Skip to content

g1t/packages/contracts/src/updates.ts

165 lines4,657 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar1/**
2 * Dependency updates: the file that asks for them, written in
3 * `dependabot.yml` (version 2) syntax, and the pull requests g1t opens from
4 * it. Mirrors `g1t_contracts::updates`.
5 */
6
7/** Where the dependency update file may be, in the order it is looked for. */
8export const DEPENDABOT_PATHS = [
9 ".g1t/dependabot.yml",
10 ".g1t/dependabot.yaml",
11 ".github/dependabot.yml",
12 ".github/dependabot.yaml",
13] as const;
14
15/** The status a pull request that changes the file gets on its head. */
16export const DEPENDABOT_CHECK = "g1t / dependabot.yml";
17
18/** One thing wrong with the dependency update file, and where. */
19export type ConfigProblem = {
20 /** 1-based; 0 when the problem is with the file as a whole. */
21 line: number;
22 column: number;
23 /** The key it is about: `updates[0].schedule.interval`. */
24 key: string;
25 message: string;
26};
27
28/** A `groups` rule. */
29export type UpdateGroup = {
30 name: string;
31 /** `version-updates` or `security-updates`. */
32 appliesTo: string;
33 patterns: string[];
34 excludePatterns: string[];
35 /** `major`, `minor`, `patch`; every one when empty. */
36 updateTypes: string[];
37 dependencyType: string | null;
38 groupBy: string | null;
39};
40
41/** An `ignore` rule. */
42export type UpdateIgnore = {
43 dependency: string;
44 versions: string[];
45 updateTypes: string[];
46};
47
48/** An `allow` rule. */
49export type UpdateAllow = {
50 dependency: string | null;
51 dependencyType: string | null;
52 updateTypes: string[];
53};
54
55/** One entry of the file's `updates`, and where its version updates stand. */
56export type VersionUpdateEntry = {
57 /** What "Check for updates" names. */
58 id: string;
59 /** `package-ecosystem`, as written. */
60 ecosystem: string;
61 directories: string[];
62 /** Whether g1t opens version update pull requests for this ecosystem. */
63 supported: boolean;
64 interval: string;
65 /** The schedule in words: "Weekdays at 05:00 (UTC)". */
66 schedule: string;
67 openPullRequestsLimit: number;
68 targetBranch: string | null;
69 multiEcosystemGroup: string | null;
70 groups: UpdateGroup[];
71 ignore: UpdateIgnore[];
72 allow: UpdateAllow[];
73 /** Null for the default labels; empty for none. */
74 labels: string[] | null;
75 assignees: string[];
76 reviewers: string[];
77 milestone: number | null;
78 versioningStrategy: string | null;
79 /** The entry as read, with the file's own key names. */
80 options: Record<string, unknown>;
81 /** Options g1t reads but does not act on, each with why. */
82 notes: string[];
83 nextRunAt: string | null;
84 lastCheckedAt: string | null;
85 lastResult: string | null;
86 lastError: string | null;
87};
88
89/** A private registry from the file, without its credentials. */
90export type UpdateRegistry = {
91 name: string;
92 kind: string;
93 url: string;
94 /** The secrets its credentials name. */
95 secrets: string[];
96};
97
98/** One dependency an update pull request raises. */
99export type UpdatedDependency = {
100 name: string;
101 from: string;
102 to: string;
103 directory: string;
104 dependencyType: string;
105 updateType: string;
106};
107
108/** A pull request g1t opened, or is making, to update dependencies. */
109export type UpdatePull = {
110 kind: "version" | "security";
111 entry: string;
112 ecosystem: string;
113 group: string | null;
114 branch: string;
115 title: string;
116 state: "requested" | "open" | "merged" | "closed" | "superseded" | "needs_code" | "failed";
117 pull: number | null;
118 dependencies: UpdatedDependency[];
119 mergeRequestedBy: string | null;
120 error: string | null;
121 updatedAt: string;
122};
123
124/** A dependency, or some of its versions, skipped because someone said so in a comment. */
125export type IgnoreCondition = {
126 ecosystem: string;
127 dependency: string;
128 versions: string | null;
129 updateType: string | null;
130 by: string;
131 pull: number | null;
132 at: string;
133};
134
135/** What the dependency update file asks for, as last read from the default branch. */
136export type VersionUpdatesState = {
137 found: boolean;
138 /** The file read. */
139 path: string | null;
140 /** Other dependency update files, not read because `path` comes first. */
141 ignoredPaths: string[];
142 /** The first problem, as a sentence. */
143 error: string | null;
144 problems: ConfigProblem[];
145 updates: VersionUpdateEntry[];
146 registries: UpdateRegistry[];
147 readAt: string | null;
148 commit: string | null;
149 pulls: UpdatePull[];
150 ignores: IgnoreCondition[];
151};
152
153/** One package of a grouped `bump`. */
154export type BumpPackage = { package: string; version: string };
155
156/** A private registry a `bump` sandbox's tools may read, with its credentials. */
157export type BumpRegistry = {
158 type: string;
159 url: string;
160 username?: string;
161 password?: string;
162 token?: string;
163 replacesBase?: boolean;
164 scopes?: string[];
165};