Commit Graph

31 Commits

Author SHA1 Message Date
Austin McKinley 519293d4d0 ci: gate per-PR OTA on the fork guard, not author_association
The author_association check skipped the job for private org members:
the pull_request webhook payload exposes only the public-safe association,
which downgrades a private member to CONTRIBUTOR/NONE, so MEMBER never
matched and no staff PR could publish.

Drop that clause and rely on the fork guard alone. A branch can only exist
in this repo if someone with write access pushed it, so an outside
contributor (fork-only) never runs this job; same-repo PRs are staff-
authored. This matches the fork-guard gate the other jobs in this workflow
already use.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-22 16:02:15 -07:00
Austin McKinley c5093818ae ci: publish OTA bundles to denis (S3) + automatic per-PR previews
Rewire OTA publishing off the legacy ota1 box onto the S3-backed denis
service, in two places:

- Prod path (bundle-deploy-eas-update.yml): dual-write the exported bundle
  to denis via `denis publish` alongside the existing ota1 upload, under the
  identical `!includes-changes && !version-changed` gate. Assumes the
  main-only `denis-ci-publish` role via OIDC (id-token: write). Both paths
  must succeed; they are removed together once denis is the sole origin.

- Per-PR previews (pull-request-commit.yml): replace the `@github-actions ota`
  comment trigger (pull-request-comment.yml, deleted) with an automatic job
  that fires on pull_request. Gated to same-repo PRs
  (head.repo.full_name == github.repository) authored by a
  MEMBER/OWNER/COLLABORATOR, so a fork or external contributor can never run
  with the publish role or repo secrets in scope. Publishes to the
  `pull-request-<N>` channel under the PR-scoped `denis-ci-publish-pr` role,
  further narrowed by an inline session policy to `pr/<N>/*`.

- setup-denis composite action: mint a short-lived github-app token
  (contents:read on private tango), download + verify the pinned
  denis release binary, put it on PATH.

denis release tag is a single `DENIS_RELEASE_TAG` env per workflow.

ROAST_SKIP: pre-commit roast flags setup-denis verifying the binary against
a checksum from the same tango release (no independent digest anchor).
Reviewed and accepted: exploitation requires compromising the private tango
release itself, and the marginal integrity gain is not worth pinning a digest
that must be bumped on every denis roll.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-22 12:50:12 -07:00
dependabot[bot] 3eab767e89 Bump actions/setup-node from 6.4.0 to 7.0.0 (#11203)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-21 05:08:41 -07:00
Samuel Newman 783dfe2a12 Cache main bundle stats for PR checks (#11172) 2026-07-17 07:28:08 +03:00
dependabot[bot] 19872124bf Bump the actions group with 6 updates (#11148) 2026-07-13 23:48:14 +03:00
Samuel Newman 640662d57c Fix zizmor findings in build workflows (#11046)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-07 04:20:50 -07:00
dependabot[bot] 86c1cbbc95 Bump actions/cache from 5.0.5 to 6.1.0 (#11078)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-07 04:18:26 -07:00
DS Boyce 133476e0cd Update advanced search suggestions (#11036) 2026-06-30 14:26:50 -07:00
DS Boyce 5e7343b0d2 Fix yaml syntax in pull-request-commit.yml (#11037) 2026-06-30 14:15:28 -07:00
Samuel Newman 57dc53fbf5 Add "fingerprint changed" label to PRs with native changes (#10742)
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-30 15:19:24 -05:00
dependabot[bot] de51ceb577 Bump actions/checkout from 6.0.3 to 7.0.0 (#11022)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-30 14:20:43 -05:00
DS Boyce 44f6a98f59 Use latest fingerprint-native action (#11016) 2026-06-30 13:40:37 -05:00
Samuel Newman b8a6a8c8ce Pin every action to latest SHA (#10779)
Co-authored-by: Eric Bailey <git@esb.lol>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-06-16 14:35:19 -05:00
dependabot[bot] a2c8b47b87 Bump marocchino/sticky-pull-request-comment from 2 to 3 (#10692)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-02 11:56:46 -07:00
Samuel Newman 806f31dc93 Use pnpm to handle node/pnpm versions in Dockerfile (#10642) 2026-05-29 05:40:24 -07:00
DS Boyce b4054bf2a7 Update GitHub Actions to Node.js v24-compatible versions (#10539) 2026-05-19 11:06:46 -07:00
Samuel Newman ff731849b0 Migrate from Yarn 1 to pnpm (#10465)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: Eric Bailey <git@esb.lol>
2026-05-18 09:51:04 -07:00
Samuel Newman 80049bbe82 exclude images from bundle size workflow (#9647) 2026-01-07 02:54:59 -08:00
hailey 699fdbac01 update actions (#9586)
* update actions

* update actions

* $

* procenv
2025-12-22 19:21:17 -08:00
Samuel Newman 31fac4a62b Use macos-26-xlarge runner, update actions to resolve caching issues (#9411)
* use xlarge runner for macos build

* try and fix yarn cache

* update actions/cache for pods step

* use expo github action main rather than v8

* update all actions to the same

* use yarn cache where missing
2025-11-20 10:07:38 -08:00
Samuel Newman 36b2a87a06 Skip intl:compile if not needed (#8837)
* skip intl compile if not needed

* add intl:compile to pull request ci

* compile -> build just to match others
2025-08-13 16:58:42 -05:00
Hailey 5ceb440d4e use custom github action for fingerprinting (#4226)
* use custom github action for fingerprinting

* update pr workflow

* update names of workflows

* make a native change (testing)

* adjust the action

* Revert "make a native change (testing)"

This reverts commit 8db9835733.

* update bundle-deploy script

* test a prod build

* crazy depth

* manually set

* use prod default

* force prod

* revert test changes

* save cache after deploy

* revert testing
2024-05-28 16:38:24 -07:00
Hailey c80dcc565e only run labelers for core team (#3426)
* use `pull_request_target` instead of `pull_request`

* adjust

* only run for core team
2024-04-05 08:58:28 -07:00
Hailey 4e59914d2a migrate to 'expo-haptics' (#3418)
* migrate to 'expo-haptics'

* run yarn install twice if necessary
2024-04-04 21:19:38 -07:00
Hailey 2e048706e9 fix comments on prs (#3406)
* fix comments on prs

* remove labels

* remove test
2024-04-04 13:52:38 -07:00
Hailey 8e393b16f5 Simplify list logic further to prevent misuse (#3334)
* simplify list logic further

more simplification

simplify by removing `isEmpty`

use `isFetchingNextPage` everywhere for clarity

change `isFetching` to `isFetchingNextPage` for clarity

remove some useless `useMemo`s

move `renderItem` and `keyExtractor` out of component

* clean bundle size check

* update deploy

* adjust

* adjust

* one test

* try now

* test it

* done
2024-04-03 20:59:33 -07:00
Hailey b1bd7ab6e3 Add webpack analyzer, PR comments for webpack bundle size (#3383)
try that again 9

try that again 8

try that again 7

try that again 6

try that again 5

try that again 4

try that again 3

try that again 2

try that again

merge base 3

merge base 2

merge base

use latest main commit rather than tag

webpack diff analyzer

use cache v4

use cache

again...

blegh

blegh

try cache again

cache

try again

one more adjutment

adjust

okay again maybe

maybe now?

maybe now

oops again

oops

add diff comments

add open analyzer script

add webpack analyzer
2024-04-03 19:31:29 -07:00
Hailey d5ebbeb3fc Use [bot] in action username (#3250) 2024-03-18 09:59:39 -07:00
Hailey 79175e2a09 Fix PR labeler bot comment delete (#3249) 2024-03-18 08:40:43 -07:00
Hailey 98bca69ae9 Adjust PR Labeler (#3224) 2024-03-15 13:42:51 -07:00
Hailey fa8b21cea7 Add package diff PR labeler (#3212)
* add PR labeler

* test cache

* rm change
2024-03-15 12:28:21 -07:00