--- name: PR Comment Trigger on: issue_comment: types: [created] # Permissions are granted per-job below; anything unlisted defaults to none permissions: {} jobs: handle-comment: if: github.event.issue.pull_request runs-on: ubuntu-latest permissions: contents: read outputs: should-deploy: ${{ steps.check-org.outputs.result }} steps: - name: Check if bot is mentioned id: check-mention env: COMMENT: ${{ github.event.comment.body }} run: | if [[ "$COMMENT" == *"@github-actions"* ]] || \ [[ "$COMMENT" == *"github-actions[bot]"* ]]; then bot_mentioned=true else bot_mentioned=false fi if [[ "$COMMENT" == *"ota"* ]]; then has_ota=true else has_ota=false fi if [[ "$bot_mentioned" == "true" ]] && [[ "$has_ota" == "true" ]]; then echo "mentioned=true" >> $GITHUB_OUTPUT else echo "mentioned=false" >> $GITHUB_OUTPUT fi - name: Check commenter has write access if: steps.check-mention.outputs.mentioned == 'true' id: check-org uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 with: script: | try { const { data: perm } = await github.rest.repos.getCollaboratorPermissionLevel({ owner: context.repo.owner, repo: context.repo.repo, username: context.payload.comment.user.login }); const hasAccess = ['admin', 'write'].includes(perm.permission); console.log(`User has ${perm.permission} access`); return hasAccess; } catch(error) { console.log('User has no repository access'); return false; } bundle-deploy: name: Bundle and Deploy EAS Update runs-on: ubuntu-latest needs: [handle-comment] if: needs.handle-comment.outputs.should-deploy == 'true' permissions: contents: read pull-requests: write steps: - name: Get PR HEAD SHA env: ISSUE_NUMBER: ${{ github.event.issue.number }} id: pr-info uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 with: script: | const pr = await github.rest.pulls.get({ owner: context.repo.owner, repo: context.repo.repo, pull_number: process.env.ISSUE_NUMBER, }); // This workflow runs with repo secrets in scope, so never build // code from a fork: the commenter authorizes the deploy, but a // fork controls what code would run during it const expected = `${context.repo.owner}/${context.repo.repo}`; const head = pr.data.head.repo?.full_name; if (head !== expected) { core.setFailed(`OTA deploys are only allowed for branches in ${expected}, not forks (got ${head})`); return; } console.log(`PR HEAD SHA: ${pr.data.head.sha}`); console.log(`PR HEAD REF: ${pr.data.head.ref}`); core.setOutput('head-sha', pr.data.head.sha); core.setOutput('head-ref', pr.data.head.ref); - name: 💬 Drop a comment uses: marocchino/sticky-pull-request-comment@0ea0beb66eb9baf113663a64ec522f60e49231c0 # v3.0.4 with: header: pull-request-eas-build-${{ steps.pr-info.outputs.head-sha }} number: ${{ github.event.issue.number }} message: | An OTA deployment has been requested and is now running for `${{ steps.pr-info.outputs.head-sha }}`. [Here is some music to listen to while you wait...](https://www.youtube.com/watch?v=VBlFHuCzPgY) --- *Generated by [PR labeler](https://github.com/expo/expo/actions/workflows/pr-labeler.yml) 🤖* - name: Check for EXPO_TOKEN run: > if [ -z "${{ secrets.EXPO_TOKEN }}" ]; then echo "You must provide an EXPO_TOKEN secret linked to this project's Expo account in this repo's secrets. Learn more: https://docs.expo.dev/eas-update/github-actions" exit 1 fi - name: ⬇️ Checkout uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 with: ref: ${{ steps.pr-info.outputs.head-sha }} - uses: pnpm/action-setup@0ebf47130e4866e96fce0953f49152a61190b271 # v6.0.9 - name: 🔧 Setup Node uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 with: node-version-file: package.json cache: pnpm - name: Install dependencies run: pnpm install --frozen-lockfile - name: 🔤 Compile translations run: pnpm intl:build 2>&1 | tee i18n.log - name: Check for i18n compilation errors run: if grep -q "invalid syntax" "i18n.log"; then echo "\n\nFound compilation errors!\n\n" && exit 1; else echo "\n\nNo compilation errors!\n\n"; fi - name: Lint check run: pnpm lint - name: Type check run: pnpm typecheck - name: 🔨 Setup EAS uses: expo/expo-github-action@eab7a230208c952974db8c3245cfd78402c7b385 # 9.0.0 with: eas-version: '19.0.5' packager: 'pnpm --allow-build=dtrace-provider' token: ${{ secrets.EXPO_TOKEN }} - name: 🪛 Setup jq uses: dcarbone/install-jq-action@4fcb5062d7ce9bc4382d1a352d19ba3ba2c317c1 # v4.0.1 - name: Env id: env run: | export json='${{ secrets.GOOGLE_SERVICES_TOKEN }}' echo "${{ secrets.ENV_TOKEN }}" > .env echo "EXPO_PUBLIC_ENV=testflight" >> .env echo "EXPO_PUBLIC_RELEASE_VERSION=$(jq -r '.version' package.json)" >> .env echo "EXPO_PUBLIC_RELEASE_VERSION=$(jq -r '.version' package.json)" >> $GITHUB_OUTPUT echo "EXPO_PUBLIC_BUNDLE_IDENTIFIER=$(git rev-parse HEAD)" >> .env echo "EXPO_PUBLIC_BUNDLE_IDENTIFIER=$(git rev-parse HEAD)" >> $GITHUB_OUTPUT echo "EXPO_PUBLIC_BUNDLE_DATE=$(date -u +"%y%m%d%H")" >> .env echo "EXPO_PUBLIC_SENTRY_DSN=${{ secrets.SENTRY_DSN }}" >> .env echo "EXPO_PUBLIC_BITDRIFT_API_KEY=${{ secrets.BITDRIFT_API_KEY }}" >> .env echo "EXPO_PUBLIC_GCP_PROJECT_ID=${{ secrets.EXPO_PUBLIC_GCP_PROJECT_ID }}" >> .env echo "$json" > google-services.json - name: 🏗️ Create Bundle run: > SENTRY_AUTH_TOKEN=${{ secrets.SENTRY_AUTH_TOKEN }} SENTRY_RELEASE=${{ steps.env.outputs.EXPO_PUBLIC_RELEASE_VERSION }} SENTRY_DIST=${{ steps.env.outputs.EXPO_PUBLIC_BUNDLE_IDENTIFIER }} pnpm export - name: 📦 Package Bundle and 🚀 Deploy run: pnpm use-build-number bash scripts/bundleUpdate.sh env: DENIS_API_KEY: ${{ secrets.DENIS_API_KEY }} CHANNEL_NAME: pull-request-${{ github.event.issue.number }} RUNTIME_VERSION: - name: 💬 Drop a comment uses: marocchino/sticky-pull-request-comment@0ea0beb66eb9baf113663a64ec522f60e49231c0 # v3.0.4 env: ISSUE_NUMBER: ${{ github.event.issue.number }} with: header: pull-request-eas-build-${{ steps.pr-info.outputs.head-sha }} number: ${{ github.event.issue.number }} message: | Your requested OTA deployment was successful! You may now apply it by either scanning the QR code or opening the deep link below in your browser: `bluesky://intent/apply-ota?channel=pull-request-${{ github.event.issue.number }}` --- *Generated by [PR labeler](https://github.com/expo/expo/actions/workflows/pr-labeler.yml) 🤖* - name: 💬 Drop a comment uses: marocchino/sticky-pull-request-comment@0ea0beb66eb9baf113663a64ec522f60e49231c0 # v3.0.4 if: failure() with: header: pull-request-eas-build-${{ steps.pr-info.outputs.head-sha }} number: ${{ github.event.issue.number }} message: | Your requested OTA deployment was unsuccessful. See action logs for more details. --- *Generated by [PR labeler](https://github.com/expo/expo/actions/workflows/pr-labeler.yml) 🤖*