name: Bump Flake Inputs on: workflow_dispatch: schedule: - cron: "45 0 * * *" # run daily at 00:45 UTC permissions: {} jobs: update-lockfile: runs-on: ubuntu-latest environment: production steps: - name: Checkout uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 with: persist-credentials: false - name: Install Lix uses: ./.github/actions/install-lix - name: Update Lockfile id: pr uses: DeterminateSystems/update-flake-lock@834c491b2ece4de0bbd00d85214bb5e83b4da5c6 # v28 with: token: ${{ secrets.GH_TOKEN_UPDATES }} git-author-name: bell's bot git-author-email: bot@isabelroses.com git-committer-name: bell's bot git-committer-email: bot@isabelroses.com commit-msg: "flake.lock: update all inputs" pr-title: "flake.lock: update all inputs" branch: update-flake-inputs pr-body: | ``` {{ env.GIT_COMMIT_MESSAGE }} ``` - name: Wait for Checks & Merge run: | # we can't instantly check for ci status or it errors; so lets horribly wait then # then check and watch ci status then merge sleep 30 gh pr checks "$PR" --watch --fail-fast gh pr merge --rebase --delete-branch "$PR" env: GH_TOKEN: ${{ secrets.GH_TOKEN_UPDATES }} PR: ${{ steps.pr.outputs.pull-request-url }}