Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 3 additions & 2 deletions .devcontainer/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# To find available Node images, see https://mcr.microsoft.com/en-us/product/devcontainers/javascript-node/tags
# Update ARG and FROM together from the Node devcontainer image tags:
# https://mcr.microsoft.com/en-us/product/devcontainers/javascript-node/tags
ARG VARIANT=dev-24-bookworm
FROM mcr.microsoft.com/devcontainers/javascript-node:dev-24-bookworm@sha256:c6c609fc8c4e9418991aae295debc1f4f94f000f4cc7ca5531446f1ea8258056
FROM mcr.microsoft.com/devcontainers/javascript-node:dev-24-bookworm@sha256:c39e4aaf0c7c4da594f845aeb98d37510343bff178b320a6f7e9e2e95ca7957e
10 changes: 2 additions & 8 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -1,10 +1,4 @@
# Order is important. The LAST matching pattern has the MOST precedence.
# gitignore style patterns are used, not globs.
# https://docs.github.com/articles/about-codeowners
# https://git-scm.com/docs/gitignore
# Last matching pattern wins.
# Patterns use gitignore syntax, not glob syntax.

# Site Policy
content/site-policy/ @github/site-policy-admins

# Requires review of #actions-oidc-integration, docs-engineering/issues/1506
# content/actions/deployment/security-hardening-your-deployments/** @github/oidc
7 changes: 4 additions & 3 deletions .github/actions/cache-nextjs/action.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
# Based on https://nextjs.org/docs/pages/building-your-application/deploying/ci-build-caching#github-actions
# Based on Next.js CI build cache guidance:
# https://nextjs.org/docs/pages/building-your-application/deploying/ci-build-caching#github-actions

name: Cache Nextjs build cache

Expand All @@ -11,8 +12,8 @@ runs:
uses: actions/cache@v4
with:
path: ${{ github.workspace }}/.next/cache
# Generate a new cache whenever packages or source files change.
# Packages and source files both invalidate the cache.
key: ${{ runner.os }}-nextjs-${{ hashFiles('**/package-lock.json') }}-${{ hashFiles('**/*.ts', '**/*.tsx') }}
# If source files changed but packages didn't, rebuild from a prior cache.
# With matching restore-key prefixes, source-only changes restore the same-package cache.
restore-keys: |
${{ runner.os }}-nextjs-${{ hashFiles('**/package-lock.json') }}-
4 changes: 1 addition & 3 deletions .github/actions/create-workflow-failure-issue/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -104,8 +104,6 @@ runs:
--body "$body")
echo "issue_url=$url" >> "$GITHUB_OUTPUT"
# Set the type separately, and tolerate failure. This action is itself the
# failure path, so losing the whole issue because issue types are unavailable
# or `gh` is too old (--type needs gh 2.94+) would hide the original failure.
# Set type separately with gh 2.94+ --type; keep the issue visible if gh or issue types lack support.
gh issue edit "$url" --type Bug \
|| echo "Warning: could not set issue type on $url; leaving it unset."
20 changes: 3 additions & 17 deletions .github/actions/labeler/labeler.ts
Original file line number Diff line number Diff line change
@@ -1,5 +1,3 @@
/* See function main in this file for documentation */

import * as coreLib from '@actions/core'
import { type Octokit } from '@octokit/rest'
import { CoreInject } from '@/links/scripts/action-injections'
Expand All @@ -18,7 +16,7 @@ type Options = {
repo?: string
}

// When this file is invoked directly from action as opposed to being imported
// Run action wiring only for direct execution, not imports from tests or other code.
if (import.meta.url.endsWith(process.argv[1])) {
if (!process.env.GITHUB_TOKEN) {
throw new Error('You must set the GITHUB_TOKEN environment variable.')
Expand All @@ -33,7 +31,7 @@ if (import.meta.url.endsWith(process.argv[1])) {
ignoreIfLabeled: boolEnvVar('IGNORE_IF_LABELED'),
}

// labels come in comma separated from actions
// Actions pass comma-separated labels.
if (typeof ADD_LABELS === 'string') {
opts.addLabels = [...ADD_LABELS.split(',')].map((l) => l.trim())
} else {
Expand All @@ -60,18 +58,6 @@ if (import.meta.url.endsWith(process.argv[1])) {
main(coreLib, octokit, opts)
}

/*
* Applies labels to an issue or pull request.
*
* opts:
* issue_number {number} id of the issue or pull request to label
* owner {string} owner of the repository
* repo {string} repository name
* addLabels {Array<string>} array of labels to apply
* removeLabels {Array<string>} array of labels to remove
* ignoreIfAssigned {boolean} don't apply labels if there are assignees
* ignoreIfLabeled {boolean} don't apply labels if there are already labels added
*/
export default async function main(
core: typeof coreLib | CoreInject,
octokit: Octokit,
Expand Down Expand Up @@ -118,7 +104,7 @@ export default async function main(
}

if (opts.removeLabels?.length) {
// removing a label fails if the label isn't already applied
// Remove only applied labels because the API rejects missing labels.
let appliedLabels = []

try {
Expand Down
3 changes: 1 addition & 2 deletions .github/actions/node-npm-setup/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,8 +9,7 @@ runs:
uses: actions/cache@v4
id: cache-node_modules
env:
# Default is 10 min, per segment, but we can make it much smaller
# because it's not the end of the world if the cache restore fails.
# Cache restore failures are acceptable, so keep the segment timeout short.
SEGMENT_DOWNLOAD_TIMEOUT_MINS: '1'
with:
path: node_modules
Expand Down
44 changes: 0 additions & 44 deletions .github/actions/precompute-pageinfo/action.yml

This file was deleted.

1 change: 0 additions & 1 deletion .github/actions/retry-command/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,6 @@ runs:
INPUT_DELAY: ${{ inputs.delay }}
INPUT_COMMAND: ${{ inputs.command }}
run: |
# Generic retry function: configurable attempts and delay
retry_command() {
local max_attempts=${INPUT_MAX_ATTEMPTS}
local delay=${INPUT_DELAY}
Expand Down
10 changes: 4 additions & 6 deletions .github/actions/setup-elasticsearch/action.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
# For the sake of saving time, only run this step if the test-group is one that will run tests against an Elasticsearch on localhost.
# Callers skip this action for test groups that do not use local Elasticsearch.
name: Set up local Elasticsearch

description: Install a local Elasticsearch with version that matches prod
Expand All @@ -10,13 +10,13 @@ inputs:
elasticsearch_version:
description: Version of Elasticsearch to install
required: true
# Make sure the version matches production and is available on Docker Hub
# Version must match production and be published on Docker Hub.
default: '8.12.0'

runs:
using: 'composite'
steps:
# Cache the elasticsearch image to prevent Docker Hub rate limiting
# Cache the Elasticsearch image to prevent Docker Hub rate limits.
- name: Cache Docker layers
id: cache-docker-layers
uses: actions/cache@v4
Expand Down Expand Up @@ -47,8 +47,7 @@ runs:
mkdir -p /tmp/docker-cache
docker save -o /tmp/docker-cache/elasticsearch.tar elasticsearch:${ES_VERSION}
# Setups the Elasticsearch container
# Derived from https://github.com/getong/elasticsearch-action
# Run a single-node container with settings copied from getong/elasticsearch-action.
- name: Run Docker container
shell: bash
env:
Expand Down Expand Up @@ -80,7 +79,6 @@ runs:
-e discovery_type=$INPUT_DISCOVERY_TYPE \
elasticsearch:$INPUT_ELASTICSEARCH_VERSION
# Check if Elasticsearch is up and running
for i in {1..120}; do
if curl --silent --fail http://localhost:9200; then
echo "Elasticsearch is up and running"
Expand Down
10 changes: 4 additions & 6 deletions .github/actions/slack-alert/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -27,9 +27,8 @@ inputs:
runs:
using: composite
steps:
# Build the Slack text here so the default message can be multi-line (real
# newlines) and conditionally include the issue link. A caller-supplied
# message is passed through verbatim for backward compatibility.
# Build default Slack text in shell so it can include real newlines and an issue link.
# Caller-supplied messages pass through unchanged for backward compatibility.
- name: Build Slack message
id: build
shell: bash
Expand All @@ -43,10 +42,9 @@ runs:
GIT_REF: ${{ github.ref }}
ACTOR: ${{ github.actor }}
run: |
# Escape Slack mrkdwn control chars in interpolated context fields so a
# crafted branch/ref (e.g. containing <!channel>) can't inject mentions.
# Escape generated fields so branch/ref text like <!channel> cannot inject Slack mentions.
esc() { printf '%s' "$1" | sed -e 's/&/\&amp;/g' -e 's/</\&lt;/g' -e 's/>/\&gt;/g'; }
# Unique heredoc delimiter so a custom message can't collide with it.
# Pick a unique heredoc delimiter so custom messages cannot collide with it.
delim="SLACK_EOF_${RANDOM}${RANDOM}"
{
printf 'text<<%s\n' "$delim"
Expand Down
14 changes: 3 additions & 11 deletions .github/actions/warmup-remotejson-cache/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,24 +10,16 @@ inputs:
runs:
using: 'composite'
steps:
# The caching technique here is to unboundedly add and add to the cache.
# You "wrap" the step that appends to disk and it will possibly retrieve
# some from the cache, then save it when it's got more in it.
# Restore a stable key, add to the cache, then save by SHA so the cache can grow without bound.
- name: Cache .remotejson-cache (restore)
uses: actions/cache/restore@v4
with:
path: .remotejson-cache
key: remotejson-cache-
restore-keys: remotejson-cache-

# When we use this composite action from deployment workflows
# we don't have any Node installed or any of its packages. I.e. we never
# run `npm ci` in those actions. For security sake.
# So we can't do things that require Node code.
# Tests and others will omit the `restore-only` input, but
# prepping for Docker build and push, will set it to a non-empty
# string which basically means "If you can restore it, great.
# If not, that's fine, don't bother".
# Deployment workflows never run npm ci for security.
# restore-only can only restore an existing cache there.
- name: Run script
if: ${{ inputs.restore-only == '' }}
shell: bash
Expand Down
6 changes: 1 addition & 5 deletions .github/config.yml
Original file line number Diff line number Diff line change
@@ -1,11 +1,7 @@
# Configuration for welcome - https://github.com/behaviorbot/welcome
# Behaviorbot welcome configuration: https://github.com/behaviorbot/welcome

# Configuration for new-issue-welcome - https://github.com/behaviorbot/new-issue-welcome
# Comment to be posted to on first time issues
newIssueWelcomeComment: >
Thanks for opening this issue. A GitHub docs team member should be by to give feedback soon. In the meantime, please check out the [contributing guidelines](https://docs.github.com/en/contributing).
# Configuration for new-pr-welcome - https://github.com/behaviorbot/new-pr-welcome
# Comment to be posted to on PRs from first time contributors in your repository
newPRWelcomeComment: >
Thanks for opening this pull request! A GitHub docs team member should be by to give feedback soon. In the meantime, please check out the [contributing guidelines](https://docs.github.com/en/contributing).
6 changes: 3 additions & 3 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
version: 2

registries:
ghcr: # Define access for a private registry
ghcr:
type: docker-registry
url: ghcr.io
username: PAT
Expand All @@ -16,7 +16,7 @@ updates:
cooldown:
default-days: 7
ignore:
# Because this is so dependent on the remote server we use
# Keep the Elasticsearch client pinned to the server-compatible version.
- dependency-name: '@elastic/elasticsearch'
- dependency-name: '*'
update-types:
Expand Down Expand Up @@ -54,4 +54,4 @@ updates:
patterns:
- '*'
ignore:
- dependency-name: 'node' # Ignore Dockerfile.openapi_decorator
- dependency-name: 'node' # Ignore Dockerfile.openapi_decorator's Node image.
7 changes: 2 additions & 5 deletions .github/workflows/keep-caches-warm.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
name: Keep caches warm

# Main-branch runs warm node_modules, Next.js, remote JSON, and pageinfo caches that
# pull request workflows and production deployments can reuse.
# Main-branch runs warm node_modules, Next.js, and remote JSON caches that pull
# request workflows can reuse.

on:
workflow_dispatch:
Expand Down Expand Up @@ -29,9 +29,6 @@ jobs:
- uses: ./.github/actions/warmup-remotejson-cache
if: github.repository == 'github/docs-internal'

- uses: ./.github/actions/precompute-pageinfo
if: github.repository == 'github/docs-internal'

- uses: ./.github/actions/create-workflow-failure-issue
id: create-failure-issue
if: ${{ failure() && github.event_name != 'workflow_dispatch' }}
Expand Down
6 changes: 0 additions & 6 deletions .github/workflows/test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -141,12 +141,6 @@ jobs:
# Only routing tests cover archived enterprise server URLs.
if: ${{ matrix.name == 'redirects' }}

- uses: ./.github/actions/precompute-pageinfo
# Only pageinfo tests cover precomputed page info.
if: ${{ matrix.name == 'article-api' }}
env:
ROOT: src/fixtures/fixtures

- name: Index fixtures into the local Elasticsearch
# Run indexing only for suites that query the local Elasticsearch service.
if: ${{ matrix.name == 'search' || matrix.name == 'languages' }}
Expand Down
10 changes: 5 additions & 5 deletions .github/zizmor.yml
Original file line number Diff line number Diff line change
@@ -1,12 +1,12 @@
rules:
# pull_request_target is required for workflows that need write access
# on PRs from forks (e.g. labeling, commenting). We audit these manually.
# Workflows need pull_request_target for write access on forked PRs.
# We audit these manually.
dangerous-triggers:
disable: true

# actions/* has immutable tags, so ref-pinning is sufficient.
# github/internal-actions is a private GitHub org repo, ref-pin is fine.
# Everything else must be hash-pinned.
# actions/* tags are immutable, so ref-pinning is sufficient.
# github/internal-actions is private, so ref-pinning is sufficient.
# Hash-pin everything else.
unpinned-uses:
config:
policies:
Expand Down
3 changes: 0 additions & 3 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -24,9 +24,6 @@
# Node.js version specification
.node-version

# Precomputed page info cache (brotli compressed)
.pageinfo-cache.json.br

# getRemoteJSON() disk cache for archived content
.remotejson-cache/

Expand Down
Loading
Loading