Conversation
|
| name: "Preflight: Schedule, Push, or PR?" | ||
| runs-on: ubuntu-latest | ||
| outputs: | ||
| do-build: ${{ steps.build-check.outputs.do-build }} | ||
| renv-needed: ${{ steps.build-check.outputs.renv-needed }} | ||
| renv-cache-hashsum: ${{ steps.build-check.outputs.renv-cache-hashsum }} | ||
| dependency-image-ref: ${{ steps.build-check.outputs.dependency-image-ref }} | ||
| workbench-container-file-exists: ${{ steps.wb-vers.outputs.workbench-container-file-exists }} | ||
| wb-vers: ${{ steps.wb-vers.outputs.container-version }} | ||
| last-wb-vers: ${{ steps.wb-vers.outputs.last-container-version }} | ||
| workbench-update: ${{ steps.wb-vers.outputs.workbench-update }} | ||
| env: | ||
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | ||
| steps: | ||
| - name: "Should we run build and deploy?" | ||
| id: build-check | ||
| uses: carpentries/actions/build-preflight@v1 | ||
|
|
||
| - name: "Checkout Lesson" | ||
| if: steps.build-check.outputs.do-build == 'true' | ||
| uses: actions/checkout@v6 | ||
|
|
||
| - name: "Get container version info" | ||
| id: wb-vers | ||
| if: steps.build-check.outputs.do-build == 'true' | ||
| uses: carpentries/actions/container-version@v1 | ||
| with: | ||
| WORKBENCH_TAG: ${{ vars.WORKBENCH_TAG }} | ||
| renv-needed: ${{ steps.build-check.outputs.renv-needed }} | ||
| token: ${{ secrets.GITHUB_TOKEN }} | ||
|
|
||
| full-build: |
|
We'll not fix license headers for the moment - let's get the site built first. |
|
@dkfellows - can I get your comment on the suggestions from copilot to limit the GITHUB_TOKEN permissions (and on the general use of the GITHUB_TOKEN)? |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Unsafe artifact interpolation, invalid workflow keys, and unresolved configuration and permission defects prevent secure, reliable execution.
Review effort: Balanced
Findings: 6
Open (15)
Fork merge workflow cannot publish with a read-only token · New Missing keep-count fallback deletes all untagged images · New Documented auto-merge opt-out variable is ignored · New Manual dispatch builds the wrong PR revision · New Untrusted artifact value enables shell command injection · New Unsupported workflow-level description key breaks validation · New Pruning job lacks permission to delete GHCR packages · New CACHE_VERSION override is not forwarded to build-preflight · New WORKBENCH_TAG is not forwarded to image resolution · New PR previews ignore the configured Workbench image tag · New Missing concurrency allows stale previews to overwrite newer ones · New Validation comment job lacks pull request write permission · New Version-only PRs are not skipped by validation · New Empty token prevents package-update PR creation · New Cleanup fallback deletes workflows unexpectedly · New
What changed in this PR
Migrates the lesson’s Carpentries Workbench automation to Docker-based workflows copied from the incubator example.
Changes:
- Replaces site deployment and PR preview workflows with container-based builds.
- Adds dependency-image publication and updates maintenance credentials and controls.
- Updates action references, version markers, and workflow documentation.
| File | Description |
|---|---|
.github/workflows/workflows-version.txt |
Records the workflow release. |
.github/workflows/update-workflows.yaml |
Updates workflow maintenance and authentication. |
.github/workflows/update-cache.yaml |
Updates package maintenance and PR creation. |
.github/workflows/sandpaper-version.txt |
Removes the legacy version marker. |
.github/workflows/sandpaper-main.yaml |
Removes the previous deployment workflow. |
.github/workflows/README.md |
Documents container workflows and configuration. |
.github/workflows/pr-receive.yaml |
Removes the previous PR build workflow. |
.github/workflows/pr-preflight.yaml |
Updates validation action references and runner. |
.github/workflows/pr-post-remove-branch.yaml |
Updates preview cleanup action references. |
.github/workflows/pr-comment.yaml |
Adapts preview commenting and validation. |
.github/workflows/pr-close-signal.yaml |
Updates artifact upload. |
.github/workflows/docker_pr_receive.yaml |
Adds container-based PR preview builds. |
.github/workflows/docker_build_deploy.yaml |
Adds container-based site deployment. |
.github/workflows/docker_apply_cache.yaml |
Adds dependency-image publication and pruning. |
.github/workbench-docker-version.txt |
Records the Workbench container version. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| required: false | ||
| default: 1 | ||
| type: number | ||
| pull_request: |
| uses: carpentries/actions/record-container-version@v1 | ||
| with: | ||
| CONTAINER_VER: ${{ needs.preflight.outputs.wb-vers }} | ||
| AUTO_MERGE: ${{ vars.AUTO_MERGE_CONTAINER_VERSION_UPDATE || 'true' }} |
| outputs: | ||
| build-site: ${{ steps.build-site.outcome }} | ||
| steps: | ||
| - uses: actions/checkout@v6 |
| env: | ||
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | ||
| run: | | ||
| ## Get list of changed files in the PR ## | ||
| ONLY_VERSION=$(gh pr view ${{ steps.get-pr.outputs.NUM }} --json files --jq ' |
| workflows: ["Bot: Receive Pull Request"] | ||
| types: | ||
| - completed |
| if: > | ||
| github.event.workflow_run.event == 'pull_request' && | ||
| github.event.workflow_run.conclusion == 'success' | ||
| runs-on: ubuntu-latest |
| id: check-pr | ||
| if: ${{ steps.dl.outputs.success == 'true' }} | ||
| uses: carpentries/actions/check-valid-pr@main | ||
| uses: carpentries/actions/check-valid-pr@v1 |
Changes were made to copyright noticesThere are copyright updates on the (temporary) add-license-headers-to-2-fix-build-failure-for-course-notes-2026-10-02-15-47-28 branch. Please review and merge, or add further commits (this branch will be deleted). |


I've copied across the workflow files from https://github.com/carpentries-incubator/python-intermediate-development - where I know that these do work.
Question will be, what do we need to add to get them to work here...