Documentation
¶
Overview ¶
Package workflowfile owns the parsed workflow YAML representation: loading, extraction of action refs, local composite discovery, and comment-preserving rewriting. It intentionally has no dependency on the lockfile or resolver packages.
Index ¶
- Constants
- func DiscoverWorkflows() ([]string, error)
- func DiscoverWorkflowsIn(dir string) ([]string, error)
- func EnsureSentinel(content []byte) []byte
- func ExtractLocalCompositeRefs(workflowPath string, localPaths []string) ([]parserlock.ActionRef, []string)
- func IsHostedRunnerLabel(label string) bool
- func KeyFromPath(workflowPath string) string
- func RegisterOrgHostedLabels(labels []string)
- type File
- func (f *File) ExtractActionRefs() ([]parserlock.ActionRef, []string, []string)
- func (f *File) ExtractRunsOnLabels() []string
- func (f *File) HasNonHostedRunnerLabels() bool
- func (f *File) NonHostedRunnerLabels() []string
- func (f *File) RewriteActionRefs(replacements map[string]string) ([]byte, int, error)
Constants ¶
const SentinelComment = "# This workflow is managed by gh actions-lock."
SentinelComment is prepended to workflow files managed by gh actions-lock so users can tell at a glance that the file's action refs are locked.
Variables ¶
This section is empty.
Functions ¶
func DiscoverWorkflows ¶
DiscoverWorkflows finds all workflow files in .github/workflows/ relative to the current directory. Returns nil if the directory doesn't exist.
func DiscoverWorkflowsIn ¶
DiscoverWorkflowsIn finds all workflow files (*.yml, *.yaml) in dir. Returns nil if the directory doesn't exist.
func EnsureSentinel ¶ added in v0.1.0
EnsureSentinel prepends the sentinel comment to the workflow content if it is not already present at the top of the file. The comment is placed before any existing content with a blank line separating it from the YAML body.
func ExtractLocalCompositeRefs ¶
func ExtractLocalCompositeRefs(workflowPath string, localPaths []string) ([]parserlock.ActionRef, []string)
ExtractLocalCompositeRefs reads action.yml files from local paths relative to the workflow file's directory and returns any repository action refs found in their steps.
func IsHostedRunnerLabel ¶ added in v0.0.15
IsHostedRunnerLabel reports whether label is a known GitHub-hosted runner.
func KeyFromPath ¶
KeyFromPath converts a workflow path discovered on disk (relative to the repo root or cwd) into the repo-relative key used inside the lockfile.
func RegisterOrgHostedLabels ¶ added in v0.0.16
func RegisterOrgHostedLabels(labels []string)
RegisterOrgHostedLabels adds labels to the hosted runner allowlist. Call before ParseAll; safe to call multiple times. The special value "*" marks all labels as hosted.
Types ¶
type File ¶
File is the parsed workflow YAML the CLI rewrites in-place. It carries the original byte content alongside the parsed node tree so RewriteActionRefs can do anchored, comment-preserving substitution.
func (*File) ExtractActionRefs ¶
func (f *File) ExtractActionRefs() ([]parserlock.ActionRef, []string, []string)
ExtractActionRefs finds all uses: references to repository actions in the workflow.
func (*File) ExtractRunsOnLabels ¶ added in v0.0.15
ExtractRunsOnLabels returns the deduplicated runs-on labels across all jobs.
func (*File) HasNonHostedRunnerLabels ¶ added in v0.0.15
HasNonHostedRunnerLabels reports whether any job uses a non-hosted runner label.
func (*File) NonHostedRunnerLabels ¶ added in v0.0.16
NonHostedRunnerLabels returns distinct non-hosted labels across all jobs.