Commit Graph
100 Commits
Author SHA1 Message Date
Daz DeBoerandGitHub 62cce3c597 FIx dependency review example in README 2023-09-30 18:24:45 -06:00
Daz DeBoerandGitHub 842c587ad8 Merge pull request #911 - Improve dependency review support 2023-10-01 02:01:56 +02:00
daz 4241e05054 Document configuration for dependency-review-action 2023-09-30 17:45:44 -06:00
daz bfa3c0508e Build outputs 2023-09-30 08:49:10 -06:00
daz c3bdce8205 Warn on dependency-graph-submit failure
A common issue when submitting a dependency graph is that the required
'contents: write' permission is not set.
We now catch any dependency submission failure and inform the user to check
that the required permissions are available.
2023-09-30 08:47:10 -06:00
daz f92e7c3428 Improve compat with dependency-review-action
When using 'download-and-submit' for dependency graphs, we now run the
submission immediately instead of waiting until the post-action.
This allows a single job to both submit the graph and run the dependency
review action.
2023-09-29 20:36:16 -06:00
daz d1b726d8c1 Do not generate dependency graph in cache-cleanup
- Allow environment variables to be overridden by system properties in dependency-graph initscript
- Set `GITHUB_DEPENDENCY_GRAPH_ENABLED=false` when executing Gradle for cache cleanup
2023-09-29 22:55:54 +02:00
Daz DeBoerandGitHub 6fcc109efa Dependency updates (#904)
### Github Action updates

Updates `gradle/gradle-build-action` from 2.8.0 to 2.8.1

### NPM updates

Updates `@octokit/webhooks-types` from 7.3.0 to 7.3.1
- [Release notes](https://github.com/octokit/webhooks/releases)
- [Commits](https://github.com/octokit/webhooks/compare/v7.3.0...v7.3.1)

Updates `@typescript-eslint/parser` from 6.7.2 to 6.7.3
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v6.7.3/packages/parser)

Updates `eslint` from 8.49.0 to 8.50.0
- [Release notes](https://github.com/eslint/eslint/releases)
- [Changelog](https://github.com/eslint/eslint/blob/main/CHANGELOG.md)
- [Commits](https://github.com/eslint/eslint/compare/v8.49.0...v8.50.0)
2023-09-29 13:55:35 -06:00
daz 324fbdc804 Update to dep-graph plugin 0.4.1 2023-09-29 13:22:08 -06:00
daz 5658338fb0 Build outputs 2023-09-26 15:51:30 +02:00
daz 87ccc98a2a Use correct SHA for pull request events
In a pull request, GITHUB_SHA is set to the "last merge commit on the GITHUB_REF branch".
This isn't the correct value to use when generating a dependency graph.
This changes to use the value of `pull_request.head.sha`, which is the correct
value for a dependency graph.

Fixes #882
2023-09-26 15:51:30 +02:00
daz 4441c9f9bf Update to dep-graph plugin 0.4.0 2023-09-26 15:51:30 +02:00
Daz DeBoerandGitHub b5126f31db Use github.getOctokit() for compat with GitHub Enterprise
Thanks @nise-nabe for the inspiration

Fixes #885
2023-09-21 10:55:26 -06:00
Daz DeBoerandGitHub d8615ccc8b Document configuration to publish to scans.gradle.com
Fixes #870
2023-09-21 10:47:51 -06:00
Daz DeBoer 444c20baf7 Test multiple dependency graphs on all os's 2023-09-21 18:22:31 +02:00
daz aea76e1766 Dependency updates 2023-09-21 10:01:33 -06:00
daz 103e3a7ba7 Build outputs 2023-09-21 08:47:55 -06:00
daz b063df05a4 Bump GE plugin versions 2023-09-21 08:41:43 -06:00
Daz DeBoerandGitHub ed940a329a Fix name of test dependency-graph workflow 2023-09-21 08:19:49 -06:00
Daz DeBoerandGitHub 3bfe3a4658 Clarify documentation
Fixes #867
2023-09-04 16:09:52 -06:00
daz 8f08e41675 Use unique cache key for workflow 2023-08-28 12:40:55 -06:00
Daz DeBoerandGitHub ef76a971e2 Simplify GE-inject config params (#863) 2023-08-28 11:59:09 -06:00
Daz DeBoerandGitHub 3122f2c659 Mention GE authentication with GE injection 2023-08-23 12:07:20 -06:00
Daz DeBoerandGitHub 53c4cf6c4c Merge pull request #861 from gradle/dd/dependency-updates
Dependency updates
2023-08-23 15:59:29 +02:00
daz f2d7085b02 Add octokit to dependabot ignores 2023-08-22 10:28:15 -06:00
Daz DeBoerandGitHub e3426b1f20 Merge pull request #857 from gradle/dd/inject-ge
Add support for Gradle Enterprise injection into Gradle Builds
2023-08-21 01:38:14 +02:00
daz d79398df06 Add docs for GE injection 2023-08-20 16:30:34 -06:00
daz b9cd1d9e69 Build outputs 2023-08-20 16:29:23 -06:00
daz d4db33d499 Add integ-test for GE injection 2023-08-20 16:29:23 -06:00
daz 05acc776e8 Wire new init-script into action
- Copy init-script to Gradle User Home
- Rename init-scripts for consistency and clarity
2023-08-20 16:29:23 -06:00
daz 33c9bfac14 Fix test for dependency graph with configuration cache 2023-08-20 16:29:23 -06:00
daz 97d9c134b7 Add init-script for Gradle Enterprise injection
Adds a new init-script which can enable and configure the Gradle Enterprise plugin(s)
for a build, without needing to modify the settings script for the project.
The functionality is enabled and configured via environment variables or system properties.

Not yet wired into `gradle-build-action`.
2023-08-20 16:29:23 -06:00
Daz DeBoerandGitHub a617adb316 Minor documentation updates 2023-08-20 15:56:45 -06:00
Daz DeBoerandGitHub b156d58cac Document the cache-overwrite-existing parameter 2023-08-20 14:14:54 -06:00
Daz DeBoerandGitHub b946c060aa Document the gradle-version output parameter 2023-08-20 14:05:33 -06:00
Daz DeBoerandGitHub 96bed685e4 Merge pull request #855 from gradle/dd/installed-toolchains
Detect installed java toolchains
2023-08-20 05:27:22 +02:00
daz 800e5e1e62 Fix check 2023-08-19 20:42:08 -06:00
daz ff3f4cfbf8 Build outputs 2023-08-19 20:14:11 -06:00
daz a07019c726 Inform Gradle where to locate pre-installed JDKs 2023-08-19 20:14:11 -06:00
daz b17d107b8c Add test for detection of java toolchains 2023-08-19 20:14:11 -06:00
daz 12dcfaa735 Bump to the latest Foojay resolver 2023-08-19 17:24:51 -06:00
Daz DeBoerandGitHub 9fb6114fb4 Merge pull request #854 from gradle/dd/existing-gradle-home
- Report the cache as disabled when Gradle User Home exists #434 
- Allow cache restore over pre-existing Gradle User Home #480
2023-08-19 22:27:30 +02:00
daz 50d07aa0e5 Build outputs 2023-08-19 13:37:53 -06:00
daz 3d49588efc Allow cache to overwrite existing Gradle User Home
Fixes #480
2023-08-19 13:37:53 -06:00
daz 68e1dcdea4 Report the cache as disabled when Gradle User Home exists
Fixes #434
2023-08-19 13:37:49 -06:00
daz 8cade330d4 Include provisioned Gradle version as action output
Fixes #259
2023-08-19 20:37:12 +02:00
daz 124cb765ee Update to Gradle 8.3 2023-08-19 10:32:05 -06:00
Daz DeBoerandGitHub 243af859f8 Improve and extend documentation for dependency-graph generation (#851)
* Improve documentation for dependency-graph generation

Fixes #849
Fixes #843
2023-08-18 15:50:06 -06:00
Daz DeBoer dc5f59ec6e Update action description for SEO 2023-08-17 17:00:13 -06:00
Daz DeBoerandGitHub c87c55823d Merge pull request #850 from gradle/dd/docs
Improve docs on Gradle User Home caching
2023-08-17 23:18:35 +02:00
daz cfdcfc37ed Docs reformat 2023-08-17 15:13:47 -06:00
daz 193108951e Improve docs on Gradle User Home caching
- Describe the limitations/properties of the GitHub Actions cache
- Document the algorithm for generating a cache key, and the way that cache entries are matched
- Describe in more detail how entries are de-duplicated
- Explain how cache entries can be optimized in Job pipelines

Fixes #831
Fixes #608
2023-08-17 14:49:12 -06:00
Daz DeBoerandGitHub f9b4995b32 Docs: clarify incompatibility with setup-java caching
Fixes #725
2023-08-16 14:26:17 -06:00
Daz DeBoerandGitHub e3028deccc Merge pull request #826 from 3flex/patch-1
Polish GitHub Dependency Graph support section
2023-08-15 15:31:22 +02:00
Daz DeBoerandGitHub cb1fda6460 Merge pull request #836 from gradle/dd/dependency-updates
Dependency updates
2023-08-15 15:17:53 +02:00
daz 19e2bdf3c0 Build outputs 2023-08-14 20:07:24 -06:00
daz 891451e1fc Update NPM dependencies 2023-08-14 20:04:27 -06:00
daz 03f0ac2c51 Bump to use the latest release 2023-08-14 19:59:38 -06:00
daz 999ba18af8 Bump dependency versions in sample app 2023-08-14 19:57:15 -06:00
daz 43f8f93391 Update to GE plugin 3.14.1 2023-08-14 19:55:05 -06:00
Daz DeBoerandGitHub a4cf152f48 Merge pull request #817 from gradle/dd/270
Prepare for 2.7.0 release
2023-07-24 17:04:07 +02:00
daz a8aac055e2 Build outputs 2023-07-24 08:55:39 -06:00
daz 7241fa5d56 Add new output to Action.yml 2023-07-24 08:43:47 -06:00
daz 9e58f8b1de Add dependency-graph-file as step output
Fixes #804
2023-07-24 08:37:14 -06:00
daz 632e888003 Update to the latest dependency-graph plugin
- Remove experimental warning
- Update documentation
2023-07-24 08:37:14 -06:00
daz ced6859e9c Update Build Scan™ to Build Scan® 2023-07-22 08:53:58 -06:00
daz 0904709a46 Bump GE plugin versions 2023-07-21 13:32:44 -06:00
daz 1b94073332 Bump development dependencies 2023-07-21 13:13:44 -06:00
Daz DeBoerandGitHub 4821f54162 Group all npm dependencies in a single dependabot PR 2023-07-21 12:19:33 -06:00
daz 915a66c096 Bump dependency-graph version number 2023-07-17 15:46:14 -06:00
daz 8e5c8782a3 Build outputs 2023-07-17 15:35:48 -06:00
daz 9f977db2d8 Update to latest plugin version 2023-07-17 15:12:30 -06:00
daz fa27d06744 Test configuration-cache compatibility 2023-07-17 14:00:55 -06:00
Daz DeBoerandGitHub a0fdbb009a Fix issue locating wrapper bat on windows 2023-07-15 23:04:38 -06:00
daz f59a6d4310 Avoid log messages for included builds 2023-07-15 22:33:54 -06:00
daz b69de5f2a9 Support multiple invocations in dependency-graph init script
If an existing dependency graph file is present for the configured job correlator,
we now generate a unique correlator value for the invocation. This allows the action
to submit dependency snapshots for a series of Gradle invocations within the same Job.

This commit updates to `github-dependency-graph-gradle-plugin@v0.0.6`, which reduces
redundancy in the mapping of resolved Gradle dependencies to the GitHub Dependency Graph.
2023-07-15 22:33:31 -06:00
daz 3c11eee5f9 Don't use full path when executing gradlew
Fixes #796
2023-07-13 16:15:54 -06:00
daz 4301451b53 Bump to Gradle 8.2.1 2023-07-13 21:38:47 +02:00
daz 295170c2ce Remove dists for removed actions 2023-07-13 13:12:44 -06:00
Daz DeBoerandGitHub ad97b0f09e Bump the github-actions group with 1 update (#784)
Bumps the github-actions group with 1 update:
[gradle/gradle-build-action](https://github.com/gradle/gradle-build-action).
2023-07-11 02:51:25 +02:00
Daz DeBoerandGitHub bd57605957 Remove 'experimental' from chapter title 2023-07-10 10:26:35 -06:00
Daz DeBoerandGitHub f464d5c9e5 Improve docs for dependency-graph 2023-07-10 10:23:31 -06:00
daz cef72ff9e4 Use latest github-dependency-graph-gradle-plugin 2023-07-10 07:16:49 -06:00
Daz DeBoerandGitHub 7a67f395d2 Add basic support for GitHub Dependency Graph (#782) 2023-07-08 04:57:02 +02:00
daz bc190ca89a Build outputs 2023-07-07 20:43:20 -06:00
daz f01b48d89d Do not attempt dependency graph on unsupported Gradle versions 2023-07-07 20:42:49 -06:00
daz 1e71bceb3f Supply plugin portal URL directly
The 'gradlePluginPortal()' convenience isn't supported in older Gradle versions.
2023-07-07 20:42:49 -06:00
Daz DeBoer 9a4d99b236 Add initial docs for dependency-graph support 2023-07-07 20:42:49 -06:00
daz 33f9bc031c Added action to clear deps for a correlator 2023-07-07 20:42:49 -06:00
daz 437bff62b6 Add basic test coverage for dependency graph
- Test workflow with dependency graph enabled
- Gradle test for init-script functionality
2023-07-07 20:42:49 -06:00
daz c0186c5832 Replace spaces with underscore in job correlator 2023-07-07 20:42:49 -06:00
daz ee7ca6ac9b Remove defunct generate actions 2023-07-07 20:42:48 -06:00
daz 063cc1c708 Allow flexible use of dependency-graph support
Adds a 'dependency-graph' parameter that has 4 options:
1. 'disabled': no dependency graph files generated (the default)
2. 'generate': dependency graph files will be generated and saved as artifacts.
3. 'generate-and-submit': dependency graph files will be generated, saved as artifacts,
   and submitted to the Dependency Submission API on job completion.
4. 'download-and-submit': any previously uploaded dependency graph artifacts will be downloaded
   and submitted to the Dependency Submission API.
2023-07-07 20:42:48 -06:00
daz 820b228f28 Switch back to using published plugin 2023-07-07 20:42:48 -06:00
daz d0ffeaa089 Reduce log level for debug message 2023-07-07 20:42:48 -06:00
daz 4c9c435d2f Configure Gradle User Home for dependency-graph
Instead of requiring an action step to generate the graph, configure Gradle User Home
so that subsequent Gradle invocations can generate a graph. Any generated graph files
are uploaded as artifacts on job completion.

- Construct job.correlator from workflow/job/matrix
- Export job.correlator as an environment var
- Upload artifacts at job completion in post-action step
- Specify the location of dependency graph report
- Only apply dependency graph init script when explicitly enabled
2023-07-07 20:42:48 -06:00
daz a6ad1901be Copy dependency graph init script to Gradle Home
- Temporarily use a hard-coded plugin for convenience
2023-07-07 20:42:48 -06:00
daz d7761f188f Update prettier to v3.0.0 2023-07-08 04:40:54 +02:00
Daz DeBoerandGitHub 92c37aaab7 Update dependencies (#779) 2023-07-08 04:12:58 +02:00
daz 1a6aca96f3 Build outputs 2023-07-07 19:56:01 -06:00