Skip to content

Update Scribe

Update Scribe #9

Workflow file for this run

# Keep Scriptorium on the newest Scribe.
#
# A git submodule pins one exact commit, which is what makes a Scriptorium
# checkout reproducible — but it also means Scribe moving forward does not move
# Scriptorium. This job does the moving: weekly (or on demand) it bumps
# lib/scribe to the tip of Scribe's main and opens a PR with the intervening
# Scribe commits in the body, so the bump is reviewed rather than silent.
#
# Note on CI: GITHUB_TOKEN-created PR runs may require Maintainer approval.
# Approve pending Governance and WFL tests runs, or use Run workflow for both
# workflows on the PR branch. Verify that successful runs cover the current
# revision before merging.
# Link both checks, including the nightly image digest; see testing.md. No extra
# token is needed for manual workflow dispatch.
# https://docs.github.com/en/actions/concepts/security/github_token
#
# To bump by hand instead, run scripts/update-scribe.sh.
name: Update Scribe
on:
schedule:
# Mondays, 06:00 UTC.
- cron: '0 6 * * 1'
workflow_dispatch:
permissions:
contents: write
pull-requests: write
concurrency:
group: update-scribe
cancel-in-progress: false
jobs:
bump:
runs-on: ubuntu-latest
steps:
- name: Check out Scriptorium (with submodules)
uses: actions/checkout@v4
with:
submodules: recursive
- name: Bump lib/scribe to the tip of Scribe main
id: bump
run: |
before="$(git -C lib/scribe rev-parse HEAD)"
git -C lib/scribe fetch --quiet origin main
after="$(git -C lib/scribe rev-parse FETCH_HEAD)"
if [ "$before" = "$after" ]; then
echo "Already on the newest Scribe ($(git -C lib/scribe log -1 --format=%h))."
echo "changed=no" >> "$GITHUB_OUTPUT"
exit 0
fi
# The pin can sit ahead of main (e.g. it points at a Scribe branch
# whose PR has not merged). Bumping would be a downgrade.
if git -C lib/scribe merge-base --is-ancestor "$after" "$before"; then
echo "The pinned Scribe is ahead of main — nothing to bump."
echo "changed=no" >> "$GITHUB_OUTPUT"
exit 0
fi
# Diverged: moving to main's tip would drop the commits unique to the
# pinned revision. Fail loudly rather than open a regression PR.
if ! git -C lib/scribe merge-base --is-ancestor "$before" "$after"; then
echo "::error::Scribe main has diverged from the pinned revision;" \
"pinned-only $(git -C lib/scribe rev-list --count "$after..$before")," \
"main-only $(git -C lib/scribe rev-list --count "$before..$after")." \
"Refusing to bump — resolve upstream first."
exit 1
fi
git -C lib/scribe log --oneline --no-decorate "$before..$after" > /tmp/scribe-log.txt
git -C lib/scribe checkout --quiet --detach "$after"
{
echo "changed=yes"
echo "before=$(git -C lib/scribe rev-parse --short "$before")"
echo "after=$(git -C lib/scribe rev-parse --short "$after")"
} >> "$GITHUB_OUTPUT"
- name: Open a pull request
if: steps.bump.outputs.changed == 'yes'
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
BEFORE: ${{ steps.bump.outputs.before }}
AFTER: ${{ steps.bump.outputs.after }}
run: |
branch="chore/update-scribe-$AFTER"
# A later run sees the same AFTER while the previous PR is still open,
# and would push a branch that already exists. If a PR for it is open,
# this run has nothing to add. If the branch exists with no open PR it
# is stale (PR closed, or a run that died before opening one), so it is
# safe to replace.
if [ -n "$(gh pr list --head "$branch" --state open --json number --jq '.[].number')" ]; then
echo "PR already open for $branch — nothing to do."
exit 0
fi
force=""
if git ls-remote --exit-code --heads origin "$branch" >/dev/null 2>&1; then
echo "Stale $branch with no open PR — replacing it."
force="--force-with-lease"
fi
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git checkout -b "$branch"
git add lib/scribe
git commit -m "chore(scribe): update lib/scribe to $AFTER"
# shellcheck disable=SC2086
git push -u $force origin "$branch"
{
echo '## Summary'
echo
echo "Update the \`lib/scribe\` pin from \`$BEFORE\` to \`$AFTER\` to pick up the latest upstream main changes while keeping checkouts reproducible."
echo
echo '## Changes'
echo
echo "Scribe commits picked up:"
echo
echo '```'
cat /tmp/scribe-log.txt
echo '```'
echo
echo "Opened automatically by \`.github/workflows/update-scribe.yml\`."
echo
echo '## Compatibility and risk'
echo
echo '- **Risk class and reason:** R2 (Scribe dependency pin); raise the class if the upstream diff affects a higher-risk boundary.'
echo '- **Affected contracts:** Scribe pin, template rendering, escaping and safe markers, Markdown, and theme output. Review the upstream diff to identify the changed paths.'
echo '- **Upgrade and recovery:** Compatibility and migration requirements are not yet verified. To undo the pin change, revert the bump commit and update submodules to restore the previous pin. Any migration needs its own tested recovery plan.'
echo '- **Remaining risks or gaps:** Upstream compatibility review and affected rendering journeys are pending. No policy exception has been recorded.'
echo
echo '## Validation'
echo
echo '- **Tested revision and environment:** Pending. Record the tested Scriptorium and Scribe revisions, OS/configuration, `wfl --version`, and relevant tool versions with the results.'
echo '- **Regression evidence:** Pending upstream diff review. Record the required before/after evidence for affected behavior, or explain why a check does not apply.'
echo
echo '| Check or exact command | Result and evidence |'
echo '|---|---|'
echo '| `wfl --execution-timeout 1200 scripts/run_tests.wfl` | Pending — this workflow prepares the dependency bump. Link WFL tests results for the current revision, including the nightly image digest and runtime version; record failures. |'
echo '| `wfl scripts/run_tests.wfl --group tooling` | Pending — Governance results are not verified by this workflow. Link results for the current revision. |'
echo '| `python scripts/check_repo_hygiene.py` | Pending — Governance results are not verified by this workflow. Link results for the current revision. |'
echo '| Affected HTTP/UI rendering journeys | Not run — upstream diff review is needed to identify affected paths. Record setup, expected/actual outcome, and evidence. |'
echo
echo 'Approve any pending Governance and WFL tests runs, or run both workflows manually on this branch. Verify that successful checks cover the current revision before merging.'
echo
echo '## Checklist'
echo
echo '- [ ] The title, summary, and risk assessment match the final diff.'
echo '- [ ] Required validation is recorded above; failures and missing checks are explicit.'
echo '- [ ] Documentation, examples, and upgrade/recovery guidance are updated where applicable.'
echo '- [ ] I reviewed the diff for repository hygiene, secrets, and private site data.'
echo
echo 'Follow [CONTRIBUTING.md](https://github.com/WebFirstLanguage/Scriptorium/blob/main/CONTRIBUTING.md), [testing.md](https://github.com/WebFirstLanguage/Scriptorium/blob/main/testing.md), and [REPOSITORY_HYGIENE.md](https://github.com/WebFirstLanguage/Scriptorium/blob/main/REPOSITORY_HYGIENE.md).'
echo
echo 'Report undisclosed vulnerabilities privately using [SECURITY.md](https://github.com/WebFirstLanguage/Scriptorium/blob/main/SECURITY.md).'
} > /tmp/pr-body.md
gh pr create \
--title "chore(scribe): update lib/scribe to $AFTER" \
--body-file /tmp/pr-body.md \
--base main \
--head "$branch"