fix(ci): avoid visual baseline pushes without bot token

This commit is contained in:
Mark IJbema
2026-06-29 12:44:01 +02:00
parent 41c6b5e4e1
commit c311986160
4 changed files with 51 additions and 28 deletions
+47 -28
View File
@@ -11,6 +11,7 @@ jobs:
outputs:
matched: ${{ steps.filter.outputs.matched }}
is_fork: ${{ steps.fork-check.outputs.is_fork }}
can_autocommit: ${{ steps.autocommit-check.outputs.can_autocommit }} # kilocode_change
steps:
- uses: actions/checkout@v6 # kilocode_change
# kilocode_change start
@@ -40,7 +41,19 @@ jobs:
else
echo "is_fork=false" >> "$GITHUB_OUTPUT"
fi
# kilocode_change start
- name: Check baseline auto-commit permissions
id: autocommit-check
env:
BOT_PAT: ${{ secrets.BOT_PAT }}
run: |
if [ "${{ steps.fork-check.outputs.is_fork }}" != "true" ] && [ -n "$BOT_PAT" ]; then
echo "can_autocommit=true" >> "$GITHUB_OUTPUT"
else
echo "can_autocommit=false" >> "$GITHUB_OUTPUT"
fi
# kilocode_change end
# kilocode_change start
visual-regression:
needs: check-paths
if: needs.check-paths.outputs.matched == 'true'
@@ -50,21 +63,22 @@ jobs:
steps:
- name: Checkout (internal)
if: needs.check-paths.outputs.is_fork != 'true'
if: needs.check-paths.outputs.can_autocommit == 'true' # kilocode_change
uses: actions/checkout@v6 # kilocode_change
with:
lfs: true
token: ${{ secrets.BOT_PAT || github.token }} # kilocode_change
# LLM note: use BOT_PAT only when later baseline pushes are allowed; github.token is read-only on Dependabot PRs.
token: ${{ secrets.BOT_PAT }} # kilocode_change
ref: ${{ github.head_ref }}
- name: Checkout (fork)
if: needs.check-paths.outputs.is_fork == 'true'
- name: Checkout (read-only)
if: needs.check-paths.outputs.can_autocommit != 'true' # kilocode_change
uses: actions/checkout@v6 # kilocode_change
with:
lfs: true
- name: Check if HEAD is a baseline update commit
if: needs.check-paths.outputs.is_fork != 'true'
if: needs.check-paths.outputs.can_autocommit == 'true' # kilocode_change
id: check-baseline-commit
run: |
COMMIT_MSG=$(git log -1 --format=%s)
@@ -74,6 +88,7 @@ jobs:
else
echo "is_baseline_update=false" >> "$GITHUB_OUTPUT"
fi
# kilocode_change end
- name: Setup Bun
uses: oven-sh/setup-bun@v2
@@ -143,23 +158,23 @@ jobs:
}
"
working-directory: packages/kilo-ui
- name: Check for baseline changes (fork PRs)
if: needs.check-paths.outputs.is_fork == 'true'
# kilocode_change start
- name: Check for baseline changes (read-only PRs)
if: needs.check-paths.outputs.can_autocommit != 'true' # kilocode_change
run: |
git add packages/kilo-docs/public/img/screenshot-tests/kilo-ui/
if git diff --cached --quiet; then
echo "No visual regression detected."
else
echo "::error::Visual regression detected. Screenshot baselines have changed."
echo "::error::Since this PR is from a fork, updated screenshots cannot be committed automatically."
echo "::error::Since this PR cannot receive baseline commits automatically, updated screenshots cannot be committed."
echo "::error::Please ask a Kilo developer for help updating the screenshots."
git diff --cached --stat
exit 1
fi
- name: Fail if baselines still changing after auto-update
if: needs.check-paths.outputs.is_fork != 'true' && steps.check-baseline-commit.outputs.is_baseline_update == 'true'
if: needs.check-paths.outputs.can_autocommit == 'true' && steps.check-baseline-commit.outputs.is_baseline_update == 'true' # kilocode_change
run: |
git add packages/kilo-docs/public/img/screenshot-tests/kilo-ui/
if git diff --cached --quiet; then
@@ -173,10 +188,10 @@ jobs:
fi
- name: Commit and push new baselines (if any)
if: needs.check-paths.outputs.is_fork != 'true' && steps.check-baseline-commit.outputs.is_baseline_update != 'true'
if: needs.check-paths.outputs.can_autocommit == 'true' && steps.check-baseline-commit.outputs.is_baseline_update != 'true' # kilocode_change
id: commit-baselines
env:
GH_TOKEN: ${{ secrets.BOT_PAT || github.token }} # kilocode_change
GH_TOKEN: ${{ secrets.BOT_PAT }} # kilocode_change
run: |
git config user.name "github-actions[bot]"
git config user.email "github-actions[bot]@users.noreply.github.com"
@@ -192,10 +207,11 @@ jobs:
fi
- name: Fail if baselines changed
if: needs.check-paths.outputs.is_fork != 'true' && steps.commit-baselines.outputs.changed == 'true'
if: needs.check-paths.outputs.can_autocommit == 'true' && steps.commit-baselines.outputs.changed == 'true' # kilocode_change
run: |
echo "::error::Visual regression baselines changed. New baselines have been committed to the branch. Please pull and review."
exit 1
# kilocode_change end
- name: Upload test results on failure
if: failure()
@@ -204,7 +220,7 @@ jobs:
name: visual-regression-results
path: packages/kilo-ui/test-results/
retention-days: 7
# kilocode_change start
visual-regression-vscode:
needs: check-paths
if: needs.check-paths.outputs.matched == 'true'
@@ -218,21 +234,22 @@ jobs:
steps:
- name: Checkout (internal)
if: needs.check-paths.outputs.is_fork != 'true'
if: needs.check-paths.outputs.can_autocommit == 'true' # kilocode_change
uses: actions/checkout@v6 # kilocode_change
with:
lfs: true
token: ${{ secrets.BOT_PAT || github.token }} # kilocode_change
# LLM note: use BOT_PAT only when later baseline pushes are allowed; github.token is read-only on Dependabot PRs.
token: ${{ secrets.BOT_PAT }} # kilocode_change
ref: ${{ github.head_ref }}
- name: Checkout (fork)
if: needs.check-paths.outputs.is_fork == 'true'
- name: Checkout (read-only)
if: needs.check-paths.outputs.can_autocommit != 'true' # kilocode_change
uses: actions/checkout@v6 # kilocode_change
with:
lfs: true
- name: Check if HEAD is a baseline update commit
if: needs.check-paths.outputs.is_fork != 'true'
if: needs.check-paths.outputs.can_autocommit == 'true' # kilocode_change
id: check-baseline-commit-vscode
run: |
COMMIT_MSG=$(git log -1 --format=%s)
@@ -242,6 +259,7 @@ jobs:
else
echo "is_baseline_update=false" >> "$GITHUB_OUTPUT"
fi
# kilocode_change end
- name: Setup Bun
uses: oven-sh/setup-bun@v2
@@ -343,23 +361,23 @@ jobs:
}
"
working-directory: packages/kilo-vscode
- name: Check for baseline changes (fork PRs)
if: needs.check-paths.outputs.is_fork == 'true'
# kilocode_change start
- name: Check for baseline changes (read-only PRs)
if: needs.check-paths.outputs.can_autocommit != 'true' # kilocode_change
run: |
git add packages/kilo-docs/public/img/screenshot-tests/kilo-vscode/
if git diff --cached --quiet; then
echo "No visual regression detected."
else
echo "::error::Visual regression detected. Screenshot baselines have changed."
echo "::error::Since this PR is from a fork, updated screenshots cannot be committed automatically."
echo "::error::Since this PR cannot receive baseline commits automatically, updated screenshots cannot be committed."
echo "::error::Please ask a Kilo developer for help updating the screenshots."
git diff --cached --stat
exit 1
fi
- name: Fail if baselines still changing after auto-update
if: needs.check-paths.outputs.is_fork != 'true' && steps.check-baseline-commit-vscode.outputs.is_baseline_update == 'true'
if: needs.check-paths.outputs.can_autocommit == 'true' && steps.check-baseline-commit-vscode.outputs.is_baseline_update == 'true' # kilocode_change
run: |
git add packages/kilo-docs/public/img/screenshot-tests/kilo-vscode/
if git diff --cached --quiet; then
@@ -373,10 +391,10 @@ jobs:
fi
- name: Commit and push new baselines (if any)
if: needs.check-paths.outputs.is_fork != 'true' && steps.check-baseline-commit-vscode.outputs.is_baseline_update != 'true'
if: needs.check-paths.outputs.can_autocommit == 'true' && steps.check-baseline-commit-vscode.outputs.is_baseline_update != 'true' # kilocode_change
id: commit-baselines-vscode
env:
GH_TOKEN: ${{ secrets.BOT_PAT || github.token }} # kilocode_change
GH_TOKEN: ${{ secrets.BOT_PAT }} # kilocode_change
run: |
git config user.name "github-actions[bot]"
git config user.email "github-actions[bot]@users.noreply.github.com"
@@ -392,10 +410,11 @@ jobs:
fi
- name: Fail if baselines changed
if: needs.check-paths.outputs.is_fork != 'true' && steps.commit-baselines-vscode.outputs.changed == 'true'
if: needs.check-paths.outputs.can_autocommit == 'true' && steps.commit-baselines-vscode.outputs.changed == 'true' # kilocode_change
run: |
echo "::error::Visual regression baselines changed. New baselines have been committed to the branch. Please pull and review."
exit 1
# kilocode_change end
- name: Upload test results on failure
if: failure()