mirror of
https://github.com/tiennm99/awesome-ai-dev-tools.git
synced 2026-10-05 16:13:56 +00:00
The CI failure on the merge commit was the one-time bootstrap ordering problem: `go run . -build` ran before any data/metadata.json existed. The nightly updater has since committed one, so the tree builds — but that commit was pushed with GITHUB_TOKEN, which by design does not re-trigger workflows, so CI never re-ran and main's status stayed red. That exposes a standing gap rather than a one-off: every nightly refresh commits the exact data the build consumes, and none of those commits run CI. A refresh that broke the build would first be noticed by Cloudflare at deploy time. Run `go run . -build` in the update workflow between the fetch and the commit, so data that does not build is never committed. Add workflow_dispatch to CI so a bot-pushed commit can still be verified on demand.
94 lines
3.7 KiB
YAML
94 lines
3.7 KiB
YAML
name: Update rankings
|
|
|
|
on:
|
|
schedule:
|
|
- cron: '0 0 * * *'
|
|
workflow_dispatch:
|
|
push:
|
|
branches: [main]
|
|
paths:
|
|
- 'data/agents.yml'
|
|
- 'templates/**'
|
|
- '**.go'
|
|
- 'go.mod'
|
|
- '.github/workflows/update.yml'
|
|
|
|
permissions:
|
|
# Uses GITHUB_TOKEN intentionally — a PAT would cause infinite trigger loops
|
|
# on the auto-commit ("chore: daily ranking refresh") because GITHUB_TOKEN-authored
|
|
# pushes do NOT re-trigger workflows, whereas a PAT would.
|
|
#
|
|
# This job only refreshes data. Publishing is Cloudflare Pages' job: it builds
|
|
# from the commit this job pushes (webhook-driven, so the GITHUB_TOKEN caveat
|
|
# above does not apply to it) by running `go run . -build`, which needs no token.
|
|
contents: write
|
|
|
|
concurrency:
|
|
group: update-rankings
|
|
cancel-in-progress: false
|
|
|
|
jobs:
|
|
update:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
|
|
- uses: actions/setup-go@v7
|
|
with:
|
|
go-version: 'stable'
|
|
cache: true
|
|
|
|
# The only step that touches the network or needs a token. It refreshes
|
|
# README.md, data/history.jsonl and data/metadata.json; rendering the
|
|
# site from those files happens later, on Cloudflare.
|
|
- name: Run updater
|
|
env:
|
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
run: go run .
|
|
|
|
# Bot commits are pushed with GITHUB_TOKEN, which by design does not
|
|
# re-trigger workflows — so CI never runs on them. Without this step a
|
|
# refresh that broke the build would be discovered by Cloudflare at deploy
|
|
# time. Running the build before the commit means unbuildable data is
|
|
# never committed in the first place.
|
|
- name: Verify the committed data builds
|
|
run: go run . -build
|
|
|
|
- name: Commit changes
|
|
run: |
|
|
git config user.name "github-actions[bot]"
|
|
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
|
|
git add README.md data/history.jsonl data/metadata.json
|
|
if git diff --staged --quiet; then
|
|
echo "no changes"
|
|
exit 0
|
|
fi
|
|
git commit -m "chore: daily ranking refresh"
|
|
# Rebase + retry guards against the race where two runs commit near-simultaneously.
|
|
# Strategy: plain rebase first; only force-resolve bot-generated files (README.md,
|
|
# data/history.jsonl, data/metadata.json) when they are the sole conflicts. If any human-maintained file
|
|
# (e.g. data/agents.yml) conflicts, abort and fail loudly so a human can investigate.
|
|
for attempt in 1 2 3; do
|
|
if git push; then exit 0; fi
|
|
echo "push attempt $attempt rejected, rebasing on origin/main"
|
|
if git pull --rebase origin main; then
|
|
# Clean rebase — no conflicts; loop back to try push again.
|
|
continue
|
|
fi
|
|
# Rebase stopped on conflicts. Inspect which files are unresolved.
|
|
conflicted=$(git diff --name-only --diff-filter=U)
|
|
echo "conflicted files: $conflicted"
|
|
# Only auto-resolve if ALL conflicts are in bot-generated files.
|
|
non_bot=$(echo "$conflicted" | grep -v -E '^(README\.md|data/history\.jsonl|data/metadata\.json)$' || true)
|
|
if [ -n "$non_bot" ]; then
|
|
echo "ERROR: conflict in human-maintained file(s): $non_bot — aborting rebase"
|
|
git rebase --abort
|
|
exit 1
|
|
fi
|
|
# Safe to force-resolve: keep our (freshest) bot-generated content.
|
|
git checkout --theirs README.md data/history.jsonl data/metadata.json 2>/dev/null || true
|
|
git add README.md data/history.jsonl data/metadata.json
|
|
GIT_EDITOR=true git rebase --continue
|
|
done
|
|
exit 1
|