Skip to content

OpenVEX Securities Syncing #367

OpenVEX Securities Syncing

OpenVEX Securities Syncing #367

Workflow file for this run

## %CopyrightBegin%
##
## SPDX-License-Identifier: Apache-2.0
##
## Copyright Ericsson AB 2024-2026. All Rights Reserved.
##
## Licensed under the Apache License, Version 2.0 (the "License");
## you may not use this file except in compliance with the License.
## You may obtain a copy of the License at
##
## http://www.apache.org/licenses/LICENSE-2.0
##
## Unless required by applicable law or agreed to in writing, software
## distributed under the License is distributed on an "AS IS" BASIS,
## WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
## See the License for the specific language governing permissions and
## limitations under the License.
##
## %CopyrightEnd%
## Periodically syncs OpenVEX files against Erlang OTP Securities,
## creating an automatic PR with the missing published securities.
name: OpenVEX Securities Syncing
description: 'Sync OpenVEX Securities with Erlang/OTP published Securities'
on:
workflow_dispatch:
schedule:
- cron: 0 1 * * *
permissions:
contents: read
jobs:
run-scheduled-openvex-sync:
runs-on: ubuntu-latest
permissions:
contents: write # use inside the otp-compliance.es
pull-requests: write # use inside the otp-compliance.es
if: github.repository == 'erlang/otp'
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # ratchet:actions/checkout@v6.0.2
with:
ref: 'openvex' # '' = default branch
persist-credentials: false
fetch-depth: 0
- name: 'Fetch Erlang/otp script dependencies'
run: |
git fetch origin master
WORKTREE=$(mktemp -d /tmp/master-worktree.XXXXXX)
git worktree add "$WORKTREE" master
mkdir -p .github/scripts/
cp -r "$WORKTREE/.github/scripts/." .github/scripts/
cp "$WORKTREE/otp_versions.table" .
git worktree remove "$WORKTREE"
- uses: erlef/setup-beam@e6d7c94229049569db56a7ad5a540c051a010af9 # ratchet:erlef/setup-beam@v1.20.4
with:
otp-version: '28'
- uses: openvex/setup-vexctl@e85ca48f3c8a376289f6476129d59cda82147e71 # ratchet:openvex/setup-vexctl@v0.1.1
with:
vexctl-release: '0.3.0'
- uses: actions/create-github-app-token@29824e69f54612133e76f7eaac726eef6c875baf # ratchet:actions/create-github-app-token@v2.2.1
id: app-token
with:
# required
app-id: ${{ vars.ERLANG_BOT_APP_ID }}
private-key: ${{ secrets.ERLANG_BOT_PRIVATE_KEY }}
owner: ${{ github.repository_owner }}
repositories: otp
permission-contents: write
permission-pull-requests: write
- name: Authenticate gh
env:
STEPS_APP_TOKEN_OUTPUTS_TOKEN: ${{ steps.app-token.outputs.token }}
run: |
echo "${STEPS_APP_TOKEN_OUTPUTS_TOKEN}" | gh auth login --with-token
# register `gh` as git credential helper => git push in otp-compliance
# uses the token from `gh`. otherwise, `persist-credentials` should not be `false`.
# changing `persist-credentials` is not a good option
- name: Configure git to use gh as credential helper
run: gh auth setup-git
- name: Get GitHub App User ID
id: get-user-id
env:
GH_TOKEN: ${{ steps.app-token.outputs.token }}
STEPS_APP_TOKEN_OUTPUTS_APP_SLUG: ${{ steps.app-token.outputs.app-slug }}
run: echo "user-id=$(gh api "/users/${STEPS_APP_TOKEN_OUTPUTS_APP_SLUG}[bot]" --jq .id)" >> "$GITHUB_OUTPUT"
- env:
STEPS_APP_TOKEN_OUTPUTS_APP_SLUG: ${{ steps.app-token.outputs.app-slug }}
STEPS_GET_USER_ID_OUTPUTS_USER_ID: ${{ steps.get-user-id.outputs.user-id }}
run: |
git config --global user.name "${STEPS_APP_TOKEN_OUTPUTS_APP_SLUG}[bot]"
git config --global user.email "${STEPS_GET_USER_ID_OUTPUTS_USER_ID}+${STEPS_APP_TOKEN_OUTPUTS_APP_SLUG}[bot]@users.noreply.github.com"
- name: 'Open OpenVEX Pull Requests for newly released vulnerabilities'
run: |
.github/scripts/otp-compliance.es vex verify -p