diff --git a/.github/workflows/update.yaml b/.github/workflows/update.yaml deleted file mode 100644 index e2d320e6cdcb..000000000000 --- a/.github/workflows/update.yaml +++ /dev/null @@ -1,79 +0,0 @@ -name: Update code-server - -on: - workflow_dispatch: - inputs: - version: - type: string - required: true - schedule: - - cron: "0 16,21 * * *" - -permissions: - contents: write # To push the update branch. - pull-requests: write # To open the update PR. - -jobs: - update: - runs-on: ubuntu-latest - env: - TAG: ${{ inputs.version }} - # A branch pushed with the built-in token does not start other - # workflows, so the update PR gets no CI. Set UPDATE_PR_TOKEN to an - # organization PAT to get it; without one this still opens the PR. - GH_TOKEN: ${{ secrets.UPDATE_PR_TOKEN || github.token }} - - steps: - - name: Fetch latest tag - if: env.TAG == '' - run: | - tag=$(curl -fsSLI -o /dev/null -w "%{url_effective}" https://github.com/microsoft/vscode/releases/latest) - tag="${tag#https://github.com/microsoft/vscode/releases/tag/}" - echo "TAG=$tag" >> $GITHUB_ENV - - - name: Remove leading v from tag - run: | - echo "VERSION=${TAG#v}" >> $GITHUB_ENV - - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 - with: - submodules: true - - - name: Check current version - id: check - run: | - commit="$(git -C lib/vscode rev-parse HEAD)" - if [[ $(git -C lib/vscode ls-remote --tags | grep "$commit") == */"$VERSION" ]] ; then - echo "$VERSION update has already been merged into $(git rev-parse --abbrev-ref HEAD)" - echo done=true >> $GITHUB_OUTPUT - elif git ls-remote --exit-code --heads origin "update/$VERSION" ; then - echo "There is already a PR for updating to $VERSION" - echo done=true >> $GITHUB_OUTPUT - else - echo "$VERSION update has not started yet" - echo done=false >> $GITHUB_OUTPUT - fi - - - uses: awalsh128/cache-apt-pkgs-action@553a35bb8ebd9fcabcb1c9451aa4c98e1b4ca8a9 # latest - if: steps.check.outputs.done == 'false' - with: - packages: quilt - version: 1.0 - - - run: ./ci/build/update-vscode.sh - if: steps.check.outputs.done == 'false' - - - name: Open PR - if: steps.check.outputs.done == 'false' - run: | - git config --global user.name "github-actions[bot]" - git config --global user.email "41898282+github-actions[bot]@users.noreply.github.com" - git checkout -b "update/$VERSION" - git add . - git commit -m "Update Code to $VERSION" - git push -u origin "$(git branch --show)" - gh pr create \ - --repo "$GITHUB_REPOSITORY" \ - --title "Update Code to $VERSION" \ - --body-file .cache/checklist \ - --draft diff --git a/docs/CONTRIBUTING.md b/docs/CONTRIBUTING.md index d857b20c3850..670046605899 100644 --- a/docs/CONTRIBUTING.md +++ b/docs/CONTRIBUTING.md @@ -257,6 +257,14 @@ Most of the meaty parts are in the Code portion of the codebase under Our modifications to Code can be found in the [patches](../patches) directory. We pull in Code as a submodule pointing to an upstream release branch. +This fork does not bump that submodule itself. Code updates arrive by merging +[coder/code-server](https://github.com/coder/code-server), whose scheduled job +does the bump and refreshes the patch stack against the new release; taking +them from there means we review one upstream merge instead of owning the +rebase. `ci/build/update-vscode.sh` is still here for the manual case: run it +with no `VERSION` to re-refresh the patches and regenerate the webview CSP +hashes when a merge leaves them conflicting. + In v1 of code-server, we had Code as a submodule and used a single massive patch that split the codebase into a front-end and a server. The front-end consisted of the UI code, while the server ran the extensions and exposed an API to the