From 70579fbd2d2eebd17af7b4b55baf0de3921eb6b3 Mon Sep 17 00:00:00 2001 From: Xueqin Cui Date: Tue, 3 Mar 2026 14:49:59 +1100 Subject: [PATCH 1/6] proto generation --- .github/workflows/generate-protos.yml | 74 +++++++++++++++++++++++++++ 1 file changed, 74 insertions(+) create mode 100644 .github/workflows/generate-protos.yml diff --git a/.github/workflows/generate-protos.yml b/.github/workflows/generate-protos.yml new file mode 100644 index 00000000000..f6b9f861a1c --- /dev/null +++ b/.github/workflows/generate-protos.yml @@ -0,0 +1,74 @@ +name: Generate Protos + +on: + push: + branches: [ master ] + paths: + - 'osv/osv-schema/proto/vulnerability.proto' + - 'osv/importfinding.proto' + - 'gcp/api/v1/osv_service_v1.proto' + workflow_dispatch: + +concurrency: + # Pushing new changes to a branch will cancel any in-progress CI runs + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true + +# Restrict jobs in this workflow to have no permissions by default; permissions +# should be granted per job as needed using a dedicated `permissions` block +permissions: {} + +jobs: + generate: + permissions: + contents: write # to fetch and commit code + actions: write # to manually dispatch checks on the pull request + pull-requests: write # Create pull requests + runs-on: ubuntu-latest + steps: + - name: Check out code + uses: actions/checkout@v4 + with: + submodules: recursive + persist-credentials: false + + - name: Set up Python + uses: actions/setup-python@v5 + with: + python-version: '3.13' + + - name: Install poetry + run: pip install poetry==2.2.1 + + - name: Set up poetry + run: poetry install + + - name: Set up Go + uses: actions/setup-go@v5 + with: + go-version: '1.26.0' + + - name: Install protoc + run: sudo apt-get install -y protobuf-compiler + + - name: Install Go proto plugins + run: | + go install google.golang.org/protobuf/cmd/protoc-gen-go@v1.36.11 + go install google.golang.org/grpc/cmd/protoc-gen-go-grpc@v1.6.1 + echo "$(go env GOPATH)/bin" >> $GITHUB_PATH + + - name: Generate protos + run: make build-protos + + - name: Create Pull Request + uses: peter-evans/create-pull-request@c0f553fe549906ede9cf27b5156039d195d2ece0 # v8.1.0 + with: + token: ${{ secrets.PR_TOKEN_BOT }} + title: "chore: regenerate protos" + body: > + The proto files have been updated. This PR contains the regenerated code. + + Please review and merge! + branch: "bot/regenerate-protos" + author: "osv-robot " + commit-message: "chore: regenerate protos" From 11358fb80ec2aab0d4bf0269f3cfdbd9ee05bb45 Mon Sep 17 00:00:00 2001 From: Xueqin Cui Date: Tue, 3 Mar 2026 15:41:12 +1100 Subject: [PATCH 2/6] pull request --- .github/workflows/generate-protos.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/.github/workflows/generate-protos.yml b/.github/workflows/generate-protos.yml index f6b9f861a1c..2b8a4e4713c 100644 --- a/.github/workflows/generate-protos.yml +++ b/.github/workflows/generate-protos.yml @@ -7,6 +7,7 @@ on: - 'osv/osv-schema/proto/vulnerability.proto' - 'osv/importfinding.proto' - 'gcp/api/v1/osv_service_v1.proto' + pull_request: workflow_dispatch: concurrency: From ff66cec3664a6b05a7382f673789d987cc249652 Mon Sep 17 00:00:00 2001 From: Xueqin Cui Date: Tue, 3 Mar 2026 15:46:55 +1100 Subject: [PATCH 3/6] install --- .github/workflows/generate-protos.yml | 26 +++++++++++--------------- 1 file changed, 11 insertions(+), 15 deletions(-) diff --git a/.github/workflows/generate-protos.yml b/.github/workflows/generate-protos.yml index 2b8a4e4713c..cfb46436bf3 100644 --- a/.github/workflows/generate-protos.yml +++ b/.github/workflows/generate-protos.yml @@ -7,7 +7,7 @@ on: - 'osv/osv-schema/proto/vulnerability.proto' - 'osv/importfinding.proto' - 'gcp/api/v1/osv_service_v1.proto' - pull_request: + pull_request: workflow_dispatch: concurrency: @@ -50,26 +50,22 @@ jobs: go-version: '1.26.0' - name: Install protoc - run: sudo apt-get install -y protobuf-compiler + run: | + sudo apt-get update + sudo apt-get install -y protobuf-compiler - name: Install Go proto plugins run: | go install google.golang.org/protobuf/cmd/protoc-gen-go@v1.36.11 go install google.golang.org/grpc/cmd/protoc-gen-go-grpc@v1.6.1 echo "$(go env GOPATH)/bin" >> $GITHUB_PATH - - name: Generate protos run: make build-protos - - name: Create Pull Request - uses: peter-evans/create-pull-request@c0f553fe549906ede9cf27b5156039d195d2ece0 # v8.1.0 - with: - token: ${{ secrets.PR_TOKEN_BOT }} - title: "chore: regenerate protos" - body: > - The proto files have been updated. This PR contains the regenerated code. - - Please review and merge! - branch: "bot/regenerate-protos" - author: "osv-robot " - commit-message: "chore: regenerate protos" + - name: Verify no changes + run: | + if [ -n "$(git status --porcelain)" ]; then + echo "::error::Generated proto files are out of sync. Please run 'make build-protos' locally and commit the changes." + git diff + exit 1 + fi From 5a0f41f0cf1cd6ac94160aa37178aace1a57e1d9 Mon Sep 17 00:00:00 2001 From: Xueqin Cui Date: Tue, 3 Mar 2026 15:52:46 +1100 Subject: [PATCH 4/6] poetry --- .github/workflows/generate-protos.yml | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/.github/workflows/generate-protos.yml b/.github/workflows/generate-protos.yml index cfb46436bf3..e5e5c2bd6fe 100644 --- a/.github/workflows/generate-protos.yml +++ b/.github/workflows/generate-protos.yml @@ -42,7 +42,9 @@ jobs: run: pip install poetry==2.2.1 - name: Set up poetry - run: poetry install + run: | + poetry install + cd gcp/api && poetry install - name: Set up Go uses: actions/setup-go@v5 From 3e9329873cd9a3d3d0bafd6abc3ef7e45c4adac4 Mon Sep 17 00:00:00 2001 From: Xueqin Cui Date: Tue, 3 Mar 2026 15:58:37 +1100 Subject: [PATCH 5/6] create pull request --- .github/workflows/generate-protos.yml | 19 ++++++++++++------- 1 file changed, 12 insertions(+), 7 deletions(-) diff --git a/.github/workflows/generate-protos.yml b/.github/workflows/generate-protos.yml index e5e5c2bd6fe..b4cdaa8c37f 100644 --- a/.github/workflows/generate-protos.yml +++ b/.github/workflows/generate-protos.yml @@ -64,10 +64,15 @@ jobs: - name: Generate protos run: make build-protos - - name: Verify no changes - run: | - if [ -n "$(git status --porcelain)" ]; then - echo "::error::Generated proto files are out of sync. Please run 'make build-protos' locally and commit the changes." - git diff - exit 1 - fi + - name: Create Pull Request + uses: peter-evans/create-pull-request@c0f553fe549906ede9cf27b5156039d195d2ece0 # v8.1.0 + with: + token: ${{ secrets.PR_TOKEN_BOT }} + title: "chore: regenerate protos" + body: > + The proto files have been updated. This PR contains the regenerated code. + + Please review and merge! + branch: "bot/regenerate-protos" + author: "osv-robot " + commit-message: "chore: regenerate protos" From dcdbe88a544f9643fa97da58e58f81e0a33a5100 Mon Sep 17 00:00:00 2001 From: Xueqin Cui Date: Tue, 3 Mar 2026 16:02:51 +1100 Subject: [PATCH 6/6] not for pull request --- .github/workflows/generate-protos.yml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/workflows/generate-protos.yml b/.github/workflows/generate-protos.yml index b4cdaa8c37f..a8ad4932c12 100644 --- a/.github/workflows/generate-protos.yml +++ b/.github/workflows/generate-protos.yml @@ -4,10 +4,9 @@ on: push: branches: [ master ] paths: - - 'osv/osv-schema/proto/vulnerability.proto' - - 'osv/importfinding.proto' - 'gcp/api/v1/osv_service_v1.proto' - pull_request: + - 'osv/importfinding.proto' + - 'osv/osv-schema/proto/vulnerability.proto' workflow_dispatch: concurrency: @@ -61,6 +60,7 @@ jobs: go install google.golang.org/protobuf/cmd/protoc-gen-go@v1.36.11 go install google.golang.org/grpc/cmd/protoc-gen-go-grpc@v1.6.1 echo "$(go env GOPATH)/bin" >> $GITHUB_PATH + - name: Generate protos run: make build-protos