Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
40 changes: 40 additions & 0 deletions .github/workflows/security-bump.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,40 @@
name: Security bump

on:
workflow_dispatch:
schedule:
# Runs at 03:30, every Saturday
- cron: "30 3 * * 6"

jobs:
bump:
runs-on: ubuntu-latest
# We don't want to run the security bump in forks.
if: github.repository == 'servo/mozangle'
permissions:
contents: write
pull-requests: write
steps:
- uses: actions/checkout@v6
- name: Configure Git
run: |
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
- run: python3 ./security-bump.py
id: bump
- run: python3 ./update.py
- name: Commit changes
if: ${{ steps.bump.outputs.tag != '' }}
# if there are no changes to the gfx/angle directory we remove all other changes
# so there will be no PR created
run: |
git add gfx/angle
git --cached diff --exit-code && git reset --hard HEAD || git commit -sam "Bump ANGLE to ${{ steps.bump.outputs.tag }}"
- name: Create Pull Request
uses: peter-evans/create-pull-request@c0f553fe549906ede9cf27b5156039d195d2ece0
with:
title: Security bump ANGLE to ${{ steps.bump.outputs.tag }}
body: |
Bump ANGLE to ${{ steps.bump.outputs.tag }}

Close and reopen this PR to trigger CI.
90 changes: 90 additions & 0 deletions security-bump.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,90 @@
#!/usr/bin/env python3

import os
import re
import subprocess
import tempfile
from pathlib import Path

upstream_txt = Path("UPSTREAM").read_text()

tag, commit = upstream_txt.removeprefix("gfx/angle is taken from ").split(": ", 1)

print(f"Existing Firefox tag: {tag} and commit: {commit}")

esr = tag.removeprefix("FIREFOX_").split("_", 1)[0]

print(f"ESR: {esr}")

with tempfile.TemporaryDirectory() as tmpdir:
subprocess.run(
[
"git",
"clone",
"--filter=blob:none",
"--no-checkout",
"https://github.com/mozilla-firefox/firefox.git",
str(tmpdir),
],
check=True,
)

subprocess.run(
["git", "fetch", "--tags"],
cwd=tmpdir,
check=True,
)

latest_tag = (
subprocess.check_output(
[
"git",
"for-each-ref",
"--sort=-creatordate",
"--format=%(refname:short)",
f"refs/tags/FIREFOX_{esr}_*_RELEASE",
],
cwd=tmpdir,
)
.decode()
.splitlines()[0]
)

latest_commit = (
subprocess.check_output(["git", "rev-list", "-n", "1", latest_tag], cwd=tmpdir)
.decode()
.strip()
)

print(f"Latest Firefox tag: {latest_tag} and commit: {latest_commit}")

Path("UPSTREAM").write_text(f"gfx/angle is taken from {latest_tag}: {latest_commit}\n")

if GITHUB_OUTPUT := os.getenv("GITHUB_OUTPUT"):
with open(GITHUB_OUTPUT, "a") as github_output_file:
print(f"tag={latest_tag}", file=github_output_file)
print(f"commit={latest_commit}", file=github_output_file)

# bump cargo.toml

toml_path = Path("Cargo.toml")

toml_text = toml_path.read_text()
# extract create version
version_match = re.search(
r'^\s*version\s*=\s*"(\d+)\.(\d+)\.(\d+)"',
toml_text,
re.MULTILINE,
)
version_major, version_minor, version_patch = map(int, version_match.groups())
print(f"Current mozangle version: {version_major}.{version_minor}.{version_patch}")
toml_text = re.sub(
r'version = "\d+\.\d+\.\d+"\n',
f'version = "{version_major}.{version_minor}.{version_patch + 1}"\n',
toml_text,
)
print(
f"Bumped mozangle version to: {version_major}.{version_minor}.{version_patch + 1}"
)

toml_path.write_text(toml_text)
Loading