diff --git a/.github/workflows/CheckMarketplaceMetadata.yml b/.github/workflows/CheckMarketplaceMetadata.yml new file mode 100644 index 0000000..a51b080 --- /dev/null +++ b/.github/workflows/CheckMarketplaceMetadata.yml @@ -0,0 +1,178 @@ +# The MIT License (MIT) +# +# Copyright © 2026 The pyTooling Authors +# +# Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated +# documentation files (the “Software”), to deal in the Software without restriction, including without limitation the +# rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit +# persons to whom the Software is furnished to do so, subject to the following conditions: +# +# The above copyright notice and this permission notice shall be included in all copies or substantial portions of the +# Software. +# +# THE SOFTWARE IS PROVIDED “AS IS”, WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE +# WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR +# COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR +name: Check Marketplace Metadata + +on: + workflow_call: + inputs: + action_file: + description: | + Action metadata file. GitHub Marketplace requires it at the repository root. + type: string + required: false + default: 'action.yml' + description_limit: + description: | + Maximum length of the action's description. The Marketplace form rejects 'description' with + "Description must be less than 125 characters.", so the limit is exclusive. + type: number + required: false + default: 125 + ubuntu_image: + description: 'Name of the Ubuntu image.' + type: string + required: false + default: 'ubuntu-26.04' + + workflow_dispatch: + +jobs: + CheckMarketplaceMetadata: + name: 🛒 Check Marketplace metadata + runs-on: ${{ inputs.ubuntu_image || 'ubuntu-26.04' }} + + steps: + - name: ⏬ Checkout repository + uses: actions/checkout@v7 + + - name: 🛒 Check the action's metadata against the Marketplace rules + id: check + shell: bash + env: + ACTION_FILE: ${{ inputs.action_file || 'action.yml' }} + DESCRIPTION_LIMIT: ${{ inputs.description_limit || 125 }} + REPOSITORY_PRIVATE: ${{ github.event.repository.private }} + run: | + # 🛒 Check the action's metadata against the Marketplace rules + set +e + + ANSI_CYAN=$'\x1b[36m' + ANSI_LIGHT_RED=$'\x1b[91m' + ANSI_LIGHT_GREEN=$'\x1b[92m' + ANSI_LIGHT_YELLOW=$'\x1b[93m' + ANSI_NOCOLOR=$'\x1b[0m' + + errors=0 + + fail() { + printf "%s\n" "${ANSI_LIGHT_RED}[FAILED]${ANSI_NOCOLOR}" + printf " ↪ %s\n" "${ANSI_LIGHT_RED}${1}${ANSI_NOCOLOR}" + printf "::error title=%s::%s\n" "Marketplace" "${1}" + errors=$((errors + 1)) + } + + printf "%s\n" "${ANSI_CYAN}Checking '${ACTION_FILE}' against the GitHub Marketplace rules ...${ANSI_NOCOLOR}" + + printf "%s" "Metadata file at the repository root ... " + if [[ ! -f "${ACTION_FILE}" ]]; then + fail "GitHub Marketplace requires an 'action.yml' or 'action.yaml' at the repository root; '${ACTION_FILE}' doesn't exist." + printf "::error title=%s::%s\n" "Marketplace" "Aborting: no metadata file to check." + exit 1 + fi + printf "%s\n" "${ANSI_LIGHT_GREEN}[OK]${ANSI_NOCOLOR}" + + # 'name', 'description' and 'branding' are read with the YAML parser rather than with grep, so a folded or + # quoted value is measured as the Marketplace sees it. + read -r -d '' script <<'PYTHON' + import sys, yaml + action = yaml.safe_load(open(sys.argv[1], encoding="utf-8")) or {} + branding = action.get("branding") or {} + # 'or ""' rather than a default: a key present with an empty value parses as None, and str(None) is the + # four-character string "None", which would pass every check below. + for key, value in ( + ("name", action.get("name") or ""), + ("description", action.get("description") or ""), + ("icon", branding.get("icon") or ""), + ("color", branding.get("color") or ""), + ): + print(f"{key}={str(value).strip()}") + PYTHON + metadata="$(python3 -c "${script}" "${ACTION_FILE}" 2>&1)" + if [[ $? -ne 0 ]]; then + fail "'${ACTION_FILE}' isn't valid YAML: ${metadata//$'\n'/ }" + exit 1 + fi + + name="$( sed -n 's/^name=//p' <<< "${metadata}")" + description="$(sed -n 's/^description=//p' <<< "${metadata}")" + icon="$( sed -n 's/^icon=//p' <<< "${metadata}")" + color="$( sed -n 's/^color=//p' <<< "${metadata}")" + + printf "%s\n" "" + printf " %-14s%s\n" "name:" "${name}" + printf " %-14s%s\n" "description:" "${description}" + printf " %-14s%s\n" "icon:" "${icon}" + printf " %-14s%s\n" "color:" "${color}" + printf "%s\n" "" + + printf "%s" "Action name is set ... " + if [[ -z "${name}" ]]; then + fail "'name' is required. It also has to be unique across GitHub Marketplace, which can't be checked here." + else + printf "%s\n" "${ANSI_LIGHT_GREEN}[OK]${ANSI_NOCOLOR}" + fi + + printf "%s" "Description is set ... " + if [[ -z "${description}" ]]; then + fail "'description' is required." + else + printf "%s\n" "${ANSI_LIGHT_GREEN}[OK]${ANSI_NOCOLOR}" + + printf "%s" "Description is shorter than ${DESCRIPTION_LIMIT} characters ... " + length="$(printf "%s" "${description}" | wc -m)" + if [[ ${length} -ge ${DESCRIPTION_LIMIT} ]]; then + fail "'description' is ${length} characters; the Marketplace requires fewer than ${DESCRIPTION_LIMIT}." + else + printf "%s\n" "${ANSI_LIGHT_GREEN}[OK]${ANSI_NOCOLOR} (${length} characters)" + fi + fi + + printf "%s" "Branding icon is set ... " + if [[ -z "${icon}" ]]; then + fail "'branding.icon' is required to list an action on the Marketplace." + elif [[ ! "${icon}" =~ ^[a-z0-9]+(-[a-z0-9]+)*$ ]]; then + fail "'branding.icon' is '${icon}', which isn't a Feather icon name." + else + printf "%s\n" "${ANSI_LIGHT_GREEN}[OK]${ANSI_NOCOLOR}" + # The accepted set is a subset of Feather, too long and too changeable to hard-code here, so the name is + # only checked for shape. A name that isn't in the set is rejected by the Marketplace form. + printf " ↪ %s\n" "${ANSI_LIGHT_YELLOW}not verified against the Feather set — see https://feathericons.com${ANSI_NOCOLOR}" + fi + + printf "%s" "Branding colour is one of the accepted values ... " + case "${color}" in + white|yellow|blue|green|orange|red|purple|gray-dark) + printf "%s\n" "${ANSI_LIGHT_GREEN}[OK]${ANSI_NOCOLOR}" ;; + "") + fail "'branding.color' is required to list an action on the Marketplace." ;; + *) + fail "'branding.color' is '${color}'; accepted are white, yellow, blue, green, orange, red, purple and gray-dark." ;; + esac + + printf "%s" "Repository is public ... " + if [[ "${REPOSITORY_PRIVATE}" == "true" ]]; then + fail "The Marketplace only lists actions from public repositories." + else + printf "%s\n" "${ANSI_LIGHT_GREEN}[OK]${ANSI_NOCOLOR}" + fi + + printf "%s\n" "" + if [[ ${errors} -ne 0 ]]; then + printf "%s\n" "${ANSI_LIGHT_RED}Counted ${errors} errors.${ANSI_NOCOLOR}" + exit 1 + fi + printf "%s\n" "${ANSI_LIGHT_GREEN}No errors found.${ANSI_NOCOLOR}" + printf "%s\n" "${ANSI_LIGHT_YELLOW}Publishing itself is a checkbox when editing the release — there is no API for it.${ANSI_NOCOLOR}" diff --git a/.github/workflows/Pipeline.yml b/.github/workflows/Pipeline.yml index 7a23b12..886cf35 100644 --- a/.github/workflows/Pipeline.yml +++ b/.github/workflows/Pipeline.yml @@ -27,6 +27,9 @@ jobs: Prepare: uses: pyTooling/Actions/.github/workflows/PrepareJob.yml@r8 + Marketplace: + uses: ./.github/workflows/CheckMarketplaceMetadata.yml + DryRun: name: 🐧 Dry-run with a valid configuration runs-on: ubuntu-26.04 @@ -140,6 +143,7 @@ jobs: uses: pyTooling/Actions/.github/workflows/TagReleaseCommit.yml@r8 needs: - Prepare + - Marketplace - DryRun - ErrorHandling - FailOnError @@ -159,6 +163,7 @@ jobs: uses: ./.github/workflows/UpdateVersionBranch.yml needs: - Prepare + - Marketplace - DryRun - ErrorHandling - FailOnError @@ -176,6 +181,7 @@ jobs: uses: pyTooling/Actions/.github/workflows/PublishReleaseNotes.yml@r8 needs: - Prepare + - Marketplace - DryRun - ErrorHandling - FailOnError diff --git a/README.md b/README.md index 6d8cdab..5aa7d0d 100644 --- a/README.md +++ b/README.md @@ -322,6 +322,16 @@ three jobs, no token, no repository touched. Beyond that it releases itself, wit there; where nothing needs rewriting, the pull-request is a plain merge of `main`. Only **self**-references are touched — `pyTooling/Actions@r8` and `actions/checkout@v7` are separate decisions and are left alone. +* **`CheckMarketplaceMetadata.yml`** — a local reusable workflow validating `action.yml` against the + [Marketplace](https://github.com/marketplace?type=actions) rules on every push: the metadata file at the repository + root, a name, a description shorter than 125 characters, a branding icon and one of the eight accepted branding + colours, and a public repository. + + **Publishing itself stays manual.** There is no API for it — an action is listed by ticking *Publish this Action to + the GitHub Marketplace* while drafting or editing its release. A tag carries exactly one release, and the + Marketplace listing is a property of that release, not a second one, so an already-published release is **edited** + rather than re-created. + So a release is one merge: open a `dev` → `main` pull-request titled `vMM.mm.pp`, write the release notes in its description, and merge it. What follows is automatic, except for the version-branch pull-request, which waits for a review. diff --git a/action.yml b/action.yml index 5ceb8b1..df3fc6f 100644 --- a/action.yml +++ b/action.yml @@ -19,7 +19,7 @@ name: 🔄 Synchronize Forked Repositories branding: icon: refresh-cw color: yellow -description: Synchronize branches and tags of forked repositories of a GitHub organisation or user account with their upstream repositories. +description: Synchronize branches and tags of forked repositories in a GitHub namespace with their upstream repositories. author: Patrick Lehmann (@Paebbels) inputs: