Sign inSign up

cenk1cenk2/pipe-github

By cenk1cenk2

•Updated 1 day ago

GitHub App tokens and commit statuses for pipelines.

Image
0

416

cenk1cenk2/pipe-github repository overview

⁠pipe-github

GitHub App tokens and commit statuses in the pipeline.

pipe-github [GLOBAL FLAGS] [COMMAND] [FLAGS]

⁠Global Flags

CLI

Flag / EnvironmentDescriptionTypeDefault
$LOG_LEVELDefine the log level for the application.string
enum("panic", "fatal", "warn", "info", "debug", "trace")
"info"
$ENV_FILEEnvironment files to inject.string[]

⁠Commands

⁠pipe-github token

Mint a GitHub App installation token into a dotenv file. Every GitHub App flag is required here.

The token lives for an hour. Expose the file as an artifacts:reports:dotenv report, and every job that needs this one receives the token as a variable, which overrides the job-level variable of the same name.

pipe-github token [FLAGS]

⁠Flags

GitHub App

Flag / EnvironmentDescriptionTypeDefault
$GITHUB_APP_IDGitHub App id the token is minted for.string
$GITHUB_APP_INSTALLATION_IDInstallation id of the GitHub App on the owner of the repository.string
$GITHUB_APP_PRIVATE_KEYPath to the private key of the GitHub App, as a GitLab file variable exports it, or the PEM contents themselves.string
$GITHUB_API_URLGitHub API URL.string"https://api.github.com"

Token

Flag / EnvironmentDescriptionTypeDefault
$GITHUB_TOKEN_REPOSITORIESRepository names, without the owner, to narrow the token down to. Left empty, the token covers every repository of the installation.string[]
$GITHUB_TOKEN_PERMISSIONSPermissions to narrow the token down to, e.g. {"statuses":"write"}. Left empty, the token carries every permission of the installation.string
format(json(map[string]string))
$GITHUB_TOKEN_VARIABLEVariable name the token is written under in the dotenv file. Left empty, the token is not written.string"GH_TOKEN"
$GITHUB_TOKEN_GIT_CREDENTIALS_VARIABLEVariable name the token is written under as an x-access-token git credential in the dotenv file, for semantic-release to push with. Left empty, no git credential is written.string"GIT_CREDENTIALS"
$GITHUB_TOKEN_FILEDotenv file the token is written into, for the job to expose as a dotenv report. Other variables in an existing file are kept.string"github.env"
⁠pipe-github status

Post a commit status to GitHub.

Given the GitHub App flags, the status mints its own token, narrowed to the repository and to writing statuses. That needs the private key in the status job as well, so prefer the token from the dotenv file and mint in place only where the pipeline can outlive the token.

A commit GitHub does not have, as on a branch that only exists on GitLab, is skipped with a warning; every other failure fails the job.

pipe-github status [FLAGS]

⁠Flags
GitHub App
Flag / EnvironmentDescriptionTypeDefault
$GITHUB_APP_IDGitHub App id the token is minted for.string
$GITHUB_APP_INSTALLATION_IDInstallation id of the GitHub App on the owner of the repository.string
$GITHUB_APP_PRIVATE_KEYPath to the private key of the GitHub App, as a GitLab file variable exports it, or the PEM contents themselves.string
$GITHUB_API_URLGitHub API URL.string"https://api.github.com"

Status

Flag / EnvironmentDescriptionTypeDefault
$GITHUB_STATUS_TOKEN
$GH_TOKEN
GitHub token to post the status with. Not needed when the GitHub App flags are given, since the status then mints its own token.string
$GITHUB_STATUS_PROJECT*GitHub repository to post the status to, as owner/repository.string
$GITHUB_STATUS_STATE
$GITHUB_STATUS_REPORT*
State of the status.string
format(enum(pending, success, failure, error))
$GITHUB_STATUS_SHA
$CI_COMMIT_SHA*
Commit sha to post the status for.string
$GITHUB_STATUS_TARGET_URL
$CI_PIPELINE_URL
URL the status links to.string
$GITHUB_STATUS_CONTEXTContext that tells this status apart from the others on the commit.string"Gitlab CI"
$GITHUB_STATUS_DESCRIPTIONShort description of the status.string

* required

Tag summary

Content type

Image

Digest

sha256:ab4a0ab7e…

Size

8.5 MB

Last updated

1 day ago

docker pull cenk1cenk2/pipe-github