mirror of
https://github.com/Mic92/sops-nix.git
synced 2024-12-14 11:57:52 +00:00
add scripts to update vendorHash
This commit is contained in:
parent
62a7c95c8c
commit
3c851dbbea
2 changed files with 45 additions and 0 deletions
28
.github/workflows/dependabot.yml
vendored
Normal file
28
.github/workflows/dependabot.yml
vendored
Normal file
|
@ -0,0 +1,28 @@
|
|||
name: Update vendorSha256
|
||||
on: pull_request
|
||||
|
||||
permissions:
|
||||
contents: write
|
||||
|
||||
jobs:
|
||||
dependabot:
|
||||
runs-on: ubuntu-latest
|
||||
if: ${{ github.actor == 'dependabot[bot]' }}
|
||||
steps:
|
||||
- uses: actions/checkout@v3
|
||||
with:
|
||||
fetch-depth: 0
|
||||
- name: Install Nix
|
||||
uses: cachix/install-nix-action@v22
|
||||
with:
|
||||
github_access_token: ${{ secrets.GITHUB_TOKEN }}
|
||||
nix_path: nixpkgs=channel:nixos-unstable
|
||||
- name: Update checksum
|
||||
run: |
|
||||
./scripts/update-vendor-hash.sh
|
||||
# git push if we have a diff
|
||||
if [[ -n $(git diff) ]]; then
|
||||
git add default.nix
|
||||
git commit -m "update vendorHash"
|
||||
git push
|
||||
fi
|
17
scripts/update-vendor-hash.sh
Executable file
17
scripts/update-vendor-hash.sh
Executable file
|
@ -0,0 +1,17 @@
|
|||
#!/usr/bin/env nix-shell
|
||||
#!nix-shell -i bash -p nix -p coreutils -p gnused -p gawk
|
||||
|
||||
set -exuo pipefail
|
||||
|
||||
failedbuild=$(nix build --impure --expr '(with import <nixpkgs> {}; pkgs.callPackage ./. { vendorHash = ""; }).sops-install-secrets' 2>&1 || true)
|
||||
echo "$failedbuild"
|
||||
checksum=$(echo "$failedbuild" | awk '/got:.*sha256/ { print $2 }')
|
||||
sed -i -e "s|vendorHash ? \".*\"|vendorHash ? \"$checksum\"|" default.nix
|
||||
|
||||
# git push if we have a diff
|
||||
if [[ -n $(git diff) ]]; then
|
||||
git add default.nix
|
||||
git commit -m "sops-install-secrets: update checksum to $checksum"
|
||||
git push
|
||||
fi
|
||||
|
Loading…
Reference in a new issue