name: Update AUR packages run-name: ${{ inputs.package && format('Update {0}', inputs.package) || 'Update AUR packages' }} on: schedule: # every 6 hours (offset from the full hour to avoid GitHub's load spikes) - cron: '37 */6 * * *' workflow_dispatch: inputs: package: # A few packages instead of all of them: a full run builds every # package in turn, and one near the end of the list waits behind every # source build before it gets its turn. description: 'Only update these package directories, comma-separated (empty: all packages)' type: string required: false default: '' push: branches: [main] paths: # any package file (PKGBUILD, pkg.sh, .desktop, ...) and the shared script - '*/*' - '.github/workflows/update.yml' # Never run twice at once: concurrent runs race on pushing to this repository # and to the AUR (e.g. a push-triggered run and a manual dispatch both creating # a new AUR repo). Queue instead of cancelling so every trigger still lands. concurrency: group: aur-update cancel-in-progress: false permissions: contents: write jobs: discover: runs-on: ubuntu-latest outputs: packages: ${{ steps.list.outputs.packages }} steps: - uses: actions/checkout@v7 - id: list env: PACKAGES: ${{ inputs.package }} run: | if [ -n "$PACKAGES" ]; then # split on commas, trim, drop empty entries and duplicates, keep # the given order (it is the build order) packages=$(jq -cn --arg s "$PACKAGES" ' $s | split(",") | map(gsub("^\\s+|\\s+$"; "") | select(. != "")) | reduce .[] as $p ([]; if any(.[]; . == $p) then . else . + [$p] end)') if [ "$packages" = "[]" ]; then echo "::error::no package name in '$PACKAGES'" exit 1 fi # report every unknown name at once, not just the first missing=0 while IFS= read -r p; do if [ ! -f "$p/PKGBUILD" ]; then echo "::error::there is no package directory named '$p'" missing=1 fi done < <(jq -r '.[]' <<< "$packages") [ "$missing" = 0 ] || exit 1 echo "packages=$packages" >> "$GITHUB_OUTPUT" else echo "packages=$(ls -d */PKGBUILD 2>/dev/null | xargs -r -n1 dirname | jq -R . | jq -cs .)" >> "$GITHUB_OUTPUT" fi update: needs: discover if: needs.discover.outputs.packages != '[]' runs-on: ubuntu-latest container: image: archlinux:base-devel strategy: fail-fast: false # serialize so parallel jobs don't race on pushing to this repository max-parallel: 1 matrix: package: ${{ fromJson(needs.discover.outputs.packages) }} env: GH_TOKEN: ${{ github.token }} steps: - name: Install base tooling run: pacman -Syu --noconfirm --needed git openssh github-cli jq zstd - uses: actions/checkout@v7 - name: Update ${{ matrix.package }} env: AUR_SSH_PRIVATE_KEY: ${{ secrets.AUR_SSH_PRIVATE_KEY }} AUR_GIT_NAME: ${{ vars.AUR_GIT_NAME }} AUR_GIT_EMAIL: ${{ secrets.AUR_GIT_EMAIL }} run: bash scripts/update-package.sh "${{ matrix.package }}"