backstage-changelog-plugin/blob/main/README.md -iconUrl: https://raw.githubusercontent.com/RSC-Labs/backstage-changelog-plugin/main/docs/plugin_icon.png -npmPackageName: '@rsc-labs/backstage-changelog-plugin' -tags: - - changelog -addedDate: '2023-10-22' From 8de08d7b0b4cdcf9be7fae5731ed9e418f3147b4 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Rados=C5=82aw?= <54472480+radoslaw-sz@users.noreply.github.com> Date: Thu, 24 Oct 2024 19:40:13 +0200 Subject: [PATCH 2/4] Delete microsite/data/plugins/highlights.yaml MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Due to different plans, I need to remove plugin from plugins Signed-off-by: Radosław <54472480+radoslaw-sz@users.noreply.github.com> --- microsite/data/plugins/highlights.yaml | 12 ------------ 1 file changed, 12 deletions(-) delete mode 100644 microsite/data/plugins/highlights.yaml diff --git a/microsite/data/plugins/highlights.yaml b/microsite/data/plugins/highlights.yaml deleted file mode 100644 index 82d303f4ed..0000000000 --- a/microsite/data/plugins/highlights.yaml +++ /dev/null @@ -1,12 +0,0 @@ ---- -title: Highlights -author: RSC Labs -authorUrl: https://rsoftcon.com/ -category: Discovery -description: Highlight what is important for you and put it on front for the quick view and access. Built-in support of Git information from GitHub and GitLab. -documentation: https://github.com/RSC-Labs/backstage-highlights-plugin/blob/main/README.md -iconUrl: https://raw.githubusercontent.com/RSC-Labs/backstage-highlights-plugin/main/docs/highlighter.png -npmPackageName: '@rsc-labs/backstage-highlights-plugin' -tags: - - highlights -addedDate: '2023-11-20' From dd640f3881b768b01efd947a6100d3165823d452 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Rados=C5=82aw?= <54472480+radoslaw-sz@users.noreply.github.com> Date: Thu, 24 Oct 2024 19:46:47 +0200 Subject: [PATCH 3/4] Delete .github/workflows directory MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Signed-off-by: Radosław <54472480+radoslaw-sz@users.noreply.github.com> --- .../api-breaking-changes-comment.yml | 111 ------- .github/workflows/api-breaking-changes.yml | 56 ---- .github/workflows/automate_area-labels.yml | 23 -- .../workflows/automate_changeset_feedback.yml | 46 --- .github/workflows/automate_merge_message.yml | 68 ----- .github/workflows/automate_stale.yml | 42 --- .github/workflows/ci-noop.yml | 47 --- .github/workflows/ci.yml | 280 ------------------ .github/workflows/cron.yml | 21 -- .github/workflows/deploy_docker-image.yml | 75 ----- .github/workflows/deploy_microsite.yml | 231 --------------- .github/workflows/deploy_packages.yml | 160 ---------- .github/workflows/issue.yaml | 31 -- .../workflows/pr-review-comment-trigger.yaml | 37 --- .github/workflows/pr-review-comment.yaml | 49 --- .github/workflows/pr.yaml | 34 --- .github/workflows/scorecard.yml | 72 ----- .github/workflows/sync_code-formatting.yml | 40 --- .../workflows/sync_dependabot-changesets.yml | 83 ------ .github/workflows/sync_release-manifest.yml | 89 ------ .../workflows/sync_renovate-changesets.yml | 102 ------- .github/workflows/sync_snyk-github-issues.yml | 48 --- .github/workflows/sync_snyk-monitor.yml | 63 ---- .github/workflows/sync_version-packages.yml | 43 --- .../workflows/verify_accessibility-noop.yml | 33 --- .github/workflows/verify_accessibility.yml | 40 --- .github/workflows/verify_codeql.yml | 83 ------ .github/workflows/verify_docs-quality.yml | 35 --- .github/workflows/verify_e2e-linux-noop.yml | 36 --- .github/workflows/verify_e2e-linux.yml | 76 ----- .github/workflows/verify_e2e-techdocs.yml | 59 ---- .github/workflows/verify_e2e-windows-noop.yml | 32 -- .github/workflows/verify_e2e-windows.yml | 91 ------ .github/workflows/verify_fossa.yml | 32 -- .github/workflows/verify_microsite-noop.yml | 28 -- .github/workflows/verify_microsite.yml | 68 ----- .../verify_microsite_accessibility-noop.yml | 31 -- .../verify_microsite_accessibility.yml | 40 --- .github/workflows/verify_storybook-noop.yml | 35 --- .github/workflows/verify_storybook.yml | 61 ---- .github/workflows/verify_windows.yml | 71 ----- 41 files changed, 2702 deletions(-) delete mode 100644 .github/workflows/api-breaking-changes-comment.yml delete mode 100644 .github/workflows/api-breaking-changes.yml delete mode 100644 .github/workflows/automate_area-labels.yml delete mode 100644 .github/workflows/automate_changeset_feedback.yml delete mode 100644 .github/workflows/automate_merge_message.yml delete mode 100644 .github/workflows/automate_stale.yml delete mode 100644 .github/workflows/ci-noop.yml delete mode 100644 .github/workflows/ci.yml delete mode 100644 .github/workflows/cron.yml delete mode 100644 .github/workflows/deploy_docker-image.yml delete mode 100644 .github/workflows/deploy_microsite.yml delete mode 100644 .github/workflows/deploy_packages.yml delete mode 100644 .github/workflows/issue.yaml delete mode 100644 .github/workflows/pr-review-comment-trigger.yaml delete mode 100644 .github/workflows/pr-review-comment.yaml delete mode 100644 .github/workflows/pr.yaml delete mode 100644 .github/workflows/scorecard.yml delete mode 100644 .github/workflows/sync_code-formatting.yml delete mode 100644 .github/workflows/sync_dependabot-changesets.yml delete mode 100644 .github/workflows/sync_release-manifest.yml delete mode 100644 .github/workflows/sync_renovate-changesets.yml delete mode 100644 .github/workflows/sync_snyk-github-issues.yml delete mode 100644 .github/workflows/sync_snyk-monitor.yml delete mode 100644 .github/workflows/sync_version-packages.yml delete mode 100644 .github/workflows/verify_accessibility-noop.yml delete mode 100644 .github/workflows/verify_accessibility.yml delete mode 100644 .github/workflows/verify_codeql.yml delete mode 100644 .github/workflows/verify_docs-quality.yml delete mode 100644 .github/workflows/verify_e2e-linux-noop.yml delete mode 100644 .github/workflows/verify_e2e-linux.yml delete mode 100644 .github/workflows/verify_e2e-techdocs.yml delete mode 100644 .github/workflows/verify_e2e-windows-noop.yml delete mode 100644 .github/workflows/verify_e2e-windows.yml delete mode 100644 .github/workflows/verify_fossa.yml delete mode 100644 .github/workflows/verify_microsite-noop.yml delete mode 100644 .github/workflows/verify_microsite.yml delete mode 100644 .github/workflows/verify_microsite_accessibility-noop.yml delete mode 100644 .github/workflows/verify_microsite_accessibility.yml delete mode 100644 .github/workflows/verify_storybook-noop.yml delete mode 100644 .github/workflows/verify_storybook.yml delete mode 100644 .github/workflows/verify_windows.yml diff --git a/.github/workflows/api-breaking-changes-comment.yml b/.github/workflows/api-breaking-changes-comment.yml deleted file mode 100644 index 038061adac..0000000000 --- a/.github/workflows/api-breaking-changes-comment.yml +++ /dev/null @@ -1,111 +0,0 @@ -name: API Breaking Changes (comment) - -on: - workflow_run: - workflows: - - 'API Breaking Changes (Trigger)' - types: - - completed - -jobs: - setup: - name: Add values from previous step - runs-on: ubuntu-latest - if: ${{ github.event.workflow_run.conclusion == 'success' }} - permissions: - # "If you specify the access for any of these scopes, all of those that are not specified are set to none." - # https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#permissions - actions: read # Access cache - outputs: - git-ref: ${{ steps.event.outputs.GIT_REF }} - pr-number: ${{ steps.event.outputs.PR_NUMBER }} - action: ${{ steps.event.outputs.ACTION }} - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - disable-sudo: true - egress-policy: block - allowed-endpoints: > - api.github.com:443 - - - name: 'Download artifacts' - # Fetch output (zip archive) from the workflow run that triggered this workflow. - uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1 - with: - script: | - let allArtifacts = await github.rest.actions.listWorkflowRunArtifacts({ - owner: context.repo.owner, - repo: context.repo.repo, - run_id: context.payload.workflow_run.id, - }); - let matchArtifact = allArtifacts.data.artifacts.filter((artifact) => { - return artifact.name == "preview-spec" - })[0]; - if (matchArtifact === undefined) { - throw TypeError('Build Artifact not found!'); - } - let download = await github.rest.actions.downloadArtifact({ - owner: context.repo.owner, - repo: context.repo.repo, - artifact_id: matchArtifact.id, - archive_format: 'zip', - }); - let fs = require('fs'); - fs.writeFileSync(`${process.env.GITHUB_WORKSPACE}/preview-spec.zip`, Buffer.from(download.data)); - - - name: 'Accept event from first stage' - run: unzip preview-spec.zip event.json - - - name: Read Event into ENV - id: event - run: | - echo PR_NUMBER=$(jq '.number | tonumber' < event.json) >> $GITHUB_OUTPUT - echo ACTION=$(jq --raw-output '.action | tostring | [scan("\\w+")][0]' < event.json) >> $GITHUB_OUTPUT - echo GIT_REF=$(jq --raw-output '.pull_request.head.sha | tostring | [scan("\\w+")][0]' < event.json) >> $GITHUB_OUTPUT - - - name: DEBUG - Print Job Outputs - if: ${{ runner.debug }} - run: | - echo "PR number: ${{ steps.event.outputs.PR_NUMBER }}" - echo "Git Ref: ${{ steps.event.outputs.GIT_REF }}" - echo "Action: ${{ steps.event.outputs.ACTION }}" - cat event.json - - - name: Get Comment - id: get-comment - run: | - unzip preview-spec.zip comment.md - ls - grep - - add-comment: - name: Write comment about issues - needs: - - setup - if: ${{ github.event.workflow_run.conclusion == 'success' }} - permissions: - contents: read - pull-requests: write - runs-on: ubuntu-latest - steps: - - name: Checkout - uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4 - - # Identify comment to be updated - - name: Find comment for API Changes - uses: peter-evans/find-comment@3eae4d37986fb5a8592848f6a574fdf654e61f9e # v3 - id: find-comment - with: - issue-number: ${{ needs.setup.outputs.pr-number }} - comment-author: 'github-actions[bot]' - body-includes: API changes - direction: last - - - name: Create or Update Comment with API Changes - uses: peter-evans/create-or-update-comment@71345be0265236311c031f5c7866368bd1eff043 # v4 - with: - comment-id: ${{ steps.find-comment.outputs.comment-id }} - issue-number: ${{ github.event.pull_request.number }} - body-path: comment.md - edit-mode: replace diff --git a/.github/workflows/api-breaking-changes.yml b/.github/workflows/api-breaking-changes.yml deleted file mode 100644 index 9c2b9229f8..0000000000 --- a/.github/workflows/api-breaking-changes.yml +++ /dev/null @@ -1,56 +0,0 @@ -name: API Breaking Changes (Trigger) -on: - pull_request: - types: [opened, synchronize, reopened, closed] - paths: - - '**/openapi.yaml' - -jobs: - get-backstage-changes: - env: - NODE_OPTIONS: --max-old-space-size=4096 - name: Build PR image - runs-on: ubuntu-latest - if: ${{ github.event_name != 'pull_request' || github.event.action != 'closed' }} - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - with: - # Fetch the commit that's merged into the base rather than the target ref - # This will let us diff only the contents of the PR, without fetching more history - ref: 'refs/pull/${{ github.event.pull_request.number }}/merge' - - name: fetch base - run: git fetch --depth 1 origin ${{ github.base_ref }} - - - name: setup-node - uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 - with: - node-version: 20.x - registry-url: https://registry.npmjs.org/ - - - name: yarn install - uses: backstage/actions/yarn-install@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 - with: - cache-prefix: linux-v20 - - - name: breaking changes check - run: | - yarn backstage-repo-tools repo schema openapi diff --since origin/${{ github.base_ref }} > comment.md - - - name: clone artifacts to current directory - run: | - cat ${{ github.event_path }} > event.json - - - name: Upload Artifacts - uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 # v4 - with: - name: preview-spec - path: | - comment.md - event.json - retention-days: 2 - overwrite: true diff --git a/.github/workflows/automate_area-labels.yml b/.github/workflows/automate_area-labels.yml deleted file mode 100644 index 89e1adc3c3..0000000000 --- a/.github/workflows/automate_area-labels.yml +++ /dev/null @@ -1,23 +0,0 @@ -name: Automate area labels -on: - - pull_request_target - -permissions: - contents: read - -jobs: - triage: - permissions: - contents: read # for actions/labeler to determine modified files - pull-requests: write # for actions/labeler to add labels to PRs - runs-on: ubuntu-latest - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - uses: actions/labeler@8558fd74291d67161a8a78ce36a881fa63b766a9 # v5.0.0 - with: - repo-token: '${{ secrets.GITHUB_TOKEN }}' - sync-labels: true diff --git a/.github/workflows/automate_changeset_feedback.yml b/.github/workflows/automate_changeset_feedback.yml deleted file mode 100644 index d7e2b56b39..0000000000 --- a/.github/workflows/automate_changeset_feedback.yml +++ /dev/null @@ -1,46 +0,0 @@ -name: Automate changeset feedback -on: - pull_request_target: - branches: ['master'] - -permissions: - pull-requests: write - actions: none - checks: none - contents: none - deployments: none - issues: none - packages: none - pages: none - repository-projects: none - security-events: none - statuses: none - -jobs: - feedback: - # prevent running towards forks and version packages - if: github.repository == 'backstage/backstage' && github.event.pull_request.user.login != 'backstage-service' - runs-on: ubuntu-latest - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - with: - # Fetch the commit that's merged into the base rather than the target ref - # This will let us diff only the contents of the PR, without fetching more history - ref: 'refs/pull/${{ github.event.pull_request.number }}/merge' - - name: fetch base - run: git fetch --depth 1 origin ${{ github.base_ref }} - - uses: backstage/actions/changeset-feedback@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 - name: Generate feedback - with: - diff-ref: 'origin/master' - marker: - issue-number: ${{ github.event.pull_request.number }} - bot-username: backstage-goalie[bot] - app-id: ${{ secrets.BACKSTAGE_GOALIE_APPLICATION_ID }} - private-key: ${{ secrets.BACKSTAGE_GOALIE_PRIVATE_KEY }} - installation-id: ${{ secrets.BACKSTAGE_GOALIE_INSTALLATION_ID }} diff --git a/.github/workflows/automate_merge_message.yml b/.github/workflows/automate_merge_message.yml deleted file mode 100644 index ece1331730..0000000000 --- a/.github/workflows/automate_merge_message.yml +++ /dev/null @@ -1,68 +0,0 @@ -name: Automate merge message -on: - pull_request_target: - branches: ['master'] - types: ['closed'] - -permissions: - pull-requests: write - actions: none - checks: none - contents: none - deployments: none - issues: none - packages: none - pages: none - repository-projects: none - security-events: none - statuses: none - -jobs: - message: - # prevent running towards forks, and only run on merged PRs - if: github.repository == 'backstage/backstage' && github.event.pull_request.merged == true - runs-on: ubuntu-latest - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - with: - ref: '${{ github.event.pull_request.merge_commit_sha }}' - - - name: fetch head & base - run: git fetch --depth 1 origin ${{ github.event.pull_request.head.sha }} ${{ github.event.pull_request.base.sha }} - - # We avoid using the in-source script since this workflow has elevated permissions that we don't want to expose - - name: Generate Message - id: generate-message - run: | - rm -f generate.js - wget -O generate.js https://raw.githubusercontent.com/backstage/backstage/master/scripts/generate-merge-message.js 1>&2 - node generate.js ${{ github.event.pull_request.base.sha }} ${{ github.event.pull_request.head.sha }} > message.txt - - - name: Post Message - uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1 - env: - ISSUE_NUMBER: ${{ github.event.pull_request.number }} - with: - script: | - const owner = "backstage"; - const repo = "backstage"; - const body = require('fs').readFileSync('message.txt', 'utf8').trim(); - const issue_number = Number(process.env.ISSUE_NUMBER); - - if (!body) { - console.log(`skipping comment for #${issue_number}`); - return; - } - - console.log(`creating comment for #${issue_number}`); - await github.rest.issues.createComment({ - owner, - repo, - issue_number, - body, - }); diff --git a/.github/workflows/automate_stale.yml b/.github/workflows/automate_stale.yml deleted file mode 100644 index b7adc5235a..0000000000 --- a/.github/workflows/automate_stale.yml +++ /dev/null @@ -1,42 +0,0 @@ -name: Automate staleness -on: - workflow_dispatch: - schedule: - - cron: '*/10 * * * *' # run every 10 minutes as it also removes labels. - -permissions: - contents: read - -jobs: - stale: - permissions: - issues: write # for actions/stale to close stale issues - pull-requests: write # for actions/stale to close stale PRs - runs-on: ubuntu-latest - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - uses: actions/stale@28ca1036281a5e5922ead5184a1bbf96e5fc984e # v9.0.0 - id: stale - with: - stale-issue-message: > - This issue has been automatically marked as stale because it has not had - recent activity. It will be closed if no further activity occurs. Thank you - for your contributions. - days-before-issue-stale: 60 - days-before-issue-close: 7 - exempt-issue-labels: plugin,after-vacations,will-fix,bep - stale-issue-label: stale - stale-pr-message: > - This PR has been automatically marked as stale because it has not had - recent activity from the author. It will be closed if no further activity occurs. - If the PR was closed and you want it re-opened, let us know - and we'll re-open the PR so that you can continue the contribution! - days-before-pr-stale: 14 - days-before-pr-close: 7 - exempt-pr-labels: after-vacations,will-fix - stale-pr-label: stale - operations-per-run: 100 diff --git a/.github/workflows/ci-noop.yml b/.github/workflows/ci-noop.yml deleted file mode 100644 index af7199ede6..0000000000 --- a/.github/workflows/ci-noop.yml +++ /dev/null @@ -1,47 +0,0 @@ -# NO-OP placeholder that always passes for other paths -# This is here so that we're able to set the status check as required - -name: CI Void -on: - pull_request: - paths: - - 'microsite/**' - - 'beps/**' - -permissions: - contents: read - -jobs: - # The verify jobs runs all the verification that doesn't require a - # diff towards master, since it takes some time to fetch that. - verify-noop: - runs-on: ubuntu-latest - - strategy: - matrix: - node-version: [20.x, 22.x] - - name: Verify ${{ matrix.node-version }} - steps: - # - name: Harden Runner - # uses: step-security/harden-runner@8ca2b8b2ece13480cda6dacd3511b49857a23c09 # v2.5.1 - # with: - # egress-policy: audit - - - run: echo NOOP - - test-noop: - runs-on: ubuntu-latest - - strategy: - matrix: - node-version: [20.x, 22.x] - - name: Test ${{ matrix.node-version }} - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - run: echo NOOP diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml deleted file mode 100644 index c15fa1483f..0000000000 --- a/.github/workflows/ci.yml +++ /dev/null @@ -1,280 +0,0 @@ -name: CI -on: - # NOTE: If you change these you must update ci-noop.yml as well - pull_request: - paths-ignore: - - 'microsite/**' - - 'beps/**' - -concurrency: - group: ${{ github.workflow }}-${{ github.ref }} - cancel-in-progress: true - -jobs: - # This step only runs yarn install to make sure that an exact match is available - # in the cache. The two following verify and tests jobs then always install from cache. - install: - runs-on: ubuntu-latest - - strategy: - fail-fast: false - matrix: - node-version: [20.x, 22.x] - - env: - CI: true - NODE_OPTIONS: --max-old-space-size=8192 - - name: Install ${{ matrix.node-version }} - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - - - name: use node.js ${{ matrix.node-version }} - uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 - with: - node-version: ${{ matrix.node-version }} - registry-url: https://registry.npmjs.org/ # Needed for auth - - - name: yarn install - uses: backstage/actions/yarn-install@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 - with: - cache-prefix: ${{ runner.os }}-v${{ matrix.node-version }} - - # The verify jobs runs all the verification that doesn't require a - # diff towards master, since it takes some time to fetch that. - verify: - runs-on: ubuntu-latest - - needs: install - - strategy: - fail-fast: false - matrix: - node-version: [20.x, 22.x] - - env: - CI: true - NODE_OPTIONS: --max-old-space-size=8192 - - name: Verify ${{ matrix.node-version }} - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - - - name: use node.js ${{ matrix.node-version }} - uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 - with: - node-version: ${{ matrix.node-version }} - registry-url: https://registry.npmjs.org/ # Needed for auth - - - name: yarn install - uses: backstage/actions/yarn-install@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 - with: - cache-prefix: ${{ runner.os }}-v${{ matrix.node-version }} - - - name: verify yarn dependency duplicates - run: node scripts/verify-lockfile-duplicates.js - - - name: verify changesets - run: node scripts/verify-changesets.js - - - name: verify local dependency ranges - run: node scripts/verify-local-dependencies.js - - - name: verify peer dependency ranges - run: yarn lint:peer-deps - - - name: check for missing repo fixes - run: yarn fix --check - - - name: validate config - run: yarn backstage-cli config:check --lax - - - name: type checking and declarations - run: yarn tsc:full - - - name: prettier - run: yarn prettier:check - - # We need to generate the API references as well, so that we can verify the doc links - - name: check api reports and generate API reference - run: yarn build:api-reports:only --ci --docs - - - name: verify api reference - run: node scripts/verify-api-reference.js - - - name: verify catalog-info.yaml consistency - run: yarn backstage-repo-tools generate-catalog-info --ci - - - name: lint openapi yaml files - run: yarn backstage-repo-tools repo schema openapi lint - - - name: verify openapi yaml file matches generated ts file - run: yarn backstage-repo-tools repo schema openapi verify - - - name: verify doc links - run: node scripts/verify-links.js - - - name: build all packages - run: yarn backstage-cli repo build --all - - - name: verify type dependencies - run: yarn lint:type-deps - - - name: ensure clean working directory - run: | - if files=$(git ls-files --exclude-standard --others --modified) && [[ -z "$files" ]]; then - exit 0 - else - echo "" - echo "Working directory has been modified:" - echo "" - git status --short - echo "" - exit 1 - fi - - # The test job runs all tests as well as any verification step that - # requires a diff towards master. - test: - runs-on: ubuntu-latest - - needs: install - - strategy: - fail-fast: false - matrix: - node-version: [20.x, 22.x] - - name: Test ${{ matrix.node-version }} - services: - postgres16: - image: postgres:16 - env: - POSTGRES_PASSWORD: postgres - options: >- - --health-cmd pg_isready - --health-interval 10s - --health-timeout 5s - --health-retries 5 - ports: - - 5432/tcp - postgres12: - image: postgres:12 - env: - POSTGRES_PASSWORD: postgres - options: >- - --health-cmd pg_isready - --health-interval 10s - --health-timeout 5s - --health-retries 5 - ports: - - 5432/tcp - mysql8: - image: mysql:8 - env: - MYSQL_ROOT_PASSWORD: root - options: >- - --health-cmd "mysqladmin ping -h localhost" - --health-interval 10s - --health-timeout 5s - --health-retries 5 - ports: - - 3306/tcp - redis: - image: redis:7 - options: >- - --health-cmd "redis-cli ping" - --health-interval 10s - --health-timeout 5s - --health-retries 5 - ports: - - 6379/tcp - - env: - CI: true - NODE_OPTIONS: --max-old-space-size=8192 --no-node-snapshot - INTEGRATION_TEST_GITHUB_TOKEN: ${{ secrets.INTEGRATION_TEST_GITHUB_TOKEN }} - INTEGRATION_TEST_GITLAB_TOKEN: ${{ secrets.INTEGRATION_TEST_GITLAB_TOKEN }} - INTEGRATION_TEST_BITBUCKET_TOKEN: ${{ secrets.INTEGRATION_TEST_BITBUCKET_TOKEN }} - INTEGRATION_TEST_AZURE_TOKEN: ${{ secrets.INTEGRATION_TEST_AZURE_TOKEN }} - - steps: - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - - name: fetch master branch - run: git fetch origin master - - # Need to fetch the base branch to be able to verify the release - - name: fetch base branch - if: github.event.pull_request.base.ref != 'master' - run: git fetch origin ${{ github.event.pull_request.base.ref }} - - - name: use node.js ${{ matrix.node-version }} - uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 - with: - node-version: ${{ matrix.node-version }} - registry-url: https://registry.npmjs.org/ # Needed for auth - - - name: yarn install - uses: backstage/actions/yarn-install@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 - with: - cache-prefix: ${{ runner.os }}-v${{ matrix.node-version }} - - # This check is done here since it needs git history - - name: verify release - run: node scripts/verify-release.js - - # Use the lower-level cache actions for the success cache, so that we can store the cache even on failed builds - - name: restore backstage-cli cache - uses: actions/cache/restore@3624ceb22c1c5a301c8db4169662070a689d9ea8 # v4 - with: - path: .cache/backstage-cli - key: ${{ runner.os }}-v${{ matrix.node-version }}-backstage-cli-${{ github.run_id }} - restore-keys: | - ${{ runner.os }}-v${{ matrix.node-version }}-backstage-cli- - - - name: lint changed packages - run: yarn backstage-cli repo lint --since origin/master --successCache --successCacheDir .cache/backstage-cli - - - name: test changed packages - run: yarn backstage-cli repo test --maxWorkers=3 --workerIdleMemoryLimit=1300M --since origin/master --successCache --successCacheDir .cache/backstage-cli - env: - BACKSTAGE_TEST_DISABLE_DOCKER: 1 - BACKSTAGE_TEST_DATABASE_POSTGRES16_CONNECTION_STRING: postgresql://postgres:postgres@localhost:${{ job.services.postgres16.ports[5432] }} - BACKSTAGE_TEST_DATABASE_POSTGRES12_CONNECTION_STRING: postgresql://postgres:postgres@localhost:${{ job.services.postgres12.ports[5432] }} - BACKSTAGE_TEST_DATABASE_MYSQL8_CONNECTION_STRING: mysql://root:root@localhost:${{ job.services.mysql8.ports[3306] }}/ignored - BACKSTAGE_TEST_CACHE_REDIS7_CONNECTION_STRING: redis://localhost:${{ job.services.redis.ports[6379] }} - - # Always save success cache even if there were failures, that way it can be used in re-triggered builds - - name: save backstage-cli cache - uses: actions/cache/save@3624ceb22c1c5a301c8db4169662070a689d9ea8 # v4 - if: always() - with: - path: .cache/backstage-cli - key: ${{ runner.os }}-v${{ matrix.node-version }}-backstage-cli-${{ github.run_id }} - - # We run the test cases before verifying the specs to prevent any failing tests from causing errors. - - name: verify openapi specs against test cases - run: yarn backstage-repo-tools repo schema openapi test - - - name: ensure clean working directory - run: | - if files=$(git ls-files --exclude-standard --others --modified) && [[ -z "$files" ]]; then - exit 0 - else - echo "" - echo "Working directory has been modified:" - echo "" - git status --short - echo "" - exit 1 - fi diff --git a/.github/workflows/cron.yml b/.github/workflows/cron.yml deleted file mode 100644 index 48ac1db289..0000000000 --- a/.github/workflows/cron.yml +++ /dev/null @@ -1,21 +0,0 @@ -name: Cron -on: - workflow_dispatch: - schedule: - - cron: '*/5 * * * *' - -jobs: - cron: - runs-on: ubuntu-latest - timeout-minutes: 10 - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - uses: backstage/actions/cron@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 - with: - app-id: ${{ secrets.BACKSTAGE_GOALIE_APPLICATION_ID }} - private-key: ${{ secrets.BACKSTAGE_GOALIE_PRIVATE_KEY }} - installation-id: ${{ secrets.BACKSTAGE_GOALIE_INSTALLATION_ID }} diff --git a/.github/workflows/deploy_docker-image.yml b/.github/workflows/deploy_docker-image.yml deleted file mode 100644 index 4176cb6e80..0000000000 --- a/.github/workflows/deploy_docker-image.yml +++ /dev/null @@ -1,75 +0,0 @@ -name: Build and push Docker image -on: - workflow_dispatch: - - repository_dispatch: - types: [release-published] - -env: - RELEASE_VERSION: v${{ github.event.client_payload.version }} - TAG_VERSION: ghcr.io/${{ github.repository_owner }}/backstage:${{ github.event.client_payload.version }} - -jobs: - build: - runs-on: ubuntu-latest - - strategy: - fail-fast: false - matrix: - node-version: [20.x] - - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - name: checkout - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - with: - path: backstage - ref: ${{ github.event.client_payload.version && env.RELEASE_VERSION || github.ref }} - - - name: use node.js ${{ matrix.node-version }} - uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 - with: - node-version: ${{ matrix.node-version }} - registry-url: https://registry.npmjs.org/ # Needed for auth - - - name: yarn install - uses: backstage/actions/yarn-install@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 - with: - cache-prefix: ${{ runner.os }}-v${{ matrix.node-version }} - - - name: create-app - run: npx @backstage/create-app - env: - BACKSTAGE_APP_NAME: example-app - YARN_ENABLE_IMMUTABLE_INSTALLS: false - - - name: yarn build - run: yarn build:backend - working-directory: ./example-app - - - name: Login to GitHub Container Registry - uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3.3.0 - with: - registry: ghcr.io - username: ${{ github.actor }} - password: ${{ secrets.GITHUB_TOKEN }} - - - name: Set up Docker Buildx - uses: docker/setup-buildx-action@c47758b77c9736f4b2ef4073d4d51994fabfe349 # v3.7.1 - - - name: Build and push - uses: docker/build-push-action@4f58ea79222b3b9dc2c8bbdd6debcef730109a75 # v6.9.0 - with: - context: './example-app' - file: ./example-app/packages/backend/Dockerfile - push: ${{ (github.event_name == 'repository_dispatch') && (github.event.action == 'release-published') }} - platforms: linux/amd64,linux/arm64 - tags: | - ghcr.io/${{ github.repository_owner }}/backstage:latest - ${{ github.event.client_payload.version && env.TAG_VERSION || '' }} - labels: | - org.opencontainers.image.description=Docker image generated from the latest Backstage release; this contains what you would get out of the box by running npx @backstage/create-app and building a Docker image from the generated source. This is meant to ease the process of evaluating Backstage for the first time, but also has the severe limitation that there is no way to install additional plugins relevant to your infrastructure. diff --git a/.github/workflows/deploy_microsite.yml b/.github/workflows/deploy_microsite.yml deleted file mode 100644 index 291786efd3..0000000000 --- a/.github/workflows/deploy_microsite.yml +++ /dev/null @@ -1,231 +0,0 @@ -name: Deploy Microsite -on: - push: - branches: - - master - -permissions: - contents: read - -jobs: - stable: - runs-on: ubuntu-latest - concurrency: - group: stable-reference-${{ github.workflow }}-${{ github.ref }} - cancel-in-progress: true - - env: - CI: true - NODE_OPTIONS: --max-old-space-size=8192 - - outputs: - release: ${{ steps.find-release.outputs.result }} - - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - name: find latest release - uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7 - id: find-release - with: - script: | - const { data } = await github.rest.repos.listTags({ - owner: context.repo.owner, - repo: context.repo.repo, - per_page: 100, - }) - - const [{tag}] = data - .map(i => i.name) - .filter(tag => tag.match(/^v\d+\.\d+\.\d+$/)) - .map(tag => ({ - tag, - val: tag - .slice(1) - .split('.') - .reduce((val, part) => Number(val) * 1000 + Number(part)) - })) - .sort((a, b) => b.val - a.val) - - return tag - result-encoding: string - - - name: checkout latest release - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - with: - ref: refs/tags/${{ steps.find-release.outputs.result }} - - - name: Use Node.js 20.x - uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 - with: - node-version: 20.x - registry-url: https://registry.npmjs.org/ # Needed for auth - - - name: yarn install - uses: backstage/actions/yarn-install@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 - with: - cache-prefix: ${{ runner.os }}-v20.x - - - name: build API reference - run: yarn build:api-docs - - - name: upload API reference - uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 # v4 - with: - name: stable-reference - path: docs/reference/ - if-no-files-found: error - retention-days: 1 - - next: - runs-on: ubuntu-latest - concurrency: - group: next-reference-${{ github.workflow }}-${{ github.ref }} - cancel-in-progress: true - env: - CI: true - NODE_OPTIONS: --max-old-space-size=8192 - - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - name: checkout master - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - - - name: Use Node.js 20.x - uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 - with: - node-version: 20.x - registry-url: https://registry.npmjs.org/ # Needed for auth - - - name: yarn install - uses: backstage/actions/yarn-install@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 - with: - cache-prefix: ${{ runner.os }}-v20.x - - - name: build API reference - run: yarn build:api-docs - - - name: upload API reference - uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 # v4 - with: - name: next-reference - path: docs/reference/ - if-no-files-found: error - retention-days: 1 - - # Also build and upload storybook - - name: storybook yarn install - run: yarn install --immutable - working-directory: storybook - - - name: storybook build - run: yarn build-storybook - working-directory: storybook - - - name: storybook upload - uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 # v4 - with: - name: storybook - path: storybook/dist/ - if-no-files-found: error - retention-days: 1 - - deploy-microsite-and-storybook: - permissions: - contents: write # for JamesIves/github-pages-deploy-action to push changes in repo - - runs-on: ubuntu-latest - - needs: - - stable - - next - - env: - CI: true - NODE_OPTIONS: --max-old-space-size=16384 - DOCUSAURUS_SSR_CONCURRENCY: 5 - - concurrency: - group: ${{ github.workflow }}-${{ github.ref }} - cancel-in-progress: true - - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - name: Use Node.js 20.x - uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 - with: - node-version: 20.x - registry-url: https://registry.npmjs.org/ # Needed for auth - - # Stable docs - - name: checkout latest release - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - with: - ref: refs/tags/${{ needs.stable.outputs.release }} - - - name: microsite yarn install - run: yarn install --immutable - working-directory: microsite - - - name: download stable reference - uses: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # v4 - with: - name: stable-reference - path: docs/reference - - - name: grab lastest releases docs - run: | - git fetch origin master --depth 1 - git checkout FETCH_HEAD -- docs/releases - - - name: generate stable docs - run: yarn docusaurus docs:version stable - working-directory: microsite - - - name: clear API reference - run: rm -r docs/reference - - # Next docs - - name: checkout master - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - with: - clean: false - - - name: microsite yarn install - run: yarn install --immutable - working-directory: microsite - - - name: download next reference - uses: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # v4 - with: - name: next-reference - path: docs/reference - - - name: build microsite - run: yarn build - working-directory: microsite - - - uses: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # v4 - with: - name: storybook - path: microsite/build/storybook - - - name: Check the build output - run: ls microsite/build && ls microsite/build/storybook - - - name: Deploy both microsite and storybook to gh-pages - uses: JamesIves/github-pages-deploy-action@881db5376404c5c8d621010bcbec0310b58d5e29 # v4.6.8 - with: - branch: gh-pages - folder: microsite/build diff --git a/.github/workflows/deploy_packages.yml b/.github/workflows/deploy_packages.yml deleted file mode 100644 index ac2389d95e..0000000000 --- a/.github/workflows/deploy_packages.yml +++ /dev/null @@ -1,160 +0,0 @@ -name: Deploy Packages -on: - push: - branches: [master, patch/*] - -jobs: - build: - runs-on: ubuntu-latest - - outputs: - needs_release: ${{ steps.release_check.outputs.needs_release }} - - strategy: - fail-fast: false - matrix: - node-version: [20.x, 22.x] - - services: - postgres16: - image: postgres:16 - env: - POSTGRES_PASSWORD: postgres - options: >- - --health-cmd pg_isready - --health-interval 10s - --health-timeout 5s - --health-retries 5 - ports: - - 5432/tcp - postgres12: - image: postgres:12 - env: - POSTGRES_PASSWORD: postgres - options: >- - --health-cmd pg_isready - --health-interval 10s - --health-timeout 5s - --health-retries 5 - ports: - - 5432/tcp - mysql8: - image: mysql:8 - env: - MYSQL_ROOT_PASSWORD: root - options: >- - --health-cmd "mysqladmin ping -h localhost" - --health-interval 10s - --health-timeout 5s - --health-retries 5 - ports: - - 3306/tcp - redis: - image: redis:7 - options: >- - --health-cmd "redis-cli ping" - --health-interval 10s - --health-timeout 5s - --health-retries 5 - ports: - - 6379/tcp - - env: - CI: true - NODE_OPTIONS: --max-old-space-size=8192 --no-node-snapshot - INTEGRATION_TEST_GITHUB_TOKEN: ${{ secrets.INTEGRATION_TEST_GITHUB_TOKEN }} - INTEGRATION_TEST_GITLAB_TOKEN: ${{ secrets.INTEGRATION_TEST_GITLAB_TOKEN }} - INTEGRATION_TEST_BITBUCKET_TOKEN: ${{ secrets.INTEGRATION_TEST_BITBUCKET_TOKEN }} - INTEGRATION_TEST_AZURE_TOKEN: ${{ secrets.INTEGRATION_TEST_AZURE_TOKEN }} - - steps: - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - - - name: use node.js ${{ matrix.node-version }} - uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 - with: - node-version: ${{ matrix.node-version }} - registry-url: https://registry.npmjs.org/ # Needed for auth - - name: yarn install - uses: backstage/actions/yarn-install@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 - with: - cache-prefix: ${{ runner.os }}-v${{ matrix.node-version }} - - - name: Fetch previous commit for release check - run: git fetch origin '${{ github.event.before }}' - - - name: Check if release - if: inputs.force_release != true - id: release_check - run: node scripts/check-if-release.js - env: - COMMIT_SHA_BEFORE: '${{ github.event.before }}' - - - name: validate config - run: yarn backstage-cli config:check --lax - - - name: backstage-cli cache - uses: actions/cache@3624ceb22c1c5a301c8db4169662070a689d9ea8 # v4 - with: - path: .cache/backstage-cli - key: ${{ runner.os }}-v${{ matrix.node-version }}-backstage-cli-${{ github.run_id }} - restore-keys: | - ${{ runner.os }}-v${{ matrix.node-version }}-backstage-cli- - - - name: lint - run: yarn backstage-cli repo lint --successCache --successCacheDir .cache/backstage-cli - - - name: type checking and declarations - run: yarn tsc:full - - - name: build - run: yarn backstage-cli repo build --all - - - name: verify type dependencies - run: yarn lint:type-deps - - - name: test (and upload coverage) - run: | - yarn backstage-cli repo test --maxWorkers=3 --workerIdleMemoryLimit=1300M --coverage --successCache --successCacheDir .cache/backstage-cli - env: - BACKSTAGE_TEST_DISABLE_DOCKER: 1 - BACKSTAGE_TEST_DATABASE_POSTGRES16_CONNECTION_STRING: postgresql://postgres:postgres@localhost:${{ job.services.postgres16.ports[5432] }} - BACKSTAGE_TEST_DATABASE_POSTGRES12_CONNECTION_STRING: postgresql://postgres:postgres@localhost:${{ job.services.postgres12.ports[5432] }} - BACKSTAGE_TEST_DATABASE_MYSQL8_CONNECTION_STRING: mysql://root:root@localhost:${{ job.services.mysql8.ports[3306] }}/ignored - BACKSTAGE_TEST_CACHE_REDIS7_CONNECTION_STRING: redis://localhost:${{ job.services.redis.ports[6379] }} - - - name: Discord notification - if: ${{ failure() }} - uses: Ilshidur/action-discord@0c4b27844ba47cb1c7bee539c8eead5284ce9fa9 # 0.3.2 - env: - DISCORD_WEBHOOK: ${{ secrets.DISCORD_WEBHOOK }} - with: - args: 'Master build failed https://github.com/{{GITHUB_REPOSITORY}}/actions/runs/{{GITHUB_RUN_ID}}' - - # A separate release build that is only run for commits that are the result of merging the "Version Packages" PR - # We can't re-use the output from the above step, but we'll have a guaranteed node_modules cache and - # only run the build steps that are necessary for publishing - release: - needs: build - - if: needs.build.outputs.needs_release == 'true' - - runs-on: ubuntu-latest - - strategy: - matrix: - node-version: [20.x] - - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - # Notify maintainers that a new release is ready to be published - - name: Discord notification - uses: Ilshidur/action-discord@0c4b27844ba47cb1c7bee539c8eead5284ce9fa9 # 0.3.2 - env: - DISCORD_WEBHOOK: ${{ secrets.DISCORD_MAINTAINERS_WEBHOOK }} - with: - args: 'A new release is ready to be [published](https://github.com/backstage/publishing/actions/workflows/publish-main.yml) from {{GITHUB_SHA}}' diff --git a/.github/workflows/issue.yaml b/.github/workflows/issue.yaml deleted file mode 100644 index 2cd355b75e..0000000000 --- a/.github/workflows/issue.yaml +++ /dev/null @@ -1,31 +0,0 @@ -name: Issue -on: - issues: - types: [opened] - -permissions: - contents: read - -jobs: - sync: - permissions: - contents: read # for github/issue-labeler to get repo contents - issues: write # for github/issue-labeler to create or remove labels - runs-on: ubuntu-latest - - if: github.repository == 'backstage/backstage' - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - name: Add issue labels - uses: github/issue-labeler@c1b0f9f52a63158c4adc09425e858e87b32e9685 # v3.4 - with: - include-title: 1 - include-body: 0 - configuration-path: .github/issue-labeler.yml - enable-versioned-regex: 0 - not-before: 2024-04-19T15:03:51Z - repo-token: '${{ secrets.GITHUB_TOKEN }}' diff --git a/.github/workflows/pr-review-comment-trigger.yaml b/.github/workflows/pr-review-comment-trigger.yaml deleted file mode 100644 index 9ebfbee3b0..0000000000 --- a/.github/workflows/pr-review-comment-trigger.yaml +++ /dev/null @@ -1,37 +0,0 @@ -# This workflow is used to trigger the "PR Review Comment" workflow. This chaining is needed -# because workflows triggered by pull_request_review_comment do not have access to secrets. - -name: PR Review Comment Trigger -on: - pull_request_review_comment: - types: - - created - -permissions: - contents: read - -jobs: - trigger: - runs-on: ubuntu-latest - - # The "PR Review Comment" workflow will check the success status of this workflow and only mark - # the PR for re-review if this workflow was successful, which is when the author leaves a review comment. - if: github.repository == 'backstage/backstage' && github.event.comment.user.id == github.event.pull_request.user.id - - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - name: Save PR number - env: - PR_NUMBER: ${{ github.event.pull_request.number }} - run: | - mkdir -p ./pr - echo $PR_NUMBER > ./pr/pr_number - - uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 # v4.4.3 - with: - name: pr_number-${{ github.event.pull_request.number }} - path: pr/ - overwrite: true diff --git a/.github/workflows/pr-review-comment.yaml b/.github/workflows/pr-review-comment.yaml deleted file mode 100644 index 517a978a83..0000000000 --- a/.github/workflows/pr-review-comment.yaml +++ /dev/null @@ -1,49 +0,0 @@ -# This workflow is triggered by "PR Review Comment Trigger" - -name: PR Review Comment -on: - workflow_run: - workflows: [PR Review Comment Trigger] - types: - - completed - -jobs: - re-review: - runs-on: ubuntu-latest - - # The triggering workflow will report success if the PR needs re-review - if: github.repository == 'backstage/backstage' && github.event.workflow_run.conclusion == 'success' - - steps: - # Inspired by https://docs.github.com/en/actions/using-workflows/events-that-trigger-workflows#using-data-from-the-triggering-workflow - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - name: Read PR Number - id: pr-number - uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1 - with: - github-token: ${{ secrets.GITHUB_TOKEN }} - script: | - const allArtifacts = await github.rest.actions.listWorkflowRunArtifacts({ - owner: context.repo.owner, - repo: context.repo.repo, - run_id: context.payload.workflow_run.id, - }); - const [artifact] = allArtifacts.data.artifacts.filter(artifact => artifact.name.startsWith('pr_number-')) - if (!artifact) { - throw new Error('No PR Number artifact available') - } - - const prNumber = artifact.name.slice('pr_number-'.length) - core.setOutput('pr-number', prNumber); - - - uses: backstage/actions/re-review@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 - with: - app-id: ${{ secrets.BACKSTAGE_GOALIE_APPLICATION_ID }} - private-key: ${{ secrets.BACKSTAGE_GOALIE_PRIVATE_KEY }} - installation-id: ${{ secrets.BACKSTAGE_GOALIE_INSTALLATION_ID }} - project-id: PVT_kwDOBFKqdc02LQ - issue-number: ${{ steps.pr-number.outputs.pr-number }} diff --git a/.github/workflows/pr.yaml b/.github/workflows/pr.yaml deleted file mode 100644 index 7639ac14db..0000000000 --- a/.github/workflows/pr.yaml +++ /dev/null @@ -1,34 +0,0 @@ -name: PR -on: - pull_request_target: - types: - - opened - - synchronize - - reopened - - closed - issue_comment: - types: - - created - -jobs: - sync: - runs-on: ubuntu-latest - - # Avoid running on issue comments - if: github.repository == 'backstage/backstage' && ( github.event.pull_request || github.event.issue.pull_request ) - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - name: PR sync - uses: backstage/actions/pr-sync@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 - with: - github-token: ${{ secrets.GH_SERVICE_ACCOUNT_TOKEN }} - app-id: ${{ secrets.BACKSTAGE_GOALIE_APPLICATION_ID }} - private-key: ${{ secrets.BACKSTAGE_GOALIE_PRIVATE_KEY }} - installation-id: ${{ secrets.BACKSTAGE_GOALIE_INSTALLATION_ID }} - project-id: PVT_kwDOBFKqdc02LQ - auto-assign: false - owning-teams: '@backstage/techdocs-core' diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml deleted file mode 100644 index a1c643377d..0000000000 --- a/.github/workflows/scorecard.yml +++ /dev/null @@ -1,72 +0,0 @@ -# This workflow uses actions that are not certified by GitHub. They are provided -# by a third-party and are governed by separate terms of service, privacy -# policy, and support documentation. - -name: Scorecard supply-chain security -on: - # For Branch-Protection check. Only the default branch is supported. See - # https://github.com/ossf/scorecard/blob/main/docs/checks.md#branch-protection - # branch_protection_rule: - # To guarantee Maintained check is occasionally updated. See - # https://github.com/ossf/scorecard/blob/main/docs/checks.md#maintained - schedule: - - cron: '41 8 * * 6' - push: - branches: ['master'] - -# Declare default permissions as read only. -permissions: read-all - -jobs: - analysis: - name: Scorecard analysis - runs-on: ubuntu-latest - permissions: - # Needed to upload the results to code-scanning dashboard. - security-events: write - # Needed to publish results and get a badge (see publish_results below). - id-token: write - - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - name: 'Checkout code' - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - with: - persist-credentials: false - - - name: 'Run analysis' - uses: ossf/scorecard-action@dc50aa9510b46c811795eb24b2f1ba02a914e534 # v2.3.3 - with: - results_file: results.sarif - results_format: sarif - # (Optional) "write" PAT token. Uncomment the `repo_token` line below if: - # - you want to enable the Branch-Protection check on a *public* repository, or - # - you are installing Scorecard on a *private* repository - # To create the PAT, follow the steps in https://github.com/ossf/scorecard-action#authentication-with-pat. - # repo_token: ${{ secrets.SCORECARD_TOKEN }} - - # Public repositories: - # - Publish results to OpenSSF REST API for easy access by consumers - # - Allows the repository to include the Scorecard badge. - # - See https://github.com/ossf/scorecard-action#publishing-results. - publish_results: true - - # Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF - # format to the repository Actions tab. - - name: 'Upload artifact' - uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 # v4.4.3 - with: - name: SARIF file - path: results.sarif - retention-days: 5 - overwrite: true - - # Upload the results to GitHub's code scanning dashboard. - - name: 'Upload to code-scanning' - uses: github/codeql-action/upload-sarif@f779452ac5af1c261dce0346a8f964149f49322b # v3.26.13 - with: - sarif_file: results.sarif diff --git a/.github/workflows/sync_code-formatting.yml b/.github/workflows/sync_code-formatting.yml deleted file mode 100644 index 23b3e8cf3f..0000000000 --- a/.github/workflows/sync_code-formatting.yml +++ /dev/null @@ -1,40 +0,0 @@ -name: Sync code formatting -on: - push: - branches: - - master - -jobs: - autofix-markdown: - name: Autofix Markdown files using Prettier - runs-on: ubuntu-latest - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - with: - # Fetch changes to previous commit - required for 'only_changed' in Prettier action - fetch-depth: 0 - - - name: use node.js ${{ matrix.node-version }} - uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 - with: - node-version: ${{ matrix.node-version }} - registry-url: https://registry.npmjs.org/ # Needed for auth - - name: yarn install - uses: backstage/actions/yarn-install@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 - with: - cache-prefix: ${{ runner.os }}-v${{ matrix.node-version }} - - - name: Run Prettier on ADOPTERS.md - uses: creyD/prettier_action@31355f8eef017f8aeba2e0bc09d8502b13dbbad1 # v4.3 - with: - # Modifies commit only if prettier autofixed the ADOPTERS.md - prettier_options: --config docs/prettier.config.js --write ADOPTERS.md - only_changed: true - commit_message: 'Autofix ADOPTERS.md using Prettier' - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/sync_dependabot-changesets.yml b/.github/workflows/sync_dependabot-changesets.yml deleted file mode 100644 index 31db319229..0000000000 --- a/.github/workflows/sync_dependabot-changesets.yml +++ /dev/null @@ -1,83 +0,0 @@ -name: Sync Dependabot changeset -on: - pull_request_target: - paths: - - '.github/workflows/sync_dependabot-changesets.yml' - - '**/yarn.lock' - -jobs: - generate-changeset: - runs-on: ubuntu-latest - if: github.actor == 'dependabot[bot]' && github.repository == 'backstage/backstage' - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - name: Checkout - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - with: - fetch-depth: 2 - ref: ${{ github.head_ref }} - token: ${{ secrets.GH_SERVICE_ACCOUNT_TOKEN }} - - name: Configure Git - run: | - git config --global user.email noreply@backstage.io - git config --global user.name 'Github changeset workflow' - - name: Generate changeset - uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1 - with: - script: | - const { promises: fs } = require('fs'); - - // Parses package.json files and returns the package names - async function getPackagesNames(files) { - const names = []; - for (const file of files) { - const data = JSON.parse(await fs.readFile(file, 'utf8')); - if (!data.private) { - names.push(data.name); - } - } - return names; - } - - async function createChangeset(fileName, commitMessage, packages) { - const pkgs = packages.map(pkg => `'${pkg}': patch`).join('\n'); - const message = commitMessage.replace(/([bB])ump ([\S]+)/, '$1ump `$2`').trim(); - const body = `---\n${pkgs}\n---\n\n${message}\n`; - await fs.writeFile(fileName, body); - } - - const branch = await exec.getExecOutput('git branch --show-current'); - if (!branch.stdout.startsWith('dependabot/')) { - console.log('Not a dependabot branch, skipping'); - return; - } - - const diffOutput = await exec.getExecOutput('git diff --name-only HEAD~1'); - const diffFiles = diffOutput.stdout.split('\n'); - - if (diffFiles.find(f => f.startsWith('.changeset'))) { - console.log('Changeset already exists, skipping'); - return; - } - - const files = diffFiles - .filter(file => file !== 'package.json') // skip root package.json - .filter(file => file.includes('package.json')); - - const packageNames = await getPackagesNames(files); - if (!packageNames.length) { - console.log('No package.json changes to published packages, skipping'); - return; - } - - const { stdout: shortHash } = await exec.getExecOutput('git rev-parse --short HEAD'); - const fileName = `.changeset/dependabot-${shortHash.trim()}.md`; - const { stdout: commitMessage } = await exec.getExecOutput('git show --pretty=format:%s -s HEAD'); - await createChangeset(fileName, commitMessage, packageNames); - await exec.exec('git', ['add', fileName]); - await exec.exec('git commit -C HEAD --amend --no-edit'); - await exec.exec('git push --force'); diff --git a/.github/workflows/sync_release-manifest.yml b/.github/workflows/sync_release-manifest.yml deleted file mode 100644 index 06e61cc7cd..0000000000 --- a/.github/workflows/sync_release-manifest.yml +++ /dev/null @@ -1,89 +0,0 @@ -name: Sync Release Manifest -on: - repository_dispatch: - types: [release-published] - -jobs: - create-new-version: - runs-on: ubuntu-latest - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - name: Checkout - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - with: - # 'v' prefix is added here for the tag, we keep it out of the manifest logic - ref: v${{ github.event.client_payload.version }} - - - name: Use Node.js 20.x - uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 - with: - node-version: 20.x - registry-url: https://registry.npmjs.org/ # Needed for auth - - - name: yarn install - uses: backstage/actions/yarn-install@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 - with: - cache-prefix: ${{ runner.os }}-v20.x - - - name: Build yarn plugin - working-directory: packages/yarn-plugin - run: yarn build - - # Checkout backstage/versions into /backstage/versions, which is where store the output - - name: Checkout versions - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - with: - repository: backstage/versions - path: versions - token: ${{ secrets.GH_SERVICE_ACCOUNT_TOKEN }} - - - name: Configure Git - run: | - git config --global user.email noreply@backstage.io - git config --global user.name 'Github versions workflow' - - - name: Create release - # This grabs the scripts from master in order to support backfills - run: | - mkdir -p scripts - wget -O scripts/assemble-manifest.js https://raw.githubusercontent.com/backstage/backstage/master/scripts/assemble-manifest.js - node scripts/assemble-manifest.js ${{ github.event.client_payload.version }} - - # Copies the build output of the yarn-plugin package to the appropriate - # directory, allowing the plugin to be installed with a command like - # `yarn plugin import https://versions.backstage.io/v1/tags/main/yarn-plugin` - - name: Add yarn plugin to release - working-directory: packages/yarn-plugin - run: >- - cp - bundles/@yarnpkg/plugin-backstage.js - ../../versions/v1/releases/${{ github.event.client_payload.version }}/yarn-plugin - - - name: Commit to versions repo - working-directory: versions - run: | - git add . - git commit -am "${{ github.event.client_payload.version }}" - git push - - - name: Dispatch update-helper update - uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1 - with: - github-token: ${{ secrets.GH_SERVICE_ACCOUNT_TOKEN }} - # TODO(Rugvip): Remove the create-app dispatch once we've been on the release version for a while - script: | - console.log('Dispatching upgrade helper sync'); - await github.rest.actions.createWorkflowDispatch({ - owner: 'backstage', - repo: 'upgrade-helper-diff', - workflow_id: 'release.yml', - ref: 'master', - inputs: { - version: require('./packages/create-app/package.json').version, - releaseVersion: require('./package.json').version - }, - }); diff --git a/.github/workflows/sync_renovate-changesets.yml b/.github/workflows/sync_renovate-changesets.yml deleted file mode 100644 index 9331dbdb05..0000000000 --- a/.github/workflows/sync_renovate-changesets.yml +++ /dev/null @@ -1,102 +0,0 @@ -name: Sync Renovate changeset -on: - pull_request_target: - paths: - - '.github/workflows/sync_renovate-changesets.yml' - - '**/yarn.lock' - -jobs: - generate-changeset: - runs-on: ubuntu-latest - if: github.actor == 'renovate[bot]' && github.repository == 'backstage/backstage' - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - name: Checkout - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - with: - fetch-depth: 2 - ref: ${{ github.head_ref }} - token: ${{ secrets.GH_SERVICE_ACCOUNT_TOKEN }} - - name: Configure Git - run: | - git config --global user.email noreply@backstage.io - git config --global user.name 'Github changeset workflow' - - name: Generate changeset - uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1 - with: - script: | - const { promises: fs } = require("fs"); - // Parses package.json files and returns the package names - async function getPackagesNames(files) { - const names = []; - for (const file of files) { - const data = JSON.parse(await fs.readFile(file, "utf8")); - if (!data.private) { - names.push(data.name); - } - } - return names; - } - - async function createChangeset(fileName, packageBumps, packages) { - let message = ""; - for (const [pkg, bump] of packageBumps) { - message = message + `Updated dependency \`${pkg}\` to \`${bump}\`.\n`; - } - - const pkgs = packages.map((pkg) => `'${pkg}': patch`).join("\n"); - const body = `---\n${pkgs}\n---\n\n${message.trim()}\n`; - await fs.writeFile(fileName, body); - } - - async function getBumps(files) { - const bumps = new Map(); - for (const file of files) { - const { stdout: changes } = await exec.getExecOutput("git", [ - "show", - file, - ]); - for (const change of changes.split("\n")) { - if (!change.startsWith("+ ")) { - continue; - } - const match = change.match(/"(.*?)"/g); - bumps.set(match[0].replace(/"/g, ""), match[1].replace(/"/g, "")); - } - } - return bumps; - } - - const branch = await exec.getExecOutput("git branch --show-current"); - if (!branch.stdout.startsWith("renovate/")) { - console.log("Not a renovate branch, skipping"); - return; - } - const diffOutput = await exec.getExecOutput("git diff --name-only HEAD~1"); - const diffFiles = diffOutput.stdout.split("\n"); - if (diffFiles.find((f) => f.startsWith(".changeset"))) { - console.log("Changeset already exists, skipping"); - return; - } - const files = diffFiles - .filter((file) => file !== "package.json") // skip root package.json - .filter((file) => file.includes("package.json")); - const packageNames = await getPackagesNames(files); - if (!packageNames.length) { - console.log("No package.json changes to published packages, skipping"); - return; - } - const { stdout: shortHash } = await exec.getExecOutput( - "git rev-parse --short HEAD" - ); - const fileName = `.changeset/renovate-${shortHash.trim()}.md`; - - const packageBumps = await getBumps(files); - await createChangeset(fileName, packageBumps, packageNames); - await exec.exec("git", ["add", fileName]); - await exec.exec("git commit -C HEAD --amend --no-edit"); - await exec.exec("git push --force"); diff --git a/.github/workflows/sync_snyk-github-issues.yml b/.github/workflows/sync_snyk-github-issues.yml deleted file mode 100644 index b51036f542..0000000000 --- a/.github/workflows/sync_snyk-github-issues.yml +++ /dev/null @@ -1,48 +0,0 @@ -name: Sync Snyk GitHub issues -on: - workflow_dispatch: - schedule: - - cron: '0 */4 * * *' - -jobs: - sync: - if: github.repository == 'backstage/backstage' # prevent running on forks - - runs-on: ubuntu-latest - - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - - - name: Use Node.js 20.x - uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 - with: - node-version: 20.x - registry-url: https://registry.npmjs.org/ # Needed for auth - - name: yarn install - uses: backstage/actions/yarn-install@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 - with: - cache-prefix: ${{ runner.os }}-v20.x - - - name: Create Snyk report - uses: snyk/actions/node@cdb760004ba9ea4d525f2e043745dfe85bb9077e # master - continue-on-error: true # Snyk CLI exits with error when vulnerabilities are found - with: - args: > - --yarn-workspaces - --org=backstage-dgh - --strict-out-of-sync=false - --json-file-output=snyk.json - --debug - json: true - env: - SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} - NODE_OPTIONS: --max-old-space-size=7168 - - name: Update Github issues - run: ./scripts/snyk-github-issue-sync.ts - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/sync_snyk-monitor.yml b/.github/workflows/sync_snyk-monitor.yml deleted file mode 100644 index c3bdb9b647..0000000000 --- a/.github/workflows/sync_snyk-monitor.yml +++ /dev/null @@ -1,63 +0,0 @@ -name: Sync Snyk Monitoring -on: - workflow_dispatch: - push: - branches: [master] - paths: - - '.github/workflows/sync_snyk-monitor.yml' - - '**/.snyk' - - '**/package.json' - - 'yarn.lock' - -# This workflow synchronizes the packages in this repo along with policies in -# each .snyk file with the remote state in our snyk org. It allows us to define -# ignore policies in the .snyk files and then have them show up in the snyk web -# UI, and also automatically adds any new packages that are created. - -permissions: - contents: read - -jobs: - sync: - permissions: - contents: read # for actions/checkout to fetch code - security-events: write # for github/codeql-action/upload-sarif to upload SARIF results - runs-on: ubuntu-latest - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - - name: Monitor and Synchronize Snyk Policies - uses: snyk/actions/node@cdb760004ba9ea4d525f2e043745dfe85bb9077e # master - with: - command: monitor - args: > - --yarn-workspaces - --org=backstage-dgh - --strict-out-of-sync=false - --remote-repo-url=https://github.com/backstage/backstage - env: - SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} - NODE_OPTIONS: --max-old-space-size=7168 - - # Above we run the `monitor` command, this runs the `test` command which is - # the one that generates the SARIF report that we can upload to GitHub. - - name: Create Snyk report - uses: snyk/actions/node@cdb760004ba9ea4d525f2e043745dfe85bb9077e # master - continue-on-error: true # To make sure that SARIF upload gets called - with: - args: > - --yarn-workspaces - --org=backstage-dgh - --strict-out-of-sync=false - --sarif-file-output=snyk.sarif - env: - SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} - NODE_OPTIONS: --max-old-space-size=7168 - - name: Upload Snyk report - uses: github/codeql-action/upload-sarif@f779452ac5af1c261dce0346a8f964149f49322b # v3.26.13 - with: - sarif_file: snyk.sarif diff --git a/.github/workflows/sync_version-packages.yml b/.github/workflows/sync_version-packages.yml deleted file mode 100644 index 970a5e0e3f..0000000000 --- a/.github/workflows/sync_version-packages.yml +++ /dev/null @@ -1,43 +0,0 @@ -name: Sync Version Packages PR -on: - push: - branches: - - master - -concurrency: - group: sync-version-packages - cancel-in-progress: true - -jobs: - create-release-pr: - name: Create Changeset PR - runs-on: ubuntu-latest - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - with: - fetch-depth: 20000 - fetch-tags: true - token: ${{ secrets.GH_SERVICE_ACCOUNT_TOKEN }} - - name: Install Dependencies - run: yarn --immutable - - name: Create Release Pull Request - uses: backstage/changesets-action@291bfc1f76d1dcfbf967f5810dc0423592eae09a # v2.3.1 - with: - # Calls out to `changeset version`, but also runs prettier - version: yarn release - env: - GITHUB_TOKEN: ${{ secrets.GH_SERVICE_ACCOUNT_TOKEN }} - HUSKY: '0' - - - name: Discord notification - if: ${{ failure() }} - uses: Ilshidur/action-discord@0c4b27844ba47cb1c7bee539c8eead5284ce9fa9 # 0.3.2 - env: - DISCORD_WEBHOOK: ${{ secrets.DISCORD_WEBHOOK }} - with: - args: 'Version Packages Sync Failed https://github.com/{{GITHUB_REPOSITORY}}/actions/runs/{{GITHUB_RUN_ID}}' diff --git a/.github/workflows/verify_accessibility-noop.yml b/.github/workflows/verify_accessibility-noop.yml deleted file mode 100644 index 37ce3513e9..0000000000 --- a/.github/workflows/verify_accessibility-noop.yml +++ /dev/null @@ -1,33 +0,0 @@ -# NO-OP placeholder that always passes for other paths -# This is here so that we're able to set the status check as required - -name: Accessibility -on: - pull_request: - branches: [master] - paths-ignore: - - 'lighthouserc.js' - - '.github/workflows/verify_accessibility.yml' - - 'plugins/catalog/src/**' - - 'plugins/catalog-react/src/**' - - 'plugins/techdocs/src/**' - - 'plugins/techdocs-react/src/**' - - 'plugins/scaffolder/src/**' - - 'plugins/scaffolder-react/src/**' - - 'plugins/search/src/**' - - 'plugins/search-react/src/**' - -permissions: - contents: read - -jobs: - noop: - name: Accessibility - runs-on: ubuntu-latest - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - run: echo NOOP diff --git a/.github/workflows/verify_accessibility.yml b/.github/workflows/verify_accessibility.yml deleted file mode 100644 index 04358bc7bb..0000000000 --- a/.github/workflows/verify_accessibility.yml +++ /dev/null @@ -1,40 +0,0 @@ -name: Accessibility -on: - # NOTE: If you change these you must update verify_accessibility-noop.yml as well - pull_request: - branches: [master] - paths: - - 'lighthouserc.js' - - '.github/workflows/verify_accessibility.yml' - - 'plugins/catalog/src/**' - - 'plugins/catalog-react/src/**' - - 'plugins/techdocs/src/**' - - 'plugins/techdocs-react/src/**' - - 'plugins/scaffolder/src/**' - - 'plugins/scaffolder-react/src/**' - - 'plugins/search/src/**' - - 'plugins/search-react/src/**' -jobs: - lhci: - name: Accessibility - runs-on: ubuntu-latest - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - - name: Use Node.js 20.x - uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 - with: - node-version: 20.x - - name: yarn install - uses: backstage/actions/yarn-install@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 - with: - cache-prefix: ${{ runner.os }}-v20.x - - name: run Lighthouse CI - run: | - yarn dlx @lhci/cli@0.11.x autorun - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/verify_codeql.yml b/.github/workflows/verify_codeql.yml deleted file mode 100644 index af16c5b5af..0000000000 --- a/.github/workflows/verify_codeql.yml +++ /dev/null @@ -1,83 +0,0 @@ -# For most projects, this workflow file will not need changing; you simply need -# to commit it to your repository. -# -# You may wish to alter this file to override the set of languages analyzed, -# or to provide custom queries or build logic. -name: Verify CodeQL - -on: - push: - branches: [master] - pull_request: - # The branches below must be a subset of the branches above - branches: [master] - # https://docs.github.com/en/free-pro-team@latest/github/finding-security-vulnerabilities-and-errors-in-your-code/configuring-code-scanning#scanning-pull-requests - paths-ignore: - - '**/*.md' - - '**/*.yml' - - '**/*.yaml' - schedule: - - cron: '0 8 * * 6' - -permissions: - contents: read - -jobs: - analyze: - permissions: - actions: read # for github/codeql-action/init to get workflow details - contents: read # for actions/checkout to fetch code - security-events: write # for github/codeql-action/autobuild to send a status report - name: Analyze - runs-on: ubuntu-latest - - strategy: - fail-fast: false - matrix: - # Override automatic language detection by changing the below list - # Supported options are ['csharp', 'cpp', 'go', 'java', 'javascript', 'python'] - language: ['javascript'] - # Learn more... - # https://docs.github.com/en/github/finding-security-vulnerabilities-and-errors-in-your-code/configuring-code-scanning#overriding-automatic-language-detection - - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - name: Checkout repository - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - with: - # We must fetch at least the immediate parents so that if this is - # a pull request then we can checkout the head. - fetch-depth: 2 - - # Initializes the CodeQL tools for scanning. - - name: Initialize CodeQL - uses: github/codeql-action/init@f779452ac5af1c261dce0346a8f964149f49322b # v3.26.13 - with: - languages: ${{ matrix.language }} - # If you wish to specify custom queries, you can do so here or in a config file. - # By default, queries listed here will override any specified in a config file. - # Prefix the list here with "+" to use these queries and those in the config file. - # queries: ./path/to/local/query, your-org/your-repo/queries@main - - # Autobuild attempts to build any compiled languages (C/C++, C#, or Java). - # If this step fails, then you should remove it and run the build manually (see below) - - name: Autobuild - uses: github/codeql-action/autobuild@f779452ac5af1c261dce0346a8f964149f49322b # v3.26.13 - - # ℹ️ Command-line programs to run using the OS shell. - # 📚 https://git.io/JvXDl - - # ✏️ If the Autobuild fails above, remove it and uncomment the following three lines - # and modify them (or add more) to build your code if your project - # uses a compiled language - - #- run: | - # make bootstrap - # make release - - - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@f779452ac5af1c261dce0346a8f964149f49322b # v3.26.13 diff --git a/.github/workflows/verify_docs-quality.yml b/.github/workflows/verify_docs-quality.yml deleted file mode 100644 index 766d289f4c..0000000000 --- a/.github/workflows/verify_docs-quality.yml +++ /dev/null @@ -1,35 +0,0 @@ -name: Verify Docs Quality -on: - pull_request: - branches: [master] - paths: - - '.github/workflows/verify_docs-quality.yml' - - '**.md' - -jobs: - check-all-files: - runs-on: ubuntu-latest - - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - - # Vale does not support file excludes, so we use the script to generate a list of files instead - # The action also does not allow args or a local config file to be passed in, so the files array - # also contains an "--config=.github/vale/config.ini" option - - name: generate vale args - id: generate - run: echo "args=$(node scripts/check-docs-quality.js --ci-args)" >> $GITHUB_OUTPUT - - - name: documentation quality check - uses: errata-ai/vale-action@d89dee975228ae261d22c15adcd03578634d429c # v2.1.1 - with: - # This also contains --config=.github/vale/config.ini ... :/ - files: '${{ steps.generate.outputs.args }}' - version: latest - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/verify_e2e-linux-noop.yml b/.github/workflows/verify_e2e-linux-noop.yml deleted file mode 100644 index 1afcd3fe17..0000000000 --- a/.github/workflows/verify_e2e-linux-noop.yml +++ /dev/null @@ -1,36 +0,0 @@ -# NO-OP placeholder that always passes for other paths -# This is here so that we're able to set the status check as required - -name: E2E Linux Void -on: - pull_request: - paths: - - '.changeset/**' - - 'contrib/**' - - 'docs/**' - - 'microsite/**' - - 'beps/**' - -concurrency: - group: ${{ github.workflow }}-${{ github.ref }} - cancel-in-progress: true - -permissions: - contents: read - -jobs: - noop: - runs-on: ubuntu-latest - - strategy: - matrix: - node-version: [20.x, 22.x] - - name: E2E Linux ${{ matrix.node-version }} - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - run: echo NOOP diff --git a/.github/workflows/verify_e2e-linux.yml b/.github/workflows/verify_e2e-linux.yml deleted file mode 100644 index 54d76db295..0000000000 --- a/.github/workflows/verify_e2e-linux.yml +++ /dev/null @@ -1,76 +0,0 @@ -name: E2E Linux -on: - # NOTE: If you change these you must update verify_e2e-linux-noop.yml as well - pull_request: - paths-ignore: - - '.changeset/**' - - 'contrib/**' - - 'docs/**' - - 'microsite/**' - - 'beps/**' - -concurrency: - group: ${{ github.workflow }}-${{ github.ref }} - cancel-in-progress: true - -jobs: - build: - runs-on: ubuntu-latest - - services: - postgres: - image: postgres:12 - env: - POSTGRES_USER: postgres - POSTGRES_PASSWORD: postgres - POSTGRES_DB: postgres - ports: - - 5432/tcp - # needed because the postgres container does not provide a healthcheck - options: --health-cmd pg_isready --health-interval 10s --health-timeout 5s --health-retries 5 - - strategy: - fail-fast: false - matrix: - node-version: [20.x, 22.x] - - env: - CI: true - NODE_OPTIONS: --max-old-space-size=8192 --no-node-snapshot - - name: E2E Linux ${{ matrix.node-version }} - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - - - name: Configure Git - run: | - git config --global user.email noreply@backstage.io - git config --global user.name 'GitHub e2e user' - - - name: use node.js ${{ matrix.node-version }} - uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 - with: - node-version: ${{ matrix.node-version }} - registry-url: https://registry.npmjs.org/ # Needed for auth - - name: yarn install - uses: backstage/actions/yarn-install@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 - with: - cache-prefix: ${{ runner.os }}-v${{ matrix.node-version }} - - - run: yarn tsc - - run: yarn backstage-cli repo build - - name: run E2E test - run: | - sudo sysctl fs.inotify.max_user_watches=524288 - yarn e2e-test run - env: - BACKSTAGE_TEST_DISABLE_DOCKER: 1 - POSTGRES_USER: postgres - POSTGRES_PASSWORD: postgres - POSTGRES_HOST: localhost - POSTGRES_PORT: ${{ job.services.postgres.ports[5432] }} diff --git a/.github/workflows/verify_e2e-techdocs.yml b/.github/workflows/verify_e2e-techdocs.yml deleted file mode 100644 index 9aad8e9699..0000000000 --- a/.github/workflows/verify_e2e-techdocs.yml +++ /dev/null @@ -1,59 +0,0 @@ -name: E2E Techdocs -on: - pull_request: - paths: - - 'yarn.lock' - - '.github/workflows/verify_e2e-techdocs.yml' - - 'packages/techdocs-cli/**' - - 'packages/techdocs-cli-embedded-app/**' - - 'plugins/techdocs/**' - -concurrency: - group: ${{ github.workflow }}-${{ github.ref }} - cancel-in-progress: true - -permissions: - contents: read - -jobs: - verify: - runs-on: ubuntu-latest - - strategy: - matrix: - node-version: [20.x, 22.x] - - env: - CI: true - NODE_OPTIONS: --max-old-space-size=4096 - - name: Techdocs - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - - uses: actions/setup-python@f677139bbe7f9c59b41e40162b753c062f5d49a3 # v5.2.0 - with: - python-version: '3.9' - - - name: install dependencies - run: yarn install --immutable - - - name: generate types - run: yarn tsc - - - name: build techdocs-cli - working-directory: packages/techdocs-cli - run: yarn build - - - name: Install mkdocs & techdocs-core - run: python -m pip install mkdocs-techdocs-core==1.1.7 mkdocs==1.4.0 - - - name: techdocs-cli e2e test - working-directory: packages/techdocs-cli - run: yarn test:e2e:ci - env: - BACKSTAGE_TEST_DISABLE_DOCKER: 1 diff --git a/.github/workflows/verify_e2e-windows-noop.yml b/.github/workflows/verify_e2e-windows-noop.yml deleted file mode 100644 index 3e415b82c6..0000000000 --- a/.github/workflows/verify_e2e-windows-noop.yml +++ /dev/null @@ -1,32 +0,0 @@ -# NO-OP placeholder that always passes for other paths -# This is here so that we're able to set the status check as required - -name: E2E Windows Void -on: - pull_request: - paths-ignore: - - 'yarn.lock' - - '.github/workflows/verify_e2e-windows.yml' - - 'packages/cli/**' - - 'packages/e2e-test/**' - - 'packages/create-app/**' - -permissions: - contents: read - -jobs: - noop: - runs-on: windows-2022 - - strategy: - matrix: - node-version: [20.x, 22.x] - - name: E2E Windows ${{ matrix.node-version }} - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - run: echo NOOP diff --git a/.github/workflows/verify_e2e-windows.yml b/.github/workflows/verify_e2e-windows.yml deleted file mode 100644 index 2934874460..0000000000 --- a/.github/workflows/verify_e2e-windows.yml +++ /dev/null @@ -1,91 +0,0 @@ -# Building on windows is really slow, so this workflow is separate from e2e.yml and only builds on changes -# to the cli itself. They're more likely to introduce issues on windows, compared to changes to core and yarn.lock. - -name: E2E Windows -on: - # NOTE: If you change these you must update verify_e2e-windows-noop.yml as well - pull_request: - paths: - - 'yarn.lock' - - '.github/workflows/verify_e2e-windows.yml' - - 'packages/cli/**' - - 'packages/e2e-test/**' - - 'packages/create-app/**' - -concurrency: - group: ${{ github.workflow }}-${{ github.ref }} - cancel-in-progress: true - -jobs: - build: - runs-on: windows-2022 - - strategy: - matrix: - node-version: [20.x, 22.x] - - env: - CI: true - NODE_OPTIONS: --max-old-space-size=8192 --no-node-snapshot - - name: E2E Windows ${{ matrix.node-version }} - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - # In order to have the create-app template function as if it was downloaded from NPM - # we need to make sure we checkout files with LF line endings only - - name: Set git to use LF - run: | - git config --global core.autocrlf false - git config --global core.eol lf - - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - - - name: Configure Git - run: | - git config --global user.email noreply@backstage.io - git config --global user.name 'GitHub e2e user' - - - name: use node.js ${{ matrix.node-version }} - uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 - with: - node-version: ${{ matrix.node-version }} - registry-url: https://registry.npmjs.org/ # Needed for auth - - - name: setup python - uses: actions/setup-python@f677139bbe7f9c59b41e40162b753c062f5d49a3 # v5.2.0 - with: - python-version: '3.10' - - - name: Add msbuild to PATH - uses: microsoft/setup-msbuild@6fb02220983dee41ce7ae257b6f4d8f9bf5ed4ce # v2.0.0 - - - name: Setup gyp env - run: | - echo 'GYP_MSVS_VERSION=2022' >> $Env:GITHUB_ENV - echo 'GYP_MSVS_OVERRIDE_PATH=C:\\Dummy' >> $Env:GITHUB_ENV - - - name: Install latest gyp and set node-gyp path - shell: powershell - run: | - npm prefix -g | % {npm config set dev_dir "c:\temp\.gyp2"} - npm prefix -g | % {npm config set node_gyp "$_\node_modules\node-gyp\bin\node-gyp.js"} - - - name: setup chrome - uses: browser-actions/setup-chrome@803ef6dfb4fdf22089c9563225d95e4a515820a0 # latest - - - name: yarn install - uses: backstage/actions/yarn-install@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 - with: - cache-prefix: ${{ runner.os }}-v${{ matrix.node-version }} - - - run: yarn tsc - - run: yarn backstage-cli repo build - - name: run E2E test - run: yarn e2e-test run - env: - DEBUG: zombie - CYPRESS_VERIFY_TIMEOUT: 600000 diff --git a/.github/workflows/verify_fossa.yml b/.github/workflows/verify_fossa.yml deleted file mode 100644 index e99ad22a9b..0000000000 --- a/.github/workflows/verify_fossa.yml +++ /dev/null @@ -1,32 +0,0 @@ -name: Verify FOSSA -on: - push: - branches: [master] - pull_request: - branches: [master] - -permissions: - contents: read - -jobs: - analyze: - runs-on: ubuntu-latest - - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - name: Checkout - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - - - name: Install Fossa - run: "curl -H 'Cache-Control: no-cache' https://raw.githubusercontent.com/fossas/fossa-cli/master/install.sh | bash" - - - name: Fossa Configure & Analyze - env: - # FOSSA Push-Only API Token - GITHUB_REF: $GITHUB_REF - FOSSA_API_KEY: 9ee7e8893660832a7387dcc32377fb61 - run: node scripts/run-fossa.js diff --git a/.github/workflows/verify_microsite-noop.yml b/.github/workflows/verify_microsite-noop.yml deleted file mode 100644 index f4c5ea4104..0000000000 --- a/.github/workflows/verify_microsite-noop.yml +++ /dev/null @@ -1,28 +0,0 @@ -# NO-OP placeholder that always passes for other paths -# This is here so that we're able to set the status check as required - -name: Microsite Void -on: - pull_request: - paths-ignore: - - '.github/workflows/verify_microsite.yml' - - 'microsite/**' - - 'beps/**' - - 'mkdocs.yml' - - 'docs/**' - -permissions: - contents: read - -jobs: - noop: - runs-on: ubuntu-latest - - name: Microsite - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - run: echo NOOP diff --git a/.github/workflows/verify_microsite.yml b/.github/workflows/verify_microsite.yml deleted file mode 100644 index c0a932b349..0000000000 --- a/.github/workflows/verify_microsite.yml +++ /dev/null @@ -1,68 +0,0 @@ -name: Microsite -on: - # NOTE: If you change these you must update verify_microsite-noop.yml as well - pull_request: - paths: - - '.github/workflows/verify_microsite.yml' - - 'microsite/**' - - 'beps/**' - - 'mkdocs.yml' - - 'docs/**' - -permissions: - contents: read - -jobs: - build-microsite: - runs-on: ubuntu-latest - - env: - CI: true - NODE_OPTIONS: --max-old-space-size=8192 - DOCUSAURUS_SSR_CONCURRENCY: 5 - - name: Microsite - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - - - name: Use Node.js 20.x - uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 - with: - node-version: 20.x - - uses: actions/setup-python@f677139bbe7f9c59b41e40162b753c062f5d49a3 # v5 - with: - python-version: '3.9' - - - name: Install MkDocs dependencies - run: pip install mkdocs mkdocs-techdocs-core - - # Skip caching of microsite dependencies, it keeps the global cache size - # smaller, which make Windows builds a lot faster for the rest of the project. - - name: top-level install - run: yarn install --immutable - - - name: yarn install - run: yarn install --immutable - working-directory: microsite - - - name: build API reference - run: yarn build:api-docs - - - name: Build MkDocs for TechDocs - run: mkdocs build --strict - - - name: verify yarn dependency duplicates - run: node scripts/verify-lockfile-duplicates.js - - - name: prettier - run: yarn prettier:check - working-directory: microsite - - - name: build microsite - run: yarn build - working-directory: microsite diff --git a/.github/workflows/verify_microsite_accessibility-noop.yml b/.github/workflows/verify_microsite_accessibility-noop.yml deleted file mode 100644 index 49721e7f51..0000000000 --- a/.github/workflows/verify_microsite_accessibility-noop.yml +++ /dev/null @@ -1,31 +0,0 @@ -# NO-OP placeholder that always passes for other paths -# This is here so that we're able to set the status check as required - -name: Microsite Accessibility -on: - pull_request: - branches: [master] - paths-ignore: - - '.github/workflows/verify_microsite_accessibility.yml' - - 'microsite/scripts/**' - - 'microsite/src/**' - - 'microsite/data/**' - - 'microsite/blog/**' - - 'microsite/static/**' - - 'beps/**' - - 'mkdocs.yml' - - 'docs/**' -permissions: - contents: read - -jobs: - noop: - name: Microsite Accessibility - runs-on: ubuntu-latest - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - run: echo NOOP diff --git a/.github/workflows/verify_microsite_accessibility.yml b/.github/workflows/verify_microsite_accessibility.yml deleted file mode 100644 index 91533bd7d8..0000000000 --- a/.github/workflows/verify_microsite_accessibility.yml +++ /dev/null @@ -1,40 +0,0 @@ -name: Microsite Accessibility -on: - # NOTE: If you change these you must update verify_microsite_accessibility-noop.yml as well - pull_request: - branches: [master] - paths: - - '.github/workflows/verify_microsite_accessibility.yml' - - 'microsite/**' - - 'beps/**' - - 'mkdocs.yml' - - 'docs/**' -jobs: - lhci: - name: Microsite Accessibility - runs-on: ubuntu-latest - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - - - name: Use Node.js 20.x - uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 - with: - node-version: 20.x - - - name: top-level install - run: yarn install --immutable - - - name: yarn install - run: yarn install --immutable - working-directory: microsite - - - name: run Lighthouse CI - run: | - yarn dlx @lhci/cli@0.11.x --config=microsite/lighthouserc.js autorun - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/verify_storybook-noop.yml b/.github/workflows/verify_storybook-noop.yml deleted file mode 100644 index 115c79c9c3..0000000000 --- a/.github/workflows/verify_storybook-noop.yml +++ /dev/null @@ -1,35 +0,0 @@ -# NO-OP placeholder that always passes for other paths -# This is here so that we're able to set the status check as required - -name: Storybook Void -on: - pull_request: - paths-ignore: - - '.github/workflows/verify_storybook.yml' - - 'storybook/**' - - 'packages/config/src/**' - - 'packages/theme/src/**' - - 'packages/types/src/**' - - 'packages/errors/src/**' - - 'packages/version-bridge/src/**' - - 'packages/test-utils/src/**' - - 'packages/core-app-api/src/**' - - 'packages/core-plugin-api/src/**' - - 'packages/core-components/src/**' - - '**/*.stories.tsx' - -permissions: - contents: read - -jobs: - noop: - runs-on: ubuntu-latest - - name: Storybook - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - run: echo NOOP diff --git a/.github/workflows/verify_storybook.yml b/.github/workflows/verify_storybook.yml deleted file mode 100644 index 8fd3f17ee4..0000000000 --- a/.github/workflows/verify_storybook.yml +++ /dev/null @@ -1,61 +0,0 @@ -name: Storybook -on: - # NOTE: If you change these you must update verify_storybook-noop.yml as well - pull_request: - paths: - - '.github/workflows/verify_storybook.yml' - - 'storybook/**' - - 'packages/config/src/**' - - 'packages/theme/src/**' - - 'packages/types/src/**' - - 'packages/errors/src/**' - - 'packages/version-bridge/src/**' - - 'packages/test-utils/src/**' - - 'packages/core-app-api/src/**' - - 'packages/core-plugin-api/src/**' - - 'packages/core-components/src/**' - - '**/*.stories.tsx' - -jobs: - chromatic: - runs-on: ${{ matrix.os }} - - strategy: - matrix: - os: [ubuntu-latest] - node-version: [20.x] - - name: Storybook - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - with: - fetch-depth: 0 # Required to retrieve git history - - - name: use node.js ${{ matrix.node-version }} - uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 - with: - node-version: ${{ matrix.node-version }} - registry-url: https://registry.npmjs.org/ # Needed for auth - - name: yarn install - uses: backstage/actions/yarn-install@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 - with: - cache-prefix: ${{ runner.os }}-v${{ matrix.node-version }} - - name: storybook yarn install - run: yarn install --immutable - working-directory: storybook - - - run: yarn build-storybook - - - uses: chromaui/action@25f8ff36486472c2d6b5b02dc2d277f051a3ecdb # v11 - with: - token: ${{ secrets.GITHUB_TOKEN }} - # projectToken intentionally shared to allow collaborators to run Chromatic on forks - # https://www.chromatic.com/docs/custom-ci-provider#run-chromatic-on-external-forks-of-open-source-projects - projectToken: 9tzak77m9nj - workingDir: storybook - storybookBuildDir: dist diff --git a/.github/workflows/verify_windows.yml b/.github/workflows/verify_windows.yml deleted file mode 100644 index 4f8afe5530..0000000000 --- a/.github/workflows/verify_windows.yml +++ /dev/null @@ -1,71 +0,0 @@ -name: Verify Master Branch on Windows -on: - workflow_dispatch: - push: - branches: [master] - pull_request: - paths: - - '.github/workflows/verify_windows.yml' - -permissions: - contents: read - -jobs: - build: - runs-on: windows-2022 - - strategy: - fail-fast: false - matrix: - node-version: [20.x, 22.x] - - env: - CI: true - NODE_OPTIONS: --max-old-space-size=8192 --no-node-snapshot - INTEGRATION_TEST_GITHUB_TOKEN: ${{ secrets.INTEGRATION_TEST_GITHUB_TOKEN }} - INTEGRATION_TEST_GITLAB_TOKEN: ${{ secrets.INTEGRATION_TEST_GITLAB_TOKEN }} - INTEGRATION_TEST_BITBUCKET_TOKEN: ${{ secrets.INTEGRATION_TEST_BITBUCKET_TOKEN }} - INTEGRATION_TEST_AZURE_TOKEN: ${{ secrets.INTEGRATION_TEST_AZURE_TOKEN }} - - steps: - - name: Harden Runner - uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 - with: - egress-policy: audit - - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - - - name: use node.js ${{ matrix.node-version }} - uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 - with: - node-version: ${{ matrix.node-version }} - registry-url: https://registry.npmjs.org/ # Needed for auth - - # Windows file operation slowness means there's no point caching this - - name: yarn install - run: yarn install --immutable - - - name: lint - run: yarn backstage-cli repo lint --successCache - - - name: type checking and declarations - run: yarn tsc:full - - - name: verify type dependencies - run: yarn lint:type-deps - - - name: test - run: yarn backstage-cli repo test --maxWorkers=3 --workerIdleMemoryLimit=1300M --successCache - env: - BACKSTAGE_TEST_DISABLE_DOCKER: 1 - - # credit: https://github.com/appleboy/discord-action/issues/3#issuecomment-731426861 - - name: Discord notification - if: ${{ failure() }} - env: - DISCORD_WEBHOOK: ${{ secrets.DISCORD_WEBHOOK }} - run: | - $MESSAGE=@" - {\"content\": \"Windows master build failed https://github.com/${{github.repository}}/actions/runs/${{github.run_id}}\"} - "@ - C:\msys64\usr\bin\curl.exe -i -H "Accept: application/json" -H "Content-Type:application/json" -X POST $env:DISCORD_WEBHOOK --data $MESSAGE From a8ad7062f703357b37cf08e295c558798a7ab426 Mon Sep 17 00:00:00 2001 From: mordivgor <54472480+mordivgor@users.noreply.github.com> Date: Thu, 24 Oct 2024 20:43:57 +0200 Subject: [PATCH 4/4] Revert accidental commit Signed-off-by: mordivgor <54472480+mordivgor@users.noreply.github.com> --- .../api-breaking-changes-comment.yml | 111 +++++++ .github/workflows/api-breaking-changes.yml | 56 ++++ .github/workflows/automate_area-labels.yml | 23 ++ .../workflows/automate_changeset_feedback.yml | 46 +++ .github/workflows/automate_merge_message.yml | 68 +++++ .github/workflows/automate_stale.yml | 42 +++ .github/workflows/ci-noop.yml | 47 +++ .github/workflows/ci.yml | 280 ++++++++++++++++++ .github/workflows/cron.yml | 21 ++ .github/workflows/deploy_docker-image.yml | 75 +++++ .github/workflows/deploy_microsite.yml | 231 +++++++++++++++ .github/workflows/deploy_packages.yml | 160 ++++++++++ .github/workflows/issue.yaml | 31 ++ .../workflows/pr-review-comment-trigger.yaml | 37 +++ .github/workflows/pr-review-comment.yaml | 49 +++ .github/workflows/pr.yaml | 34 +++ .github/workflows/scorecard.yml | 72 +++++ .github/workflows/sync_code-formatting.yml | 40 +++ .../workflows/sync_dependabot-changesets.yml | 83 ++++++ .github/workflows/sync_release-manifest.yml | 89 ++++++ .../workflows/sync_renovate-changesets.yml | 102 +++++++ .github/workflows/sync_snyk-github-issues.yml | 48 +++ .github/workflows/sync_snyk-monitor.yml | 63 ++++ .github/workflows/sync_version-packages.yml | 43 +++ .../workflows/verify_accessibility-noop.yml | 33 +++ .github/workflows/verify_accessibility.yml | 40 +++ .github/workflows/verify_codeql.yml | 83 ++++++ .github/workflows/verify_docs-quality.yml | 35 +++ .github/workflows/verify_e2e-linux-noop.yml | 36 +++ .github/workflows/verify_e2e-linux.yml | 76 +++++ .github/workflows/verify_e2e-techdocs.yml | 59 ++++ .github/workflows/verify_e2e-windows-noop.yml | 32 ++ .github/workflows/verify_e2e-windows.yml | 91 ++++++ .github/workflows/verify_fossa.yml | 32 ++ .github/workflows/verify_microsite-noop.yml | 28 ++ .github/workflows/verify_microsite.yml | 68 +++++ .../verify_microsite_accessibility-noop.yml | 31 ++ .../verify_microsite_accessibility.yml | 40 +++ .github/workflows/verify_storybook-noop.yml | 35 +++ .github/workflows/verify_storybook.yml | 61 ++++ .github/workflows/verify_windows.yml | 71 +++++ 41 files changed, 2702 insertions(+) create mode 100644 .github/workflows/api-breaking-changes-comment.yml create mode 100644 .github/workflows/api-breaking-changes.yml create mode 100644 .github/workflows/automate_area-labels.yml create mode 100644 .github/workflows/automate_changeset_feedback.yml create mode 100644 .github/workflows/automate_merge_message.yml create mode 100644 .github/workflows/automate_stale.yml create mode 100644 .github/workflows/ci-noop.yml create mode 100644 .github/workflows/ci.yml create mode 100644 .github/workflows/cron.yml create mode 100644 .github/workflows/deploy_docker-image.yml create mode 100644 .github/workflows/deploy_microsite.yml create mode 100644 .github/workflows/deploy_packages.yml create mode 100644 .github/workflows/issue.yaml create mode 100644 .github/workflows/pr-review-comment-trigger.yaml create mode 100644 .github/workflows/pr-review-comment.yaml create mode 100644 .github/workflows/pr.yaml create mode 100644 .github/workflows/scorecard.yml create mode 100644 .github/workflows/sync_code-formatting.yml create mode 100644 .github/workflows/sync_dependabot-changesets.yml create mode 100644 .github/workflows/sync_release-manifest.yml create mode 100644 .github/workflows/sync_renovate-changesets.yml create mode 100644 .github/workflows/sync_snyk-github-issues.yml create mode 100644 .github/workflows/sync_snyk-monitor.yml create mode 100644 .github/workflows/sync_version-packages.yml create mode 100644 .github/workflows/verify_accessibility-noop.yml create mode 100644 .github/workflows/verify_accessibility.yml create mode 100644 .github/workflows/verify_codeql.yml create mode 100644 .github/workflows/verify_docs-quality.yml create mode 100644 .github/workflows/verify_e2e-linux-noop.yml create mode 100644 .github/workflows/verify_e2e-linux.yml create mode 100644 .github/workflows/verify_e2e-techdocs.yml create mode 100644 .github/workflows/verify_e2e-windows-noop.yml create mode 100644 .github/workflows/verify_e2e-windows.yml create mode 100644 .github/workflows/verify_fossa.yml create mode 100644 .github/workflows/verify_microsite-noop.yml create mode 100644 .github/workflows/verify_microsite.yml create mode 100644 .github/workflows/verify_microsite_accessibility-noop.yml create mode 100644 .github/workflows/verify_microsite_accessibility.yml create mode 100644 .github/workflows/verify_storybook-noop.yml create mode 100644 .github/workflows/verify_storybook.yml create mode 100644 .github/workflows/verify_windows.yml diff --git a/.github/workflows/api-breaking-changes-comment.yml b/.github/workflows/api-breaking-changes-comment.yml new file mode 100644 index 0000000000..038061adac --- /dev/null +++ b/.github/workflows/api-breaking-changes-comment.yml @@ -0,0 +1,111 @@ +name: API Breaking Changes (comment) + +on: + workflow_run: + workflows: + - 'API Breaking Changes (Trigger)' + types: + - completed + +jobs: + setup: + name: Add values from previous step + runs-on: ubuntu-latest + if: ${{ github.event.workflow_run.conclusion == 'success' }} + permissions: + # "If you specify the access for any of these scopes, all of those that are not specified are set to none." + # https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#permissions + actions: read # Access cache + outputs: + git-ref: ${{ steps.event.outputs.GIT_REF }} + pr-number: ${{ steps.event.outputs.PR_NUMBER }} + action: ${{ steps.event.outputs.ACTION }} + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + disable-sudo: true + egress-policy: block + allowed-endpoints: > + api.github.com:443 + + - name: 'Download artifacts' + # Fetch output (zip archive) from the workflow run that triggered this workflow. + uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1 + with: + script: | + let allArtifacts = await github.rest.actions.listWorkflowRunArtifacts({ + owner: context.repo.owner, + repo: context.repo.repo, + run_id: context.payload.workflow_run.id, + }); + let matchArtifact = allArtifacts.data.artifacts.filter((artifact) => { + return artifact.name == "preview-spec" + })[0]; + if (matchArtifact === undefined) { + throw TypeError('Build Artifact not found!'); + } + let download = await github.rest.actions.downloadArtifact({ + owner: context.repo.owner, + repo: context.repo.repo, + artifact_id: matchArtifact.id, + archive_format: 'zip', + }); + let fs = require('fs'); + fs.writeFileSync(`${process.env.GITHUB_WORKSPACE}/preview-spec.zip`, Buffer.from(download.data)); + + - name: 'Accept event from first stage' + run: unzip preview-spec.zip event.json + + - name: Read Event into ENV + id: event + run: | + echo PR_NUMBER=$(jq '.number | tonumber' < event.json) >> $GITHUB_OUTPUT + echo ACTION=$(jq --raw-output '.action | tostring | [scan("\\w+")][0]' < event.json) >> $GITHUB_OUTPUT + echo GIT_REF=$(jq --raw-output '.pull_request.head.sha | tostring | [scan("\\w+")][0]' < event.json) >> $GITHUB_OUTPUT + + - name: DEBUG - Print Job Outputs + if: ${{ runner.debug }} + run: | + echo "PR number: ${{ steps.event.outputs.PR_NUMBER }}" + echo "Git Ref: ${{ steps.event.outputs.GIT_REF }}" + echo "Action: ${{ steps.event.outputs.ACTION }}" + cat event.json + + - name: Get Comment + id: get-comment + run: | + unzip preview-spec.zip comment.md + ls + grep + + add-comment: + name: Write comment about issues + needs: + - setup + if: ${{ github.event.workflow_run.conclusion == 'success' }} + permissions: + contents: read + pull-requests: write + runs-on: ubuntu-latest + steps: + - name: Checkout + uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4 + + # Identify comment to be updated + - name: Find comment for API Changes + uses: peter-evans/find-comment@3eae4d37986fb5a8592848f6a574fdf654e61f9e # v3 + id: find-comment + with: + issue-number: ${{ needs.setup.outputs.pr-number }} + comment-author: 'github-actions[bot]' + body-includes: API changes + direction: last + + - name: Create or Update Comment with API Changes + uses: peter-evans/create-or-update-comment@71345be0265236311c031f5c7866368bd1eff043 # v4 + with: + comment-id: ${{ steps.find-comment.outputs.comment-id }} + issue-number: ${{ github.event.pull_request.number }} + body-path: comment.md + edit-mode: replace diff --git a/.github/workflows/api-breaking-changes.yml b/.github/workflows/api-breaking-changes.yml new file mode 100644 index 0000000000..9c2b9229f8 --- /dev/null +++ b/.github/workflows/api-breaking-changes.yml @@ -0,0 +1,56 @@ +name: API Breaking Changes (Trigger) +on: + pull_request: + types: [opened, synchronize, reopened, closed] + paths: + - '**/openapi.yaml' + +jobs: + get-backstage-changes: + env: + NODE_OPTIONS: --max-old-space-size=4096 + name: Build PR image + runs-on: ubuntu-latest + if: ${{ github.event_name != 'pull_request' || github.event.action != 'closed' }} + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + with: + # Fetch the commit that's merged into the base rather than the target ref + # This will let us diff only the contents of the PR, without fetching more history + ref: 'refs/pull/${{ github.event.pull_request.number }}/merge' + - name: fetch base + run: git fetch --depth 1 origin ${{ github.base_ref }} + + - name: setup-node + uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 + with: + node-version: 20.x + registry-url: https://registry.npmjs.org/ + + - name: yarn install + uses: backstage/actions/yarn-install@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 + with: + cache-prefix: linux-v20 + + - name: breaking changes check + run: | + yarn backstage-repo-tools repo schema openapi diff --since origin/${{ github.base_ref }} > comment.md + + - name: clone artifacts to current directory + run: | + cat ${{ github.event_path }} > event.json + + - name: Upload Artifacts + uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 # v4 + with: + name: preview-spec + path: | + comment.md + event.json + retention-days: 2 + overwrite: true diff --git a/.github/workflows/automate_area-labels.yml b/.github/workflows/automate_area-labels.yml new file mode 100644 index 0000000000..89e1adc3c3 --- /dev/null +++ b/.github/workflows/automate_area-labels.yml @@ -0,0 +1,23 @@ +name: Automate area labels +on: + - pull_request_target + +permissions: + contents: read + +jobs: + triage: + permissions: + contents: read # for actions/labeler to determine modified files + pull-requests: write # for actions/labeler to add labels to PRs + runs-on: ubuntu-latest + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - uses: actions/labeler@8558fd74291d67161a8a78ce36a881fa63b766a9 # v5.0.0 + with: + repo-token: '${{ secrets.GITHUB_TOKEN }}' + sync-labels: true diff --git a/.github/workflows/automate_changeset_feedback.yml b/.github/workflows/automate_changeset_feedback.yml new file mode 100644 index 0000000000..d7e2b56b39 --- /dev/null +++ b/.github/workflows/automate_changeset_feedback.yml @@ -0,0 +1,46 @@ +name: Automate changeset feedback +on: + pull_request_target: + branches: ['master'] + +permissions: + pull-requests: write + actions: none + checks: none + contents: none + deployments: none + issues: none + packages: none + pages: none + repository-projects: none + security-events: none + statuses: none + +jobs: + feedback: + # prevent running towards forks and version packages + if: github.repository == 'backstage/backstage' && github.event.pull_request.user.login != 'backstage-service' + runs-on: ubuntu-latest + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + with: + # Fetch the commit that's merged into the base rather than the target ref + # This will let us diff only the contents of the PR, without fetching more history + ref: 'refs/pull/${{ github.event.pull_request.number }}/merge' + - name: fetch base + run: git fetch --depth 1 origin ${{ github.base_ref }} + - uses: backstage/actions/changeset-feedback@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 + name: Generate feedback + with: + diff-ref: 'origin/master' + marker: + issue-number: ${{ github.event.pull_request.number }} + bot-username: backstage-goalie[bot] + app-id: ${{ secrets.BACKSTAGE_GOALIE_APPLICATION_ID }} + private-key: ${{ secrets.BACKSTAGE_GOALIE_PRIVATE_KEY }} + installation-id: ${{ secrets.BACKSTAGE_GOALIE_INSTALLATION_ID }} diff --git a/.github/workflows/automate_merge_message.yml b/.github/workflows/automate_merge_message.yml new file mode 100644 index 0000000000..ece1331730 --- /dev/null +++ b/.github/workflows/automate_merge_message.yml @@ -0,0 +1,68 @@ +name: Automate merge message +on: + pull_request_target: + branches: ['master'] + types: ['closed'] + +permissions: + pull-requests: write + actions: none + checks: none + contents: none + deployments: none + issues: none + packages: none + pages: none + repository-projects: none + security-events: none + statuses: none + +jobs: + message: + # prevent running towards forks, and only run on merged PRs + if: github.repository == 'backstage/backstage' && github.event.pull_request.merged == true + runs-on: ubuntu-latest + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + with: + ref: '${{ github.event.pull_request.merge_commit_sha }}' + + - name: fetch head & base + run: git fetch --depth 1 origin ${{ github.event.pull_request.head.sha }} ${{ github.event.pull_request.base.sha }} + + # We avoid using the in-source script since this workflow has elevated permissions that we don't want to expose + - name: Generate Message + id: generate-message + run: | + rm -f generate.js + wget -O generate.js https://raw.githubusercontent.com/backstage/backstage/master/scripts/generate-merge-message.js 1>&2 + node generate.js ${{ github.event.pull_request.base.sha }} ${{ github.event.pull_request.head.sha }} > message.txt + + - name: Post Message + uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1 + env: + ISSUE_NUMBER: ${{ github.event.pull_request.number }} + with: + script: | + const owner = "backstage"; + const repo = "backstage"; + const body = require('fs').readFileSync('message.txt', 'utf8').trim(); + const issue_number = Number(process.env.ISSUE_NUMBER); + + if (!body) { + console.log(`skipping comment for #${issue_number}`); + return; + } + + console.log(`creating comment for #${issue_number}`); + await github.rest.issues.createComment({ + owner, + repo, + issue_number, + body, + }); diff --git a/.github/workflows/automate_stale.yml b/.github/workflows/automate_stale.yml new file mode 100644 index 0000000000..b7adc5235a --- /dev/null +++ b/.github/workflows/automate_stale.yml @@ -0,0 +1,42 @@ +name: Automate staleness +on: + workflow_dispatch: + schedule: + - cron: '*/10 * * * *' # run every 10 minutes as it also removes labels. + +permissions: + contents: read + +jobs: + stale: + permissions: + issues: write # for actions/stale to close stale issues + pull-requests: write # for actions/stale to close stale PRs + runs-on: ubuntu-latest + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - uses: actions/stale@28ca1036281a5e5922ead5184a1bbf96e5fc984e # v9.0.0 + id: stale + with: + stale-issue-message: > + This issue has been automatically marked as stale because it has not had + recent activity. It will be closed if no further activity occurs. Thank you + for your contributions. + days-before-issue-stale: 60 + days-before-issue-close: 7 + exempt-issue-labels: plugin,after-vacations,will-fix,bep + stale-issue-label: stale + stale-pr-message: > + This PR has been automatically marked as stale because it has not had + recent activity from the author. It will be closed if no further activity occurs. + If the PR was closed and you want it re-opened, let us know + and we'll re-open the PR so that you can continue the contribution! + days-before-pr-stale: 14 + days-before-pr-close: 7 + exempt-pr-labels: after-vacations,will-fix + stale-pr-label: stale + operations-per-run: 100 diff --git a/.github/workflows/ci-noop.yml b/.github/workflows/ci-noop.yml new file mode 100644 index 0000000000..af7199ede6 --- /dev/null +++ b/.github/workflows/ci-noop.yml @@ -0,0 +1,47 @@ +# NO-OP placeholder that always passes for other paths +# This is here so that we're able to set the status check as required + +name: CI Void +on: + pull_request: + paths: + - 'microsite/**' + - 'beps/**' + +permissions: + contents: read + +jobs: + # The verify jobs runs all the verification that doesn't require a + # diff towards master, since it takes some time to fetch that. + verify-noop: + runs-on: ubuntu-latest + + strategy: + matrix: + node-version: [20.x, 22.x] + + name: Verify ${{ matrix.node-version }} + steps: + # - name: Harden Runner + # uses: step-security/harden-runner@8ca2b8b2ece13480cda6dacd3511b49857a23c09 # v2.5.1 + # with: + # egress-policy: audit + + - run: echo NOOP + + test-noop: + runs-on: ubuntu-latest + + strategy: + matrix: + node-version: [20.x, 22.x] + + name: Test ${{ matrix.node-version }} + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - run: echo NOOP diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml new file mode 100644 index 0000000000..c15fa1483f --- /dev/null +++ b/.github/workflows/ci.yml @@ -0,0 +1,280 @@ +name: CI +on: + # NOTE: If you change these you must update ci-noop.yml as well + pull_request: + paths-ignore: + - 'microsite/**' + - 'beps/**' + +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true + +jobs: + # This step only runs yarn install to make sure that an exact match is available + # in the cache. The two following verify and tests jobs then always install from cache. + install: + runs-on: ubuntu-latest + + strategy: + fail-fast: false + matrix: + node-version: [20.x, 22.x] + + env: + CI: true + NODE_OPTIONS: --max-old-space-size=8192 + + name: Install ${{ matrix.node-version }} + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + + - name: use node.js ${{ matrix.node-version }} + uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 + with: + node-version: ${{ matrix.node-version }} + registry-url: https://registry.npmjs.org/ # Needed for auth + + - name: yarn install + uses: backstage/actions/yarn-install@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 + with: + cache-prefix: ${{ runner.os }}-v${{ matrix.node-version }} + + # The verify jobs runs all the verification that doesn't require a + # diff towards master, since it takes some time to fetch that. + verify: + runs-on: ubuntu-latest + + needs: install + + strategy: + fail-fast: false + matrix: + node-version: [20.x, 22.x] + + env: + CI: true + NODE_OPTIONS: --max-old-space-size=8192 + + name: Verify ${{ matrix.node-version }} + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + + - name: use node.js ${{ matrix.node-version }} + uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 + with: + node-version: ${{ matrix.node-version }} + registry-url: https://registry.npmjs.org/ # Needed for auth + + - name: yarn install + uses: backstage/actions/yarn-install@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 + with: + cache-prefix: ${{ runner.os }}-v${{ matrix.node-version }} + + - name: verify yarn dependency duplicates + run: node scripts/verify-lockfile-duplicates.js + + - name: verify changesets + run: node scripts/verify-changesets.js + + - name: verify local dependency ranges + run: node scripts/verify-local-dependencies.js + + - name: verify peer dependency ranges + run: yarn lint:peer-deps + + - name: check for missing repo fixes + run: yarn fix --check + + - name: validate config + run: yarn backstage-cli config:check --lax + + - name: type checking and declarations + run: yarn tsc:full + + - name: prettier + run: yarn prettier:check + + # We need to generate the API references as well, so that we can verify the doc links + - name: check api reports and generate API reference + run: yarn build:api-reports:only --ci --docs + + - name: verify api reference + run: node scripts/verify-api-reference.js + + - name: verify catalog-info.yaml consistency + run: yarn backstage-repo-tools generate-catalog-info --ci + + - name: lint openapi yaml files + run: yarn backstage-repo-tools repo schema openapi lint + + - name: verify openapi yaml file matches generated ts file + run: yarn backstage-repo-tools repo schema openapi verify + + - name: verify doc links + run: node scripts/verify-links.js + + - name: build all packages + run: yarn backstage-cli repo build --all + + - name: verify type dependencies + run: yarn lint:type-deps + + - name: ensure clean working directory + run: | + if files=$(git ls-files --exclude-standard --others --modified) && [[ -z "$files" ]]; then + exit 0 + else + echo "" + echo "Working directory has been modified:" + echo "" + git status --short + echo "" + exit 1 + fi + + # The test job runs all tests as well as any verification step that + # requires a diff towards master. + test: + runs-on: ubuntu-latest + + needs: install + + strategy: + fail-fast: false + matrix: + node-version: [20.x, 22.x] + + name: Test ${{ matrix.node-version }} + services: + postgres16: + image: postgres:16 + env: + POSTGRES_PASSWORD: postgres + options: >- + --health-cmd pg_isready + --health-interval 10s + --health-timeout 5s + --health-retries 5 + ports: + - 5432/tcp + postgres12: + image: postgres:12 + env: + POSTGRES_PASSWORD: postgres + options: >- + --health-cmd pg_isready + --health-interval 10s + --health-timeout 5s + --health-retries 5 + ports: + - 5432/tcp + mysql8: + image: mysql:8 + env: + MYSQL_ROOT_PASSWORD: root + options: >- + --health-cmd "mysqladmin ping -h localhost" + --health-interval 10s + --health-timeout 5s + --health-retries 5 + ports: + - 3306/tcp + redis: + image: redis:7 + options: >- + --health-cmd "redis-cli ping" + --health-interval 10s + --health-timeout 5s + --health-retries 5 + ports: + - 6379/tcp + + env: + CI: true + NODE_OPTIONS: --max-old-space-size=8192 --no-node-snapshot + INTEGRATION_TEST_GITHUB_TOKEN: ${{ secrets.INTEGRATION_TEST_GITHUB_TOKEN }} + INTEGRATION_TEST_GITLAB_TOKEN: ${{ secrets.INTEGRATION_TEST_GITLAB_TOKEN }} + INTEGRATION_TEST_BITBUCKET_TOKEN: ${{ secrets.INTEGRATION_TEST_BITBUCKET_TOKEN }} + INTEGRATION_TEST_AZURE_TOKEN: ${{ secrets.INTEGRATION_TEST_AZURE_TOKEN }} + + steps: + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + - name: fetch master branch + run: git fetch origin master + + # Need to fetch the base branch to be able to verify the release + - name: fetch base branch + if: github.event.pull_request.base.ref != 'master' + run: git fetch origin ${{ github.event.pull_request.base.ref }} + + - name: use node.js ${{ matrix.node-version }} + uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 + with: + node-version: ${{ matrix.node-version }} + registry-url: https://registry.npmjs.org/ # Needed for auth + + - name: yarn install + uses: backstage/actions/yarn-install@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 + with: + cache-prefix: ${{ runner.os }}-v${{ matrix.node-version }} + + # This check is done here since it needs git history + - name: verify release + run: node scripts/verify-release.js + + # Use the lower-level cache actions for the success cache, so that we can store the cache even on failed builds + - name: restore backstage-cli cache + uses: actions/cache/restore@3624ceb22c1c5a301c8db4169662070a689d9ea8 # v4 + with: + path: .cache/backstage-cli + key: ${{ runner.os }}-v${{ matrix.node-version }}-backstage-cli-${{ github.run_id }} + restore-keys: | + ${{ runner.os }}-v${{ matrix.node-version }}-backstage-cli- + + - name: lint changed packages + run: yarn backstage-cli repo lint --since origin/master --successCache --successCacheDir .cache/backstage-cli + + - name: test changed packages + run: yarn backstage-cli repo test --maxWorkers=3 --workerIdleMemoryLimit=1300M --since origin/master --successCache --successCacheDir .cache/backstage-cli + env: + BACKSTAGE_TEST_DISABLE_DOCKER: 1 + BACKSTAGE_TEST_DATABASE_POSTGRES16_CONNECTION_STRING: postgresql://postgres:postgres@localhost:${{ job.services.postgres16.ports[5432] }} + BACKSTAGE_TEST_DATABASE_POSTGRES12_CONNECTION_STRING: postgresql://postgres:postgres@localhost:${{ job.services.postgres12.ports[5432] }} + BACKSTAGE_TEST_DATABASE_MYSQL8_CONNECTION_STRING: mysql://root:root@localhost:${{ job.services.mysql8.ports[3306] }}/ignored + BACKSTAGE_TEST_CACHE_REDIS7_CONNECTION_STRING: redis://localhost:${{ job.services.redis.ports[6379] }} + + # Always save success cache even if there were failures, that way it can be used in re-triggered builds + - name: save backstage-cli cache + uses: actions/cache/save@3624ceb22c1c5a301c8db4169662070a689d9ea8 # v4 + if: always() + with: + path: .cache/backstage-cli + key: ${{ runner.os }}-v${{ matrix.node-version }}-backstage-cli-${{ github.run_id }} + + # We run the test cases before verifying the specs to prevent any failing tests from causing errors. + - name: verify openapi specs against test cases + run: yarn backstage-repo-tools repo schema openapi test + + - name: ensure clean working directory + run: | + if files=$(git ls-files --exclude-standard --others --modified) && [[ -z "$files" ]]; then + exit 0 + else + echo "" + echo "Working directory has been modified:" + echo "" + git status --short + echo "" + exit 1 + fi diff --git a/.github/workflows/cron.yml b/.github/workflows/cron.yml new file mode 100644 index 0000000000..48ac1db289 --- /dev/null +++ b/.github/workflows/cron.yml @@ -0,0 +1,21 @@ +name: Cron +on: + workflow_dispatch: + schedule: + - cron: '*/5 * * * *' + +jobs: + cron: + runs-on: ubuntu-latest + timeout-minutes: 10 + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - uses: backstage/actions/cron@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 + with: + app-id: ${{ secrets.BACKSTAGE_GOALIE_APPLICATION_ID }} + private-key: ${{ secrets.BACKSTAGE_GOALIE_PRIVATE_KEY }} + installation-id: ${{ secrets.BACKSTAGE_GOALIE_INSTALLATION_ID }} diff --git a/.github/workflows/deploy_docker-image.yml b/.github/workflows/deploy_docker-image.yml new file mode 100644 index 0000000000..4176cb6e80 --- /dev/null +++ b/.github/workflows/deploy_docker-image.yml @@ -0,0 +1,75 @@ +name: Build and push Docker image +on: + workflow_dispatch: + + repository_dispatch: + types: [release-published] + +env: + RELEASE_VERSION: v${{ github.event.client_payload.version }} + TAG_VERSION: ghcr.io/${{ github.repository_owner }}/backstage:${{ github.event.client_payload.version }} + +jobs: + build: + runs-on: ubuntu-latest + + strategy: + fail-fast: false + matrix: + node-version: [20.x] + + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - name: checkout + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + with: + path: backstage + ref: ${{ github.event.client_payload.version && env.RELEASE_VERSION || github.ref }} + + - name: use node.js ${{ matrix.node-version }} + uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 + with: + node-version: ${{ matrix.node-version }} + registry-url: https://registry.npmjs.org/ # Needed for auth + + - name: yarn install + uses: backstage/actions/yarn-install@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 + with: + cache-prefix: ${{ runner.os }}-v${{ matrix.node-version }} + + - name: create-app + run: npx @backstage/create-app + env: + BACKSTAGE_APP_NAME: example-app + YARN_ENABLE_IMMUTABLE_INSTALLS: false + + - name: yarn build + run: yarn build:backend + working-directory: ./example-app + + - name: Login to GitHub Container Registry + uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3.3.0 + with: + registry: ghcr.io + username: ${{ github.actor }} + password: ${{ secrets.GITHUB_TOKEN }} + + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@c47758b77c9736f4b2ef4073d4d51994fabfe349 # v3.7.1 + + - name: Build and push + uses: docker/build-push-action@4f58ea79222b3b9dc2c8bbdd6debcef730109a75 # v6.9.0 + with: + context: './example-app' + file: ./example-app/packages/backend/Dockerfile + push: ${{ (github.event_name == 'repository_dispatch') && (github.event.action == 'release-published') }} + platforms: linux/amd64,linux/arm64 + tags: | + ghcr.io/${{ github.repository_owner }}/backstage:latest + ${{ github.event.client_payload.version && env.TAG_VERSION || '' }} + labels: | + org.opencontainers.image.description=Docker image generated from the latest Backstage release; this contains what you would get out of the box by running npx @backstage/create-app and building a Docker image from the generated source. This is meant to ease the process of evaluating Backstage for the first time, but also has the severe limitation that there is no way to install additional plugins relevant to your infrastructure. diff --git a/.github/workflows/deploy_microsite.yml b/.github/workflows/deploy_microsite.yml new file mode 100644 index 0000000000..291786efd3 --- /dev/null +++ b/.github/workflows/deploy_microsite.yml @@ -0,0 +1,231 @@ +name: Deploy Microsite +on: + push: + branches: + - master + +permissions: + contents: read + +jobs: + stable: + runs-on: ubuntu-latest + concurrency: + group: stable-reference-${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true + + env: + CI: true + NODE_OPTIONS: --max-old-space-size=8192 + + outputs: + release: ${{ steps.find-release.outputs.result }} + + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - name: find latest release + uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7 + id: find-release + with: + script: | + const { data } = await github.rest.repos.listTags({ + owner: context.repo.owner, + repo: context.repo.repo, + per_page: 100, + }) + + const [{tag}] = data + .map(i => i.name) + .filter(tag => tag.match(/^v\d+\.\d+\.\d+$/)) + .map(tag => ({ + tag, + val: tag + .slice(1) + .split('.') + .reduce((val, part) => Number(val) * 1000 + Number(part)) + })) + .sort((a, b) => b.val - a.val) + + return tag + result-encoding: string + + - name: checkout latest release + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + with: + ref: refs/tags/${{ steps.find-release.outputs.result }} + + - name: Use Node.js 20.x + uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 + with: + node-version: 20.x + registry-url: https://registry.npmjs.org/ # Needed for auth + + - name: yarn install + uses: backstage/actions/yarn-install@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 + with: + cache-prefix: ${{ runner.os }}-v20.x + + - name: build API reference + run: yarn build:api-docs + + - name: upload API reference + uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 # v4 + with: + name: stable-reference + path: docs/reference/ + if-no-files-found: error + retention-days: 1 + + next: + runs-on: ubuntu-latest + concurrency: + group: next-reference-${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true + env: + CI: true + NODE_OPTIONS: --max-old-space-size=8192 + + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - name: checkout master + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + + - name: Use Node.js 20.x + uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 + with: + node-version: 20.x + registry-url: https://registry.npmjs.org/ # Needed for auth + + - name: yarn install + uses: backstage/actions/yarn-install@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 + with: + cache-prefix: ${{ runner.os }}-v20.x + + - name: build API reference + run: yarn build:api-docs + + - name: upload API reference + uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 # v4 + with: + name: next-reference + path: docs/reference/ + if-no-files-found: error + retention-days: 1 + + # Also build and upload storybook + - name: storybook yarn install + run: yarn install --immutable + working-directory: storybook + + - name: storybook build + run: yarn build-storybook + working-directory: storybook + + - name: storybook upload + uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 # v4 + with: + name: storybook + path: storybook/dist/ + if-no-files-found: error + retention-days: 1 + + deploy-microsite-and-storybook: + permissions: + contents: write # for JamesIves/github-pages-deploy-action to push changes in repo + + runs-on: ubuntu-latest + + needs: + - stable + - next + + env: + CI: true + NODE_OPTIONS: --max-old-space-size=16384 + DOCUSAURUS_SSR_CONCURRENCY: 5 + + concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true + + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - name: Use Node.js 20.x + uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 + with: + node-version: 20.x + registry-url: https://registry.npmjs.org/ # Needed for auth + + # Stable docs + - name: checkout latest release + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + with: + ref: refs/tags/${{ needs.stable.outputs.release }} + + - name: microsite yarn install + run: yarn install --immutable + working-directory: microsite + + - name: download stable reference + uses: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # v4 + with: + name: stable-reference + path: docs/reference + + - name: grab lastest releases docs + run: | + git fetch origin master --depth 1 + git checkout FETCH_HEAD -- docs/releases + + - name: generate stable docs + run: yarn docusaurus docs:version stable + working-directory: microsite + + - name: clear API reference + run: rm -r docs/reference + + # Next docs + - name: checkout master + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + with: + clean: false + + - name: microsite yarn install + run: yarn install --immutable + working-directory: microsite + + - name: download next reference + uses: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # v4 + with: + name: next-reference + path: docs/reference + + - name: build microsite + run: yarn build + working-directory: microsite + + - uses: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # v4 + with: + name: storybook + path: microsite/build/storybook + + - name: Check the build output + run: ls microsite/build && ls microsite/build/storybook + + - name: Deploy both microsite and storybook to gh-pages + uses: JamesIves/github-pages-deploy-action@881db5376404c5c8d621010bcbec0310b58d5e29 # v4.6.8 + with: + branch: gh-pages + folder: microsite/build diff --git a/.github/workflows/deploy_packages.yml b/.github/workflows/deploy_packages.yml new file mode 100644 index 0000000000..ac2389d95e --- /dev/null +++ b/.github/workflows/deploy_packages.yml @@ -0,0 +1,160 @@ +name: Deploy Packages +on: + push: + branches: [master, patch/*] + +jobs: + build: + runs-on: ubuntu-latest + + outputs: + needs_release: ${{ steps.release_check.outputs.needs_release }} + + strategy: + fail-fast: false + matrix: + node-version: [20.x, 22.x] + + services: + postgres16: + image: postgres:16 + env: + POSTGRES_PASSWORD: postgres + options: >- + --health-cmd pg_isready + --health-interval 10s + --health-timeout 5s + --health-retries 5 + ports: + - 5432/tcp + postgres12: + image: postgres:12 + env: + POSTGRES_PASSWORD: postgres + options: >- + --health-cmd pg_isready + --health-interval 10s + --health-timeout 5s + --health-retries 5 + ports: + - 5432/tcp + mysql8: + image: mysql:8 + env: + MYSQL_ROOT_PASSWORD: root + options: >- + --health-cmd "mysqladmin ping -h localhost" + --health-interval 10s + --health-timeout 5s + --health-retries 5 + ports: + - 3306/tcp + redis: + image: redis:7 + options: >- + --health-cmd "redis-cli ping" + --health-interval 10s + --health-timeout 5s + --health-retries 5 + ports: + - 6379/tcp + + env: + CI: true + NODE_OPTIONS: --max-old-space-size=8192 --no-node-snapshot + INTEGRATION_TEST_GITHUB_TOKEN: ${{ secrets.INTEGRATION_TEST_GITHUB_TOKEN }} + INTEGRATION_TEST_GITLAB_TOKEN: ${{ secrets.INTEGRATION_TEST_GITLAB_TOKEN }} + INTEGRATION_TEST_BITBUCKET_TOKEN: ${{ secrets.INTEGRATION_TEST_BITBUCKET_TOKEN }} + INTEGRATION_TEST_AZURE_TOKEN: ${{ secrets.INTEGRATION_TEST_AZURE_TOKEN }} + + steps: + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + + - name: use node.js ${{ matrix.node-version }} + uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 + with: + node-version: ${{ matrix.node-version }} + registry-url: https://registry.npmjs.org/ # Needed for auth + - name: yarn install + uses: backstage/actions/yarn-install@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 + with: + cache-prefix: ${{ runner.os }}-v${{ matrix.node-version }} + + - name: Fetch previous commit for release check + run: git fetch origin '${{ github.event.before }}' + + - name: Check if release + if: inputs.force_release != true + id: release_check + run: node scripts/check-if-release.js + env: + COMMIT_SHA_BEFORE: '${{ github.event.before }}' + + - name: validate config + run: yarn backstage-cli config:check --lax + + - name: backstage-cli cache + uses: actions/cache@3624ceb22c1c5a301c8db4169662070a689d9ea8 # v4 + with: + path: .cache/backstage-cli + key: ${{ runner.os }}-v${{ matrix.node-version }}-backstage-cli-${{ github.run_id }} + restore-keys: | + ${{ runner.os }}-v${{ matrix.node-version }}-backstage-cli- + + - name: lint + run: yarn backstage-cli repo lint --successCache --successCacheDir .cache/backstage-cli + + - name: type checking and declarations + run: yarn tsc:full + + - name: build + run: yarn backstage-cli repo build --all + + - name: verify type dependencies + run: yarn lint:type-deps + + - name: test (and upload coverage) + run: | + yarn backstage-cli repo test --maxWorkers=3 --workerIdleMemoryLimit=1300M --coverage --successCache --successCacheDir .cache/backstage-cli + env: + BACKSTAGE_TEST_DISABLE_DOCKER: 1 + BACKSTAGE_TEST_DATABASE_POSTGRES16_CONNECTION_STRING: postgresql://postgres:postgres@localhost:${{ job.services.postgres16.ports[5432] }} + BACKSTAGE_TEST_DATABASE_POSTGRES12_CONNECTION_STRING: postgresql://postgres:postgres@localhost:${{ job.services.postgres12.ports[5432] }} + BACKSTAGE_TEST_DATABASE_MYSQL8_CONNECTION_STRING: mysql://root:root@localhost:${{ job.services.mysql8.ports[3306] }}/ignored + BACKSTAGE_TEST_CACHE_REDIS7_CONNECTION_STRING: redis://localhost:${{ job.services.redis.ports[6379] }} + + - name: Discord notification + if: ${{ failure() }} + uses: Ilshidur/action-discord@0c4b27844ba47cb1c7bee539c8eead5284ce9fa9 # 0.3.2 + env: + DISCORD_WEBHOOK: ${{ secrets.DISCORD_WEBHOOK }} + with: + args: 'Master build failed https://github.com/{{GITHUB_REPOSITORY}}/actions/runs/{{GITHUB_RUN_ID}}' + + # A separate release build that is only run for commits that are the result of merging the "Version Packages" PR + # We can't re-use the output from the above step, but we'll have a guaranteed node_modules cache and + # only run the build steps that are necessary for publishing + release: + needs: build + + if: needs.build.outputs.needs_release == 'true' + + runs-on: ubuntu-latest + + strategy: + matrix: + node-version: [20.x] + + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + # Notify maintainers that a new release is ready to be published + - name: Discord notification + uses: Ilshidur/action-discord@0c4b27844ba47cb1c7bee539c8eead5284ce9fa9 # 0.3.2 + env: + DISCORD_WEBHOOK: ${{ secrets.DISCORD_MAINTAINERS_WEBHOOK }} + with: + args: 'A new release is ready to be [published](https://github.com/backstage/publishing/actions/workflows/publish-main.yml) from {{GITHUB_SHA}}' diff --git a/.github/workflows/issue.yaml b/.github/workflows/issue.yaml new file mode 100644 index 0000000000..2cd355b75e --- /dev/null +++ b/.github/workflows/issue.yaml @@ -0,0 +1,31 @@ +name: Issue +on: + issues: + types: [opened] + +permissions: + contents: read + +jobs: + sync: + permissions: + contents: read # for github/issue-labeler to get repo contents + issues: write # for github/issue-labeler to create or remove labels + runs-on: ubuntu-latest + + if: github.repository == 'backstage/backstage' + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - name: Add issue labels + uses: github/issue-labeler@c1b0f9f52a63158c4adc09425e858e87b32e9685 # v3.4 + with: + include-title: 1 + include-body: 0 + configuration-path: .github/issue-labeler.yml + enable-versioned-regex: 0 + not-before: 2024-04-19T15:03:51Z + repo-token: '${{ secrets.GITHUB_TOKEN }}' diff --git a/.github/workflows/pr-review-comment-trigger.yaml b/.github/workflows/pr-review-comment-trigger.yaml new file mode 100644 index 0000000000..9ebfbee3b0 --- /dev/null +++ b/.github/workflows/pr-review-comment-trigger.yaml @@ -0,0 +1,37 @@ +# This workflow is used to trigger the "PR Review Comment" workflow. This chaining is needed +# because workflows triggered by pull_request_review_comment do not have access to secrets. + +name: PR Review Comment Trigger +on: + pull_request_review_comment: + types: + - created + +permissions: + contents: read + +jobs: + trigger: + runs-on: ubuntu-latest + + # The "PR Review Comment" workflow will check the success status of this workflow and only mark + # the PR for re-review if this workflow was successful, which is when the author leaves a review comment. + if: github.repository == 'backstage/backstage' && github.event.comment.user.id == github.event.pull_request.user.id + + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - name: Save PR number + env: + PR_NUMBER: ${{ github.event.pull_request.number }} + run: | + mkdir -p ./pr + echo $PR_NUMBER > ./pr/pr_number + - uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 # v4.4.3 + with: + name: pr_number-${{ github.event.pull_request.number }} + path: pr/ + overwrite: true diff --git a/.github/workflows/pr-review-comment.yaml b/.github/workflows/pr-review-comment.yaml new file mode 100644 index 0000000000..517a978a83 --- /dev/null +++ b/.github/workflows/pr-review-comment.yaml @@ -0,0 +1,49 @@ +# This workflow is triggered by "PR Review Comment Trigger" + +name: PR Review Comment +on: + workflow_run: + workflows: [PR Review Comment Trigger] + types: + - completed + +jobs: + re-review: + runs-on: ubuntu-latest + + # The triggering workflow will report success if the PR needs re-review + if: github.repository == 'backstage/backstage' && github.event.workflow_run.conclusion == 'success' + + steps: + # Inspired by https://docs.github.com/en/actions/using-workflows/events-that-trigger-workflows#using-data-from-the-triggering-workflow + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - name: Read PR Number + id: pr-number + uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1 + with: + github-token: ${{ secrets.GITHUB_TOKEN }} + script: | + const allArtifacts = await github.rest.actions.listWorkflowRunArtifacts({ + owner: context.repo.owner, + repo: context.repo.repo, + run_id: context.payload.workflow_run.id, + }); + const [artifact] = allArtifacts.data.artifacts.filter(artifact => artifact.name.startsWith('pr_number-')) + if (!artifact) { + throw new Error('No PR Number artifact available') + } + + const prNumber = artifact.name.slice('pr_number-'.length) + core.setOutput('pr-number', prNumber); + + - uses: backstage/actions/re-review@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 + with: + app-id: ${{ secrets.BACKSTAGE_GOALIE_APPLICATION_ID }} + private-key: ${{ secrets.BACKSTAGE_GOALIE_PRIVATE_KEY }} + installation-id: ${{ secrets.BACKSTAGE_GOALIE_INSTALLATION_ID }} + project-id: PVT_kwDOBFKqdc02LQ + issue-number: ${{ steps.pr-number.outputs.pr-number }} diff --git a/.github/workflows/pr.yaml b/.github/workflows/pr.yaml new file mode 100644 index 0000000000..7639ac14db --- /dev/null +++ b/.github/workflows/pr.yaml @@ -0,0 +1,34 @@ +name: PR +on: + pull_request_target: + types: + - opened + - synchronize + - reopened + - closed + issue_comment: + types: + - created + +jobs: + sync: + runs-on: ubuntu-latest + + # Avoid running on issue comments + if: github.repository == 'backstage/backstage' && ( github.event.pull_request || github.event.issue.pull_request ) + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - name: PR sync + uses: backstage/actions/pr-sync@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 + with: + github-token: ${{ secrets.GH_SERVICE_ACCOUNT_TOKEN }} + app-id: ${{ secrets.BACKSTAGE_GOALIE_APPLICATION_ID }} + private-key: ${{ secrets.BACKSTAGE_GOALIE_PRIVATE_KEY }} + installation-id: ${{ secrets.BACKSTAGE_GOALIE_INSTALLATION_ID }} + project-id: PVT_kwDOBFKqdc02LQ + auto-assign: false + owning-teams: '@backstage/techdocs-core' diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml new file mode 100644 index 0000000000..a1c643377d --- /dev/null +++ b/.github/workflows/scorecard.yml @@ -0,0 +1,72 @@ +# This workflow uses actions that are not certified by GitHub. They are provided +# by a third-party and are governed by separate terms of service, privacy +# policy, and support documentation. + +name: Scorecard supply-chain security +on: + # For Branch-Protection check. Only the default branch is supported. See + # https://github.com/ossf/scorecard/blob/main/docs/checks.md#branch-protection + # branch_protection_rule: + # To guarantee Maintained check is occasionally updated. See + # https://github.com/ossf/scorecard/blob/main/docs/checks.md#maintained + schedule: + - cron: '41 8 * * 6' + push: + branches: ['master'] + +# Declare default permissions as read only. +permissions: read-all + +jobs: + analysis: + name: Scorecard analysis + runs-on: ubuntu-latest + permissions: + # Needed to upload the results to code-scanning dashboard. + security-events: write + # Needed to publish results and get a badge (see publish_results below). + id-token: write + + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - name: 'Checkout code' + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + with: + persist-credentials: false + + - name: 'Run analysis' + uses: ossf/scorecard-action@dc50aa9510b46c811795eb24b2f1ba02a914e534 # v2.3.3 + with: + results_file: results.sarif + results_format: sarif + # (Optional) "write" PAT token. Uncomment the `repo_token` line below if: + # - you want to enable the Branch-Protection check on a *public* repository, or + # - you are installing Scorecard on a *private* repository + # To create the PAT, follow the steps in https://github.com/ossf/scorecard-action#authentication-with-pat. + # repo_token: ${{ secrets.SCORECARD_TOKEN }} + + # Public repositories: + # - Publish results to OpenSSF REST API for easy access by consumers + # - Allows the repository to include the Scorecard badge. + # - See https://github.com/ossf/scorecard-action#publishing-results. + publish_results: true + + # Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF + # format to the repository Actions tab. + - name: 'Upload artifact' + uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 # v4.4.3 + with: + name: SARIF file + path: results.sarif + retention-days: 5 + overwrite: true + + # Upload the results to GitHub's code scanning dashboard. + - name: 'Upload to code-scanning' + uses: github/codeql-action/upload-sarif@f779452ac5af1c261dce0346a8f964149f49322b # v3.26.13 + with: + sarif_file: results.sarif diff --git a/.github/workflows/sync_code-formatting.yml b/.github/workflows/sync_code-formatting.yml new file mode 100644 index 0000000000..23b3e8cf3f --- /dev/null +++ b/.github/workflows/sync_code-formatting.yml @@ -0,0 +1,40 @@ +name: Sync code formatting +on: + push: + branches: + - master + +jobs: + autofix-markdown: + name: Autofix Markdown files using Prettier + runs-on: ubuntu-latest + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + with: + # Fetch changes to previous commit - required for 'only_changed' in Prettier action + fetch-depth: 0 + + - name: use node.js ${{ matrix.node-version }} + uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 + with: + node-version: ${{ matrix.node-version }} + registry-url: https://registry.npmjs.org/ # Needed for auth + - name: yarn install + uses: backstage/actions/yarn-install@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 + with: + cache-prefix: ${{ runner.os }}-v${{ matrix.node-version }} + + - name: Run Prettier on ADOPTERS.md + uses: creyD/prettier_action@31355f8eef017f8aeba2e0bc09d8502b13dbbad1 # v4.3 + with: + # Modifies commit only if prettier autofixed the ADOPTERS.md + prettier_options: --config docs/prettier.config.js --write ADOPTERS.md + only_changed: true + commit_message: 'Autofix ADOPTERS.md using Prettier' + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/sync_dependabot-changesets.yml b/.github/workflows/sync_dependabot-changesets.yml new file mode 100644 index 0000000000..31db319229 --- /dev/null +++ b/.github/workflows/sync_dependabot-changesets.yml @@ -0,0 +1,83 @@ +name: Sync Dependabot changeset +on: + pull_request_target: + paths: + - '.github/workflows/sync_dependabot-changesets.yml' + - '**/yarn.lock' + +jobs: + generate-changeset: + runs-on: ubuntu-latest + if: github.actor == 'dependabot[bot]' && github.repository == 'backstage/backstage' + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - name: Checkout + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + with: + fetch-depth: 2 + ref: ${{ github.head_ref }} + token: ${{ secrets.GH_SERVICE_ACCOUNT_TOKEN }} + - name: Configure Git + run: | + git config --global user.email noreply@backstage.io + git config --global user.name 'Github changeset workflow' + - name: Generate changeset + uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1 + with: + script: | + const { promises: fs } = require('fs'); + + // Parses package.json files and returns the package names + async function getPackagesNames(files) { + const names = []; + for (const file of files) { + const data = JSON.parse(await fs.readFile(file, 'utf8')); + if (!data.private) { + names.push(data.name); + } + } + return names; + } + + async function createChangeset(fileName, commitMessage, packages) { + const pkgs = packages.map(pkg => `'${pkg}': patch`).join('\n'); + const message = commitMessage.replace(/([bB])ump ([\S]+)/, '$1ump `$2`').trim(); + const body = `---\n${pkgs}\n---\n\n${message}\n`; + await fs.writeFile(fileName, body); + } + + const branch = await exec.getExecOutput('git branch --show-current'); + if (!branch.stdout.startsWith('dependabot/')) { + console.log('Not a dependabot branch, skipping'); + return; + } + + const diffOutput = await exec.getExecOutput('git diff --name-only HEAD~1'); + const diffFiles = diffOutput.stdout.split('\n'); + + if (diffFiles.find(f => f.startsWith('.changeset'))) { + console.log('Changeset already exists, skipping'); + return; + } + + const files = diffFiles + .filter(file => file !== 'package.json') // skip root package.json + .filter(file => file.includes('package.json')); + + const packageNames = await getPackagesNames(files); + if (!packageNames.length) { + console.log('No package.json changes to published packages, skipping'); + return; + } + + const { stdout: shortHash } = await exec.getExecOutput('git rev-parse --short HEAD'); + const fileName = `.changeset/dependabot-${shortHash.trim()}.md`; + const { stdout: commitMessage } = await exec.getExecOutput('git show --pretty=format:%s -s HEAD'); + await createChangeset(fileName, commitMessage, packageNames); + await exec.exec('git', ['add', fileName]); + await exec.exec('git commit -C HEAD --amend --no-edit'); + await exec.exec('git push --force'); diff --git a/.github/workflows/sync_release-manifest.yml b/.github/workflows/sync_release-manifest.yml new file mode 100644 index 0000000000..06e61cc7cd --- /dev/null +++ b/.github/workflows/sync_release-manifest.yml @@ -0,0 +1,89 @@ +name: Sync Release Manifest +on: + repository_dispatch: + types: [release-published] + +jobs: + create-new-version: + runs-on: ubuntu-latest + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - name: Checkout + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + with: + # 'v' prefix is added here for the tag, we keep it out of the manifest logic + ref: v${{ github.event.client_payload.version }} + + - name: Use Node.js 20.x + uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 + with: + node-version: 20.x + registry-url: https://registry.npmjs.org/ # Needed for auth + + - name: yarn install + uses: backstage/actions/yarn-install@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 + with: + cache-prefix: ${{ runner.os }}-v20.x + + - name: Build yarn plugin + working-directory: packages/yarn-plugin + run: yarn build + + # Checkout backstage/versions into /backstage/versions, which is where store the output + - name: Checkout versions + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + with: + repository: backstage/versions + path: versions + token: ${{ secrets.GH_SERVICE_ACCOUNT_TOKEN }} + + - name: Configure Git + run: | + git config --global user.email noreply@backstage.io + git config --global user.name 'Github versions workflow' + + - name: Create release + # This grabs the scripts from master in order to support backfills + run: | + mkdir -p scripts + wget -O scripts/assemble-manifest.js https://raw.githubusercontent.com/backstage/backstage/master/scripts/assemble-manifest.js + node scripts/assemble-manifest.js ${{ github.event.client_payload.version }} + + # Copies the build output of the yarn-plugin package to the appropriate + # directory, allowing the plugin to be installed with a command like + # `yarn plugin import https://versions.backstage.io/v1/tags/main/yarn-plugin` + - name: Add yarn plugin to release + working-directory: packages/yarn-plugin + run: >- + cp + bundles/@yarnpkg/plugin-backstage.js + ../../versions/v1/releases/${{ github.event.client_payload.version }}/yarn-plugin + + - name: Commit to versions repo + working-directory: versions + run: | + git add . + git commit -am "${{ github.event.client_payload.version }}" + git push + + - name: Dispatch update-helper update + uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1 + with: + github-token: ${{ secrets.GH_SERVICE_ACCOUNT_TOKEN }} + # TODO(Rugvip): Remove the create-app dispatch once we've been on the release version for a while + script: | + console.log('Dispatching upgrade helper sync'); + await github.rest.actions.createWorkflowDispatch({ + owner: 'backstage', + repo: 'upgrade-helper-diff', + workflow_id: 'release.yml', + ref: 'master', + inputs: { + version: require('./packages/create-app/package.json').version, + releaseVersion: require('./package.json').version + }, + }); diff --git a/.github/workflows/sync_renovate-changesets.yml b/.github/workflows/sync_renovate-changesets.yml new file mode 100644 index 0000000000..9331dbdb05 --- /dev/null +++ b/.github/workflows/sync_renovate-changesets.yml @@ -0,0 +1,102 @@ +name: Sync Renovate changeset +on: + pull_request_target: + paths: + - '.github/workflows/sync_renovate-changesets.yml' + - '**/yarn.lock' + +jobs: + generate-changeset: + runs-on: ubuntu-latest + if: github.actor == 'renovate[bot]' && github.repository == 'backstage/backstage' + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - name: Checkout + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + with: + fetch-depth: 2 + ref: ${{ github.head_ref }} + token: ${{ secrets.GH_SERVICE_ACCOUNT_TOKEN }} + - name: Configure Git + run: | + git config --global user.email noreply@backstage.io + git config --global user.name 'Github changeset workflow' + - name: Generate changeset + uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1 + with: + script: | + const { promises: fs } = require("fs"); + // Parses package.json files and returns the package names + async function getPackagesNames(files) { + const names = []; + for (const file of files) { + const data = JSON.parse(await fs.readFile(file, "utf8")); + if (!data.private) { + names.push(data.name); + } + } + return names; + } + + async function createChangeset(fileName, packageBumps, packages) { + let message = ""; + for (const [pkg, bump] of packageBumps) { + message = message + `Updated dependency \`${pkg}\` to \`${bump}\`.\n`; + } + + const pkgs = packages.map((pkg) => `'${pkg}': patch`).join("\n"); + const body = `---\n${pkgs}\n---\n\n${message.trim()}\n`; + await fs.writeFile(fileName, body); + } + + async function getBumps(files) { + const bumps = new Map(); + for (const file of files) { + const { stdout: changes } = await exec.getExecOutput("git", [ + "show", + file, + ]); + for (const change of changes.split("\n")) { + if (!change.startsWith("+ ")) { + continue; + } + const match = change.match(/"(.*?)"/g); + bumps.set(match[0].replace(/"/g, ""), match[1].replace(/"/g, "")); + } + } + return bumps; + } + + const branch = await exec.getExecOutput("git branch --show-current"); + if (!branch.stdout.startsWith("renovate/")) { + console.log("Not a renovate branch, skipping"); + return; + } + const diffOutput = await exec.getExecOutput("git diff --name-only HEAD~1"); + const diffFiles = diffOutput.stdout.split("\n"); + if (diffFiles.find((f) => f.startsWith(".changeset"))) { + console.log("Changeset already exists, skipping"); + return; + } + const files = diffFiles + .filter((file) => file !== "package.json") // skip root package.json + .filter((file) => file.includes("package.json")); + const packageNames = await getPackagesNames(files); + if (!packageNames.length) { + console.log("No package.json changes to published packages, skipping"); + return; + } + const { stdout: shortHash } = await exec.getExecOutput( + "git rev-parse --short HEAD" + ); + const fileName = `.changeset/renovate-${shortHash.trim()}.md`; + + const packageBumps = await getBumps(files); + await createChangeset(fileName, packageBumps, packageNames); + await exec.exec("git", ["add", fileName]); + await exec.exec("git commit -C HEAD --amend --no-edit"); + await exec.exec("git push --force"); diff --git a/.github/workflows/sync_snyk-github-issues.yml b/.github/workflows/sync_snyk-github-issues.yml new file mode 100644 index 0000000000..b51036f542 --- /dev/null +++ b/.github/workflows/sync_snyk-github-issues.yml @@ -0,0 +1,48 @@ +name: Sync Snyk GitHub issues +on: + workflow_dispatch: + schedule: + - cron: '0 */4 * * *' + +jobs: + sync: + if: github.repository == 'backstage/backstage' # prevent running on forks + + runs-on: ubuntu-latest + + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + + - name: Use Node.js 20.x + uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 + with: + node-version: 20.x + registry-url: https://registry.npmjs.org/ # Needed for auth + - name: yarn install + uses: backstage/actions/yarn-install@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 + with: + cache-prefix: ${{ runner.os }}-v20.x + + - name: Create Snyk report + uses: snyk/actions/node@cdb760004ba9ea4d525f2e043745dfe85bb9077e # master + continue-on-error: true # Snyk CLI exits with error when vulnerabilities are found + with: + args: > + --yarn-workspaces + --org=backstage-dgh + --strict-out-of-sync=false + --json-file-output=snyk.json + --debug + json: true + env: + SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} + NODE_OPTIONS: --max-old-space-size=7168 + - name: Update Github issues + run: ./scripts/snyk-github-issue-sync.ts + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/sync_snyk-monitor.yml b/.github/workflows/sync_snyk-monitor.yml new file mode 100644 index 0000000000..c3bdb9b647 --- /dev/null +++ b/.github/workflows/sync_snyk-monitor.yml @@ -0,0 +1,63 @@ +name: Sync Snyk Monitoring +on: + workflow_dispatch: + push: + branches: [master] + paths: + - '.github/workflows/sync_snyk-monitor.yml' + - '**/.snyk' + - '**/package.json' + - 'yarn.lock' + +# This workflow synchronizes the packages in this repo along with policies in +# each .snyk file with the remote state in our snyk org. It allows us to define +# ignore policies in the .snyk files and then have them show up in the snyk web +# UI, and also automatically adds any new packages that are created. + +permissions: + contents: read + +jobs: + sync: + permissions: + contents: read # for actions/checkout to fetch code + security-events: write # for github/codeql-action/upload-sarif to upload SARIF results + runs-on: ubuntu-latest + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + - name: Monitor and Synchronize Snyk Policies + uses: snyk/actions/node@cdb760004ba9ea4d525f2e043745dfe85bb9077e # master + with: + command: monitor + args: > + --yarn-workspaces + --org=backstage-dgh + --strict-out-of-sync=false + --remote-repo-url=https://github.com/backstage/backstage + env: + SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} + NODE_OPTIONS: --max-old-space-size=7168 + + # Above we run the `monitor` command, this runs the `test` command which is + # the one that generates the SARIF report that we can upload to GitHub. + - name: Create Snyk report + uses: snyk/actions/node@cdb760004ba9ea4d525f2e043745dfe85bb9077e # master + continue-on-error: true # To make sure that SARIF upload gets called + with: + args: > + --yarn-workspaces + --org=backstage-dgh + --strict-out-of-sync=false + --sarif-file-output=snyk.sarif + env: + SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} + NODE_OPTIONS: --max-old-space-size=7168 + - name: Upload Snyk report + uses: github/codeql-action/upload-sarif@f779452ac5af1c261dce0346a8f964149f49322b # v3.26.13 + with: + sarif_file: snyk.sarif diff --git a/.github/workflows/sync_version-packages.yml b/.github/workflows/sync_version-packages.yml new file mode 100644 index 0000000000..970a5e0e3f --- /dev/null +++ b/.github/workflows/sync_version-packages.yml @@ -0,0 +1,43 @@ +name: Sync Version Packages PR +on: + push: + branches: + - master + +concurrency: + group: sync-version-packages + cancel-in-progress: true + +jobs: + create-release-pr: + name: Create Changeset PR + runs-on: ubuntu-latest + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + with: + fetch-depth: 20000 + fetch-tags: true + token: ${{ secrets.GH_SERVICE_ACCOUNT_TOKEN }} + - name: Install Dependencies + run: yarn --immutable + - name: Create Release Pull Request + uses: backstage/changesets-action@291bfc1f76d1dcfbf967f5810dc0423592eae09a # v2.3.1 + with: + # Calls out to `changeset version`, but also runs prettier + version: yarn release + env: + GITHUB_TOKEN: ${{ secrets.GH_SERVICE_ACCOUNT_TOKEN }} + HUSKY: '0' + + - name: Discord notification + if: ${{ failure() }} + uses: Ilshidur/action-discord@0c4b27844ba47cb1c7bee539c8eead5284ce9fa9 # 0.3.2 + env: + DISCORD_WEBHOOK: ${{ secrets.DISCORD_WEBHOOK }} + with: + args: 'Version Packages Sync Failed https://github.com/{{GITHUB_REPOSITORY}}/actions/runs/{{GITHUB_RUN_ID}}' diff --git a/.github/workflows/verify_accessibility-noop.yml b/.github/workflows/verify_accessibility-noop.yml new file mode 100644 index 0000000000..37ce3513e9 --- /dev/null +++ b/.github/workflows/verify_accessibility-noop.yml @@ -0,0 +1,33 @@ +# NO-OP placeholder that always passes for other paths +# This is here so that we're able to set the status check as required + +name: Accessibility +on: + pull_request: + branches: [master] + paths-ignore: + - 'lighthouserc.js' + - '.github/workflows/verify_accessibility.yml' + - 'plugins/catalog/src/**' + - 'plugins/catalog-react/src/**' + - 'plugins/techdocs/src/**' + - 'plugins/techdocs-react/src/**' + - 'plugins/scaffolder/src/**' + - 'plugins/scaffolder-react/src/**' + - 'plugins/search/src/**' + - 'plugins/search-react/src/**' + +permissions: + contents: read + +jobs: + noop: + name: Accessibility + runs-on: ubuntu-latest + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - run: echo NOOP diff --git a/.github/workflows/verify_accessibility.yml b/.github/workflows/verify_accessibility.yml new file mode 100644 index 0000000000..04358bc7bb --- /dev/null +++ b/.github/workflows/verify_accessibility.yml @@ -0,0 +1,40 @@ +name: Accessibility +on: + # NOTE: If you change these you must update verify_accessibility-noop.yml as well + pull_request: + branches: [master] + paths: + - 'lighthouserc.js' + - '.github/workflows/verify_accessibility.yml' + - 'plugins/catalog/src/**' + - 'plugins/catalog-react/src/**' + - 'plugins/techdocs/src/**' + - 'plugins/techdocs-react/src/**' + - 'plugins/scaffolder/src/**' + - 'plugins/scaffolder-react/src/**' + - 'plugins/search/src/**' + - 'plugins/search-react/src/**' +jobs: + lhci: + name: Accessibility + runs-on: ubuntu-latest + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + - name: Use Node.js 20.x + uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 + with: + node-version: 20.x + - name: yarn install + uses: backstage/actions/yarn-install@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 + with: + cache-prefix: ${{ runner.os }}-v20.x + - name: run Lighthouse CI + run: | + yarn dlx @lhci/cli@0.11.x autorun + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/verify_codeql.yml b/.github/workflows/verify_codeql.yml new file mode 100644 index 0000000000..af16c5b5af --- /dev/null +++ b/.github/workflows/verify_codeql.yml @@ -0,0 +1,83 @@ +# For most projects, this workflow file will not need changing; you simply need +# to commit it to your repository. +# +# You may wish to alter this file to override the set of languages analyzed, +# or to provide custom queries or build logic. +name: Verify CodeQL + +on: + push: + branches: [master] + pull_request: + # The branches below must be a subset of the branches above + branches: [master] + # https://docs.github.com/en/free-pro-team@latest/github/finding-security-vulnerabilities-and-errors-in-your-code/configuring-code-scanning#scanning-pull-requests + paths-ignore: + - '**/*.md' + - '**/*.yml' + - '**/*.yaml' + schedule: + - cron: '0 8 * * 6' + +permissions: + contents: read + +jobs: + analyze: + permissions: + actions: read # for github/codeql-action/init to get workflow details + contents: read # for actions/checkout to fetch code + security-events: write # for github/codeql-action/autobuild to send a status report + name: Analyze + runs-on: ubuntu-latest + + strategy: + fail-fast: false + matrix: + # Override automatic language detection by changing the below list + # Supported options are ['csharp', 'cpp', 'go', 'java', 'javascript', 'python'] + language: ['javascript'] + # Learn more... + # https://docs.github.com/en/github/finding-security-vulnerabilities-and-errors-in-your-code/configuring-code-scanning#overriding-automatic-language-detection + + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - name: Checkout repository + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + with: + # We must fetch at least the immediate parents so that if this is + # a pull request then we can checkout the head. + fetch-depth: 2 + + # Initializes the CodeQL tools for scanning. + - name: Initialize CodeQL + uses: github/codeql-action/init@f779452ac5af1c261dce0346a8f964149f49322b # v3.26.13 + with: + languages: ${{ matrix.language }} + # If you wish to specify custom queries, you can do so here or in a config file. + # By default, queries listed here will override any specified in a config file. + # Prefix the list here with "+" to use these queries and those in the config file. + # queries: ./path/to/local/query, your-org/your-repo/queries@main + + # Autobuild attempts to build any compiled languages (C/C++, C#, or Java). + # If this step fails, then you should remove it and run the build manually (see below) + - name: Autobuild + uses: github/codeql-action/autobuild@f779452ac5af1c261dce0346a8f964149f49322b # v3.26.13 + + # ℹ️ Command-line programs to run using the OS shell. + # 📚 https://git.io/JvXDl + + # ✏️ If the Autobuild fails above, remove it and uncomment the following three lines + # and modify them (or add more) to build your code if your project + # uses a compiled language + + #- run: | + # make bootstrap + # make release + + - name: Perform CodeQL Analysis + uses: github/codeql-action/analyze@f779452ac5af1c261dce0346a8f964149f49322b # v3.26.13 diff --git a/.github/workflows/verify_docs-quality.yml b/.github/workflows/verify_docs-quality.yml new file mode 100644 index 0000000000..766d289f4c --- /dev/null +++ b/.github/workflows/verify_docs-quality.yml @@ -0,0 +1,35 @@ +name: Verify Docs Quality +on: + pull_request: + branches: [master] + paths: + - '.github/workflows/verify_docs-quality.yml' + - '**.md' + +jobs: + check-all-files: + runs-on: ubuntu-latest + + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + + # Vale does not support file excludes, so we use the script to generate a list of files instead + # The action also does not allow args or a local config file to be passed in, so the files array + # also contains an "--config=.github/vale/config.ini" option + - name: generate vale args + id: generate + run: echo "args=$(node scripts/check-docs-quality.js --ci-args)" >> $GITHUB_OUTPUT + + - name: documentation quality check + uses: errata-ai/vale-action@d89dee975228ae261d22c15adcd03578634d429c # v2.1.1 + with: + # This also contains --config=.github/vale/config.ini ... :/ + files: '${{ steps.generate.outputs.args }}' + version: latest + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/verify_e2e-linux-noop.yml b/.github/workflows/verify_e2e-linux-noop.yml new file mode 100644 index 0000000000..1afcd3fe17 --- /dev/null +++ b/.github/workflows/verify_e2e-linux-noop.yml @@ -0,0 +1,36 @@ +# NO-OP placeholder that always passes for other paths +# This is here so that we're able to set the status check as required + +name: E2E Linux Void +on: + pull_request: + paths: + - '.changeset/**' + - 'contrib/**' + - 'docs/**' + - 'microsite/**' + - 'beps/**' + +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true + +permissions: + contents: read + +jobs: + noop: + runs-on: ubuntu-latest + + strategy: + matrix: + node-version: [20.x, 22.x] + + name: E2E Linux ${{ matrix.node-version }} + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - run: echo NOOP diff --git a/.github/workflows/verify_e2e-linux.yml b/.github/workflows/verify_e2e-linux.yml new file mode 100644 index 0000000000..54d76db295 --- /dev/null +++ b/.github/workflows/verify_e2e-linux.yml @@ -0,0 +1,76 @@ +name: E2E Linux +on: + # NOTE: If you change these you must update verify_e2e-linux-noop.yml as well + pull_request: + paths-ignore: + - '.changeset/**' + - 'contrib/**' + - 'docs/**' + - 'microsite/**' + - 'beps/**' + +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true + +jobs: + build: + runs-on: ubuntu-latest + + services: + postgres: + image: postgres:12 + env: + POSTGRES_USER: postgres + POSTGRES_PASSWORD: postgres + POSTGRES_DB: postgres + ports: + - 5432/tcp + # needed because the postgres container does not provide a healthcheck + options: --health-cmd pg_isready --health-interval 10s --health-timeout 5s --health-retries 5 + + strategy: + fail-fast: false + matrix: + node-version: [20.x, 22.x] + + env: + CI: true + NODE_OPTIONS: --max-old-space-size=8192 --no-node-snapshot + + name: E2E Linux ${{ matrix.node-version }} + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + + - name: Configure Git + run: | + git config --global user.email noreply@backstage.io + git config --global user.name 'GitHub e2e user' + + - name: use node.js ${{ matrix.node-version }} + uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 + with: + node-version: ${{ matrix.node-version }} + registry-url: https://registry.npmjs.org/ # Needed for auth + - name: yarn install + uses: backstage/actions/yarn-install@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 + with: + cache-prefix: ${{ runner.os }}-v${{ matrix.node-version }} + + - run: yarn tsc + - run: yarn backstage-cli repo build + - name: run E2E test + run: | + sudo sysctl fs.inotify.max_user_watches=524288 + yarn e2e-test run + env: + BACKSTAGE_TEST_DISABLE_DOCKER: 1 + POSTGRES_USER: postgres + POSTGRES_PASSWORD: postgres + POSTGRES_HOST: localhost + POSTGRES_PORT: ${{ job.services.postgres.ports[5432] }} diff --git a/.github/workflows/verify_e2e-techdocs.yml b/.github/workflows/verify_e2e-techdocs.yml new file mode 100644 index 0000000000..9aad8e9699 --- /dev/null +++ b/.github/workflows/verify_e2e-techdocs.yml @@ -0,0 +1,59 @@ +name: E2E Techdocs +on: + pull_request: + paths: + - 'yarn.lock' + - '.github/workflows/verify_e2e-techdocs.yml' + - 'packages/techdocs-cli/**' + - 'packages/techdocs-cli-embedded-app/**' + - 'plugins/techdocs/**' + +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true + +permissions: + contents: read + +jobs: + verify: + runs-on: ubuntu-latest + + strategy: + matrix: + node-version: [20.x, 22.x] + + env: + CI: true + NODE_OPTIONS: --max-old-space-size=4096 + + name: Techdocs + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + - uses: actions/setup-python@f677139bbe7f9c59b41e40162b753c062f5d49a3 # v5.2.0 + with: + python-version: '3.9' + + - name: install dependencies + run: yarn install --immutable + + - name: generate types + run: yarn tsc + + - name: build techdocs-cli + working-directory: packages/techdocs-cli + run: yarn build + + - name: Install mkdocs & techdocs-core + run: python -m pip install mkdocs-techdocs-core==1.1.7 mkdocs==1.4.0 + + - name: techdocs-cli e2e test + working-directory: packages/techdocs-cli + run: yarn test:e2e:ci + env: + BACKSTAGE_TEST_DISABLE_DOCKER: 1 diff --git a/.github/workflows/verify_e2e-windows-noop.yml b/.github/workflows/verify_e2e-windows-noop.yml new file mode 100644 index 0000000000..3e415b82c6 --- /dev/null +++ b/.github/workflows/verify_e2e-windows-noop.yml @@ -0,0 +1,32 @@ +# NO-OP placeholder that always passes for other paths +# This is here so that we're able to set the status check as required + +name: E2E Windows Void +on: + pull_request: + paths-ignore: + - 'yarn.lock' + - '.github/workflows/verify_e2e-windows.yml' + - 'packages/cli/**' + - 'packages/e2e-test/**' + - 'packages/create-app/**' + +permissions: + contents: read + +jobs: + noop: + runs-on: windows-2022 + + strategy: + matrix: + node-version: [20.x, 22.x] + + name: E2E Windows ${{ matrix.node-version }} + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - run: echo NOOP diff --git a/.github/workflows/verify_e2e-windows.yml b/.github/workflows/verify_e2e-windows.yml new file mode 100644 index 0000000000..2934874460 --- /dev/null +++ b/.github/workflows/verify_e2e-windows.yml @@ -0,0 +1,91 @@ +# Building on windows is really slow, so this workflow is separate from e2e.yml and only builds on changes +# to the cli itself. They're more likely to introduce issues on windows, compared to changes to core and yarn.lock. + +name: E2E Windows +on: + # NOTE: If you change these you must update verify_e2e-windows-noop.yml as well + pull_request: + paths: + - 'yarn.lock' + - '.github/workflows/verify_e2e-windows.yml' + - 'packages/cli/**' + - 'packages/e2e-test/**' + - 'packages/create-app/**' + +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true + +jobs: + build: + runs-on: windows-2022 + + strategy: + matrix: + node-version: [20.x, 22.x] + + env: + CI: true + NODE_OPTIONS: --max-old-space-size=8192 --no-node-snapshot + + name: E2E Windows ${{ matrix.node-version }} + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + # In order to have the create-app template function as if it was downloaded from NPM + # we need to make sure we checkout files with LF line endings only + - name: Set git to use LF + run: | + git config --global core.autocrlf false + git config --global core.eol lf + + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + + - name: Configure Git + run: | + git config --global user.email noreply@backstage.io + git config --global user.name 'GitHub e2e user' + + - name: use node.js ${{ matrix.node-version }} + uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 + with: + node-version: ${{ matrix.node-version }} + registry-url: https://registry.npmjs.org/ # Needed for auth + + - name: setup python + uses: actions/setup-python@f677139bbe7f9c59b41e40162b753c062f5d49a3 # v5.2.0 + with: + python-version: '3.10' + + - name: Add msbuild to PATH + uses: microsoft/setup-msbuild@6fb02220983dee41ce7ae257b6f4d8f9bf5ed4ce # v2.0.0 + + - name: Setup gyp env + run: | + echo 'GYP_MSVS_VERSION=2022' >> $Env:GITHUB_ENV + echo 'GYP_MSVS_OVERRIDE_PATH=C:\\Dummy' >> $Env:GITHUB_ENV + + - name: Install latest gyp and set node-gyp path + shell: powershell + run: | + npm prefix -g | % {npm config set dev_dir "c:\temp\.gyp2"} + npm prefix -g | % {npm config set node_gyp "$_\node_modules\node-gyp\bin\node-gyp.js"} + + - name: setup chrome + uses: browser-actions/setup-chrome@803ef6dfb4fdf22089c9563225d95e4a515820a0 # latest + + - name: yarn install + uses: backstage/actions/yarn-install@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 + with: + cache-prefix: ${{ runner.os }}-v${{ matrix.node-version }} + + - run: yarn tsc + - run: yarn backstage-cli repo build + - name: run E2E test + run: yarn e2e-test run + env: + DEBUG: zombie + CYPRESS_VERIFY_TIMEOUT: 600000 diff --git a/.github/workflows/verify_fossa.yml b/.github/workflows/verify_fossa.yml new file mode 100644 index 0000000000..e99ad22a9b --- /dev/null +++ b/.github/workflows/verify_fossa.yml @@ -0,0 +1,32 @@ +name: Verify FOSSA +on: + push: + branches: [master] + pull_request: + branches: [master] + +permissions: + contents: read + +jobs: + analyze: + runs-on: ubuntu-latest + + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - name: Checkout + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + + - name: Install Fossa + run: "curl -H 'Cache-Control: no-cache' https://raw.githubusercontent.com/fossas/fossa-cli/master/install.sh | bash" + + - name: Fossa Configure & Analyze + env: + # FOSSA Push-Only API Token + GITHUB_REF: $GITHUB_REF + FOSSA_API_KEY: 9ee7e8893660832a7387dcc32377fb61 + run: node scripts/run-fossa.js diff --git a/.github/workflows/verify_microsite-noop.yml b/.github/workflows/verify_microsite-noop.yml new file mode 100644 index 0000000000..f4c5ea4104 --- /dev/null +++ b/.github/workflows/verify_microsite-noop.yml @@ -0,0 +1,28 @@ +# NO-OP placeholder that always passes for other paths +# This is here so that we're able to set the status check as required + +name: Microsite Void +on: + pull_request: + paths-ignore: + - '.github/workflows/verify_microsite.yml' + - 'microsite/**' + - 'beps/**' + - 'mkdocs.yml' + - 'docs/**' + +permissions: + contents: read + +jobs: + noop: + runs-on: ubuntu-latest + + name: Microsite + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - run: echo NOOP diff --git a/.github/workflows/verify_microsite.yml b/.github/workflows/verify_microsite.yml new file mode 100644 index 0000000000..c0a932b349 --- /dev/null +++ b/.github/workflows/verify_microsite.yml @@ -0,0 +1,68 @@ +name: Microsite +on: + # NOTE: If you change these you must update verify_microsite-noop.yml as well + pull_request: + paths: + - '.github/workflows/verify_microsite.yml' + - 'microsite/**' + - 'beps/**' + - 'mkdocs.yml' + - 'docs/**' + +permissions: + contents: read + +jobs: + build-microsite: + runs-on: ubuntu-latest + + env: + CI: true + NODE_OPTIONS: --max-old-space-size=8192 + DOCUSAURUS_SSR_CONCURRENCY: 5 + + name: Microsite + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + + - name: Use Node.js 20.x + uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 + with: + node-version: 20.x + - uses: actions/setup-python@f677139bbe7f9c59b41e40162b753c062f5d49a3 # v5 + with: + python-version: '3.9' + + - name: Install MkDocs dependencies + run: pip install mkdocs mkdocs-techdocs-core + + # Skip caching of microsite dependencies, it keeps the global cache size + # smaller, which make Windows builds a lot faster for the rest of the project. + - name: top-level install + run: yarn install --immutable + + - name: yarn install + run: yarn install --immutable + working-directory: microsite + + - name: build API reference + run: yarn build:api-docs + + - name: Build MkDocs for TechDocs + run: mkdocs build --strict + + - name: verify yarn dependency duplicates + run: node scripts/verify-lockfile-duplicates.js + + - name: prettier + run: yarn prettier:check + working-directory: microsite + + - name: build microsite + run: yarn build + working-directory: microsite diff --git a/.github/workflows/verify_microsite_accessibility-noop.yml b/.github/workflows/verify_microsite_accessibility-noop.yml new file mode 100644 index 0000000000..49721e7f51 --- /dev/null +++ b/.github/workflows/verify_microsite_accessibility-noop.yml @@ -0,0 +1,31 @@ +# NO-OP placeholder that always passes for other paths +# This is here so that we're able to set the status check as required + +name: Microsite Accessibility +on: + pull_request: + branches: [master] + paths-ignore: + - '.github/workflows/verify_microsite_accessibility.yml' + - 'microsite/scripts/**' + - 'microsite/src/**' + - 'microsite/data/**' + - 'microsite/blog/**' + - 'microsite/static/**' + - 'beps/**' + - 'mkdocs.yml' + - 'docs/**' +permissions: + contents: read + +jobs: + noop: + name: Microsite Accessibility + runs-on: ubuntu-latest + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - run: echo NOOP diff --git a/.github/workflows/verify_microsite_accessibility.yml b/.github/workflows/verify_microsite_accessibility.yml new file mode 100644 index 0000000000..91533bd7d8 --- /dev/null +++ b/.github/workflows/verify_microsite_accessibility.yml @@ -0,0 +1,40 @@ +name: Microsite Accessibility +on: + # NOTE: If you change these you must update verify_microsite_accessibility-noop.yml as well + pull_request: + branches: [master] + paths: + - '.github/workflows/verify_microsite_accessibility.yml' + - 'microsite/**' + - 'beps/**' + - 'mkdocs.yml' + - 'docs/**' +jobs: + lhci: + name: Microsite Accessibility + runs-on: ubuntu-latest + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + + - name: Use Node.js 20.x + uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 + with: + node-version: 20.x + + - name: top-level install + run: yarn install --immutable + + - name: yarn install + run: yarn install --immutable + working-directory: microsite + + - name: run Lighthouse CI + run: | + yarn dlx @lhci/cli@0.11.x --config=microsite/lighthouserc.js autorun + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/verify_storybook-noop.yml b/.github/workflows/verify_storybook-noop.yml new file mode 100644 index 0000000000..115c79c9c3 --- /dev/null +++ b/.github/workflows/verify_storybook-noop.yml @@ -0,0 +1,35 @@ +# NO-OP placeholder that always passes for other paths +# This is here so that we're able to set the status check as required + +name: Storybook Void +on: + pull_request: + paths-ignore: + - '.github/workflows/verify_storybook.yml' + - 'storybook/**' + - 'packages/config/src/**' + - 'packages/theme/src/**' + - 'packages/types/src/**' + - 'packages/errors/src/**' + - 'packages/version-bridge/src/**' + - 'packages/test-utils/src/**' + - 'packages/core-app-api/src/**' + - 'packages/core-plugin-api/src/**' + - 'packages/core-components/src/**' + - '**/*.stories.tsx' + +permissions: + contents: read + +jobs: + noop: + runs-on: ubuntu-latest + + name: Storybook + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - run: echo NOOP diff --git a/.github/workflows/verify_storybook.yml b/.github/workflows/verify_storybook.yml new file mode 100644 index 0000000000..8fd3f17ee4 --- /dev/null +++ b/.github/workflows/verify_storybook.yml @@ -0,0 +1,61 @@ +name: Storybook +on: + # NOTE: If you change these you must update verify_storybook-noop.yml as well + pull_request: + paths: + - '.github/workflows/verify_storybook.yml' + - 'storybook/**' + - 'packages/config/src/**' + - 'packages/theme/src/**' + - 'packages/types/src/**' + - 'packages/errors/src/**' + - 'packages/version-bridge/src/**' + - 'packages/test-utils/src/**' + - 'packages/core-app-api/src/**' + - 'packages/core-plugin-api/src/**' + - 'packages/core-components/src/**' + - '**/*.stories.tsx' + +jobs: + chromatic: + runs-on: ${{ matrix.os }} + + strategy: + matrix: + os: [ubuntu-latest] + node-version: [20.x] + + name: Storybook + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + with: + fetch-depth: 0 # Required to retrieve git history + + - name: use node.js ${{ matrix.node-version }} + uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 + with: + node-version: ${{ matrix.node-version }} + registry-url: https://registry.npmjs.org/ # Needed for auth + - name: yarn install + uses: backstage/actions/yarn-install@25145dd4117d50e1da9330e9ed2893bc6b75373e # v0.6.15 + with: + cache-prefix: ${{ runner.os }}-v${{ matrix.node-version }} + - name: storybook yarn install + run: yarn install --immutable + working-directory: storybook + + - run: yarn build-storybook + + - uses: chromaui/action@25f8ff36486472c2d6b5b02dc2d277f051a3ecdb # v11 + with: + token: ${{ secrets.GITHUB_TOKEN }} + # projectToken intentionally shared to allow collaborators to run Chromatic on forks + # https://www.chromatic.com/docs/custom-ci-provider#run-chromatic-on-external-forks-of-open-source-projects + projectToken: 9tzak77m9nj + workingDir: storybook + storybookBuildDir: dist diff --git a/.github/workflows/verify_windows.yml b/.github/workflows/verify_windows.yml new file mode 100644 index 0000000000..4f8afe5530 --- /dev/null +++ b/.github/workflows/verify_windows.yml @@ -0,0 +1,71 @@ +name: Verify Master Branch on Windows +on: + workflow_dispatch: + push: + branches: [master] + pull_request: + paths: + - '.github/workflows/verify_windows.yml' + +permissions: + contents: read + +jobs: + build: + runs-on: windows-2022 + + strategy: + fail-fast: false + matrix: + node-version: [20.x, 22.x] + + env: + CI: true + NODE_OPTIONS: --max-old-space-size=8192 --no-node-snapshot + INTEGRATION_TEST_GITHUB_TOKEN: ${{ secrets.INTEGRATION_TEST_GITHUB_TOKEN }} + INTEGRATION_TEST_GITLAB_TOKEN: ${{ secrets.INTEGRATION_TEST_GITLAB_TOKEN }} + INTEGRATION_TEST_BITBUCKET_TOKEN: ${{ secrets.INTEGRATION_TEST_BITBUCKET_TOKEN }} + INTEGRATION_TEST_AZURE_TOKEN: ${{ secrets.INTEGRATION_TEST_AZURE_TOKEN }} + + steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + + - name: use node.js ${{ matrix.node-version }} + uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4 + with: + node-version: ${{ matrix.node-version }} + registry-url: https://registry.npmjs.org/ # Needed for auth + + # Windows file operation slowness means there's no point caching this + - name: yarn install + run: yarn install --immutable + + - name: lint + run: yarn backstage-cli repo lint --successCache + + - name: type checking and declarations + run: yarn tsc:full + + - name: verify type dependencies + run: yarn lint:type-deps + + - name: test + run: yarn backstage-cli repo test --maxWorkers=3 --workerIdleMemoryLimit=1300M --successCache + env: + BACKSTAGE_TEST_DISABLE_DOCKER: 1 + + # credit: https://github.com/appleboy/discord-action/issues/3#issuecomment-731426861 + - name: Discord notification + if: ${{ failure() }} + env: + DISCORD_WEBHOOK: ${{ secrets.DISCORD_WEBHOOK }} + run: | + $MESSAGE=@" + {\"content\": \"Windows master build failed https://github.com/${{github.repository}}/actions/runs/${{github.run_id}}\"} + "@ + C:\msys64\usr\bin\curl.exe -i -H "Accept: application/json" -H "Content-Type:application/json" -X POST $env:DISCORD_WEBHOOK --data $MESSAGE