workflows#
Check .github/workflows folder content.
- copy_workflow_file(session: Session, /, *, filename: str, repository: str | None = None) None[source]#
Install a workflow that is copied verbatim from the policy templates.
- preserve_action_versions(expected: str, existing: str) str[source]#
Restore the GitHub Action references that a repository already uses.
Policy-managed workflows own their structure, but not the versions of the actions they call: a downstream repository may pin an action to the immutable commit SHA of an exact release, and that pin has to survive the next policy run. Each
uses:reference in expected is therefore replaced by the reference that the same action has in existing — matched on the action name in front of the@, and by order of appearance when one action is used several times.>>> expected = "jobs:\n build:\n steps:\n - uses: actions/checkout@v7\n" >>> existing = " - uses: actions/checkout@3d3c42e # v7.0.1\n" >>> print(preserve_action_versions(expected, existing), end="") jobs: build: steps: - uses: actions/checkout@3d3c42e # v7.0.1
An action that the repository does not call yet keeps the template version:
>>> print(preserve_action_versions(" - uses: actions/setup-uv@v7\n", existing)) - uses: actions/setup-uv@v7
- resolve_self_references(workflow: str, repository: str) str[source]#
Resolve references to the current repository at the workflow commit.
>>> resolve_self_references( ... " uses: ComPWA/actions/.github/workflows/ci.yml@v4.0\n", ... "ComPWA/actions", ... ) ' uses: $/.github/workflows/ci.yml\n' >>> resolve_self_references( ... " uses: ComPWA/actions/clean-caches@v4\n", ... "ComPWA/policy", ... ) ' uses: ComPWA/actions/clean-caches@v4\n'