231 Commits

Author SHA1 Message Date
Martin Fischer
bf338732f2 nixpkgs-update: update links after move to NixOS org 2026-10-02 08:21:41 +02:00
Matt Sturgeon
37d1dadbcc ci/github-script/merge: indicate how to join nixos/nixpkgs-maintainers (#519945) 2026-10-01 06:31:55 +00:00
Peder Bergebakken Sundt
470629541d ci/github-script/merge: indicate how to join nixos/nixpkgs-maintainers
Many simply never saw the invite email from github, and this error message is pretty unactionable.

It would also be a good idea to update the "About" description in https://github.com/orgs/NixOS/teams/nixpkgs-maintainers to indicate how to join.
2026-10-01 00:28:30 +02:00
Victor Engmark
795f334f07 doc: Use more common spelling of "style guide"
See
[trend](https://trends.google.com/explore?q=styleguide%2Cstyle%2520guide&date=all&geo=Worldwide)
for one indication that the new spelling is much more common.
2026-09-27 10:17:36 +02:00
Michael Daniels
da1f7a1117 ci/github-script: convert various to TypeScript (#567205) 2026-09-27 03:45:59 +00:00
Michael Daniels
5a6dae1394 ci/github-script/bot: replace "unmaintained" label with "no default reviewers" 2026-09-26 16:52:35 -04:00
Michael Daniels
32675f4b92 ci/github-script: convert various to TypeScript 2026-09-26 12:48:43 -04:00
Michael Daniels
b7a3adaa10 ci/github-script/commits: convert to TypeScript (#559961) 2026-09-26 00:21:56 +00:00
Matt Sturgeon
8eafff1303 ci/github-script/bot: label PRs for unmaintained packages (#565394) 2026-09-23 14:02:32 +00:00
Ryan Hendrickson
db2eedfcba ci/github-script/bot: label PRs for unmaintained packages 2026-09-22 20:32:37 -04:00
Matt Sturgeon
27ed56e84d ci: point documentation PRs at the styleguide (#562912) 2026-09-22 13:02:06 +00:00
Johannes Kirschbauer
40bb73107d ci: post a reminder for updated paths
docs are the first example

Assisted-by: Oh My Pi (Claude Opus 5)
2026-09-22 14:41:40 +02:00
Michael Daniels
7f822c9dc8 ci/github-script/commits: convert to TypeScript
Assisted-by: gpt-5.6-terra (Codex)
2026-09-19 11:33:08 -04:00
Michael Daniels
4a7ddd0795 ci/github-script/manual-file-edits: convert to TypeScript 2026-09-18 19:24:33 -04:00
Michael Daniels
b5a80c77fb ci/github-script/bot.js: make llm-assisted label sticky (#559739) 2026-09-06 15:52:07 +00:00
Michael Daniels
2e4bd2166b ci/github-script/bot: fix pagination 2026-09-04 19:57:11 -04:00
Michael Daniels
8cc85b1852 ci/github-script/bot: log pagination cursor
This doesn't seem to change, even when it should.

I suspect this is related to the rate limit errors.
2026-09-04 16:33:09 -04:00
Ihar Hrachyshka
9686621d1b ci/github-script/bot.js: make llm-assisted label sticky
By popular demand, this patch lets folks manually label PRs with the
label and make it stick, even if auto-labeler wouldn't label it itself
(presumably because the author didn't mark their commits according to
automation policy).

Assisted-by: Codex gpt-5.6-sol medium
2026-09-03 23:35:08 -04:00
zowoq
5a4d138f79 ci/github-script/check-target-branch-policy: add exemption for kernels
kernel updates go to staging-nixos, they shouldn't be flagged
2026-09-03 09:38:44 +10:00
Michael Daniels
375b60d66b ci/github-script/commits.js: unbreak
This succeeded before the ESM conversion because we weren't in strict mode
(and therefore `line` was added to the global scope).

ES Modules run in strict mode by default, so this is a `ReferenceError` now.

TypeScript would have caught this! I will keep working on converting to it.
2026-09-01 19:27:05 -04:00
Matt Sturgeon
05e7795a4a ci/commits: CJS __dirname → ESM
ESM modules no longer support CJS-style `__dirname` or `__filename`,
instead we should use `import.meta.dirname` and `import.meta.filename`
respectively.

https://nodejs.org/api/esm.html#no-__filename-or-__dirname
2026-09-01 02:18:58 +01:00
Michael Daniels
eb501c45ae ci/github-script: convert to ES modules
ES modules work better with TypeScript than CommonJS modules do.

Assisted-by: GPT 5.6 Luna & Terra (Codex)
2026-08-31 18:09:18 -04:00
Michael Daniels
2d813b7719 ci/supportedBranches.js: move to ci/github-script
This way it will be covered by our package.json when we configure ES Modules
in the next commit.
2026-08-31 18:06:11 -04:00
Ihar Hrachyshka
30a8636adf ci/github-script/check-target-branch: evaluate exemptions in policy
Assisted-by: Codex gpt-5.6-sol medium
2026-08-21 18:32:31 -04:00
Ihar Hrachyshka
221930c60c ci/github-script/check-target-branch: check staging-nixos mass rebuilds
Assisted-by: Codex gpt-5.6-sol medium
2026-08-21 18:32:29 -04:00
Ihar Hrachyshka
403d5922cf ci/github-script/check-target-branch: simplify policy decisions
This commit hopefully improves readability: encapsulates some
intermediary decisions in variable, plus adopts early return decision
tree.

Assisted-by: Codex gpt-5.6-sol medium
2026-08-21 18:32:27 -04:00
Ihar Hrachyshka
e1aa8c4d16 ci/github-script/check-target-branch: add policy tests
Tests reflect status quo. They establish baseline for later policy
changes. Some test cases are obvious bugs (e.g. mass rebuild checks are
skipped on staging-nixos), others may also be questionable.

Assisted-by: Codex gpt-5.6-sol medium
2026-08-21 18:32:26 -04:00
Ihar Hrachyshka
198d0cd473 ci/github-script: add npm scripts
Allows running `npm run typecheck` or `npm test`.
2026-08-20 17:33:22 -04:00
Ihar Hrachyshka
3d17eabf1a ci/github-script/check-target-branch: extract policy decision
This is in preparation to test the extracted pure function in the next
commit.

Assisted-by: Codex gpt-5.6-sol medium
2026-08-20 17:32:55 -04:00
Ihar Hrachyshka
d003d54dc4 ci/github-script/check-target-branch: extract review helpers
Assisted-by: Codex gpt-5.6-sol medium
2026-08-20 17:32:53 -04:00
Michael Daniels
7b972175eb ci/github-script: add *.tsbuildinfo to gitignore 2026-08-18 18:20:04 -04:00
Michael Daniels
2496d47b76 ci/github-script/check-target-branch: convert to TypeScript
Only doing this one for now as a proof-of-concept.
2026-08-10 20:26:01 -04:00
Michael Daniels
7045e3afe1 ci/github-script: check types by default 2026-08-10 20:26:01 -04:00
Michael Daniels
578ac00958 ci/github-script/run: correct variable name 2026-08-10 20:26:01 -04:00
Michael Daniels
78df5b944f ci/github-script/.gitignore: add comparison artifact
Needed by check-target-branch.
2026-08-10 20:26:00 -04:00
Michael Daniels
f746c52b23 ci/github-script: fix types for context 2026-08-08 09:30:32 -04:00
Michael Daniels
03bf53cdb5 Revert "ci/github-script/get-pr-commit-details: output file list for merge commits" 2026-08-05 17:33:01 -04:00
Ben Siraphob
39940b557c ci: fix typos
Assisted-by: Claude Code (claude-opus-5)
2026-08-02 11:15:26 -07:00
Michael Daniels
e7804286db ci/github-script/get-pr-commit-details: output file list for merge commits
Fixes a bug that was originally found by Claude and reported to the NixOS
security team by Anthropic as a security issue.

Previously, the file list was never output for merge commits.

This could have allowed someone who buried an edit to a file that shouldn't be
edited manually in a merge commit to not trigger the check.

It isn't a security issue, though, because the manual-file-edits check is not
a security boundary (just a friendly reminder to committers).

Anthropic report ID: ANT-2026-223Q3FSE
2026-08-01 20:28:39 -04:00
Matt Sturgeon
88cc2017b8 ci/github-script/lint-commits: add more conventional commit prefixes (#544032) 2026-07-22 13:22:29 +00:00
Michael Daniels
4a45de05bd workflows: appease zizmor by installing npm pkgs from lockfile 2026-07-21 19:30:53 -04:00
Michael Daniels
1c28135859 ci/github-script/lint-commits: add more conventional commit prefixes
Fixes #543681
2026-07-21 19:11:43 -04:00
Ethan Carter Edwards
7eb5f48146 ci/github-script/bot: label llm-assisted PRs accordingly
Discussed in AGENTS.md debate PR

Assisted by https://regex101.com/, my brain, and love for humanity and free software

Signed-off-by: Ethan Carter Edwards <ethan@ethancedwards.com>
2026-07-17 10:48:15 -07:00
Aliaksandr
0c1c3d4813 ci/github-script/merge: share reviews fetch with bot.js, drop events
`bot.js` already pulls reviews via GraphQL for the approval-count
labels. Move that fetch above the `handleMerge` call, add `commit
{ oid }` to the query, and pass the result through. `handleMerge` no
longer issues its own `listReviews` REST call.

While here, the `approvals` set is now derived from the same reviews
data. Two upsides:

- A reviewer who approved and was later dismissed no longer counts
  towards the approval check; their review now surfaces with state
  DISMISSED instead of leaving a stale `reviewed` event behind.
- `events` is no longer needed by `runChecklist` (it was only feeding
  the approvals filter); the parameter is dropped from both call
  sites. `handleMerge` still uses `events` for tracking the latest
  push and merge-command comments.

Also drop the redundant `user` truthy checks (and the stale "some
users have been deleted" comment) in `runChecklist`. The GraphQL
query uses `author { ... on User { login id } }` and bot.js then
filters via `r.user?.login`, so by the time reviews reach
`runChecklist` every entry already has a populated `user`. Verified
by querying real PRs: bots surface as `{__typename: "Bot"}` (no
`login`/`id`, filtered out by bot.js), and deleted accounts surface
as the "ghost" user (login `"ghost"`, id `10137`), which passes the
filter but matches no committer - harmless for both checks.

Assisted-by: claude-code with claude-opus-4-8[1m]-high
2026-06-25 18:05:32 +03:00
Aliaksandr
6f9325fb5d ci/github-script/merge: clarify Auto Merge follow-up tip
The previous tip ("Sometimes GitHub gets stuck after enabling Auto
Merge") didn't explain why nothing happens immediately after the bot's
"Enabled Auto Merge" reply, leaving maintainers unsure whether to wait
or intervene. Spell out that Auto Merge waits for required CI before
queueing, that a later CI failure leaves the PR un-queued until it is
fixed, and link to GitHub's documentation; keep the existing "leave
another approval" workaround for the rare cases where Auto Merge stalls
after CI completes.

Assisted-by: claude-code with claude-opus-4-8[1m]-high
2026-06-25 18:05:32 +03:00
Aliaksandr
b94b44d3f9 ci/github-script/merge: refuse merge when a committer has requested changes
A "changes requested" review from a committer blocks both the merge
queue and auto-merge, but unlike approvals it isn't auto-dismissed
when new commits are pushed. Surface it as a checklist item so the
bot's reply explains the block instead of silently enabling
auto-merge that will never trigger.

Implementation pulls every review for the PR via `listReviews` and,
for each committer, takes the latest review whose state is
`APPROVED`/`CHANGES_REQUESTED`. The check fails if any committer's
latest stance is `CHANGES_REQUESTED`. Other review states fall out
naturally:

- A dismissed review surfaces as `DISMISSED`, so a committer
  dismissing their own changes-requested review unblocks the PR.
- A comment-only follow-up surfaces as `COMMENTED`, so it doesn't
  override an earlier actionable review - the prior stance still
  stands until the committer explicitly approves or requests changes
  again.

Assisted-by: claude-code with claude-opus-4-8[1m]-high
2026-06-25 17:57:03 +03:00
Aliaksandr
da97bf8423 ci/github-script/merge: skip auto-merge when CI has already failed
The merge bot falls back to GitHub Auto Merge whenever the merge queue
won't accept a PR yet. That is the right move while CI is still
running, but pointless once CI has already failed: Auto Merge can never
trigger, and fixing CI requires a new push, which invalidates the merge
command anyway (the bot only acts on comments after the latest push).

Fetch the `no PR failures` commit status and, when the merge-queue
enqueue fails, branch on it. If CI has already failed
(`error`/`failure`), skip Auto Merge and reply that a fresh
`@NixOS/nixpkgs-merge-bot merge` comment is needed once CI is green
again. Otherwise (pending or missing status) enable Auto Merge as
before.

`merge()` now returns `{ reaction, messages }` so the CI-failure path
can leave a thumbs-down reaction rather than the rocket used for an
actual merge.

Closes #512554.

Assisted-by: claude-code with claude-opus-4-8[1m]-high
2026-06-25 17:57:03 +03:00
Michael Daniels
41876c6de2 ci/github-script/merge: ignore case when checking for merge bot comment 2026-06-06 14:17:11 -04:00
zowoq
10056dd40d linux: add stable staging-nixos workflow
stable counterpart to d28cc2a2f5
2026-05-28 09:42:28 +10:00
zowoq
c103da6a19 ci: add nixosTests.simple-container
nixosTests.simple-vm but using an nspawn container
2026-05-22 21:24:34 +10:00