From 831bd4fe94d7de4b0440629bb5da1344addfb8dd Mon Sep 17 00:00:00 2001 From: Anthony Stirling <77850077+Frooodle@users.noreply.github.com> Date: Fri, 24 Jul 2026 10:52:26 +0100 Subject: [PATCH] Remove depot.dev support from GitHub Actions workflows (#7148) --- .github/workflows/PR-Auto-Deploy-V2.yml | 39 ++-------- .../workflows/PR-Demo-Comment-with-react.yml | 54 ++----------- .github/workflows/_runner-pick.yml | 35 +-------- .github/workflows/ai-engine.yml | 2 - .github/workflows/backend-build.yml | 8 +- .github/workflows/build-enterprise.yml | 21 +----- .github/workflows/build.yml | 1 - .github/workflows/check-generated-models.yml | 2 - .github/workflows/check-licence.yml | 2 - .github/workflows/check-openapi.yml | 8 +- .github/workflows/coverage-aggregate.yml | 6 +- .github/workflows/db-migration-test.yml | 8 +- .github/workflows/deploy-on-v2-commit.yml | 53 ++----------- .github/workflows/docker-compose-tests.yml | 13 +--- .github/workflows/e2e-live.yml | 12 +-- .github/workflows/e2e-stubbed.yml | 12 +-- .../frontend-backend-licenses-update.yml | 16 ++-- .github/workflows/frontend-validation.yml | 6 +- .github/workflows/multiOSReleases.yml | 17 ++--- .github/workflows/nightly.yml | 6 +- .github/workflows/swagger.yml | 8 +- .github/workflows/tauri-build.yml | 1 - .github/workflows/test-build-docker.yml | 75 ++----------------- .github/workflows/testdriver.yml | 43 ++--------- settings.gradle | 25 ------- 25 files changed, 59 insertions(+), 414 deletions(-) diff --git a/.github/workflows/PR-Auto-Deploy-V2.yml b/.github/workflows/PR-Auto-Deploy-V2.yml index 172d72ee5c..a19a616735 100644 --- a/.github/workflows/PR-Auto-Deploy-V2.yml +++ b/.github/workflows/PR-Auto-Deploy-V2.yml @@ -23,13 +23,9 @@ permissions: pull-requests: write jobs: - pick: - uses: ./.github/workflows/_runner-pick.yml - check-pr: if: (github.event_name == 'pull_request' && github.event.action != 'closed') || github.event_name == 'workflow_dispatch' - needs: pick - runs-on: ${{ needs.pick.outputs.use_depot == 'true' && 'depot-ubuntu-24.04-4' || 'ubuntu-latest' }} + runs-on: ubuntu-latest outputs: should_deploy: ${{ steps.decide.outputs.should_deploy }} is_fork: ${{ steps.resolve.outputs.is_fork }} @@ -101,8 +97,8 @@ jobs: echo "allow_fork=${allow_fork:-false}" >> $GITHUB_OUTPUT deploy-v2-pr: - needs: [pick, check-pr] - runs-on: ${{ needs.pick.outputs.use_depot == 'true' && 'depot-ubuntu-24.04-4' || 'ubuntu-latest' }} + needs: check-pr + runs-on: ubuntu-latest if: needs.check-pr.outputs.should_deploy == 'true' && (needs.check-pr.outputs.is_fork == 'false' || needs.check-pr.outputs.allow_fork == 'true') # Concurrency control - only one deployment per PR at a time concurrency: @@ -112,10 +108,7 @@ jobs: contents: read issues: write pull-requests: write - id-token: write env: - USE_DEPOT: ${{ needs.pick.outputs.use_depot == 'true' }} - DEPOT_TOKEN: ${{ secrets.DEPOT_TOKEN }} # Single source of truth for whether this preview embeds the admin portal: # drives the image build-arg and the deployment comment. BUILD_PORTAL: "true" @@ -190,12 +183,7 @@ jobs: token: ${{ secrets.GITHUB_TOKEN }} fetch-depth: 0 # Fetch full history for commit hash detection - - name: Set up Depot CLI - if: env.USE_DEPOT == 'true' - uses: depot/setup-action@15c09a5f77a0840ad4bce955686522a257853461 # v1.0.0 - - name: Set up Docker Buildx - if: env.USE_DEPOT != 'true' uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0 - name: Get version number @@ -240,22 +228,8 @@ jobs: echo "Image needs to be built" fi - - name: Build and push V2 image (Depot) - if: env.USE_DEPOT == 'true' && steps.check-image.outputs.exists == 'false' - uses: depot/build-push-action@98e78adca7817480b8185f474a400b451d74e287 # v1.16.0 - with: - project: ${{ vars.DEPOT_PROJECT_ID }} - context: . - file: ./docker/embedded/Dockerfile - push: true - tags: ${{ secrets.DOCKER_HUB_USERNAME }}/test:v2-${{ steps.commit-hash.outputs.app_short }} - build-args: | - VERSION_TAG=v2-alpha - BUILD_PORTAL=${{ env.BUILD_PORTAL }} - platforms: linux/amd64 - - - name: Build and push V2 image (Docker fork fallback) - if: env.USE_DEPOT != 'true' && steps.check-image.outputs.exists == 'false' + - name: Build and push V2 image + if: steps.check-image.outputs.exists == 'false' uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0 with: context: . @@ -474,8 +448,7 @@ jobs: cleanup-v2-deployment: if: github.event.action == 'closed' - needs: pick - runs-on: ${{ needs.pick.outputs.use_depot == 'true' && 'depot-ubuntu-24.04-4' || 'ubuntu-latest' }} + runs-on: ubuntu-latest permissions: contents: read issues: write diff --git a/.github/workflows/PR-Demo-Comment-with-react.yml b/.github/workflows/PR-Demo-Comment-with-react.yml index bde9061ab7..2b81b8c777 100644 --- a/.github/workflows/PR-Demo-Comment-with-react.yml +++ b/.github/workflows/PR-Demo-Comment-with-react.yml @@ -34,12 +34,8 @@ permissions: pull-requests: read jobs: - pick: - uses: ./.github/workflows/_runner-pick.yml - check-comment: - needs: pick - runs-on: ${{ needs.pick.outputs.use_depot == 'true' && 'depot-ubuntu-24.04-4' || 'ubuntu-latest' }} + runs-on: ubuntu-latest permissions: issues: write if: | @@ -179,15 +175,11 @@ jobs: } deploy-pr: - needs: [pick, check-comment] - runs-on: ${{ needs.pick.outputs.use_depot == 'true' && 'depot-ubuntu-24.04-4' || 'ubuntu-latest' }} + needs: check-comment + runs-on: ubuntu-latest permissions: issues: write pull-requests: write - id-token: write - env: - USE_DEPOT: ${{ needs.pick.outputs.use_depot == 'true' }} - DEPOT_TOKEN: ${{ secrets.DEPOT_TOKEN }} steps: - name: Harden Runner @@ -240,12 +232,7 @@ jobs: MAVEN_PUBLIC_URL: ${{ secrets.MAVEN_PUBLIC_URL }} STIRLING_PDF_DESKTOP_UI: false - - name: Set up Depot CLI - if: env.USE_DEPOT == 'true' - uses: depot/setup-action@15c09a5f77a0840ad4bce955686522a257853461 # v1.0.0 - - name: Set up Docker Buildx - if: env.USE_DEPOT != 'true' uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0 - name: Login to Docker Hub @@ -254,22 +241,7 @@ jobs: username: ${{ secrets.DOCKER_HUB_USERNAME }} password: ${{ secrets.DOCKER_HUB_API }} - - name: Build and push PR-specific image (Depot) - if: env.USE_DEPOT == 'true' - uses: depot/build-push-action@98e78adca7817480b8185f474a400b451d74e287 # v1.16.0 - with: - project: ${{ vars.DEPOT_PROJECT_ID }} - context: . - file: ./docker/embedded/Dockerfile - push: true - tags: ${{ secrets.DOCKER_HUB_USERNAME }}/test:pr-${{ needs.check-comment.outputs.pr_number }} - build-args: | - VERSION_TAG=alpha - PROTOTYPES_BUILD=${{ needs.check-comment.outputs.enable_prototypes }} - platforms: linux/amd64 - - - name: Build and push PR-specific image (Docker fork fallback) - if: env.USE_DEPOT != 'true' + - name: Build and push PR-specific image uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0 with: context: . @@ -283,19 +255,8 @@ jobs: PROTOTYPES_BUILD=${{ needs.check-comment.outputs.enable_prototypes }} platforms: linux/amd64 - - name: Build and push engine image (Depot) - if: env.USE_DEPOT == 'true' && needs.check-comment.outputs.enable_prototypes == 'true' - uses: depot/build-push-action@98e78adca7817480b8185f474a400b451d74e287 # v1.16.0 - with: - project: ${{ vars.DEPOT_PROJECT_ID }} - context: ./engine - file: ./engine/Dockerfile - push: true - tags: ${{ secrets.DOCKER_HUB_USERNAME }}/test:engine-pr-${{ needs.check-comment.outputs.pr_number }} - platforms: linux/amd64 - - - name: Build and push engine image (Docker fork fallback) - if: env.USE_DEPOT != 'true' && needs.check-comment.outputs.enable_prototypes == 'true' + - name: Build and push engine image + if: needs.check-comment.outputs.enable_prototypes == 'true' uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0 with: context: ./engine @@ -510,8 +471,7 @@ jobs: handle-label-commands: if: ${{ github.event.issue.pull_request != null }} - needs: pick - runs-on: ${{ needs.pick.outputs.use_depot == 'true' && 'depot-ubuntu-24.04-4' || 'ubuntu-latest' }} + runs-on: ubuntu-latest steps: - name: Harden Runner uses: step-security/harden-runner@ab7a9404c0f3da075243ca237b5fac12c98deaa5 # v2.19.3 diff --git a/.github/workflows/_runner-pick.yml b/.github/workflows/_runner-pick.yml index 09959f3353..0f32d79b95 100644 --- a/.github/workflows/_runner-pick.yml +++ b/.github/workflows/_runner-pick.yml @@ -2,13 +2,8 @@ name: _runner-pick # Tiny reusable workflow that classifies the trigger as either a "fork PR # from an untrusted contributor" or a "trusted commit" so downstream jobs -# can pick a runner class without each one duplicating the 200-char gate -# expression in their own `runs-on:`. -# -# It also owns the single Depot kill-switch (use_depot). Depot is currently -# disabled repo-wide; downstream jobs gate their Depot runner/build usage on -# use_depot so nothing has to be deleted to turn Depot off. Flip DEPOT_ENABLED -# in the decide step to switch Depot back on. +# can trust-gate (skip secret-dependent jobs on forks) without each one +# duplicating the gate expression. # # Caller pattern: # @@ -18,15 +13,12 @@ name: _runner-pick # # real-work: # needs: pick -# runs-on: ${{ needs.pick.outputs.use_depot == 'true' && 'depot-ubuntu-24.04-8' || 'ubuntu-latest' }} +# if: needs.pick.outputs.is_fork != 'true' # steps: [...] # # Outputs: # is_fork: "true" when the trigger is a pull_request from a fork or an -# untrusted author_association, "false" otherwise. Use this for -# trust gating (skipping secret-dependent jobs on forks). -# use_depot: "true" when downstream jobs should use Depot runners/builders. -# Currently forced "false" (Depot disabled repo-wide). +# untrusted author_association, "false" otherwise. on: workflow_call: @@ -34,9 +26,6 @@ on: is_fork: description: '"true" if the trigger is an untrusted fork PR.' value: ${{ jobs.pick.outputs.is_fork }} - use_depot: - description: '"true" when downstream jobs should use Depot. Currently forced off.' - value: ${{ jobs.pick.outputs.use_depot }} permissions: contents: read @@ -47,7 +36,6 @@ jobs: timeout-minutes: 1 outputs: is_fork: ${{ steps.decide.outputs.is_fork }} - use_depot: ${{ steps.decide.outputs.use_depot }} steps: - name: Harden the runner (Audit all outbound calls) uses: step-security/harden-runner@ab7a9404c0f3da075243ca237b5fac12c98deaa5 # v2.19.3 @@ -63,12 +51,6 @@ jobs: run: | set -eu - # Depot kill-switch. Depot is disabled repo-wide: no job uses Depot - # runners or the Depot build actions while this is false. All the - # Depot wiring is left in place - set DEPOT_ENABLED=true to switch it - # back on (it then activates on trusted, non-fork triggers as before). - DEPOT_ENABLED=false - if [ -z "${PR_NUMBER:-}" ]; then # Not a pull_request event at all (push, schedule, workflow_dispatch, # workflow_call from a non-PR trigger) -> trusted by default. @@ -82,13 +64,4 @@ jobs: esac fi - # Depot only ever ran on trusted triggers, so gate it on both the - # kill-switch and is_fork. - if [ "${DEPOT_ENABLED}" = "true" ] && [ "${is_fork}" = "false" ]; then - use_depot=true - else - use_depot=false - fi - echo "is_fork=${is_fork}" >> "$GITHUB_OUTPUT" - echo "use_depot=${use_depot}" >> "$GITHUB_OUTPUT" diff --git a/.github/workflows/ai-engine.yml b/.github/workflows/ai-engine.yml index 58fe551c33..fbc9848eaf 100644 --- a/.github/workflows/ai-engine.yml +++ b/.github/workflows/ai-engine.yml @@ -18,8 +18,6 @@ jobs: permissions: contents: read pull-requests: write - env: - DEPOT_TOKEN: ${{ secrets.DEPOT_TOKEN }} steps: - name: Harden the runner (Audit all outbound calls) uses: step-security/harden-runner@ab7a9404c0f3da075243ca237b5fac12c98deaa5 # v2.19.3 diff --git a/.github/workflows/backend-build.yml b/.github/workflows/backend-build.yml index b06e94be38..28974a5ff6 100644 --- a/.github/workflows/backend-build.yml +++ b/.github/workflows/backend-build.yml @@ -19,14 +19,8 @@ permissions: pull-requests: write jobs: - pick: - uses: ./.github/workflows/_runner-pick.yml - build: - needs: pick - runs-on: ${{ needs.pick.outputs.use_depot == 'true' && 'depot-ubuntu-24.04-8' || 'ubuntu-latest' }} - env: - DEPOT_TOKEN: ${{ secrets.DEPOT_TOKEN }} + runs-on: ubuntu-latest strategy: fail-fast: false matrix: diff --git a/.github/workflows/build-enterprise.yml b/.github/workflows/build-enterprise.yml index 5aab6529b4..8c06175a5d 100644 --- a/.github/workflows/build-enterprise.yml +++ b/.github/workflows/build-enterprise.yml @@ -15,23 +15,11 @@ name: Enterprise E2E (Playwright) on: workflow_call: - inputs: - depot_cores: - description: "Depot runner vCPU count (used in runs-on). Override for benchmarking." - required: false - type: string - default: "8" push: branches: ["main"] schedule: - cron: "0 4 * * *" workflow_dispatch: - inputs: - depot_cores: - description: "Depot runner vCPU count (used in runs-on). Override for benchmarking." - required: false - type: string - default: "8" # No `concurrency:` block here on purpose. When this workflow is called via # workflow_call from build.yml, ${{ github.workflow }}/event_name/pr_number @@ -50,17 +38,16 @@ jobs: playwright-e2e-enterprise: needs: pick - # Skip on fork PRs / untrusted authors: they have no PREMIUM_KEY_ENTERPRISE - # (nor DEPOT_TOKEN), so the suite can't boot premium and would fail. See the - # header comment. GitHub reports the skipped reusable workflow as success. + # Skip on fork PRs / untrusted authors: they have no PREMIUM_KEY_ENTERPRISE, + # so the suite can't boot premium and would fail. See the header comment. + # GitHub reports the skipped reusable workflow as success. if: needs.pick.outputs.is_fork != 'true' - runs-on: ${{ needs.pick.outputs.use_depot == 'true' && format('depot-ubuntu-24.04-{0}', inputs.depot_cores || '8') || 'ubuntu-latest' }} + runs-on: ubuntu-latest timeout-minutes: 45 env: PREMIUM_KEY: ${{ secrets.PREMIUM_KEY_ENTERPRISE }} PREMIUM_ENABLED: "true" SYSTEM_ENABLEANALYTICS: "false" - DEPOT_TOKEN: ${{ secrets.DEPOT_TOKEN }} steps: - name: Harden Runner uses: step-security/harden-runner@ab7a9404c0f3da075243ca237b5fac12c98deaa5 # v2.19.3 diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 5689afe532..7d4130f214 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -149,7 +149,6 @@ jobs: permissions: contents: read packages: read - id-token: write uses: ./.github/workflows/test-build-docker.yml secrets: inherit with: diff --git a/.github/workflows/check-generated-models.yml b/.github/workflows/check-generated-models.yml index 0d8f784b4a..eef119cd02 100644 --- a/.github/workflows/check-generated-models.yml +++ b/.github/workflows/check-generated-models.yml @@ -21,8 +21,6 @@ jobs: permissions: contents: read pull-requests: write - env: - DEPOT_TOKEN: ${{ secrets.DEPOT_TOKEN }} steps: - name: Harden the runner (Audit all outbound calls) uses: step-security/harden-runner@ab7a9404c0f3da075243ca237b5fac12c98deaa5 # v2.19.3 diff --git a/.github/workflows/check-licence.yml b/.github/workflows/check-licence.yml index 027632b50b..9f6cfb39a0 100644 --- a/.github/workflows/check-licence.yml +++ b/.github/workflows/check-licence.yml @@ -11,8 +11,6 @@ permissions: jobs: check-licence: runs-on: ubuntu-latest - env: - DEPOT_TOKEN: ${{ secrets.DEPOT_TOKEN }} steps: - name: Harden Runner uses: step-security/harden-runner@ab7a9404c0f3da075243ca237b5fac12c98deaa5 # v2.19.3 diff --git a/.github/workflows/check-openapi.yml b/.github/workflows/check-openapi.yml index c823a3d5d1..d853afa86f 100644 --- a/.github/workflows/check-openapi.yml +++ b/.github/workflows/check-openapi.yml @@ -10,14 +10,8 @@ permissions: contents: read jobs: - pick: - uses: ./.github/workflows/_runner-pick.yml - check-generate-openapi-docs: - needs: pick - runs-on: ${{ needs.pick.outputs.use_depot == 'true' && 'depot-ubuntu-24.04-4' || 'ubuntu-latest' }} - env: - DEPOT_TOKEN: ${{ secrets.DEPOT_TOKEN }} + runs-on: ubuntu-latest steps: - name: Harden Runner uses: step-security/harden-runner@ab7a9404c0f3da075243ca237b5fac12c98deaa5 # v2.19.3 diff --git a/.github/workflows/coverage-aggregate.yml b/.github/workflows/coverage-aggregate.yml index b4d47fdc3e..bbed57db4d 100644 --- a/.github/workflows/coverage-aggregate.yml +++ b/.github/workflows/coverage-aggregate.yml @@ -29,12 +29,8 @@ permissions: contents: read jobs: - pick: - uses: ./.github/workflows/_runner-pick.yml - aggregate: - needs: pick - runs-on: ${{ needs.pick.outputs.use_depot == 'true' && 'depot-ubuntu-24.04-4' || 'ubuntu-latest' }} + runs-on: ubuntu-latest timeout-minutes: 15 steps: - name: Harden Runner diff --git a/.github/workflows/db-migration-test.yml b/.github/workflows/db-migration-test.yml index dfbde51e30..c6ebc481a7 100644 --- a/.github/workflows/db-migration-test.yml +++ b/.github/workflows/db-migration-test.yml @@ -12,15 +12,9 @@ permissions: contents: read jobs: - pick: - uses: ./.github/workflows/_runner-pick.yml - migration-test: - needs: pick - runs-on: ${{ needs.pick.outputs.use_depot == 'true' && 'depot-ubuntu-24.04-8' || 'ubuntu-latest' }} + runs-on: ubuntu-latest timeout-minutes: 30 - env: - DEPOT_TOKEN: ${{ secrets.DEPOT_TOKEN }} steps: - name: Harden Runner uses: step-security/harden-runner@ab7a9404c0f3da075243ca237b5fac12c98deaa5 # v2.19.3 diff --git a/.github/workflows/deploy-on-v2-commit.yml b/.github/workflows/deploy-on-v2-commit.yml index a932581840..2dcbe2ae65 100644 --- a/.github/workflows/deploy-on-v2-commit.yml +++ b/.github/workflows/deploy-on-v2-commit.yml @@ -10,21 +10,11 @@ permissions: contents: read jobs: - pick: - uses: ./.github/workflows/_runner-pick.yml - deploy-v2-on-push: - needs: pick - runs-on: ${{ needs.pick.outputs.use_depot == 'true' && 'depot-ubuntu-24.04-4' || 'ubuntu-latest' }} + runs-on: ubuntu-latest concurrency: group: deploy-v2-push-V2 cancel-in-progress: true - permissions: - contents: read - id-token: write - env: - USE_DEPOT: ${{ needs.pick.outputs.use_depot == 'true' }} - DEPOT_TOKEN: ${{ secrets.DEPOT_TOKEN }} steps: - name: Harden Runner @@ -35,12 +25,7 @@ jobs: - name: Checkout code uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - - name: Set up Depot CLI - if: env.USE_DEPOT == 'true' - uses: depot/setup-action@15c09a5f77a0840ad4bce955686522a257853461 # v1.0.0 - - name: Set up Docker Buildx - if: env.USE_DEPOT != 'true' uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0 - name: Get commit hashes for frontend and backend @@ -105,22 +90,8 @@ jobs: username: ${{ secrets.DOCKER_HUB_USERNAME }} password: ${{ secrets.DOCKER_HUB_API }} - - name: Build and push frontend image (Depot) - if: env.USE_DEPOT == 'true' && steps.check-frontend.outputs.exists == 'false' - uses: depot/build-push-action@98e78adca7817480b8185f474a400b451d74e287 # v1.16.0 - with: - project: ${{ vars.DEPOT_PROJECT_ID }} - context: . - file: ./docker/frontend/Dockerfile - push: true - tags: | - ${{ secrets.DOCKER_HUB_USERNAME }}/test:v2-frontend-${{ steps.commit-hashes.outputs.frontend_short }} - ${{ secrets.DOCKER_HUB_USERNAME }}/test:v2-frontend-latest - build-args: VERSION_TAG=v2-alpha - platforms: linux/amd64 - - - name: Build and push frontend image (Docker fork fallback) - if: env.USE_DEPOT != 'true' && steps.check-frontend.outputs.exists == 'false' + - name: Build and push frontend image + if: steps.check-frontend.outputs.exists == 'false' uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0 with: context: . @@ -134,22 +105,8 @@ jobs: build-args: VERSION_TAG=v2-alpha platforms: linux/amd64 - - name: Build and push backend image (Depot) - if: env.USE_DEPOT == 'true' && steps.check-backend.outputs.exists == 'false' - uses: depot/build-push-action@98e78adca7817480b8185f474a400b451d74e287 # v1.16.0 - with: - project: ${{ vars.DEPOT_PROJECT_ID }} - context: . - file: ./docker/backend/Dockerfile - push: true - tags: | - ${{ secrets.DOCKER_HUB_USERNAME }}/test:v2-backend-${{ steps.commit-hashes.outputs.backend_short }} - ${{ secrets.DOCKER_HUB_USERNAME }}/test:v2-backend-latest - build-args: VERSION_TAG=v2-alpha - platforms: linux/amd64 - - - name: Build and push backend image (Docker fork fallback) - if: env.USE_DEPOT != 'true' && steps.check-backend.outputs.exists == 'false' + - name: Build and push backend image + if: steps.check-backend.outputs.exists == 'false' uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0 with: context: . diff --git a/.github/workflows/docker-compose-tests.yml b/.github/workflows/docker-compose-tests.yml index 92faaeefee..2db9e5cf72 100644 --- a/.github/workflows/docker-compose-tests.yml +++ b/.github/workflows/docker-compose-tests.yml @@ -11,28 +11,17 @@ on: required: false type: string default: "false" - depot_cores: - description: "Depot runner vCPU count (used in runs-on). Override for benchmarking. Tuned to 4 because bench showed 16 was within noise of 4." - required: false - type: string - default: "4" permissions: contents: read jobs: - pick: - uses: ./.github/workflows/_runner-pick.yml - docker-compose-tests: - needs: pick - runs-on: ${{ needs.pick.outputs.use_depot == 'true' && format('depot-ubuntu-24.04-{0}', inputs.depot_cores || '4') || 'ubuntu-latest' }} + runs-on: ubuntu-latest permissions: actions: write contents: read checks: write - env: - DEPOT_TOKEN: ${{ secrets.DEPOT_TOKEN }} steps: - name: Harden Runner diff --git a/.github/workflows/e2e-live.yml b/.github/workflows/e2e-live.yml index f2904220b9..3a1b4e3af1 100644 --- a/.github/workflows/e2e-live.yml +++ b/.github/workflows/e2e-live.yml @@ -5,23 +5,13 @@ name: Playwright E2E (live backend) # server. on: workflow_call: - inputs: - depot_cores: - description: "Depot runner vCPU count (used in runs-on). Override for benchmarking." - required: false - type: string - default: "8" permissions: contents: read jobs: - pick: - uses: ./.github/workflows/_runner-pick.yml - playwright-e2e-live: - needs: pick - runs-on: ${{ needs.pick.outputs.use_depot == 'true' && format('depot-ubuntu-24.04-{0}', inputs.depot_cores || '8') || 'ubuntu-latest' }} + runs-on: ubuntu-latest timeout-minutes: 30 steps: - name: Harden Runner diff --git a/.github/workflows/e2e-stubbed.yml b/.github/workflows/e2e-stubbed.yml index b16e538114..214a7188df 100644 --- a/.github/workflows/e2e-stubbed.yml +++ b/.github/workflows/e2e-stubbed.yml @@ -5,23 +5,13 @@ name: Playwright E2E (stubbed) # mocks API responses in the browser. on: workflow_call: - inputs: - depot_cores: - description: "Depot runner vCPU count (used in runs-on). Override for benchmarking. Tuned to 8 to match the other playwright workflows; bench showed flat scaling above 8." - required: false - type: string - default: "8" permissions: contents: read jobs: - pick: - uses: ./.github/workflows/_runner-pick.yml - playwright-e2e: - needs: pick - runs-on: ${{ needs.pick.outputs.use_depot == 'true' && format('depot-ubuntu-24.04-{0}', inputs.depot_cores || '8') || 'ubuntu-latest' }} + runs-on: ubuntu-latest steps: - name: Harden Runner uses: step-security/harden-runner@ab7a9404c0f3da075243ca237b5fac12c98deaa5 # v2.19.3 diff --git a/.github/workflows/frontend-backend-licenses-update.yml b/.github/workflows/frontend-backend-licenses-update.yml index 4f7212495f..fcf6e18d0e 100644 --- a/.github/workflows/frontend-backend-licenses-update.yml +++ b/.github/workflows/frontend-backend-licenses-update.yml @@ -19,13 +19,9 @@ permissions: contents: read jobs: - pick: - uses: ./.github/workflows/_runner-pick.yml - files-changed: name: detect what files changed - needs: pick - runs-on: ${{ needs.pick.outputs.use_depot == 'true' && 'depot-ubuntu-24.04-4' || 'ubuntu-latest' }} + runs-on: ubuntu-latest timeout-minutes: 3 outputs: licenses-frontend: ${{ steps.changes.outputs.licenses-frontend }} @@ -48,8 +44,8 @@ jobs: generate-frontend-license-report: if: needs.files-changed.outputs.licenses-frontend == 'true' name: Generate Frontend License Report - needs: [pick, files-changed] - runs-on: ${{ needs.pick.outputs.use_depot == 'true' && 'depot-ubuntu-24.04-4' || 'ubuntu-latest' }} + needs: files-changed + runs-on: ubuntu-latest permissions: contents: write pull-requests: write @@ -321,15 +317,13 @@ jobs: generate-backend-license-report: if: needs.files-changed.outputs.licenses-backend == 'true' - needs: [pick, files-changed] + needs: files-changed name: Generate Backend License Report - runs-on: ${{ needs.pick.outputs.use_depot == 'true' && 'depot-ubuntu-24.04-4' || 'ubuntu-latest' }} + runs-on: ubuntu-latest permissions: contents: write pull-requests: write repository-projects: write # Required for enabling automerge - env: - DEPOT_TOKEN: ${{ secrets.DEPOT_TOKEN }} steps: - name: Harden Runner uses: step-security/harden-runner@ab7a9404c0f3da075243ca237b5fac12c98deaa5 # v2.19.3 diff --git a/.github/workflows/frontend-validation.yml b/.github/workflows/frontend-validation.yml index ad689149db..a539a1b7b7 100644 --- a/.github/workflows/frontend-validation.yml +++ b/.github/workflows/frontend-validation.yml @@ -11,12 +11,8 @@ permissions: pull-requests: write jobs: - pick: - uses: ./.github/workflows/_runner-pick.yml - frontend-validation: - needs: pick - runs-on: ${{ needs.pick.outputs.use_depot == 'true' && 'depot-ubuntu-24.04-4' || 'ubuntu-latest' }} + runs-on: ubuntu-latest steps: - name: Harden Runner uses: step-security/harden-runner@ab7a9404c0f3da075243ca237b5fac12c98deaa5 # v2.19.3 diff --git a/.github/workflows/multiOSReleases.yml b/.github/workflows/multiOSReleases.yml index 69121e1a00..41ddeb7a13 100644 --- a/.github/workflows/multiOSReleases.yml +++ b/.github/workflows/multiOSReleases.yml @@ -36,13 +36,9 @@ permissions: contents: read jobs: - pick: - uses: ./.github/workflows/_runner-pick.yml - determine-matrix: if: ${{ vars.CI_PROFILE != 'lite' }} - needs: pick - runs-on: ${{ needs.pick.outputs.use_depot == 'true' && 'depot-ubuntu-24.04-4' || 'ubuntu-latest' }} + runs-on: ubuntu-latest outputs: matrix: ${{ steps.set-matrix.outputs.matrix }} version: ${{ steps.versionNumber.outputs.versionNumber }} @@ -112,10 +108,8 @@ jobs: fi build-jars: - needs: [pick, determine-matrix] - runs-on: ${{ needs.pick.outputs.use_depot == 'true' && 'depot-ubuntu-24.04-4' || 'ubuntu-latest' }} - env: - DEPOT_TOKEN: ${{ secrets.DEPOT_TOKEN }} + needs: determine-matrix + runs-on: ubuntu-latest strategy: matrix: variant: @@ -195,7 +189,6 @@ jobs: SM_API_KEY: ${{ secrets.SM_API_KEY }} WINDOWS_CERTIFICATE: ${{ secrets.WINDOWS_CERTIFICATE }} RELEASE_GPG_PRIVATE_KEY: ${{ secrets.RELEASE_GPG_PRIVATE_KEY }} - DEPOT_TOKEN: ${{ secrets.DEPOT_TOKEN }} steps: - name: Harden Runner uses: step-security/harden-runner@ab7a9404c0f3da075243ca237b5fac12c98deaa5 # v2.19.3 @@ -638,8 +631,8 @@ jobs: retention-days: 1 collect-and-release: - needs: [pick, determine-matrix, build, build-jars] - runs-on: ${{ needs.pick.outputs.use_depot == 'true' && 'depot-ubuntu-24.04-4' || 'ubuntu-latest' }} + needs: [determine-matrix, build, build-jars] + runs-on: ubuntu-latest permissions: contents: write steps: diff --git a/.github/workflows/nightly.yml b/.github/workflows/nightly.yml index eca963c060..4047157a45 100644 --- a/.github/workflows/nightly.yml +++ b/.github/workflows/nightly.yml @@ -13,13 +13,9 @@ permissions: contents: read jobs: - pick: - uses: ./.github/workflows/_runner-pick.yml - playwright-all-browsers: name: Playwright (chromium + firefox + webkit) - needs: pick - runs-on: ${{ needs.pick.outputs.use_depot == 'true' && 'depot-ubuntu-24.04-4' || 'ubuntu-latest' }} + runs-on: ubuntu-latest steps: - name: Harden the runner (Audit all outbound calls) uses: step-security/harden-runner@ab7a9404c0f3da075243ca237b5fac12c98deaa5 # v2.19.3 diff --git a/.github/workflows/swagger.yml b/.github/workflows/swagger.yml index a546996302..90c5984693 100644 --- a/.github/workflows/swagger.yml +++ b/.github/workflows/swagger.yml @@ -22,15 +22,9 @@ permissions: contents: read jobs: - pick: - uses: ./.github/workflows/_runner-pick.yml - push: if: ${{ vars.CI_PROFILE != 'lite' }} - needs: pick - runs-on: ${{ needs.pick.outputs.use_depot == 'true' && 'depot-ubuntu-24.04-4' || 'ubuntu-latest' }} - env: - DEPOT_TOKEN: ${{ secrets.DEPOT_TOKEN }} + runs-on: ubuntu-latest steps: - name: Harden Runner uses: step-security/harden-runner@ab7a9404c0f3da075243ca237b5fac12c98deaa5 # v2.19.3 diff --git a/.github/workflows/tauri-build.yml b/.github/workflows/tauri-build.yml index 62cd0667e6..c97ae4eaef 100644 --- a/.github/workflows/tauri-build.yml +++ b/.github/workflows/tauri-build.yml @@ -106,7 +106,6 @@ jobs: WINDOWS_CERTIFICATE: ${{ secrets.WINDOWS_CERTIFICATE }} APPLE_CERTIFICATE: ${{ secrets.APPLE_CERTIFICATE }} RELEASE_GPG_PRIVATE_KEY: ${{ secrets.RELEASE_GPG_PRIVATE_KEY }} - DEPOT_TOKEN: ${{ secrets.DEPOT_TOKEN }} steps: - name: Harden Runner uses: step-security/harden-runner@ab7a9404c0f3da075243ca237b5fac12c98deaa5 # v2.19.3 diff --git a/.github/workflows/test-build-docker.yml b/.github/workflows/test-build-docker.yml index 0c86efd391..f8344da116 100644 --- a/.github/workflows/test-build-docker.yml +++ b/.github/workflows/test-build-docker.yml @@ -17,19 +17,11 @@ on: required: false type: string default: "false" - depot_cores: - description: "Depot runner vCPU count (used in runs-on). Override for benchmarking." - required: false - type: string - default: "8" permissions: contents: read jobs: - pick: - uses: ./.github/workflows/_runner-pick.yml - # TODO: extract a pre-matrix `prepare` job that runs once and produces # shared artifacts for the three matrix entries below to consume: # 1. `task backend:build` — currently runs 3× in parallel with @@ -45,14 +37,7 @@ jobs: # spring-security=true matrix entry if `task backend:build` and # `task backend:build:ci` produce equivalent JARs (verify before wiring). test-build-docker-images: - needs: pick - runs-on: ${{ needs.pick.outputs.use_depot == 'true' && format('depot-ubuntu-24.04-{0}', inputs.depot_cores || '8') || 'ubuntu-latest' }} - permissions: - contents: read - id-token: write - env: - USE_DEPOT: ${{ needs.pick.outputs.use_depot == 'true' && inputs.docker-base-changed != 'true' }} - DEPOT_TOKEN: ${{ secrets.DEPOT_TOKEN }} + runs-on: ubuntu-latest strategy: fail-fast: false matrix: @@ -125,16 +110,10 @@ jobs: DISABLE_ADDITIONAL_FEATURES: true STIRLING_PDF_DESKTOP_UI: false - - name: Set up Depot CLI - if: env.USE_DEPOT == 'true' - uses: depot/setup-action@15c09a5f77a0840ad4bce955686522a257853461 # v1.0.0 - - name: Set up QEMU - if: env.USE_DEPOT != 'true' uses: docker/setup-qemu-action@ce360397dd3f832beb865e1373c09c0e9f86d70a # v4.0.0 - name: Set up Docker Buildx - if: env.USE_DEPOT != 'true' id: buildx uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0 @@ -182,24 +161,10 @@ jobs: --tag stirling-pdf-embedded:pr-test \ . - - name: Build ${{ matrix.docker-rev }} (Depot) - if: env.USE_DEPOT == 'true' - uses: depot/build-push-action@98e78adca7817480b8185f474a400b451d74e287 # v1.16.0 - with: - project: ${{ vars.DEPOT_PROJECT_ID }} - context: . - file: ./${{ matrix.docker-rev }} - push: false - platforms: ${{ steps.build-params.outputs.platforms }} - build-args: | - BASE_IMAGE=${{ steps.build-params.outputs.base_image }} - provenance: true - sbom: true - - # Fork PRs that did NOT change the base use the buildx container builder + # PRs that did NOT change the base use the buildx container builder # (multi-platform + gha cache) against the published base image. - - name: Build ${{ matrix.docker-rev }} (Docker fork fallback) - if: env.USE_DEPOT != 'true' && inputs.docker-base-changed != 'true' + - name: Build ${{ matrix.docker-rev }} + if: inputs.docker-base-changed != 'true' uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0 with: builder: ${{ steps.buildx.outputs.name }} @@ -227,14 +192,7 @@ jobs: if-no-files-found: warn test-build-unoserver-image: - needs: pick - runs-on: ${{ needs.pick.outputs.use_depot == 'true' && format('depot-ubuntu-24.04-{0}', inputs.depot_cores || '8') || 'ubuntu-latest' }} - permissions: - contents: read - id-token: write - env: - USE_DEPOT: ${{ needs.pick.outputs.use_depot == 'true' && inputs.docker-base-changed != 'true' }} - DEPOT_TOKEN: ${{ secrets.DEPOT_TOKEN }} + runs-on: ubuntu-latest steps: - name: Harden Runner uses: step-security/harden-runner@ab7a9404c0f3da075243ca237b5fac12c98deaa5 # v2.19.3 @@ -244,35 +202,14 @@ jobs: - name: Checkout Repository uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - - name: Set up Depot CLI - if: env.USE_DEPOT == 'true' - uses: depot/setup-action@15c09a5f77a0840ad4bce955686522a257853461 # v1.0.0 - - name: Set up QEMU - if: env.USE_DEPOT != 'true' uses: docker/setup-qemu-action@ce360397dd3f832beb865e1373c09c0e9f86d70a # v4.0.0 - name: Set up Docker Buildx - if: env.USE_DEPOT != 'true' id: buildx uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0 - - name: Build docker/unoserver/Dockerfile (Depot) - if: env.USE_DEPOT == 'true' - uses: depot/build-push-action@98e78adca7817480b8185f474a400b451d74e287 # v1.16.0 - with: - project: ${{ vars.DEPOT_PROJECT_ID }} - context: . - file: ./docker/unoserver/Dockerfile - push: false - load: true - platforms: linux/amd64 - tags: stirling-unoserver:pr-test - provenance: false - sbom: false - - - name: Build docker/unoserver/Dockerfile (Docker fork fallback) - if: env.USE_DEPOT != 'true' + - name: Build docker/unoserver/Dockerfile uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0 with: builder: ${{ steps.buildx.outputs.name }} diff --git a/.github/workflows/testdriver.yml b/.github/workflows/testdriver.yml index fdeb964a8c..f86191656f 100644 --- a/.github/workflows/testdriver.yml +++ b/.github/workflows/testdriver.yml @@ -20,19 +20,9 @@ permissions: contents: read jobs: - pick: - uses: ./.github/workflows/_runner-pick.yml - deploy: if: ${{ vars.CI_PROFILE != 'lite' }} - needs: pick - runs-on: ${{ needs.pick.outputs.use_depot == 'true' && 'depot-ubuntu-24.04-4' || 'ubuntu-latest' }} - permissions: - contents: read - id-token: write - env: - USE_DEPOT: ${{ needs.pick.outputs.use_depot == 'true' }} - DEPOT_TOKEN: ${{ secrets.DEPOT_TOKEN }} + runs-on: ubuntu-latest steps: - name: Harden Runner uses: step-security/harden-runner@ab7a9404c0f3da075243ca237b5fac12c98deaa5 # v2.19.3 @@ -61,12 +51,7 @@ jobs: MAVEN_PUBLIC_URL: ${{ secrets.MAVEN_PUBLIC_URL }} DISABLE_ADDITIONAL_FEATURES: true - - name: Set up Depot CLI - if: env.USE_DEPOT == 'true' - uses: depot/setup-action@15c09a5f77a0840ad4bce955686522a257853461 # v1.0.0 - - name: Set up Docker Buildx - if: env.USE_DEPOT != 'true' uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0 - name: Get version number @@ -81,20 +66,7 @@ jobs: username: ${{ secrets.DOCKER_HUB_USERNAME }} password: ${{ secrets.DOCKER_HUB_API }} - - name: Build and push test image (Depot) - if: env.USE_DEPOT == 'true' - uses: depot/build-push-action@98e78adca7817480b8185f474a400b451d74e287 # v1.16.0 - with: - project: ${{ vars.DEPOT_PROJECT_ID }} - context: . - file: ./docker/embedded/Dockerfile - push: true - tags: ${{ secrets.DOCKER_HUB_USERNAME }}/test:test-${{ github.sha }} - build-args: VERSION_TAG=${{ steps.versionNumber.outputs.versionNumber }} - platforms: linux/amd64 - - - name: Build and push test image (Docker fork fallback) - if: env.USE_DEPOT != 'true' + - name: Build and push test image uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0 with: context: . @@ -153,8 +125,7 @@ jobs: files-changed: if: always() name: detect what files changed - needs: pick - runs-on: ${{ needs.pick.outputs.use_depot == 'true' && 'depot-ubuntu-24.04-4' || 'ubuntu-latest' }} + runs-on: ubuntu-latest timeout-minutes: 3 outputs: frontend: ${{ steps.changes.outputs.frontend }} @@ -174,8 +145,8 @@ jobs: test: if: needs.files-changed.outputs.frontend == 'true' - needs: [pick, deploy, files-changed] - runs-on: ${{ needs.pick.outputs.use_depot == 'true' && 'depot-ubuntu-24.04-4' || 'ubuntu-latest' }} + needs: [deploy, files-changed] + runs-on: ubuntu-latest steps: - name: Harden Runner uses: step-security/harden-runner@ab7a9404c0f3da075243ca237b5fac12c98deaa5 # v2.19.3 @@ -208,8 +179,8 @@ jobs: FORCE_COLOR: "3" cleanup: - needs: [pick, deploy, test] - runs-on: ${{ needs.pick.outputs.use_depot == 'true' && 'depot-ubuntu-24.04-4' || 'ubuntu-latest' }} + needs: [deploy, test] + runs-on: ubuntu-latest if: always() steps: diff --git a/settings.gradle b/settings.gradle index aa90b41375..85b1c45207 100644 --- a/settings.gradle +++ b/settings.gradle @@ -23,31 +23,6 @@ plugins { id 'org.gradle.toolchains.foojay-resolver-convention' version '1.0.0' } -// Depot remote build cache. Disabled repo-wide via depotCacheEnabled below; -// flip it back to true to re-enable. Even when enabled it silently no-ops -// without DEPOT_TOKEN (local dev without depot login, and fork PRs where -// GitHub hides secrets), so contributors build fine on local cache only. -buildCache { - def depotCacheEnabled = false - def depotToken = System.getenv('DEPOT_TOKEN') - local { - enabled = true - } - if (depotCacheEnabled && depotToken) { - remote(HttpBuildCache) { - url = 'https://cache.depot.dev' - enabled = true - // Only CI runs push to the shared cache; dev laptops pull-only - // so a misconfigured local task can't poison everyone else. - push = System.getenv('CI') == 'true' - credentials { - username = '' - password = depotToken - } - } - } -} - rootProject.name = 'Stirling PDF' // Flavors: core | proprietary (default) | saas.