From 2a3720f406f9002b6c7483f1b930df9d827d2eb2 Mon Sep 17 00:00:00 2001 From: michaelchang Date: Tue, 14 Apr 2026 16:42:02 +0800 Subject: [PATCH 1/3] fix: refine workflow --- .github/workflows/Send_message_to_slack.yml | 123 +++++++++++--------- .github/workflows/release_framework.yml | 43 ++++--- 2 files changed, 95 insertions(+), 71 deletions(-) diff --git a/.github/workflows/Send_message_to_slack.yml b/.github/workflows/Send_message_to_slack.yml index 347df76..798c415 100644 --- a/.github/workflows/Send_message_to_slack.yml +++ b/.github/workflows/Send_message_to_slack.yml @@ -6,22 +6,35 @@ on: is_success: type: string required: true + secrets: + SLACK_BOT_OAUTH_TOKEN: + required: true jobs: send_message: runs-on: ubuntu-latest + permissions: + contents: read environment: ENV steps: - id: messages + env: + PR_HEAD_REPO_FULL_NAME: ${{ github.event.pull_request.head.repo.full_name }} + SERVER_URL: ${{ github.server_url }} + REPOSITORY: ${{ github.repository }} + IS_SUCCESS: ${{ inputs.is_success }} + WORKFLOW_NAME: ${{ github.workflow }} + PR_TITLE: ${{ github.event.pull_request.title }} + RUN_ID: ${{ github.run_id }} run: | - if [ -n "${{ github.event.pull_request.head.repo.full_name }}" ]; then - REPO="<${{ github.server_url }}/${{ github.repository }}|${{ github.event.pull_request.head.repo.full_name }}>" + if [ -n "$PR_HEAD_REPO_FULL_NAME" ]; then + REPO="<$SERVER_URL/$REPOSITORY|$PR_HEAD_REPO_FULL_NAME>" else - REPO="<${{ github.server_url }}/${{ github.repository }}|${{ github.repository }}>" + REPO="<$SERVER_URL/$REPOSITORY|$REPOSITORY>" fi - if [[ ${{ inputs.is_success }} == "true" ]]; then + if [[ "$IS_SUCCESS" == "true" ]]; then echo ATTACHMENT_COLOR="#36a64f" >> $GITHUB_OUTPUT else echo ATTACHMENT_COLOR="#e23636" >> $GITHUB_OUTPUT @@ -29,74 +42,68 @@ jobs: echo TITLE="\n:apple2: ${REPO}" >> $GITHUB_OUTPUT - echo WORKFLOW="${{ github.workflow }}" >> $GITHUB_OUTPUT + echo WORKFLOW="$WORKFLOW_NAME" >> $GITHUB_OUTPUT - echo PR="${{ github.event.pull_request.title }}" >> $GITHUB_OUTPUT + echo PR="$PR_TITLE" >> $GITHUB_OUTPUT - echo RUN="" >> $GITHUB_OUTPUT + echo RUN="" >> $GITHUB_OUTPUT - id: payload + env: + TITLE: ${{ steps.messages.outputs.TITLE }} + ATTACHMENT_COLOR: ${{ steps.messages.outputs.ATTACHMENT_COLOR }} + WORKFLOW: ${{ steps.messages.outputs.WORKFLOW }} + PR: ${{ steps.messages.outputs.PR }} + RUN: ${{ steps.messages.outputs.RUN }} run: | - # Initialize the original payload string with placeholders - payload='{ - "blocks": [ - { - "type": "section", - "text": { - "type": "mrkdwn", - "text": "${{ steps.messages.outputs.TITLE }}" - } - } - ], - "attachments": [ + payload=$(jq -n \ + --arg title "$TITLE" \ + --arg color "$ATTACHMENT_COLOR" \ + --arg workflow "$WORKFLOW" \ + --arg pr "$PR" \ + --arg run "$RUN" \ + ' { - "color": "${{ steps.messages.outputs.ATTACHMENT_COLOR }}", - "blocks": [ - ##PLACEHOLDER## + blocks: [ + { + type: "section", + text: { + type: "mrkdwn", + text: $title + } + } + ], + attachments: [ + { + color: $color, + blocks: [ + {label: "Workflow", value: $workflow}, + {label: "PR", value: $pr}, + {label: "Run", value: $run} + ] + | map(select(.value != "") | { + type: "section", + text: { + type: "mrkdwn", + text: ("*" + .label + "*\\n" + .value) + } + }) + } ] } - ] - }' - - # Function to add a section block if an input is provided - add_section() { - local input_value="$1" - local input_label="$2" - - if [ -n "$input_value" ]; then - new_section='{ - "type": "section", - "text": { - "type": "mrkdwn", - "text": "*'"${input_label}"'*\n'"${input_value}"'" - } - },' - # Append the new section to the payload - payload=${payload/'##PLACEHOLDER##'/$new_section##PLACEHOLDER##} - fi - } - - # Add sections based on inputs - add_section "${{ steps.messages.outputs.WORKFLOW }}" "Workflow" - add_section "${{ steps.messages.outputs.PR }}" "PR" - add_section "${{ steps.messages.outputs.RUN }}" "Run" - - # Remove any remaining placeholder - payload=${payload/',##PLACEHOLDER##'/} - payload=${payload/'##PLACEHOLDER##'/} + ') - # Output the final payload - echo "${payload}" + echo "$payload" - echo "PAYLOAD<> "$GITHUB_ENV" - echo "${payload}" >> "$GITHUB_ENV" - echo "EOF" >> "$GITHUB_ENV" + echo "payload<> "$GITHUB_OUTPUT" + echo "$payload" >> "$GITHUB_OUTPUT" + echo "EOF" >> "$GITHUB_OUTPUT" - name: Send GitHub Action trigger data to Slack workflow id: slack - uses: slackapi/slack-github-action@v1.26.0 + uses: slackapi/slack-github-action@70cd7be8e40a46e8b0eced40b0de447bdb42f68e # v1.26.0 with: channel-id: "${{ vars.NOTIFY_SLACK_CHANNEL_ID }}" - payload: "${{ env.PAYLOAD }}" + payload: "${{ steps.payload.outputs.payload }}" env: SLACK_BOT_TOKEN: '${{ secrets.SLACK_BOT_OAUTH_TOKEN }}' diff --git a/.github/workflows/release_framework.yml b/.github/workflows/release_framework.yml index f752d0d..b1c2d36 100644 --- a/.github/workflows/release_framework.yml +++ b/.github/workflows/release_framework.yml @@ -1,5 +1,8 @@ name: Release framework +permissions: + contents: read + on: pull_request: types: @@ -29,18 +32,23 @@ jobs: steps: - name: Check release conditions id: check + env: + EVENT_NAME: ${{ github.event_name }} + REF_NAME: ${{ github.ref_name }} + HEAD_REF: ${{ github.head_ref }} + PR_MERGED: ${{ github.event.pull_request.merged }} run: | - if [[ "${{ github.event_name }}" == "workflow_dispatch" ]]; then + if [[ "$EVENT_NAME" == "workflow_dispatch" ]]; then # workflow_dispatch: only allow on master branch - if [[ "${{ github.ref_name }}" == "master" ]]; then + if [[ "$REF_NAME" == "master" ]]; then echo "should_release=true" >> $GITHUB_OUTPUT else echo "should_release=false" >> $GITHUB_OUTPUT fi - elif [[ "${{ github.event_name }}" == "pull_request" ]]; then + elif [[ "$EVENT_NAME" == "pull_request" ]]; then # PR: check if it's a release/prerelease branch and merged - head_ref="${{ github.head_ref }}" - is_merged=${{ github.event.pull_request.merged }} + head_ref="$HEAD_REF" + is_merged="$PR_MERGED" if [[ ("$head_ref" == release* || "$head_ref" == prerelease*) && "$is_merged" == "true" ]]; then echo "should_release=true" >> $GITHUB_OUTPUT @@ -59,7 +67,7 @@ jobs: release_created: ${{ steps.release.outputs.created }} steps: - name: Checkout repository - uses: actions/checkout@v4 + uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 - name: Setup gem uses: appier/appier-ios-framework/.github/actions/install_gem_dependencies@master @@ -70,10 +78,11 @@ jobs: id: release env: GITHUB_TOKEN: ${{ secrets.GH_TOKEN }} + REF_NAME: ${{ github.ref_name }} run: | is_prerelease=false - if [[ "${{ github.ref_name }}" == "prerelease" || "${{ github.ref_name }}" == prerelease* ]]; then + if [[ "$REF_NAME" == "prerelease" || "$REF_NAME" == prerelease* ]]; then is_prerelease=true fi @@ -86,7 +95,7 @@ jobs: runs-on: macos-latest steps: - name: Checkout repository - uses: actions/checkout@v4 + uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 - name: Setup gem uses: appier/appier-ios-framework/.github/actions/install_gem_dependencies@master @@ -104,7 +113,7 @@ jobs: runs-on: macos-latest steps: - name: Checkout repository - uses: actions/checkout@v4 + uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 - name: Setup gem uses: appier/appier-ios-framework/.github/actions/install_gem_dependencies@master @@ -120,20 +129,26 @@ jobs: needs: [prepare, create_release] if: needs.prepare.outputs.should_release == 'true' && needs.create_release.outputs.release_created == 'true' runs-on: ubuntu-latest + permissions: + contents: read steps: - name: Enable Build app with release framework workflow + env: + GH_TOKEN: ${{ secrets.GH_TOKEN }} run: | curl -X PUT \ -H "Accept: application/vnd.github+json" \ - -H "Authorization: Bearer ${{ secrets.GH_TOKEN }}" \ + -H "Authorization: Bearer $GH_TOKEN" \ -H "X-GitHub-Api-Version: 2022-11-28" \ "https://api.github.com/repos/plaxieappier/appier-ios-automation-test-app/actions/workflows/build_app_from_release_sources.yml/enable" - name: Enable Build demo app workflow + env: + GH_TOKEN: ${{ secrets.GH_TOKEN }} run: | curl -X PUT \ -H "Accept: application/vnd.github+json" \ - -H "Authorization: Bearer ${{ secrets.GH_TOKEN }}" \ + -H "Authorization: Bearer $GH_TOKEN" \ -H "X-GitHub-Api-Version: 2022-11-28" \ "https://api.github.com/repos/plaxieappier/aiqua-ios-demo/actions/workflows/build_and_upload_demo_app.yml/enable" @@ -141,7 +156,8 @@ jobs: needs: [deploy_pod_framework, deploy_pod_extension] if: ${{ always() && !contains(needs.*.result, 'failure') && !contains(needs.*.result, 'cancelled') && !contains(needs.*.result, 'skipped') }} uses: ./.github/workflows/Send_message_to_slack.yml - secrets: inherit + secrets: + SLACK_BOT_OAUTH_TOKEN: ${{ secrets.SLACK_BOT_OAUTH_TOKEN }} with: is_success: "true" @@ -149,6 +165,7 @@ jobs: needs: [deploy_pod_framework, deploy_pod_extension] if: ${{ always() && contains(needs.*.result, 'failure') }} uses: ./.github/workflows/Send_message_to_slack.yml - secrets: inherit + secrets: + SLACK_BOT_OAUTH_TOKEN: ${{ secrets.SLACK_BOT_OAUTH_TOKEN }} with: is_success: "false" From f3ca9762cf5447caeaf27dd62e17aeec543e2092 Mon Sep 17 00:00:00 2001 From: michaelchang Date: Tue, 14 Apr 2026 17:05:53 +0800 Subject: [PATCH 2/3] fix: update indentation --- .github/workflows/Send_message_to_slack.yml | 158 ++++++++++---------- 1 file changed, 79 insertions(+), 79 deletions(-) diff --git a/.github/workflows/Send_message_to_slack.yml b/.github/workflows/Send_message_to_slack.yml index 798c415..a219e4a 100644 --- a/.github/workflows/Send_message_to_slack.yml +++ b/.github/workflows/Send_message_to_slack.yml @@ -18,92 +18,92 @@ jobs: environment: ENV steps: - - id: messages - env: - PR_HEAD_REPO_FULL_NAME: ${{ github.event.pull_request.head.repo.full_name }} - SERVER_URL: ${{ github.server_url }} - REPOSITORY: ${{ github.repository }} - IS_SUCCESS: ${{ inputs.is_success }} - WORKFLOW_NAME: ${{ github.workflow }} - PR_TITLE: ${{ github.event.pull_request.title }} - RUN_ID: ${{ github.run_id }} - run: | - if [ -n "$PR_HEAD_REPO_FULL_NAME" ]; then - REPO="<$SERVER_URL/$REPOSITORY|$PR_HEAD_REPO_FULL_NAME>" - else - REPO="<$SERVER_URL/$REPOSITORY|$REPOSITORY>" - fi + - id: messages + env: + PR_HEAD_REPO_FULL_NAME: ${{ github.event.pull_request.head.repo.full_name }} + SERVER_URL: ${{ github.server_url }} + REPOSITORY: ${{ github.repository }} + IS_SUCCESS: ${{ inputs.is_success }} + WORKFLOW_NAME: ${{ github.workflow }} + PR_TITLE: ${{ github.event.pull_request.title }} + RUN_ID: ${{ github.run_id }} + run: | + if [ -n "$PR_HEAD_REPO_FULL_NAME" ]; then + REPO="<$SERVER_URL/$REPOSITORY|$PR_HEAD_REPO_FULL_NAME>" + else + REPO="<$SERVER_URL/$REPOSITORY|$REPOSITORY>" + fi - if [[ "$IS_SUCCESS" == "true" ]]; then - echo ATTACHMENT_COLOR="#36a64f" >> $GITHUB_OUTPUT - else - echo ATTACHMENT_COLOR="#e23636" >> $GITHUB_OUTPUT - fi + if [[ "$IS_SUCCESS" == "true" ]]; then + echo ATTACHMENT_COLOR="#36a64f" >> $GITHUB_OUTPUT + else + echo ATTACHMENT_COLOR="#e23636" >> $GITHUB_OUTPUT + fi - echo TITLE="\n:apple2: ${REPO}" >> $GITHUB_OUTPUT + echo TITLE="\n:apple2: ${REPO}" >> $GITHUB_OUTPUT - echo WORKFLOW="$WORKFLOW_NAME" >> $GITHUB_OUTPUT + echo WORKFLOW="$WORKFLOW_NAME" >> $GITHUB_OUTPUT - echo PR="$PR_TITLE" >> $GITHUB_OUTPUT + echo PR="$PR_TITLE" >> $GITHUB_OUTPUT - echo RUN="" >> $GITHUB_OUTPUT + echo RUN="" >> $GITHUB_OUTPUT - - id: payload - env: - TITLE: ${{ steps.messages.outputs.TITLE }} - ATTACHMENT_COLOR: ${{ steps.messages.outputs.ATTACHMENT_COLOR }} - WORKFLOW: ${{ steps.messages.outputs.WORKFLOW }} - PR: ${{ steps.messages.outputs.PR }} - RUN: ${{ steps.messages.outputs.RUN }} - run: | - payload=$(jq -n \ - --arg title "$TITLE" \ - --arg color "$ATTACHMENT_COLOR" \ - --arg workflow "$WORKFLOW" \ - --arg pr "$PR" \ - --arg run "$RUN" \ - ' - { - blocks: [ - { - type: "section", - text: { - type: "mrkdwn", - text: $title + - id: payload + env: + TITLE: ${{ steps.messages.outputs.TITLE }} + ATTACHMENT_COLOR: ${{ steps.messages.outputs.ATTACHMENT_COLOR }} + WORKFLOW: ${{ steps.messages.outputs.WORKFLOW }} + PR: ${{ steps.messages.outputs.PR }} + RUN: ${{ steps.messages.outputs.RUN }} + run: | + payload=$(jq -n \ + --arg title "$TITLE" \ + --arg color "$ATTACHMENT_COLOR" \ + --arg workflow "$WORKFLOW" \ + --arg pr "$PR" \ + --arg run "$RUN" \ + ' + { + blocks: [ + { + type: "section", + text: { + type: "mrkdwn", + text: $title + } } - } - ], - attachments: [ - { - color: $color, - blocks: [ - {label: "Workflow", value: $workflow}, - {label: "PR", value: $pr}, - {label: "Run", value: $run} - ] - | map(select(.value != "") | { - type: "section", - text: { - type: "mrkdwn", - text: ("*" + .label + "*\\n" + .value) - } - }) - } - ] - } - ') + ], + attachments: [ + { + color: $color, + blocks: [ + {label: "Workflow", value: $workflow}, + {label: "PR", value: $pr}, + {label: "Run", value: $run} + ] + | map(select(.value != "") | { + type: "section", + text: { + type: "mrkdwn", + text: ("*" + .label + "*\\n" + .value) + } + }) + } + ] + } + ') - echo "$payload" + echo "$payload" - echo "payload<> "$GITHUB_OUTPUT" - echo "$payload" >> "$GITHUB_OUTPUT" - echo "EOF" >> "$GITHUB_OUTPUT" + echo "payload<> "$GITHUB_OUTPUT" + echo "$payload" >> "$GITHUB_OUTPUT" + echo "EOF" >> "$GITHUB_OUTPUT" - - name: Send GitHub Action trigger data to Slack workflow - id: slack - uses: slackapi/slack-github-action@70cd7be8e40a46e8b0eced40b0de447bdb42f68e # v1.26.0 - with: - channel-id: "${{ vars.NOTIFY_SLACK_CHANNEL_ID }}" - payload: "${{ steps.payload.outputs.payload }}" - env: - SLACK_BOT_TOKEN: '${{ secrets.SLACK_BOT_OAUTH_TOKEN }}' + - name: Send GitHub Action trigger data to Slack workflow + id: slack + uses: slackapi/slack-github-action@70cd7be8e40a46e8b0eced40b0de447bdb42f68e # v1.26.0 + with: + channel-id: "${{ vars.NOTIFY_SLACK_CHANNEL_ID }}" + payload: "${{ steps.payload.outputs.payload }}" + env: + SLACK_BOT_TOKEN: '${{ secrets.SLACK_BOT_OAUTH_TOKEN }}' From 6ca4f339b3c355391ca3fe05130d173797bc464b Mon Sep 17 00:00:00 2001 From: michaelchang Date: Wed, 15 Apr 2026 15:49:24 +0800 Subject: [PATCH 3/3] fix: correct Slack mrkdwn newline handling --- .github/workflows/Send_message_to_slack.yml | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/.github/workflows/Send_message_to_slack.yml b/.github/workflows/Send_message_to_slack.yml index a219e4a..a869b6a 100644 --- a/.github/workflows/Send_message_to_slack.yml +++ b/.github/workflows/Send_message_to_slack.yml @@ -40,7 +40,12 @@ jobs: echo ATTACHMENT_COLOR="#e23636" >> $GITHUB_OUTPUT fi - echo TITLE="\n:apple2: ${REPO}" >> $GITHUB_OUTPUT + { + echo "TITLE<" + echo ":apple2: ${REPO}" + echo "EOF" + } >> "$GITHUB_OUTPUT" echo WORKFLOW="$WORKFLOW_NAME" >> $GITHUB_OUTPUT @@ -85,7 +90,7 @@ jobs: type: "section", text: { type: "mrkdwn", - text: ("*" + .label + "*\\n" + .value) + text: ("*" + .label + "*\n" + .value) } }) }