mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-06 21:05:21 +02:00
## Thinking Path Paid cells now reuse the AWS image's system Chrome, but Playwright video recording still resolves its revision-pinned FFmpeg helper from the Playwright cache. Run 33875618534 proved Chrome qualification succeeds and then failed before provider startup because that helper was absent. The same run also exposed that generic lock repair can churn unrelated package platform metadata, so the automated repair paths need resolution-only regeneration rather than lockfile-only metadata refresh. ## What Changed - install Playwright FFmpeg only on the AWS/system-Chrome path - retry the small helper installation up to three times before provider secrets are exposed - keep the GitHub-hosted Chromium fallback unchanged - bind static coverage to the exact FFmpeg step block and its pre-secret ordering - add pnpm `--resolution-only` to all four automated lock-repair paths while retaining full transitive resolution - require resolution-only repair in the shared workflow regression The actual generated lockfile correction remains bot-owned by PR #12828 and is intentionally not committed here. ## Verification - `node --test .github/scripts/tests/lockfile-refresh-workflows.test.mjs` - `actionlint -ignore SC2012` on all modified workflows - focused Prettier checks - `git diff --check` - prior run 33875618534: system Chrome 151 qualified; missing Playwright FFmpeg was the sole cell startup failure ## Risks Low. The new network operation is limited to Playwright's pinned FFmpeg payload, happens before paid credentials are exposed, and leaves the hosted-runner path unchanged. Resolution-only is still a full dependency-resolution pass, unlike lockfile-only, while avoiding unrelated current-platform metadata churn. ## Model Used GPT-5
97 lines
2.9 KiB
YAML
97 lines
2.9 KiB
YAML
name: Refresh Lockfile
|
|
|
|
on:
|
|
push:
|
|
branches:
|
|
- master
|
|
workflow_dispatch:
|
|
|
|
concurrency:
|
|
group: refresh-lockfile-master
|
|
cancel-in-progress: false
|
|
|
|
jobs:
|
|
refresh:
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 10
|
|
permissions:
|
|
contents: write
|
|
pull-requests: write
|
|
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@v7
|
|
|
|
- name: Setup pnpm
|
|
uses: pnpm/action-setup@v6
|
|
with:
|
|
version: 9.15.4
|
|
run_install: false
|
|
|
|
- name: Setup Node.js
|
|
uses: actions/setup-node@v7
|
|
with:
|
|
node-version: 24
|
|
cache: pnpm
|
|
|
|
- name: Refresh pnpm lockfile
|
|
run: pnpm install --resolution-only --ignore-scripts --no-frozen-lockfile
|
|
|
|
- name: Fail on unexpected file changes
|
|
run: |
|
|
changed="$(git status --porcelain)"
|
|
if [ -z "$changed" ]; then
|
|
echo "Lockfile is already up to date."
|
|
exit 0
|
|
fi
|
|
if printf '%s\n' "$changed" | grep -Fvq ' pnpm-lock.yaml'; then
|
|
echo "Unexpected files changed during lockfile refresh:"
|
|
echo "$changed"
|
|
exit 1
|
|
fi
|
|
|
|
- name: Create or update pull request
|
|
id: upsert-pr
|
|
env:
|
|
GH_TOKEN: ${{ github.token }}
|
|
REPO_OWNER: ${{ github.repository_owner }}
|
|
run: |
|
|
if git diff --quiet -- pnpm-lock.yaml; then
|
|
echo "Lockfile unchanged, nothing to do."
|
|
echo "pr_url=" >> "$GITHUB_OUTPUT"
|
|
exit 0
|
|
fi
|
|
|
|
BRANCH="chore/refresh-lockfile"
|
|
git config user.name "lockfile-bot"
|
|
git config user.email "lockfile-bot@users.noreply.github.com"
|
|
|
|
git checkout -B "$BRANCH"
|
|
git add pnpm-lock.yaml
|
|
git commit -m "chore(lockfile): refresh pnpm-lock.yaml"
|
|
git push --force origin "$BRANCH"
|
|
|
|
# Only reuse an open PR from this repository owner, not a fork with the same branch name.
|
|
pr_url="$(
|
|
gh pr list --state open --head "$BRANCH" --json url,headRepositoryOwner \
|
|
--jq ".[] | select(.headRepositoryOwner.login == \"$REPO_OWNER\") | .url" |
|
|
head -n 1
|
|
)"
|
|
if [ -z "$pr_url" ]; then
|
|
pr_url="$(gh pr create \
|
|
--head "$BRANCH" \
|
|
--title "chore(lockfile): refresh pnpm-lock.yaml" \
|
|
--body "Auto-generated lockfile refresh after dependencies changed on master. This PR only updates pnpm-lock.yaml.")"
|
|
echo "Created new PR: $pr_url"
|
|
else
|
|
echo "PR already exists: $pr_url"
|
|
fi
|
|
echo "pr_url=$pr_url" >> "$GITHUB_OUTPUT"
|
|
|
|
- name: Enable auto-merge for lockfile PR
|
|
if: steps.upsert-pr.outputs.pr_url != ''
|
|
env:
|
|
GH_TOKEN: ${{ github.token }}
|
|
run: |
|
|
gh pr merge --auto --squash --delete-branch "${{ steps.upsert-pr.outputs.pr_url }}"
|