From 0813b225e624563cd48ca414c84e6fa0d69def44 Mon Sep 17 00:00:00 2001 From: Dominion Date: Sat, 29 Apr 2023 09:45:08 -0400 Subject: [PATCH 1/9] Minor corrections to Master Merge workflow --- .github/workflows/stable-merge.yml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/workflows/stable-merge.yml b/.github/workflows/stable-merge.yml index e70a60b577..a1aa943f3a 100644 --- a/.github/workflows/stable-merge.yml +++ b/.github/workflows/stable-merge.yml @@ -1,9 +1,9 @@ name: 'Master Merge' on: - push: - branches: - - master + push: + branches: + - master jobs: master-merge: From 6cb1de0f7bed1db2c4905211f66c761aba5a5c41 Mon Sep 17 00:00:00 2001 From: Dominion Date: Sat, 29 Apr 2023 11:12:40 -0400 Subject: [PATCH 2/9] CI Overhaul - Switched from `pull_request` to `pull_request_target`, explicitly checking out the PR code. - Added security-checkpoint job that will fail on pull requests from forks. - Added concurrency limiter. - Added missing live tests filter. - Fixed bad indentation. Fixes #1107 --- .github/workflows/ci-suite.yml | 642 ++++++++++++++++++++------------- 1 file changed, 390 insertions(+), 252 deletions(-) diff --git a/.github/workflows/ci-suite.yml b/.github/workflows/ci-suite.yml index 852d85dbfb..c68d96617e 100644 --- a/.github/workflows/ci-suite.yml +++ b/.github/workflows/ci-suite.yml @@ -5,7 +5,8 @@ on: branches: - dev - master - pull_request: + pull_request_target: + types: [opened, reopened, labeled, synchronize] branches: - dev - master @@ -19,9 +20,35 @@ env: TGS_TEST_GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} TGS_RELEASE_NOTES_TOKEN: ${{ secrets.DEV_PUSH_TOKEN }} +concurrency: + group: "ci-${{ (github.event_name == 'push' ? github.head_ref : github.event.number) }}" + cancel-in-progress: true + jobs: + security-checkpoint: + name: Check CI Clearance + needs: security-checkpoint + runs-on: ubuntu-latest + steps: + - name: Comment on new Fork PR + if: github.event_name != 'push' && github.pull_request.head.repo.id != github.repository.id && github.event.action == 'opened' + uses: thollander/actions-comment-pull-request@v2 + with: + message: Thank you for contributing to tgstation-server! As this pull request is from a fork, we can't allow the CI actions which require repository secrets to run on it without approval. After a brief review to make sure you're not misusing those secrets, a maintainer will add the `CI Cleared` label to allow the CI suite to run. Maintainers, please note that any changes to workflow files will not be reflected in the CI run. + + - name: "Remove Stale 'CI Cleared' Label" + if: github.event_name != 'push' && github.pull_request.head.repo.id != github.repository.id && (github.event.action == 'synchronize' || github.event.action == 'reopened') + uses: actions-ecosystem/action-remove-labels@v1 + with: + labels: CI Cleared + + - name: Fail Clearance Check if PR has Unlabeled new Commits from Fork + if: github.event_name != 'push' && github.pull_request.head.repo.id != github.repository.id && (github.event.action != 'labeled' || !contains(github.event.pull_request.labels.*.name, 'CI Cleared')) + run: exit 1 + analyze: name: Code Scanning + needs: security-checkpoint runs-on: ubuntu-latest steps: - name: Install Node 12.X @@ -32,11 +59,19 @@ jobs: - name: Upgrade NPM run: npm install -g npm - - name: Checkout repository + - name: Checkout (Branch Push) uses: actions/checkout@v3 + if: github.event_name == 'push' with: fetch-depth: 2 + - name: Checkout (PR Merge) + uses: actions/checkout@v3 + if: github.event_name != 'push' + with: + fetch-depth: 2 + ref: "refs/pull/${{ github.event.number }}/merge" + - name: Initialize CodeQL uses: github/codeql-action/init@v2 with: @@ -73,8 +108,15 @@ jobs: make here exit 0 - - name: Checkout + - name: Checkout (Branch Push) uses: actions/checkout@v3 + if: github.event_name == 'push' + + - name: Checkout (PR Merge) + uses: actions/checkout@v3 + if: github.event_name != 'push' + with: + ref: "refs/pull/${{ github.event.number }}/merge" - name: Build DMAPI Test Project run: | @@ -100,58 +142,70 @@ jobs: name: Build Doxygen Site runs-on: ubuntu-latest steps: - - name: Checkout - uses: actions/checkout@v3 + - name: Checkout (Branch Push) + uses: actions/checkout@v3 + if: github.event_name == 'push' - - name: Patch Doxyfile - run: | - VERSION=$(cat "build/Version.props" | grep -oPm1 "(?<=)[^<]+") - echo -e "\nPROJECT_NUMBER = $VERSION\nINPUT = .\nOUTPUT_DIRECTORY = ./doxout\nPROJECT_LOGO = ./build/tgs.ico\nHAVE_DOT=YES" >> "docs/Doxyfile" + - name: Checkout (PR Merge) + uses: actions/checkout@v3 + if: github.event_name != 'push' + with: + ref: "refs/pull/${{ github.event.number }}/merge" - - name: Doxygen Build - uses: mattnotmitt/doxygen-action@v1 - with: - doxyfile-path: 'docs/Doxyfile' + - name: Patch Doxyfile + run: | + VERSION=$(cat "build/Version.props" | grep -oPm1 "(?<=)[^<]+") + echo -e "\nPROJECT_NUMBER = $VERSION\nINPUT = .\nOUTPUT_DIRECTORY = ./doxout\nPROJECT_LOGO = ./build/tgs.ico\nHAVE_DOT=YES" >> "docs/Doxyfile" - - name: gh-pages push - if: github.event_name == 'push' && github.event.ref == 'refs/heads/dev' - run: | - git clone -b gh-pages --single-branch "https://git@github.com/tgstation/tgstation-server" $HOME/tgsdox - pushd $HOME/tgsdox - rm -r * - popd - echo ./doxout/* | xargs -n 10 sudo mv -t $HOME/tgsdox - cd $HOME/tgsdox - git config --global push.default simple - git config user.name "tgstation-server" - git config user.email "tgstation-server@tgstation13.org" - echo '# THIS BRANCH IS AUTO GENERATED BY GITHUB ACTIONS' > README.md + - name: Doxygen Build + uses: mattnotmitt/doxygen-action@v1 + with: + doxyfile-path: 'docs/Doxyfile' - # Need to create a .nojekyll file to allow filenames starting with an underscore - # to be seen on the gh-pages site. Therefore creating an empty .nojekyll file. - echo "" > .nojekyll - echo "Adding files..." - git add --all - echo "Committing..." - git diff-index --quiet HEAD || git commit -m "Deploy code docs to GitHub Pages for workflow run ${{ github.run_number }}" -m "Commit: ${{ github.event.head_commit.id }}" - echo "Pushing..." - git push -f "https://${{ secrets.DEV_PUSH_TOKEN }}@github.com/tgstation/tgstation-server" 2>&1 + - name: gh-pages push + if: github.event_name == 'push' && github.event.ref == 'refs/heads/dev' + run: | + git clone -b gh-pages --single-branch "https://git@github.com/tgstation/tgstation-server" $HOME/tgsdox + pushd $HOME/tgsdox + rm -r * + popd + echo ./doxout/* | xargs -n 10 sudo mv -t $HOME/tgsdox + cd $HOME/tgsdox + git config --global push.default simple + git config user.name "tgstation-server" + git config user.email "tgstation-server@tgstation13.org" + echo '# THIS BRANCH IS AUTO GENERATED BY GITHUB ACTIONS' > README.md + + # Need to create a .nojekyll file to allow filenames starting with an underscore + # to be seen on the gh-pages site. Therefore creating an empty .nojekyll file. + echo "" > .nojekyll + echo "Adding files..." + git add --all + echo "Committing..." + git diff-index --quiet HEAD || git commit -m "Deploy code docs to GitHub Pages for workflow run ${{ github.run_number }}" -m "Commit: ${{ github.event.head_commit.id }}" + echo "Pushing..." + git push -f "https://${{ secrets.DEV_PUSH_TOKEN }}@github.com/tgstation/tgstation-server" 2>&1 docker-build: name: Build Docker Image runs-on: ubuntu-latest steps: - - name: Checkout + - name: Checkout (Branch Push) uses: actions/checkout@v3 + if: github.event_name == 'push' - - name: Upgrade NPM - run: sudo npm install -g npm + - name: Checkout (PR Merge) + uses: actions/checkout@v3 + if: github.event_name != 'push' + with: + ref: "refs/pull/${{ github.event.number }}/merge" - name: Build Docker Image run: docker build . -f build/Dockerfile linux-unit-tests: name: Linux Tests + needs: security-checkpoint strategy: fail-fast: false matrix: @@ -163,8 +217,15 @@ jobs: with: dotnet-version: ${{ env.TGS_DOTNET_VERSION }} - - name: Checkout + - name: Checkout (Branch Push) uses: actions/checkout@v3 + if: github.event_name == 'push' + + - name: Checkout (PR Merge) + uses: actions/checkout@v3 + if: github.event_name != 'push' + with: + ref: "refs/pull/${{ github.event.number }}/merge" - name: Upgrade NPM run: sudo npm install -g npm @@ -183,6 +244,7 @@ jobs: windows-unit-tests: name: Windows Tests + needs: security-checkpoint strategy: fail-fast: false matrix: @@ -194,8 +256,15 @@ jobs: with: dotnet-version: ${{ env.TGS_DOTNET_VERSION }} - - name: Checkout + - name: Checkout (Branch Push) uses: actions/checkout@v3 + if: github.event_name == 'push' + + - name: Checkout (PR Merge) + uses: actions/checkout@v3 + if: github.event_name != 'push' + with: + ref: "refs/pull/${{ github.event.number }}/merge" - name: Upgrade NPM run: npm install -g npm @@ -214,7 +283,7 @@ jobs: windows-integration-test: name: Windows Live Tests - needs: dmapi-build + needs: [security-checkpoint, dmapi-build] env: TGS_TEST_DATABASE_TYPE: SqlServer TGS_TEST_DUMP_API_SPEC: yes @@ -243,17 +312,24 @@ jobs: TGS_CONNSTRING_VALUE="Server=(localdb)\MSSQLLocalDB;Integrated Security=true;Initial Catalog=TGS_${{ matrix.watchdog-type }}_${{ matrix.configuration }};Application Name=tgstation-server" echo "TGS_TEST_CONNECTION_STRING=$(echo $TGS_CONNSTRING_VALUE)" >> $GITHUB_ENV - - name: Checkout + - name: Checkout (Branch Push) uses: actions/checkout@v3 + if: github.event_name == 'push' + + - name: Checkout (PR Merge) + uses: actions/checkout@v3 + if: github.event_name != 'push' + with: + ref: "refs/pull/${{ github.event.number }}/merge" - name: Build run: dotnet build -c ${{ matrix.configuration }} tests/Tgstation.Server.Tests/Tgstation.Server.Tests.csproj - - name: Run Integration Test + - name: Run Live Tests run: | cd tests/Tgstation.Server.Tests Start-Sleep -Seconds 10 - dotnet test -c ${{ matrix.configuration }} --no-build --logger GitHubActions --collect:"XPlat Code Coverage" --settings ../../build/coverlet.runsettings --results-directory ../../TestResults + dotnet test -c ${{ matrix.configuration }} --no-build --filter FullyQualifiedName~TestLiveServer --logger GitHubActions --collect:"XPlat Code Coverage" --settings ../../build/coverlet.runsettings --results-directory ../../TestResults - name: Store Code Coverage uses: actions/upload-artifact@v3 @@ -286,7 +362,7 @@ jobs: linux-integration-tests: name: Linux Live Tests - needs: dmapi-build + needs: [security-checkpoint, dmapi-build] services: # We start all dbs here so we can just code the stuff once postgres: image: cyberboss/postgres-max-connections # Fork of _/postgres:latest with max_connections=500 becuase GitHub actions service containers have no way to set command lines. Rebuilds with updates. @@ -380,17 +456,24 @@ jobs: if: ${{ matrix.watchdog-type == 'Basic' }} run: echo "General__UseBasicWatchdog=true" >> $GITHUB_ENV - - name: Checkout + - name: Checkout (Branch Push) uses: actions/checkout@v3 + if: github.event_name == 'push' + + - name: Checkout (PR Merge) + uses: actions/checkout@v3 + if: github.event_name != 'push' + with: + ref: "refs/pull/${{ github.event.number }}/merge" - name: Build run: dotnet build -c ${{ matrix.configuration }}NoService tests/Tgstation.Server.Tests/Tgstation.Server.Tests.csproj - - name: Run Integration Test + - name: Run Live Tests run: | cd tests/Tgstation.Server.Tests sleep 10 - dotnet test -c ${{ matrix.configuration }}NoService --logger GitHubActions --no-build --collect:"XPlat Code Coverage" --settings ../../build/coverlet.runsettings --results-directory ../../TestResults + dotnet test -c ${{ matrix.configuration }}NoService --filter FullyQualifiedName~TestLiveServer --logger GitHubActions --no-build --collect:"XPlat Code Coverage" --settings ../../build/coverlet.runsettings --results-directory ../../TestResults - name: Store Code Coverage uses: actions/upload-artifact@v3 @@ -441,8 +524,15 @@ jobs: - name: Install IBM OpenAPI Validator run: npm i -g ibm-openapi-validator@0.51.3 - - name: Checkout + - name: Checkout (Branch Push) uses: actions/checkout@v3 + if: github.event_name == 'push' + + - name: Checkout (PR Merge) + uses: actions/checkout@v3 + if: github.event_name != 'push' + with: + ref: "refs/pull/${{ github.event.number }}/merge" - name: Retrieve OpenAPI Spec uses: actions/download-artifact@v3 @@ -458,8 +548,15 @@ jobs: needs: [linux-unit-tests, linux-integration-tests, windows-unit-tests, windows-integration-test] runs-on: ubuntu-latest steps: - - name: Checkout for .codecov.yml + - name: Checkout (Branch Push) uses: actions/checkout@v3 + if: github.event_name == 'push' + + - name: Checkout (PR Merge) + uses: actions/checkout@v3 + if: github.event_name != 'push' + with: + ref: "refs/pull/${{ github.event.number }}/merge" - name: Retrieve Linux Unit Test Coverage (Debug) uses: actions/download-artifact@v3 @@ -540,42 +637,49 @@ jobs: runs-on: windows-latest if: github.event_name == 'push' && contains(github.event.head_commit.message, '[APIDeploy]') steps: - - name: Checkout - uses: actions/checkout@v3 + - name: Checkout (Branch Push) + uses: actions/checkout@v3 + if: github.event_name == 'push' - - name: Parse API version - shell: powershell - run: | - [XML]$versionXML = Get-Content build/Version.props - $apiVersion = $versionXML.Project.PropertyGroup.TgsApiVersion - echo "TGS_API_VERSION=$apiVersion" | Out-File -FilePath $Env:GITHUB_ENV -Encoding utf8 -Append + - name: Checkout (PR Merge) + uses: actions/checkout@v3 + if: github.event_name != 'push' + with: + ref: "refs/pull/${{ github.event.number }}/merge" - - name: Retrieve OpenAPI Spec - uses: actions/download-artifact@v3 - with: - name: openapi-spec - path: swagger + - name: Parse API version + shell: powershell + run: | + [XML]$versionXML = Get-Content build/Version.props + $apiVersion = $versionXML.Project.PropertyGroup.TgsApiVersion + echo "TGS_API_VERSION=$apiVersion" | Out-File -FilePath $Env:GITHUB_ENV -Encoding utf8 -Append - - name: Create GitHub Release - uses: juitnow/github-action-create-release@v1 - id: create_release - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - with: - tag_name: api-v${{ env.TGS_API_VERSION }} - release_name: tgstation-server API v${{ env.TGS_API_VERSION }} - body: The TGS HTTP API - commitish: ${{ github.event.head_commit.id }} + - name: Retrieve OpenAPI Spec + uses: actions/download-artifact@v3 + with: + name: openapi-spec + path: swagger - - name: Upload OpenApi Spec - uses: actions/upload-release-asset@v1 - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - with: - upload_url: ${{ steps.create_release.outputs.upload_url }} - asset_path: ./swagger/swagger.json - asset_name: swagger.json - asset_content_type: application/json + - name: Create GitHub Release + uses: juitnow/github-action-create-release@v1 + id: create_release + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + with: + tag_name: api-v${{ env.TGS_API_VERSION }} + release_name: tgstation-server API v${{ env.TGS_API_VERSION }} + body: The TGS HTTP API + commitish: ${{ github.event.head_commit.id }} + + - name: Upload OpenApi Spec + uses: actions/upload-release-asset@v1 + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + with: + upload_url: ${{ steps.create_release.outputs.upload_url }} + asset_path: ./swagger/swagger.json + asset_name: swagger.json + asset_content_type: application/json deploy-dm: name: Deploy DreamMaker API @@ -583,42 +687,48 @@ jobs: runs-on: windows-latest if: github.event_name == 'push' && contains(github.event.head_commit.message, '[DMDeploy]') steps: + - name: Checkout (Branch Push) + uses: actions/checkout@v3 + if: github.event_name == 'push' - - name: Checkout - uses: actions/checkout@v3 + - name: Checkout (PR Merge) + uses: actions/checkout@v3 + if: github.event_name != 'push' + with: + ref: "refs/pull/${{ github.event.number }}/merge" - - name: Parse DMAPI version - shell: powershell - run: | - [XML]$versionXML = Get-Content build/Version.props - $dmVersion = $versionXML.Project.PropertyGroup.TgsDmapiVersion - echo "TGS_DM_VERSION=$dmVersion" | Out-File -FilePath $Env:GITHUB_ENV -Encoding utf8 -Append + - name: Parse DMAPI version + shell: powershell + run: | + [XML]$versionXML = Get-Content build/Version.props + $dmVersion = $versionXML.Project.PropertyGroup.TgsDmapiVersion + echo "TGS_DM_VERSION=$dmVersion" | Out-File -FilePath $Env:GITHUB_ENV -Encoding utf8 -Append - - name: Zip DMAPI - shell: powershell - run: | - &"C:/Program Files/7-Zip/7z.exe" a DMAPI.zip ./src/DMAPI/* -tzip + - name: Zip DMAPI + shell: powershell + run: | + &"C:/Program Files/7-Zip/7z.exe" a DMAPI.zip ./src/DMAPI/* -tzip - - name: Create GitHub Release - uses: juitnow/github-action-create-release@v1 - id: create_release - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - with: - tag_name: dmapi-v${{ env.TGS_DM_VERSION }} - release_name: tgstation-server DMAPI v${{ env.TGS_DM_VERSION }} - body: The TGS DMAPI \#tgs-dmapi-release - commitish: ${{ github.event.head_commit.id }} + - name: Create GitHub Release + uses: juitnow/github-action-create-release@v1 + id: create_release + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + with: + tag_name: dmapi-v${{ env.TGS_DM_VERSION }} + release_name: tgstation-server DMAPI v${{ env.TGS_DM_VERSION }} + body: The TGS DMAPI \#tgs-dmapi-release + commitish: ${{ github.event.head_commit.id }} - - name: Upload DMAPI Artifact - uses: actions/upload-release-asset@v1 - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - with: - upload_url: ${{ steps.create_release.outputs.upload_url }} - asset_path: ./DMAPI.zip - asset_name: DMAPI.zip - asset_content_type: application/zip + - name: Upload DMAPI Artifact + uses: actions/upload-release-asset@v1 + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + with: + upload_url: ${{ steps.create_release.outputs.upload_url }} + asset_path: ./DMAPI.zip + asset_name: DMAPI.zip + asset_content_type: application/zip deploy-client: name: Deploy Nuget Packages @@ -626,29 +736,36 @@ jobs: runs-on: ubuntu-latest if: github.event_name == 'push' && contains(github.event.head_commit.message, '[NugetDeploy]') steps: - - name: Setup dotnet - uses: actions/setup-dotnet@v2 - with: - dotnet-version: ${{ env.TGS_DOTNET_VERSION }} + - name: Setup dotnet + uses: actions/setup-dotnet@v2 + with: + dotnet-version: ${{ env.TGS_DOTNET_VERSION }} - - name: Checkout - uses: actions/checkout@v3 + - name: Checkout (Branch Push) + uses: actions/checkout@v3 + if: github.event_name == 'push' - - name: Publish API to NuGet - uses: alirezanet/publish-nuget@v3.0.0 - with: - PROJECT_FILE_PATH: src/Tgstation.Server.Api/Tgstation.Server.Api.csproj - TAG_COMMIT: false - INCLUDE_SYMBOLS: true - NUGET_KEY: ${{ secrets.NUGET_API_KEY }} + - name: Checkout (PR Merge) + uses: actions/checkout@v3 + if: github.event_name != 'push' + with: + ref: "refs/pull/${{ github.event.number }}/merge" - - name: Publish Client to NuGet - uses: alirezanet/publish-nuget@v3.0.0 - with: - PROJECT_FILE_PATH: src/Tgstation.Server.Client/Tgstation.Server.Client.csproj - TAG_COMMIT: false - INCLUDE_SYMBOLS: true - NUGET_KEY: ${{ secrets.NUGET_API_KEY }} + - name: Publish API to NuGet + uses: alirezanet/publish-nuget@v3.0.0 + with: + PROJECT_FILE_PATH: src/Tgstation.Server.Api/Tgstation.Server.Api.csproj + TAG_COMMIT: false + INCLUDE_SYMBOLS: true + NUGET_KEY: ${{ secrets.NUGET_API_KEY }} + + - name: Publish Client to NuGet + uses: alirezanet/publish-nuget@v3.0.0 + with: + PROJECT_FILE_PATH: src/Tgstation.Server.Client/Tgstation.Server.Client.csproj + TAG_COMMIT: false + INCLUDE_SYMBOLS: true + NUGET_KEY: ${{ secrets.NUGET_API_KEY }} ensure-release: name: Ensure TGS Release is Latest GitHub Release @@ -656,16 +773,23 @@ jobs: runs-on: ubuntu-latest if: always() && github.event_name == 'push' && !contains(github.event.head_commit.message, '[TGSDeploy]') && (contains(github.event.head_commit.message, '[APIDeploy]') || contains(github.event.head_commit.message, '[DMDeploy]')) steps: - - name: Setup dotnet - uses: actions/setup-dotnet@v2 - with: - dotnet-version: ${{ env.TGS_DOTNET_VERSION }} + - name: Setup dotnet + uses: actions/setup-dotnet@v2 + with: + dotnet-version: ${{ env.TGS_DOTNET_VERSION }} - - name: Checkout - uses: actions/checkout@v3 + - name: Checkout (Branch Push) + uses: actions/checkout@v3 + if: github.event_name == 'push' - - name: Run ReleaseNotes with --ensure-release - run: dotnet run -c Release --project tools/ReleaseNotes --ensure-release + - name: Checkout (PR Merge) + uses: actions/checkout@v3 + if: github.event_name != 'push' + with: + ref: "refs/pull/${{ github.event.number }}/merge" + + - name: Run ReleaseNotes with --ensure-release + run: dotnet run -c Release --project tools/ReleaseNotes --ensure-release deploy-tgs: name: Deploy TGS @@ -673,136 +797,150 @@ jobs: runs-on: windows-latest if: github.event_name == 'push' && github.event.ref == 'refs/heads/master' && contains(github.event.head_commit.message, '[TGSDeploy]') steps: - - name: Setup dotnet - uses: actions/setup-dotnet@v2 - with: - dotnet-version: ${{ env.TGS_DOTNET_VERSION }} + - name: Setup dotnet + uses: actions/setup-dotnet@v2 + with: + dotnet-version: ${{ env.TGS_DOTNET_VERSION }} - - name: Checkout - uses: actions/checkout@v3 + - name: Checkout (Branch Push) + uses: actions/checkout@v3 + if: github.event_name == 'push' - - name: Parse TGS version - shell: powershell - run: | - [XML]$versionXML = Get-Content build/Version.props - $tgsVersion = $versionXML.Project.PropertyGroup.TgsCoreVersion - echo "TGS_VERSION=$tgsVersion" | Out-File -FilePath $Env:GITHUB_ENV -Encoding utf8 -Append + - name: Checkout (PR Merge) + uses: actions/checkout@v3 + if: github.event_name != 'push' + with: + ref: "refs/pull/${{ github.event.number }}/merge" - - name: Retrieve Server Service - uses: actions/download-artifact@v3 - with: - name: ServerService - path: ServerService + - name: Parse TGS version + shell: powershell + run: | + [XML]$versionXML = Get-Content build/Version.props + $tgsVersion = $versionXML.Project.PropertyGroup.TgsCoreVersion + echo "TGS_VERSION=$tgsVersion" | Out-File -FilePath $Env:GITHUB_ENV -Encoding utf8 -Append - - name: Retrieve Server Console - uses: actions/download-artifact@v3 - with: - name: ServerConsole - path: ServerConsole + - name: Retrieve Server Service + uses: actions/download-artifact@v3 + with: + name: ServerService + path: ServerService - - name: Retrieve Server Update Package - uses: actions/download-artifact@v3 - with: - name: ServerUpdatePackage - path: ServerUpdatePackage + - name: Retrieve Server Console + uses: actions/download-artifact@v3 + with: + name: ServerConsole + path: ServerConsole - - name: Retrieve OpenAPI Spec - uses: actions/download-artifact@v3 - with: - name: openapi-spec - path: swagger + - name: Retrieve Server Update Package + uses: actions/download-artifact@v3 + with: + name: ServerUpdatePackage + path: ServerUpdatePackage - - name: Zip Artifacts - shell: powershell - run: | - &"C:/Program Files/7-Zip/7z.exe" a DMAPI.zip ./src/DMAPI/* -tzip - &"C:/Program Files/7-Zip/7z.exe" a ServerService.zip ./ServerService/* -tzip - &"C:/Program Files/7-Zip/7z.exe" a ServerConsole.zip ./ServerConsole/* -tzip - &"C:/Program Files/7-Zip/7z.exe" a ServerUpdatePackage.zip ./ServerUpdatePackage/* -tzip + - name: Retrieve OpenAPI Spec + uses: actions/download-artifact@v3 + with: + name: openapi-spec + path: swagger - - name: Generate Release Notes - run: dotnet run -c Release --project tools/ReleaseNotes ${{ env.TGS_VERSION }} + - name: Zip Artifacts + shell: powershell + run: | + &"C:/Program Files/7-Zip/7z.exe" a DMAPI.zip ./src/DMAPI/* -tzip + &"C:/Program Files/7-Zip/7z.exe" a ServerService.zip ./ServerService/* -tzip + &"C:/Program Files/7-Zip/7z.exe" a ServerConsole.zip ./ServerConsole/* -tzip + &"C:/Program Files/7-Zip/7z.exe" a ServerUpdatePackage.zip ./ServerUpdatePackage/* -tzip - - name: Create GitHub Release - uses: actions/create-release@v1 - id: create_release - env: - GITHUB_TOKEN: ${{ secrets.DEV_PUSH_TOKEN }} - with: - tag_name: tgstation-server-v${{ env.TGS_VERSION }} - release_name: tgstation-server-v${{ env.TGS_VERSION }} - body_path: release_notes.md - commitish: ${{ github.event.head_commit.id }} + - name: Generate Release Notes + run: dotnet run -c Release --project tools/ReleaseNotes ${{ env.TGS_VERSION }} - - name: Upload Server Console Artifact - uses: actions/upload-release-asset@v1 - env: - GITHUB_TOKEN: ${{ secrets.DEV_PUSH_TOKEN }} - with: - upload_url: ${{ steps.create_release.outputs.upload_url }} - asset_path: ./ServerConsole.zip - asset_name: ServerConsole.zip - asset_content_type: application/zip + - name: Create GitHub Release + uses: actions/create-release@v1 + id: create_release + env: + GITHUB_TOKEN: ${{ secrets.DEV_PUSH_TOKEN }} + with: + tag_name: tgstation-server-v${{ env.TGS_VERSION }} + release_name: tgstation-server-v${{ env.TGS_VERSION }} + body_path: release_notes.md + commitish: ${{ github.event.head_commit.id }} - - name: Upload Server Service Artifact - uses: actions/upload-release-asset@v1 - env: - GITHUB_TOKEN: ${{ secrets.DEV_PUSH_TOKEN }} - with: - upload_url: ${{ steps.create_release.outputs.upload_url }} - asset_path: ./ServerService.zip - asset_name: ServerService.zip - asset_content_type: application/zip + - name: Upload Server Console Artifact + uses: actions/upload-release-asset@v1 + env: + GITHUB_TOKEN: ${{ secrets.DEV_PUSH_TOKEN }} + with: + upload_url: ${{ steps.create_release.outputs.upload_url }} + asset_path: ./ServerConsole.zip + asset_name: ServerConsole.zip + asset_content_type: application/zip - - name: Upload DMAPI Artifact - uses: actions/upload-release-asset@v1 - env: - GITHUB_TOKEN: ${{ secrets.DEV_PUSH_TOKEN }} - with: - upload_url: ${{ steps.create_release.outputs.upload_url }} - asset_path: ./DMAPI.zip - asset_name: DMAPI.zip - asset_content_type: application/zip + - name: Upload Server Service Artifact + uses: actions/upload-release-asset@v1 + env: + GITHUB_TOKEN: ${{ secrets.DEV_PUSH_TOKEN }} + with: + upload_url: ${{ steps.create_release.outputs.upload_url }} + asset_path: ./ServerService.zip + asset_name: ServerService.zip + asset_content_type: application/zip - - name: Upload OpenApi Spec Artifact - uses: actions/upload-release-asset@v1 - env: - GITHUB_TOKEN: ${{ secrets.DEV_PUSH_TOKEN }} - with: - upload_url: ${{ steps.create_release.outputs.upload_url }} - asset_path: ./swagger/swagger.json - asset_name: swagger.json - asset_content_type: application/json + - name: Upload DMAPI Artifact + uses: actions/upload-release-asset@v1 + env: + GITHUB_TOKEN: ${{ secrets.DEV_PUSH_TOKEN }} + with: + upload_url: ${{ steps.create_release.outputs.upload_url }} + asset_path: ./DMAPI.zip + asset_name: DMAPI.zip + asset_content_type: application/zip - - name: Upload Server Update Package Artifact - uses: actions/upload-release-asset@v1 - env: - GITHUB_TOKEN: ${{ secrets.DEV_PUSH_TOKEN }} - with: - upload_url: ${{ steps.create_release.outputs.upload_url }} - asset_path: ./ServerUpdatePackage.zip - asset_name: ServerUpdatePackage.zip - asset_content_type: application/zip + - name: Upload OpenApi Spec Artifact + uses: actions/upload-release-asset@v1 + env: + GITHUB_TOKEN: ${{ secrets.DEV_PUSH_TOKEN }} + with: + upload_url: ${{ steps.create_release.outputs.upload_url }} + asset_path: ./swagger/swagger.json + asset_name: swagger.json + asset_content_type: application/json + + - name: Upload Server Update Package Artifact + uses: actions/upload-release-asset@v1 + env: + GITHUB_TOKEN: ${{ secrets.DEV_PUSH_TOKEN }} + with: + upload_url: ${{ steps.create_release.outputs.upload_url }} + asset_path: ./ServerUpdatePackage.zip + asset_name: ServerUpdatePackage.zip + asset_content_type: application/zip deploy-docker: name: Deploy TGS (Docker) needs: [deploy-tgs] runs-on: ubuntu-latest steps: - - name: Checkout - uses: actions/checkout@v3 + - name: Checkout (Branch Push) + uses: actions/checkout@v3 + if: github.event_name == 'push' - - name: Parse TGS version - run: | - sudo apt-get update - sudo apt-get install -y xmlstarlet - echo "TGS_VERSION=$(xmlstarlet sel -N X="http://schemas.microsoft.com/developer/msbuild/2003" --template --value-of /X:Project/X:PropertyGroup/X:TgsCoreVersion build/Version.props)" >> $GITHUB_ENV + - name: Checkout (PR Merge) + uses: actions/checkout@v3 + if: github.event_name != 'push' + with: + ref: "refs/pull/${{ github.event.number }}/merge" - - name: Docker Build and Push - uses: elgohr/Publish-Docker-Github-Action@v5 - with: - name: tgstation/server - username: ${{ secrets.DOCKER_USERNAME }} - password: ${{ secrets.DOCKER_PASSWORD }} - dockerfile: build/Dockerfile - tags: "latest,v${{ env.TGS_VERSION }}" + - name: Parse TGS version + run: | + sudo apt-get update + sudo apt-get install -y xmlstarlet + echo "TGS_VERSION=$(xmlstarlet sel -N X="http://schemas.microsoft.com/developer/msbuild/2003" --template --value-of /X:Project/X:PropertyGroup/X:TgsCoreVersion build/Version.props)" >> $GITHUB_ENV + + - name: Docker Build and Push + uses: elgohr/Publish-Docker-Github-Action@v5 + with: + name: tgstation/server + username: ${{ secrets.DOCKER_USERNAME }} + password: ${{ secrets.DOCKER_PASSWORD }} + dockerfile: build/Dockerfile + tags: "latest,v${{ env.TGS_VERSION }}" From 6957ccba26ad465b61b2af04387e64f4ac68ae04 Mon Sep 17 00:00:00 2001 From: Dominion Date: Sat, 29 Apr 2023 11:34:12 -0400 Subject: [PATCH 3/9] Use standard pull_request event when working in the same repo --- .github/workflows/ci-suite.yml | 30 ++++++++++++++++++++++-------- 1 file changed, 22 insertions(+), 8 deletions(-) diff --git a/.github/workflows/ci-suite.yml b/.github/workflows/ci-suite.yml index c68d96617e..ab628812d8 100644 --- a/.github/workflows/ci-suite.yml +++ b/.github/workflows/ci-suite.yml @@ -5,6 +5,10 @@ on: branches: - dev - master + pull_request: + branches: + - dev + - master pull_request_target: types: [opened, reopened, labeled, synchronize] branches: @@ -29,26 +33,33 @@ jobs: name: Check CI Clearance needs: security-checkpoint runs-on: ubuntu-latest + if: github.event_name == 'pull_request_target' && github.pull_request.head.repo.id != github.repository.id steps: - name: Comment on new Fork PR - if: github.event_name != 'push' && github.pull_request.head.repo.id != github.repository.id && github.event.action == 'opened' + if: github.event.action == 'opened' && !contains(github.event.pull_request.labels.*.name, 'CI Cleared') uses: thollander/actions-comment-pull-request@v2 with: message: Thank you for contributing to tgstation-server! As this pull request is from a fork, we can't allow the CI actions which require repository secrets to run on it without approval. After a brief review to make sure you're not misusing those secrets, a maintainer will add the `CI Cleared` label to allow the CI suite to run. Maintainers, please note that any changes to workflow files will not be reflected in the CI run. - name: "Remove Stale 'CI Cleared' Label" - if: github.event_name != 'push' && github.pull_request.head.repo.id != github.repository.id && (github.event.action == 'synchronize' || github.event.action == 'reopened') + if: github.event.action == 'synchronize' || github.event.action == 'reopened' uses: actions-ecosystem/action-remove-labels@v1 with: labels: CI Cleared - name: Fail Clearance Check if PR has Unlabeled new Commits from Fork - if: github.event_name != 'push' && github.pull_request.head.repo.id != github.repository.id && (github.event.action != 'labeled' || !contains(github.event.pull_request.labels.*.name, 'CI Cleared')) + if: (github.event.action == 'synchronize' || github.event.action == 'reopened') && !contains(github.event.pull_request.labels.*.name, 'CI Cleared') run: exit 1 + start-ci-run-gate: + name: Start CI Run Gate + needs: security-checkpoint + runs-on: ubuntu-latest + if: always() && (needs.security-check.result == 'success' || needs.security-check.result == 'skipped') + analyze: name: Code Scanning - needs: security-checkpoint + needs: start-ci-run-gate runs-on: ubuntu-latest steps: - name: Install Node 12.X @@ -85,6 +96,7 @@ jobs: dmapi-build: name: Build DMAPI + needs: start-ci-run-gate env: BYOND_MAJOR: 515 BYOND_MINOR: 1592 @@ -141,6 +153,7 @@ jobs: dox-build: name: Build Doxygen Site runs-on: ubuntu-latest + needs: start-ci-run-gate steps: - name: Checkout (Branch Push) uses: actions/checkout@v3 @@ -189,6 +202,7 @@ jobs: docker-build: name: Build Docker Image runs-on: ubuntu-latest + needs: start-ci-run-gate steps: - name: Checkout (Branch Push) uses: actions/checkout@v3 @@ -205,7 +219,7 @@ jobs: linux-unit-tests: name: Linux Tests - needs: security-checkpoint + needs: start-ci-run-gate strategy: fail-fast: false matrix: @@ -244,7 +258,7 @@ jobs: windows-unit-tests: name: Windows Tests - needs: security-checkpoint + needs: start-ci-run-gate strategy: fail-fast: false matrix: @@ -283,7 +297,7 @@ jobs: windows-integration-test: name: Windows Live Tests - needs: [security-checkpoint, dmapi-build] + needs: dmapi-build env: TGS_TEST_DATABASE_TYPE: SqlServer TGS_TEST_DUMP_API_SPEC: yes @@ -362,7 +376,7 @@ jobs: linux-integration-tests: name: Linux Live Tests - needs: [security-checkpoint, dmapi-build] + needs: dmapi-build services: # We start all dbs here so we can just code the stuff once postgres: image: cyberboss/postgres-max-connections # Fork of _/postgres:latest with max_connections=500 becuase GitHub actions service containers have no way to set command lines. Rebuilds with updates. From 3eee1a2b032da94bed56ed7c5b5d2cbcd3dcabcf Mon Sep 17 00:00:00 2001 From: Dominion Date: Sat, 29 Apr 2023 11:35:32 -0400 Subject: [PATCH 4/9] Fix job self-dependency --- .github/workflows/ci-suite.yml | 1 - 1 file changed, 1 deletion(-) diff --git a/.github/workflows/ci-suite.yml b/.github/workflows/ci-suite.yml index ab628812d8..056ef7021e 100644 --- a/.github/workflows/ci-suite.yml +++ b/.github/workflows/ci-suite.yml @@ -31,7 +31,6 @@ concurrency: jobs: security-checkpoint: name: Check CI Clearance - needs: security-checkpoint runs-on: ubuntu-latest if: github.event_name == 'pull_request_target' && github.pull_request.head.repo.id != github.repository.id steps: From 1f073e6ca4a638f93002da98fd0d63a140afc112 Mon Sep 17 00:00:00 2001 From: Dominion Date: Sat, 29 Apr 2023 11:37:11 -0400 Subject: [PATCH 5/9] Fix start-ci-run-gate having no steps --- .github/workflows/ci-suite.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/ci-suite.yml b/.github/workflows/ci-suite.yml index 056ef7021e..11c1dd6b3b 100644 --- a/.github/workflows/ci-suite.yml +++ b/.github/workflows/ci-suite.yml @@ -55,6 +55,9 @@ jobs: needs: security-checkpoint runs-on: ubuntu-latest if: always() && (needs.security-check.result == 'success' || needs.security-check.result == 'skipped') + steps: + - name: GitHub Requires at Least One Step for a Job + run: exit 0 analyze: name: Code Scanning From 7aaa1619b8a99d53874f35335a940e98c992a30a Mon Sep 17 00:00:00 2001 From: Dominion Date: Sat, 29 Apr 2023 11:39:17 -0400 Subject: [PATCH 6/9] Actions doesn't like ternery expressions --- .github/workflows/ci-suite.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/ci-suite.yml b/.github/workflows/ci-suite.yml index 11c1dd6b3b..a1f111c9ff 100644 --- a/.github/workflows/ci-suite.yml +++ b/.github/workflows/ci-suite.yml @@ -25,7 +25,7 @@ env: TGS_RELEASE_NOTES_TOKEN: ${{ secrets.DEV_PUSH_TOKEN }} concurrency: - group: "ci-${{ (github.event_name == 'push' ? github.head_ref : github.event.number) }}" + group: "ci-${{ github.event.number || github.head_ref }}" cancel-in-progress: true jobs: From ab9506895a13e996424b5373e2766cdf8cf23463 Mon Sep 17 00:00:00 2001 From: Dominion Date: Sat, 29 Apr 2023 11:49:54 -0400 Subject: [PATCH 7/9] Fix typo and incorrect conditional in start-ci-run-gate if expression. --- .github/workflows/ci-suite.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/ci-suite.yml b/.github/workflows/ci-suite.yml index a1f111c9ff..4456f2f71e 100644 --- a/.github/workflows/ci-suite.yml +++ b/.github/workflows/ci-suite.yml @@ -54,7 +54,7 @@ jobs: name: Start CI Run Gate needs: security-checkpoint runs-on: ubuntu-latest - if: always() && (needs.security-check.result == 'success' || needs.security-check.result == 'skipped') + if: always() && (needs.security-checkpoint.result == 'success' || (needs.security-checkpoint.result == 'skipped' && (github.event_name == 'push' || github.pull_request.head.repo.id == github.repository.id))) steps: - name: GitHub Requires at Least One Step for a Job run: exit 0 From b96b1cfc0dcd20944dcf3e1b25d290c8ae374845 Mon Sep 17 00:00:00 2001 From: Dominion Date: Sat, 29 Apr 2023 11:53:35 -0400 Subject: [PATCH 8/9] I think the last job might have gotten cancelled because pull_request_target ran simultaneously? --- .github/workflows/ci-suite.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/ci-suite.yml b/.github/workflows/ci-suite.yml index 4456f2f71e..26c92ff1e7 100644 --- a/.github/workflows/ci-suite.yml +++ b/.github/workflows/ci-suite.yml @@ -25,7 +25,7 @@ env: TGS_RELEASE_NOTES_TOKEN: ${{ secrets.DEV_PUSH_TOKEN }} concurrency: - group: "ci-${{ github.event.number || github.head_ref }}" + group: "ci-${{ github.event.number || github.head_ref }}-${{ github.event_name }}" cancel-in-progress: true jobs: From 2aeeff930304fc131e20780c8fefa6ba3977f02a Mon Sep 17 00:00:00 2001 From: Dominion Date: Sat, 29 Apr 2023 12:03:29 -0400 Subject: [PATCH 9/9] Workaround for GitHub runner bug https://github.com/actions/runner/issues/2205 Also fixes ordering of TGS deploy dependencies. The graph is honestly better this way. --- .github/workflows/ci-suite.yml | 23 +++++++++++++++++------ 1 file changed, 17 insertions(+), 6 deletions(-) diff --git a/.github/workflows/ci-suite.yml b/.github/workflows/ci-suite.yml index 26c92ff1e7..4671343bb1 100644 --- a/.github/workflows/ci-suite.yml +++ b/.github/workflows/ci-suite.yml @@ -62,6 +62,7 @@ jobs: analyze: name: Code Scanning needs: start-ci-run-gate + if: always() && needs.start-ci-run-gate.result == 'success' runs-on: ubuntu-latest steps: - name: Install Node 12.X @@ -99,6 +100,7 @@ jobs: dmapi-build: name: Build DMAPI needs: start-ci-run-gate + if: always() && needs.start-ci-run-gate.result == 'success' env: BYOND_MAJOR: 515 BYOND_MINOR: 1592 @@ -156,6 +158,7 @@ jobs: name: Build Doxygen Site runs-on: ubuntu-latest needs: start-ci-run-gate + if: always() && needs.start-ci-run-gate.result == 'success' steps: - name: Checkout (Branch Push) uses: actions/checkout@v3 @@ -205,6 +208,7 @@ jobs: name: Build Docker Image runs-on: ubuntu-latest needs: start-ci-run-gate + if: always() && needs.start-ci-run-gate.result == 'success' steps: - name: Checkout (Branch Push) uses: actions/checkout@v3 @@ -222,6 +226,7 @@ jobs: linux-unit-tests: name: Linux Tests needs: start-ci-run-gate + if: always() && needs.start-ci-run-gate.result == 'success' strategy: fail-fast: false matrix: @@ -261,6 +266,7 @@ jobs: windows-unit-tests: name: Windows Tests needs: start-ci-run-gate + if: always() && needs.start-ci-run-gate.result == 'success' strategy: fail-fast: false matrix: @@ -300,6 +306,7 @@ jobs: windows-integration-test: name: Windows Live Tests needs: dmapi-build + if: always() && needs.dmapi-build.result == 'success' env: TGS_TEST_DATABASE_TYPE: SqlServer TGS_TEST_DUMP_API_SPEC: yes @@ -379,6 +386,7 @@ jobs: linux-integration-tests: name: Linux Live Tests needs: dmapi-build + if: always() && needs.dmapi-build.result == 'success' services: # We start all dbs here so we can just code the stuff once postgres: image: cyberboss/postgres-max-connections # Fork of _/postgres:latest with max_connections=500 becuase GitHub actions service containers have no way to set command lines. Rebuilds with updates. @@ -530,6 +538,7 @@ jobs: validate-openapi-spec: name: OpenAPI Spec Validation needs: windows-integration-test + if: always() && needs.windows-integration-test.result == 'success' runs-on: ubuntu-latest steps: - name: Install Node 12.X @@ -562,6 +571,7 @@ jobs: upload-code-coverage: name: Upload Code Coverage needs: [linux-unit-tests, linux-integration-tests, windows-unit-tests, windows-integration-test] + if: always() && needs.linux-unit-tests.result == 'success' && needs.linux-integration-tests.result == 'success' && needs.windows-unit-tests.result == 'success' && needs.windows-integration-test.result == 'success' runs-on: ubuntu-latest steps: - name: Checkout (Branch Push) @@ -651,7 +661,7 @@ jobs: name: Deploy HTTP API needs: [upload-code-coverage, validate-openapi-spec] runs-on: windows-latest - if: github.event_name == 'push' && contains(github.event.head_commit.message, '[APIDeploy]') + if: always() && needs.upload-code-coverage.result == 'success' && needs.validate-openapi-spec.result == 'success' && github.event_name == 'push' && contains(github.event.head_commit.message, '[APIDeploy]') steps: - name: Checkout (Branch Push) uses: actions/checkout@v3 @@ -701,7 +711,7 @@ jobs: name: Deploy DreamMaker API needs: [upload-code-coverage, validate-openapi-spec] runs-on: windows-latest - if: github.event_name == 'push' && contains(github.event.head_commit.message, '[DMDeploy]') + if: always() && needs.upload-code-coverage.result == 'success' && needs.validate-openapi-spec.result == 'success' && github.event_name == 'push' && contains(github.event.head_commit.message, '[DMDeploy]') steps: - name: Checkout (Branch Push) uses: actions/checkout@v3 @@ -750,7 +760,7 @@ jobs: name: Deploy Nuget Packages needs: [upload-code-coverage, validate-openapi-spec] runs-on: ubuntu-latest - if: github.event_name == 'push' && contains(github.event.head_commit.message, '[NugetDeploy]') + if: always() && needs.upload-code-coverage.result == 'success' && needs.validate-openapi-spec.result == 'success' && github.event_name == 'push' && contains(github.event.head_commit.message, '[NugetDeploy]') steps: - name: Setup dotnet uses: actions/setup-dotnet@v2 @@ -787,7 +797,7 @@ jobs: name: Ensure TGS Release is Latest GitHub Release needs: [deploy-dm, deploy-http] runs-on: ubuntu-latest - if: always() && github.event_name == 'push' && !contains(github.event.head_commit.message, '[TGSDeploy]') && (contains(github.event.head_commit.message, '[APIDeploy]') || contains(github.event.head_commit.message, '[DMDeploy]')) + if: always() && (needs.deploy-dm.result == 'success' || needs.deploy-http.result == 'success') && !contains(github.event.head_commit.message, '[TGSDeploy]') steps: - name: Setup dotnet uses: actions/setup-dotnet@v2 @@ -809,9 +819,9 @@ jobs: deploy-tgs: name: Deploy TGS - needs: [upload-code-coverage, validate-openapi-spec] + needs: [deploy-dm, deploy-http, upload-code-coverage, validate-openapi-spec] runs-on: windows-latest - if: github.event_name == 'push' && github.event.ref == 'refs/heads/master' && contains(github.event.head_commit.message, '[TGSDeploy]') + if: always() && (needs.upload-code-coverage.result == 'success' || needs.validate-openapi-spec.result == 'success') && github.event_name == 'push' && github.event.ref == 'refs/heads/master' && contains(github.event.head_commit.message, '[TGSDeploy]') steps: - name: Setup dotnet uses: actions/setup-dotnet@v2 @@ -934,6 +944,7 @@ jobs: deploy-docker: name: Deploy TGS (Docker) needs: [deploy-tgs] + if: always() && needs.deploy-tgs.result == 'success' runs-on: ubuntu-latest steps: - name: Checkout (Branch Push)