From ffcc1235cc2791aff2fc647f3a219e90ef79d2b4 Mon Sep 17 00:00:00 2001 From: marius-kilocode Date: Wed, 8 Jul 2026 19:40:53 +0200 Subject: [PATCH] fix(ci): use maintainer app for baseline commits --- .github/workflows/visual-regression.yml | 71 +++++++++++++++---------- 1 file changed, 42 insertions(+), 29 deletions(-) diff --git a/.github/workflows/visual-regression.yml b/.github/workflows/visual-regression.yml index 6181b7b7d50..81baf52d865 100644 --- a/.github/workflows/visual-regression.yml +++ b/.github/workflows/visual-regression.yml @@ -6,7 +6,7 @@ on: types: [opened, synchronize, reopened] permissions: - contents: write + contents: read pull-requests: read jobs: @@ -46,9 +46,10 @@ jobs: - name: Check baseline auto-commit permissions id: autocommit-check env: - BOT_PAT: ${{ secrets.BOT_PAT }} + MAINTAINER_APP_ID: ${{ secrets.KILO_MAINTAINER_APP_ID }} + MAINTAINER_APP_SECRET: ${{ secrets.KILO_MAINTAINER_APP_SECRET }} run: | - if [ "${{ steps.fork-check.outputs.is_fork }}" != "true" ] && [ -n "$BOT_PAT" ]; then + if [ "${{ steps.fork-check.outputs.is_fork }}" != "true" ] && [ -n "$MAINTAINER_APP_ID" ] && [ -n "$MAINTAINER_APP_SECRET" ]; then echo "can_autocommit=true" >> "$GITHUB_OUTPUT" else echo "can_autocommit=false" >> "$GITHUB_OUTPUT" @@ -67,7 +68,7 @@ jobs: uses: actions/checkout@v6 with: lfs: true - # Use github.token for LFS access. BOT_PAT is used only for the final ref push. + # Use github.token for LFS access. The maintainer app is used only for generated commits. token: ${{ github.token }} ref: ${{ github.head_ref }} @@ -175,27 +176,33 @@ jobs: exit 1 fi - - name: Commit and push new baselines (if any) + - name: Check for baseline updates if: needs.check-paths.outputs.can_autocommit == 'true' && steps.check-baseline-commit.outputs.is_baseline_update != 'true' - id: commit-baselines - env: - BOT_PAT: ${{ secrets.BOT_PAT }} + id: baseline-changes run: | - git config user.name "github-actions[bot]" - git config user.email "github-actions[bot]@users.noreply.github.com" git add packages/kilo-docs/public/img/screenshot-tests/kilo-ui/ if git diff --cached --quiet; then - echo "No new baselines — nothing to commit." echo "changed=false" >> "$GITHUB_OUTPUT" else - git commit -m "chore: update visual regression baselines" - git lfs push --all origin - git -c http.https://github.com/.extraheader= push --no-verify \ - "https://x-access-token:${BOT_PAT}@github.com/${GITHUB_REPOSITORY}.git" \ - "HEAD:${GITHUB_HEAD_REF}" echo "changed=true" >> "$GITHUB_OUTPUT" fi + - name: Setup Git Committer + if: steps.baseline-changes.outputs.changed == 'true' + uses: ./.github/actions/setup-git-committer + with: + kilo-maintainer-app-id: ${{ secrets.KILO_MAINTAINER_APP_ID }} + kilo-maintainer-app-secret: ${{ secrets.KILO_MAINTAINER_APP_SECRET }} + + - name: Commit and push new baselines (if any) + if: steps.baseline-changes.outputs.changed == 'true' + id: commit-baselines + run: | + git commit -m "chore: update visual regression baselines" + git lfs push --all origin + git push --no-verify origin "HEAD:${GITHUB_HEAD_REF}" + echo "changed=true" >> "$GITHUB_OUTPUT" + - name: Fail if baselines changed if: needs.check-paths.outputs.can_autocommit == 'true' && steps.commit-baselines.outputs.changed == 'true' run: | @@ -225,7 +232,7 @@ jobs: uses: actions/checkout@v6 with: lfs: true - # Use github.token for LFS access. BOT_PAT is used only for the final ref push. + # Use github.token for LFS access. The maintainer app is used only for generated commits. token: ${{ github.token }} ref: ${{ github.head_ref }} @@ -363,27 +370,33 @@ jobs: exit 1 fi - - name: Commit and push new baselines (if any) + - name: Check for baseline updates if: needs.check-paths.outputs.can_autocommit == 'true' && steps.check-baseline-commit-vscode.outputs.is_baseline_update != 'true' - id: commit-baselines-vscode - env: - BOT_PAT: ${{ secrets.BOT_PAT }} + id: baseline-changes-vscode run: | - git config user.name "github-actions[bot]" - git config user.email "github-actions[bot]@users.noreply.github.com" git add packages/kilo-docs/public/img/screenshot-tests/kilo-vscode/ if git diff --cached --quiet; then - echo "No new baselines — nothing to commit." echo "changed=false" >> "$GITHUB_OUTPUT" else - git commit -m "chore: update kilo-vscode visual regression baselines" - git lfs push --all origin - git -c http.https://github.com/.extraheader= push --no-verify \ - "https://x-access-token:${BOT_PAT}@github.com/${GITHUB_REPOSITORY}.git" \ - "HEAD:${GITHUB_HEAD_REF}" echo "changed=true" >> "$GITHUB_OUTPUT" fi + - name: Setup Git Committer + if: steps.baseline-changes-vscode.outputs.changed == 'true' + uses: ./.github/actions/setup-git-committer + with: + kilo-maintainer-app-id: ${{ secrets.KILO_MAINTAINER_APP_ID }} + kilo-maintainer-app-secret: ${{ secrets.KILO_MAINTAINER_APP_SECRET }} + + - name: Commit and push new baselines (if any) + if: steps.baseline-changes-vscode.outputs.changed == 'true' + id: commit-baselines-vscode + run: | + git commit -m "chore: update kilo-vscode visual regression baselines" + git lfs push --all origin + git push --no-verify origin "HEAD:${GITHUB_HEAD_REF}" + echo "changed=true" >> "$GITHUB_OUTPUT" + - name: Fail if baselines changed if: needs.check-paths.outputs.can_autocommit == 'true' && steps.commit-baselines-vscode.outputs.changed == 'true' run: |