Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,13 +7,16 @@ version: 2
updates:
- package-ecosystem: "npm"
directory: "/"
# Bumps go through dev like any other change; main deploys to production.
target-branch: "dev"
schedule:
interval: "weekly"
labels:
- "dependencies"

- package-ecosystem: "github-actions"
directory: "/"
target-branch: "dev"
schedule:
interval: "weekly"
labels:
Expand Down
13 changes: 9 additions & 4 deletions .github/workflows/dependabot-auto-merge.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,17 +8,22 @@ permissions:
jobs:
dependabot:
runs-on: ubuntu-latest
if: github.actor == 'dependabot[bot]'
# The PR author, not github.actor: the actor is whoever triggered this run,
# which a human re-running it or pushing to the branch can make misleading.
if: github.event.pull_request.user.login == 'dependabot[bot]'
steps:
- name: Dependabot metadata
id: metadata
uses: dependabot/fetch-metadata@v3
with:
github-token: "${{ secrets.GITHUB_TOKEN }}"
- name: Command Dependabot to merge
# Automatically merge if it's a minor/patch update. You can adjust this to your liking.
# GitHub removed the "@dependabot merge" comment command on 2026-01-27, so
# commenting it does nothing. Native auto-merge instead: it merges once the
# ruleset is satisfied, which still means a code-owner approval. Needs
# "Allow auto-merge" on in the repo settings.
- name: Enable auto-merge for minor and patch updates
if: steps.metadata.outputs.update-type != 'version-update:semver-major'
run: gh pr comment "$PR_URL" -b "@dependabot merge"
run: gh pr merge --auto --squash "$PR_URL"
env:
PR_URL: ${{github.event.pull_request.html_url}}
GH_TOKEN: ${{secrets.GITHUB_TOKEN}}
13 changes: 13 additions & 0 deletions .github/workflows/dev-to-main-pr.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,12 @@ on:
push:
branches:
- dev
# Backstop for merges the push trigger never sees. Dependabot PRs are merged
# by native auto-merge under GITHUB_TOKEN, and pushes made with that token
# start no workflows, so a bump could sit on dev with no promotion PR.
schedule:
- cron: "0 13 * * *"
workflow_dispatch:

jobs:
create-pull-request:
Expand All @@ -19,6 +25,13 @@ jobs:
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
# A scheduled run finds dev level with main most days, and gh pr create
# fails with "no commits between" rather than doing nothing.
ahead=$(gh api "repos/${{ github.repository }}/compare/main...dev" --jq .ahead_by)
if [ "$ahead" = "0" ]; then
echo "dev has nothing ahead of main."
exit 0
fi
# Only "a PR already exists" is expected; anything else should fail
# the job rather than be swallowed by || true. Same-repo PRs only: a
# fork's branch of the same name must not suppress this one.
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/firebase-hosting-pull-request.yml
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,10 @@ jobs:
- name: Build Hacklytics 2027
run: pnpm turbo run build --filter=hacklytics2027

# Dependabot PRs get no repo secrets, so the deploy would fail on a
# missing service account. The build above still checks the bump.
- uses: FirebaseExtended/action-hosting-deploy@v0
if: ${{ github.event.pull_request.user.login != 'dependabot[bot]' }}
with:
repoToken: ${{ secrets.GITHUB_TOKEN }}
firebaseServiceAccount: ${{ secrets.FIREBASE_SERVICE_ACCOUNT_DSGT_WEBSITE }}
Expand Down
15 changes: 14 additions & 1 deletion firebase.json
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@
"trailingSlash": true,
"headers": [
{
"source": "**/*.@(js|css|woff|woff2|ttf|eot|otf|jpg|jpeg|png|gif|webp|avif|ico|svg)",
"source": "**/*.@(js|css|woff|woff2|ttf|eot|otf)",
"headers": [
{
"key": "Cache-Control",
Expand All @@ -25,6 +25,19 @@
}
]
},
{
"source": "**/*.@(jpg|jpeg|png|gif|webp|avif|ico|svg)",
"headers": [
{
"key": "Cache-Control",
"value": "public, max-age=86400, stale-while-revalidate=604800"
},
{
"key": "X-Content-Type-Options",
"value": "nosniff"
}
]
},
{
"source": "**/*.html",
"headers": [
Expand Down
48 changes: 47 additions & 1 deletion graphify-out/.graphify_labels.json
Original file line number Diff line number Diff line change
Expand Up @@ -132,5 +132,51 @@
"130": "Community 130",
"131": "Community 131",
"132": "Community 132",
"133": "Community 133"
"133": "Community 133",
"134": "Community 134",
"135": "Community 135",
"136": "Community 136",
"137": "Community 137",
"138": "Community 138",
"139": "Community 139",
"140": "Community 140",
"141": "Community 141",
"142": "Community 142",
"143": "Community 143",
"144": "Community 144",
"145": "Community 145",
"146": "Community 146",
"147": "Community 147",
"148": "Community 148",
"149": "Community 149",
"150": "Community 150",
"151": "Community 151",
"152": "Community 152",
"153": "Community 153",
"154": "Community 154",
"155": "Community 155",
"156": "Community 156",
"157": "Community 157",
"158": "Community 158",
"159": "Community 159",
"160": "Community 160",
"161": "Community 161",
"162": "Community 162",
"163": "Community 163",
"164": "Community 164",
"165": "Community 165",
"166": "Community 166",
"167": "Community 167",
"168": "Community 168",
"169": "Community 169",
"170": "Community 170",
"171": "Community 171",
"172": "Community 172",
"173": "Community 173",
"174": "Community 174",
"175": "Community 175",
"176": "Community 176",
"177": "Community 177",
"178": "Community 178",
"179": "Community 179"
}
Loading
Loading