Skip to content

update to carpentry workflows from incubator example - #3

Open
douglowe wants to merge 5 commits into
mainfrom
2-fix-build-failure-for-course-notes
Open

douglowe wants to merge 5 commits into
mainfrom
2-fix-build-failure-for-course-notes

Conversation

@douglowe

@douglowe douglowe commented Oct 2, 2026

Copy link
Copy Markdown
Member

I've copied across the workflow files from https://github.com/carpentries-incubator/python-intermediate-development - where I know that these do work.

Question will be, what do we need to add to get them to work here...

Copilot AI balanced review requested due to automatic review settings October 2, 2026 14:13
@douglowe douglowe linked an issue Oct 2, 2026 that may be closed by this pull request
@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

⚠️ WARNING ⚠️

This pull request contains a mix of workflow files and regular files. This could be malicious. No preview will be created.

regular files:

  • .github/workbench-docker-version.txt
  • .github/workflows/README.md
  • .github/workflows/sandpaper-version.txt
  • .github/workflows/workflows-version.txt
  • episodes/introduction.Rmd
  • renv/activate.R
  • renv/profile
  • renv/profiles/lesson-requirements/renv.lock
  • renv/profiles/lesson-requirements/renv/.gitignore
  • renv/profiles/lesson-requirements/renv/settings.json

workflow files:

  • .github/workflows/docker_build_deploy.yaml
  • .github/workflows/docker_pr_receive.yaml
  • .github/workflows/pr-close-signal.yaml
  • .github/workflows/pr-comment.yaml
  • .github/workflows/pr-post-remove-branch.yaml
  • .github/workflows/pr-preflight.yaml
  • .github/workflows/pr-receive.yaml
  • .github/workflows/sandpaper-main.yaml
  • .github/workflows/update-cache.yaml
  • .github/workflows/update-workflows.yaml

Comment thread .github/workflows/docker_apply_cache.yaml Fixed
Comment thread .github/workflows/docker_apply_cache.yaml Fixed
Comment thread .github/workflows/docker_apply_cache.yaml Fixed
Comment thread .github/workflows/docker_apply_cache.yaml Fixed
Comment thread .github/workflows/docker_apply_cache.yaml Fixed
Comment on lines +45 to +76
name: "Preflight: Schedule, Push, or PR?"
runs-on: ubuntu-latest
outputs:
do-build: ${{ steps.build-check.outputs.do-build }}
renv-needed: ${{ steps.build-check.outputs.renv-needed }}
renv-cache-hashsum: ${{ steps.build-check.outputs.renv-cache-hashsum }}
dependency-image-ref: ${{ steps.build-check.outputs.dependency-image-ref }}
workbench-container-file-exists: ${{ steps.wb-vers.outputs.workbench-container-file-exists }}
wb-vers: ${{ steps.wb-vers.outputs.container-version }}
last-wb-vers: ${{ steps.wb-vers.outputs.last-container-version }}
workbench-update: ${{ steps.wb-vers.outputs.workbench-update }}
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
steps:
- name: "Should we run build and deploy?"
id: build-check
uses: carpentries/actions/build-preflight@v1

- name: "Checkout Lesson"
if: steps.build-check.outputs.do-build == 'true'
uses: actions/checkout@v6

- name: "Get container version info"
id: wb-vers
if: steps.build-check.outputs.do-build == 'true'
uses: carpentries/actions/container-version@v1
with:
WORKBENCH_TAG: ${{ vars.WORKBENCH_TAG }}
renv-needed: ${{ steps.build-check.outputs.renv-needed }}
token: ${{ secrets.GITHUB_TOKEN }}

full-build:
Comment thread .github/workflows/update-cache.yaml Fixed
@douglowe

douglowe commented Oct 2, 2026

Copy link
Copy Markdown
Member Author

We'll not fix license headers for the moment - let's get the site built first.

@douglowe
douglowe requested a review from dkfellows October 2, 2026 14:19
@douglowe

douglowe commented Oct 2, 2026

Copy link
Copy Markdown
Member Author

@dkfellows - can I get your comment on the suggestions from copilot to limit the GITHUB_TOKEN permissions (and on the general use of the GITHUB_TOKEN)?

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Unsafe artifact interpolation, invalid workflow keys, and unresolved configuration and permission defects prevent secure, reliable execution.

Review effort: Balanced
Findings: 6 High severity · 9 Medium severity

Open (15)
What changed in this PR

Migrates the lesson’s Carpentries Workbench automation to Docker-based workflows copied from the incubator example.

Changes:

  • Replaces site deployment and PR preview workflows with container-based builds.
  • Adds dependency-image publication and updates maintenance credentials and controls.
  • Updates action references, version markers, and workflow documentation.
File Description
.github/​workflows/​workflows-version.txt Records the workflow release.
.github/​workflows/​update-workflows.yaml Updates workflow maintenance and authentication.
.github/​workflows/​update-cache.yaml Updates package maintenance and PR creation.
.github/​workflows/​sandpaper-version.txt Removes the legacy version marker.
.github/​workflows/​sandpaper-main.yaml Removes the previous deployment workflow.
.github/​workflows/​README.md Documents container workflows and configuration.
.github/​workflows/​pr-receive.yaml Removes the previous PR build workflow.
.github/​workflows/​pr-preflight.yaml Updates validation action references and runner.
.github/​workflows/​pr-post-remove-branch.yaml Updates preview cleanup action references.
.github/​workflows/​pr-comment.yaml Adapts preview commenting and validation.
.github/​workflows/​pr-close-signal.yaml Updates artifact upload.
.github/​workflows/​docker_pr_receive.yaml Adds container-based PR preview builds.
.github/​workflows/​docker_build_deploy.yaml Adds container-based site deployment.
.github/​workflows/​docker_apply_cache.yaml Adds dependency-image publication and pruning.
.github/​workbench-docker-version.txt Records the Workbench container version.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

required: false
default: 1
type: number
pull_request:
Comment thread .github/workflows/docker_apply_cache.yaml Outdated
uses: carpentries/actions/record-container-version@v1
with:
CONTAINER_VER: ${{ needs.preflight.outputs.wb-vers }}
AUTO_MERGE: ${{ vars.AUTO_MERGE_CONTAINER_VERSION_UPDATE || 'true' }}
outputs:
build-site: ${{ steps.build-site.outcome }}
steps:
- uses: actions/checkout@v6
Comment on lines +49 to +53
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
## Get list of changed files in the PR ##
ONLY_VERSION=$(gh pr view ${{ steps.get-pr.outputs.NUM }} --json files --jq '
Comment on lines +5 to 7
workflows: ["Bot: Receive Pull Request"]
types:
- completed
if: >
github.event.workflow_run.event == 'pull_request' &&
github.event.workflow_run.conclusion == 'success'
runs-on: ubuntu-latest
id: check-pr
if: ${{ steps.dl.outputs.success == 'true' }}
uses: carpentries/actions/check-valid-pr@main
uses: carpentries/actions/check-valid-pr@v1
Comment thread .github/workflows/update-cache.yaml Outdated
Comment thread .github/workflows/update-workflows.yaml Outdated
@douglowe douglowe self-assigned this Oct 2, 2026
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown

Changes were made to copyright notices

There are copyright updates on the (temporary) add-license-headers-to-2-fix-build-failure-for-course-notes-2026-10-02-15-47-28 branch. Please review and merge, or add further commits (this branch will be deleted).

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Fix build failure for course notes

3 participants