gnodet-bot commented on code in PR #13166:
URL: https://github.com/apache/maven/pull/13166#discussion_r4041365734


##########
.github/workflows/update-lifecycle-plugins.yml:
##########
@@ -0,0 +1,94 @@
+# Licensed to the Apache Software Foundation (ASF) under one
+# or more contributor license agreements.  See the NOTICE file
+# distributed with this work for additional information
+# regarding copyright ownership.  The ASF licenses this file
+# to you under the Apache License, Version 2.0 (the
+# "License"); you may not use this file except in compliance
+# with the License.  You may obtain a copy of the License at
+#
+#   http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing,
+# software distributed under the License is distributed on an
+# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
+# KIND, either express or implied.  See the License for the
+# specific language governing permissions and limitations
+# under the License.
+
+name: Update lifecycle plugin versions
+
+on:
+  schedule:
+    # Every Monday at 08:00 UTC
+    - cron: '0 8 * * 1'
+  workflow_dispatch:
+
+permissions:
+  contents: read
+
+jobs:
+  update-lifecycle-plugins:
+    runs-on: ubuntu-latest
+    permissions:
+      contents: write
+      pull-requests: write
+    strategy:
+      fail-fast: false
+      matrix:
+        branch: [master, maven-4.0.x]
+    steps:
+      - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # 
v7.0.1
+        with:
+          ref: ${{ matrix.branch }}
+          persist-credentials: false
+
+      - uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # 
v6.0.1
+        with:
+          java-version: '21'
+          distribution: 'temurin'
+          cache: maven
+
+      - name: Update lifecycle plugin versions
+        run: |
+          mvn -B eu.maveniverse.maven.plugins:toolbox:0.16.0:plugin-versions \
+            -f impl/maven-core \
+            -DartifactMatcherSpec="groupId(org.apache.maven.plugins)" \
+            -DartifactVersionMatcherSpec="not(any(snapshotOrPreview()))" \
+            -Dapply
+
+      - name: Create Pull Request
+        env:
+          GH_TOKEN: ${{ secrets.GH_TOKEN }}
+          BRANCH: update/lifecycle-plugins-${{ matrix.branch }}
+          BASE_BRANCH: ${{ matrix.branch }}
+        run: |
+          if git diff --quiet impl/maven-core/pom.xml; then
+            echo "No lifecycle plugin version changes detected."
+            exit 0
+          fi
+
+          echo "--- Updated properties ---"
+          git diff impl/maven-core/pom.xml | grep '^[+-].*version\.maven' | 
grep -v '^---\|^+++'
+
+          git config user.name "github-actions[bot]"
+          git config user.email 
"41898282+github-actions[bot]@users.noreply.github.com"
+          git switch --create "${BRANCH}"
+          git add impl/maven-core/pom.xml
+          git commit -m "chore: update Maven lifecycle plugin versions"
+          git remote set-url origin 
"https://x-access-token:${GH_TOKEN}@github.com/${GITHUB_REPOSITORY}.git";
+          git push --force-with-lease --set-upstream origin "${BRANCH}"

Review Comment:
   💡 **`--force-with-lease` without a remote tracking ref = unconditional force 
push.** `actions/checkout` checks out `matrix.branch` and doesn't fetch 
`update/lifecycle-plugins-*`; `git switch --create` creates a local branch with 
no upstream tracking ref. Without a tracking ref to lease against, 
`--force-with-lease` silently falls back to `--force` — so it provides no 
protection on the second and subsequent runs.
   
   For a bot-owned throwaway branch this is safe in practice, but the flag is 
misleading. Either use plain `--force` (honest) or fetch the remote tracking 
ref first:
   
   ```suggestion
             git push --force --set-upstream origin "${BRANCH}"
   ```



##########
.github/workflows/update-lifecycle-plugins.yml:
##########
@@ -0,0 +1,94 @@
+# Licensed to the Apache Software Foundation (ASF) under one
+# or more contributor license agreements.  See the NOTICE file
+# distributed with this work for additional information
+# regarding copyright ownership.  The ASF licenses this file
+# to you under the Apache License, Version 2.0 (the
+# "License"); you may not use this file except in compliance
+# with the License.  You may obtain a copy of the License at
+#
+#   http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing,
+# software distributed under the License is distributed on an
+# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
+# KIND, either express or implied.  See the License for the
+# specific language governing permissions and limitations
+# under the License.
+
+name: Update lifecycle plugin versions
+
+on:
+  schedule:
+    # Every Monday at 08:00 UTC
+    - cron: '0 8 * * 1'
+  workflow_dispatch:
+
+permissions:
+  contents: read
+
+jobs:
+  update-lifecycle-plugins:
+    runs-on: ubuntu-latest
+    permissions:
+      contents: write
+      pull-requests: write
+    strategy:
+      fail-fast: false
+      matrix:
+        branch: [master, maven-4.0.x]
+    steps:
+      - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # 
v7.0.1
+        with:
+          ref: ${{ matrix.branch }}
+          persist-credentials: false
+
+      - uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # 
v6.0.1
+        with:
+          java-version: '21'
+          distribution: 'temurin'
+          cache: maven
+
+      - name: Update lifecycle plugin versions
+        run: |
+          mvn -B eu.maveniverse.maven.plugins:toolbox:0.16.0:plugin-versions \
+            -f impl/maven-core \
+            -DartifactMatcherSpec="groupId(org.apache.maven.plugins)" \
+            -DartifactVersionMatcherSpec="not(any(snapshotOrPreview()))" \
+            -Dapply
+
+      - name: Create Pull Request
+        env:
+          GH_TOKEN: ${{ secrets.GH_TOKEN }}
+          BRANCH: update/lifecycle-plugins-${{ matrix.branch }}
+          BASE_BRANCH: ${{ matrix.branch }}
+        run: |
+          if git diff --quiet impl/maven-core/pom.xml; then
+            echo "No lifecycle plugin version changes detected."
+            exit 0
+          fi
+
+          echo "--- Updated properties ---"
+          git diff impl/maven-core/pom.xml | grep '^[+-].*version\.maven' | 
grep -v '^---\|^+++'
+
+          git config user.name "github-actions[bot]"
+          git config user.email 
"41898282+github-actions[bot]@users.noreply.github.com"
+          git switch --create "${BRANCH}"
+          git add impl/maven-core/pom.xml
+          git commit -m "chore: update Maven lifecycle plugin versions"
+          git remote set-url origin 
"https://x-access-token:${GH_TOKEN}@github.com/${GITHUB_REPOSITORY}.git";
+          git push --force-with-lease --set-upstream origin "${BRANCH}"
+
+          if gh pr list \
+              --repo "${GITHUB_REPOSITORY}" \
+              --state open \
+              --head "${BRANCH}" \
+              --json number \
+              --jq 'length' | grep -q '^0$'; then
+            gh pr create \
+              --repo "${GITHUB_REPOSITORY}" \
+              --base "${BASE_BRANCH}" \
+              --head "${BRANCH}" \
+              --title "chore: update Maven lifecycle plugin versions 
(${BASE_BRANCH})" \
+              --body "Automated update of Maven lifecycle plugin versions via 
\`toolbox:plugin-versions\`. These versions are declared in 
\`impl/maven-core/pom.xml\` and are used by the Maven default lifecycle 
binding. They are filtered at build time into \`plugin-versions.properties\` 
and loaded at runtime by \`PluginVersions\\`. This PR was created automatically 
by the \`update-lifecycle-plugins\` workflow." \

Review Comment:
   🔧 **(nit) Spurious backslash before closing backtick in `--body`.** The 
shell sequence `\\\`` inside double-quotes expands to `\`` — a literal 
backslash followed by a backtick. GitHub renders this as `PluginVersions\`.` in 
the PR body (the backslash appears before the period). The trailing `\` is 
unintentional — drop it:
   
   ```suggestion
                 --body "Automated update of Maven lifecycle plugin versions 
via \`toolbox:plugin-versions\`. These versions are declared in 
\`impl/maven-core/pom.xml\` and are used by the Maven default lifecycle 
binding. They are filtered at build time into \`plugin-versions.properties\` 
and loaded at runtime by \`PluginVersions\`. This PR was created automatically 
by the \`update-lifecycle-plugins\` workflow." \
   ```



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to