Parent directory

dependencies.yml

1555 bytes
 1name: Update dependencies
 2on:
 3  workflow_dispatch: {}
 4  schedule:
 5    - cron: "0 6 * * 0"
 6
 7permissions:
 8  contents: read
 9
10jobs:
11  check:
12    name: Check for updates
13    runs-on: ubuntu-latest
14    if: github.repository == 'ohmyzsh/ohmyzsh'
15    permissions:
16      contents: write # this is needed to push commits and branches
17    steps:
18      - name: Harden the runner (Audit all outbound calls)
19        uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
20        with:
21          egress-policy: audit
22
23      - name: Checkout
24        uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
25        with:
26          fetch-depth: 0
27      - name: Authenticate as @ohmyzsh
28        id: generate-token
29        uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
30        with:
31          client-id: ${{ secrets.OHMYZSH_CLIENT_ID }}
32          private-key: ${{ secrets.OHMYZSH_APP_PRIVATE_KEY }}
33      - name: Setup Python
34        uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
35        with:
36          python-version: "3.12"
37          cache: "pip"
38      - name: Process dependencies
39        env:
40          GH_TOKEN: ${{ steps.generate-token.outputs.token }}
41          GIT_APP_NAME: ohmyzsh[bot]
42          GIT_APP_EMAIL: 54982679+ohmyzsh[bot]@users.noreply.github.com
43          TMP_DIR: ${{ runner.temp }}
44        run: |
45          pip install -r .github/workflows/dependencies/requirements.txt
46          python3 .github/workflows/dependencies/updater.py