Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
180 changes: 96 additions & 84 deletions .github/workflows/Send_message_to_slack.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,97 +6,109 @@ on:
is_success:
type: string
required: true
secrets:
SLACK_BOT_OAUTH_TOKEN:
required: true

jobs:
send_message:
runs-on: ubuntu-latest
permissions:
contents: read
environment: ENV
steps:

- id: messages
run: |
if [ -n "${{ github.event.pull_request.head.repo.full_name }}" ]; then
REPO="<${{ github.server_url }}/${{ github.repository }}|${{ github.event.pull_request.head.repo.full_name }}>"
else
REPO="<${{ github.server_url }}/${{ github.repository }}|${{ github.repository }}>"
fi

if [[ ${{ inputs.is_success }} == "true" ]]; then
echo ATTACHMENT_COLOR="#36a64f" >> $GITHUB_OUTPUT
else
echo ATTACHMENT_COLOR="#e23636" >> $GITHUB_OUTPUT
fi

echo TITLE="<!subteam^S042H1N39E3>\n:apple2: ${REPO}" >> $GITHUB_OUTPUT

echo WORKFLOW="${{ github.workflow }}" >> $GITHUB_OUTPUT

echo PR="${{ github.event.pull_request.title }}" >> $GITHUB_OUTPUT

echo RUN="<https://github.com/${{ github.repository }}/actions/runs/${{ github.run_id }}|#${{ github.run_id }}>" >> $GITHUB_OUTPUT

- id: payload
run: |
# Initialize the original payload string with placeholders
payload='{
"blocks": [
{
"type": "section",
"text": {
"type": "mrkdwn",
"text": "${{ steps.messages.outputs.TITLE }}"
}
}
],
"attachments": [
{
"color": "${{ steps.messages.outputs.ATTACHMENT_COLOR }}",
"blocks": [
##PLACEHOLDER##
]
}
]
}'

# Function to add a section block if an input is provided
add_section() {
local input_value="$1"
local input_label="$2"

if [ -n "$input_value" ]; then
new_section='{
"type": "section",
"text": {
"type": "mrkdwn",
"text": "*'"${input_label}"'*\n'"${input_value}"'"
}
},'
# Append the new section to the payload
payload=${payload/'##PLACEHOLDER##'/$new_section##PLACEHOLDER##}
- id: messages
env:
PR_HEAD_REPO_FULL_NAME: ${{ github.event.pull_request.head.repo.full_name }}
SERVER_URL: ${{ github.server_url }}
REPOSITORY: ${{ github.repository }}
IS_SUCCESS: ${{ inputs.is_success }}
WORKFLOW_NAME: ${{ github.workflow }}
PR_TITLE: ${{ github.event.pull_request.title }}
RUN_ID: ${{ github.run_id }}
run: |
if [ -n "$PR_HEAD_REPO_FULL_NAME" ]; then
REPO="<$SERVER_URL/$REPOSITORY|$PR_HEAD_REPO_FULL_NAME>"
else
REPO="<$SERVER_URL/$REPOSITORY|$REPOSITORY>"
fi
}

# Add sections based on inputs
add_section "${{ steps.messages.outputs.WORKFLOW }}" "Workflow"
add_section "${{ steps.messages.outputs.PR }}" "PR"
add_section "${{ steps.messages.outputs.RUN }}" "Run"

# Remove any remaining placeholder
payload=${payload/',##PLACEHOLDER##'/}
payload=${payload/'##PLACEHOLDER##'/}

# Output the final payload
echo "${payload}"

echo "PAYLOAD<<EOF" >> "$GITHUB_ENV"
echo "${payload}" >> "$GITHUB_ENV"
echo "EOF" >> "$GITHUB_ENV"
if [[ "$IS_SUCCESS" == "true" ]]; then
echo ATTACHMENT_COLOR="#36a64f" >> $GITHUB_OUTPUT
else
echo ATTACHMENT_COLOR="#e23636" >> $GITHUB_OUTPUT
fi

- name: Send GitHub Action trigger data to Slack workflow
id: slack
uses: slackapi/slack-github-action@v1.26.0
with:
channel-id: "${{ vars.NOTIFY_SLACK_CHANNEL_ID }}"
payload: "${{ env.PAYLOAD }}"
env:
SLACK_BOT_TOKEN: '${{ secrets.SLACK_BOT_OAUTH_TOKEN }}'
{
echo "TITLE<<EOF"
echo "<!subteam^S042H1N39E3>"
echo ":apple2: ${REPO}"
echo "EOF"
} >> "$GITHUB_OUTPUT"

echo WORKFLOW="$WORKFLOW_NAME" >> $GITHUB_OUTPUT

echo PR="$PR_TITLE" >> $GITHUB_OUTPUT

Copilot AI Apr 15, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

PR_TITLE comes from the PR metadata and can contain newlines or other characters that can break the $GITHUB_OUTPUT file format (output injection), potentially corrupting subsequent outputs and the Slack payload. Write this output using the multiline <<EOF syntax (or otherwise escape/encode the value) rather than echo PR="$PR_TITLE" >> $GITHUB_OUTPUT.

Suggested change
echo PR="$PR_TITLE" >> $GITHUB_OUTPUT
{
echo "PR<<EOF"
echo "$PR_TITLE"
echo "EOF"
} >> "$GITHUB_OUTPUT"

Copilot uses AI. Check for mistakes.

echo RUN="<https://github.com/$REPOSITORY/actions/runs/$RUN_ID|#$RUN_ID>" >> $GITHUB_OUTPUT

- id: payload
env:
TITLE: ${{ steps.messages.outputs.TITLE }}
ATTACHMENT_COLOR: ${{ steps.messages.outputs.ATTACHMENT_COLOR }}
WORKFLOW: ${{ steps.messages.outputs.WORKFLOW }}
PR: ${{ steps.messages.outputs.PR }}
RUN: ${{ steps.messages.outputs.RUN }}
run: |
payload=$(jq -n \
--arg title "$TITLE" \
--arg color "$ATTACHMENT_COLOR" \
--arg workflow "$WORKFLOW" \
--arg pr "$PR" \
--arg run "$RUN" \
'
{
blocks: [
{
type: "section",
text: {
type: "mrkdwn",
text: $title
}
}
],
attachments: [
{
color: $color,
blocks: [
{label: "Workflow", value: $workflow},
{label: "PR", value: $pr},
{label: "Run", value: $run}
]
| map(select(.value != "") | {
type: "section",
text: {
type: "mrkdwn",
text: ("*" + .label + "*\n" + .value)
}
})
}
]
}
')

echo "$payload"

echo "payload<<EOF" >> "$GITHUB_OUTPUT"
echo "$payload" >> "$GITHUB_OUTPUT"
echo "EOF" >> "$GITHUB_OUTPUT"

- name: Send GitHub Action trigger data to Slack workflow
id: slack
uses: slackapi/slack-github-action@70cd7be8e40a46e8b0eced40b0de447bdb42f68e # v1.26.0
with:
channel-id: "${{ vars.NOTIFY_SLACK_CHANNEL_ID }}"
payload: "${{ steps.payload.outputs.payload }}"
env:
SLACK_BOT_TOKEN: '${{ secrets.SLACK_BOT_OAUTH_TOKEN }}'
43 changes: 30 additions & 13 deletions .github/workflows/release_framework.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,8 @@
name: Release framework

permissions:
contents: read

on:
pull_request:
types:
Expand Down Expand Up @@ -29,18 +32,23 @@ jobs:
steps:
- name: Check release conditions
id: check
env:
EVENT_NAME: ${{ github.event_name }}
REF_NAME: ${{ github.ref_name }}
HEAD_REF: ${{ github.head_ref }}
PR_MERGED: ${{ github.event.pull_request.merged }}
run: |
if [[ "${{ github.event_name }}" == "workflow_dispatch" ]]; then
if [[ "$EVENT_NAME" == "workflow_dispatch" ]]; then
# workflow_dispatch: only allow on master branch
if [[ "${{ github.ref_name }}" == "master" ]]; then
if [[ "$REF_NAME" == "master" ]]; then
echo "should_release=true" >> $GITHUB_OUTPUT
else
echo "should_release=false" >> $GITHUB_OUTPUT
fi
elif [[ "${{ github.event_name }}" == "pull_request" ]]; then
elif [[ "$EVENT_NAME" == "pull_request" ]]; then
# PR: check if it's a release/prerelease branch and merged
head_ref="${{ github.head_ref }}"
is_merged=${{ github.event.pull_request.merged }}
head_ref="$HEAD_REF"
is_merged="$PR_MERGED"

if [[ ("$head_ref" == release* || "$head_ref" == prerelease*) && "$is_merged" == "true" ]]; then
echo "should_release=true" >> $GITHUB_OUTPUT
Expand All @@ -59,7 +67,7 @@ jobs:
release_created: ${{ steps.release.outputs.created }}
steps:
- name: Checkout repository
uses: actions/checkout@v4
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4

- name: Setup gem
uses: appier/appier-ios-framework/.github/actions/install_gem_dependencies@master

Copilot AI Apr 15, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This workflow pins actions/checkout to a commit SHA, but appier/appier-ios-framework/.github/actions/install_gem_dependencies@master is still a mutable ref. For supply-chain safety and reproducibility, consider pinning this action to an immutable commit SHA (and optionally add a version comment as done for other pinned actions).

Suggested change
uses: appier/appier-ios-framework/.github/actions/install_gem_dependencies@master
uses: ./.github/actions/install_gem_dependencies

Copilot uses AI. Check for mistakes.
Expand All @@ -70,10 +78,11 @@ jobs:
id: release
env:
GITHUB_TOKEN: ${{ secrets.GH_TOKEN }}
REF_NAME: ${{ github.ref_name }}
run: |
is_prerelease=false

if [[ "${{ github.ref_name }}" == "prerelease" || "${{ github.ref_name }}" == prerelease* ]]; then
if [[ "$REF_NAME" == "prerelease" || "$REF_NAME" == prerelease* ]]; then
is_prerelease=true
fi

Expand All @@ -86,7 +95,7 @@ jobs:
runs-on: macos-latest
steps:
- name: Checkout repository
uses: actions/checkout@v4
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4

- name: Setup gem
uses: appier/appier-ios-framework/.github/actions/install_gem_dependencies@master
Comment on lines 97 to 101

Copilot AI Apr 15, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

install_gem_dependencies is referenced via @master, which is a mutable ref. To keep workflows reproducible and reduce supply-chain risk (especially now that other actions are pinned), consider pinning this to a commit SHA.

Copilot uses AI. Check for mistakes.
Expand All @@ -104,7 +113,7 @@ jobs:
runs-on: macos-latest
steps:
- name: Checkout repository
uses: actions/checkout@v4
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4

- name: Setup gem
uses: appier/appier-ios-framework/.github/actions/install_gem_dependencies@master
Comment on lines 115 to 119

Copilot AI Apr 15, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This step still uses install_gem_dependencies@master (mutable ref). If the goal is fully deterministic workflows, pin this action to a commit SHA here as well.

Copilot uses AI. Check for mistakes.
Expand All @@ -120,35 +129,43 @@ jobs:
needs: [prepare, create_release]
if: needs.prepare.outputs.should_release == 'true' && needs.create_release.outputs.release_created == 'true'
runs-on: ubuntu-latest
permissions:
contents: read
steps:
- name: Enable Build app with release framework workflow
env:
GH_TOKEN: ${{ secrets.GH_TOKEN }}
run: |
curl -X PUT \
-H "Accept: application/vnd.github+json" \
-H "Authorization: Bearer ${{ secrets.GH_TOKEN }}" \
-H "Authorization: Bearer $GH_TOKEN" \
-H "X-GitHub-Api-Version: 2022-11-28" \
"https://api.github.com/repos/plaxieappier/appier-ios-automation-test-app/actions/workflows/build_app_from_release_sources.yml/enable"

- name: Enable Build demo app workflow
env:
GH_TOKEN: ${{ secrets.GH_TOKEN }}
run: |
curl -X PUT \
-H "Accept: application/vnd.github+json" \
-H "Authorization: Bearer ${{ secrets.GH_TOKEN }}" \
-H "Authorization: Bearer $GH_TOKEN" \
-H "X-GitHub-Api-Version: 2022-11-28" \
"https://api.github.com/repos/plaxieappier/aiqua-ios-demo/actions/workflows/build_and_upload_demo_app.yml/enable"

release_success_message:
needs: [deploy_pod_framework, deploy_pod_extension]
if: ${{ always() && !contains(needs.*.result, 'failure') && !contains(needs.*.result, 'cancelled') && !contains(needs.*.result, 'skipped') }}
uses: ./.github/workflows/Send_message_to_slack.yml
secrets: inherit
secrets:
SLACK_BOT_OAUTH_TOKEN: ${{ secrets.SLACK_BOT_OAUTH_TOKEN }}
with:
is_success: "true"

release_fail_message:
needs: [deploy_pod_framework, deploy_pod_extension]
if: ${{ always() && contains(needs.*.result, 'failure') }}
uses: ./.github/workflows/Send_message_to_slack.yml
secrets: inherit
secrets:
SLACK_BOT_OAUTH_TOKEN: ${{ secrets.SLACK_BOT_OAUTH_TOKEN }}
with:
is_success: "false"