Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 14 additions & 0 deletions .github/workflows/publish-crate.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,10 +19,13 @@ on:
permissions:
contents: read
id-token: write
pull-requests: read

jobs:
publish:
runs-on: ubuntu-latest
outputs:
crate_version: ${{ steps.version.outputs.version }}
steps:
- name: Checkout repo
uses: actions/checkout@v4
Expand Down Expand Up @@ -74,3 +77,14 @@ jobs:
env:
CARGO_REGISTRY_TOKEN: ${{ steps.auth.outputs.token }}
run: cargo publish --manifest-path="sds/Cargo.toml" --allow-dirty

trigger:
needs: publish
if: ${{ github.ref == 'refs/heads/main' && (github.event_name == 'push' || !inputs.dry_run) }}
uses: ./.github/workflows/trigger_pr.yml
permissions:
contents: read
pull-requests: read
with:
crate_version: ${{ needs.publish.outputs.crate_version }}
secrets: inherit
86 changes: 53 additions & 33 deletions .github/workflows/trigger_pr.yml
Original file line number Diff line number Diff line change
@@ -1,30 +1,50 @@
name: Create a PR in sds repo to bump the version
on:
push:
branches:
- main
workflow_call:
inputs:
crate_version:
description: Published dd-sensitive-data-scanner crates.io version
required: true
type: string

permissions:
contents: read
pull-requests: read

jobs:
trigger:
runs-on: ubuntu-latest
environment: protected
steps:
- name: Extract PR information from github
- name: Verify published version is available
env:
CRATE_VERSION: ${{ inputs.crate_version }}
run: |
for attempt in {1..12}; do
if curl --fail-with-body --silent --show-error --max-time 20 \
https://index.crates.io/dd/-s/dd-sensitive-data-scanner \
| jq -se --arg version "$CRATE_VERSION" 'any(.[]; .vers == $version and .yanked == false)' > /dev/null; then
exit 0
fi
if [ "$attempt" -lt 12 ]; then

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't understand why we need this if, but it's probably not a big deal

(is attempt not always less than 12?)

@GeoffreyRdn GeoffreyRdn Sep 24, 2026 •

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It is inclusive, so 12 can be triggered in the last round. Basically we wait except for last try.
Proof:

for attempt in {1..12}; do echo $attempt; done
1
2
3
4
5
6
7
8
9
10
11
12

sleep 5
fi
done
echo "Published crate version $CRATE_VERSION is not available in the crates.io index" >&2
exit 1
- name: Extract PR information from GitHub
id: extract-pr-info
env:
GH_TOKEN: ${{ github.token }}
run: |
echo "Extracting PR information"
echo "/repos/$GITHUB_REPOSITORY/commits/$GITHUB_SHA/pulls"
res=$(curl -L \
-H "Authorization: Bearer ${{ secrets.GITHUB_TOKEN }}" \
response=$(curl --fail-with-body --silent --show-error --location \
-H "Authorization: Bearer $GH_TOKEN" \
-H "Accept: application/vnd.github+json" \
-H "X-GitHub-Api-Version: 2022-11-28" \
https://api.github.com/repos/$GITHUB_REPOSITORY/commits/$GITHUB_SHA/pulls)

pr_url=`echo $res | jq -r 'if .[0] then .[0].html_url else "UNKNOWN" end'`
author=`echo $res | jq -r 'if .[0] then .[0].user.login else "UNKNOWN" end'`
echo $res
echo $pr_url
echo $author
"https://api.github.com/repos/$GITHUB_REPOSITORY/commits/$GITHUB_SHA/pulls")
pr_url=$(jq -r --arg fallback "$GITHUB_SERVER_URL/$GITHUB_REPOSITORY/commit/$GITHUB_SHA" \
'.[0].html_url // $fallback' <<< "$response")
author=$(jq -r --arg fallback "$GITHUB_ACTOR" '.[0].user.login // $fallback' <<< "$response")
echo "PR_URL=$pr_url" >> "$GITHUB_OUTPUT"
echo "COMMIT_AUTHOR=$author" >> "$GITHUB_OUTPUT"
- name: Generate a token
Expand All @@ -33,22 +53,22 @@ jobs:
with:
app-id: ${{ vars.TRIGGER_APP_ID }}
private-key: ${{ secrets.TRIGGER_GITHUB_APP_PRIVATE_KEY }}
owner: DataDog
repositories: "sds-shared-library"
- name: Trigger Workflow in Another Repository
owner: ddoghq
repositories: sds-shared-library
- name: Trigger dependency bump
env:
DISPATCH_TOKEN: ${{ steps.generate-token.outputs.token }}
CRATE_VERSION: ${{ inputs.crate_version }}
PR_URL: ${{ steps.extract-pr-info.outputs.PR_URL }}
COMMIT_AUTHOR: ${{ steps.extract-pr-info.outputs.COMMIT_AUTHOR }}
run: |
# Set the required variables
repo_owner="DataDog"
repo_name="sds-shared-library"
event_type="create_pr"
# Trigger the workflow
curl -L \
-X POST \
-H "Accept: application/vnd.github+json" \
-H "Authorization: Bearer ${{ steps.generate-token.outputs.token }}" \
-H "X-GitHub-Api-Version: 2022-11-28" \
https://api.github.com/repos/$repo_owner/$repo_name/dispatches \
-d "{\"event_type\": \"$event_type\", \"client_payload\": {\"commit_hash\": \"$GITHUB_SHA\" \
, \"pr_url\": \"${{steps.extract-pr-info.outputs.pr_url}}\" \
, \"commit_author\": \"${{steps.extract-pr-info.outputs.commit_author}}\" \
}}"
payload=$(jq -n --arg version "$CRATE_VERSION" --arg pr_url "$PR_URL" \
--arg author "$COMMIT_AUTHOR" \
'{event_type: "create_pr", client_payload: {crate_version: $version, pr_url: $pr_url, commit_author: $author}}')
curl --fail-with-body --silent --show-error --location \
-X POST \
-H "Accept: application/vnd.github+json" \
-H "Authorization: Bearer $DISPATCH_TOKEN" \
-H "X-GitHub-Api-Version: 2022-11-28" \
https://api.github.com/repos/ddoghq/sds-shared-library/dispatches \
--data "$payload"
6 changes: 6 additions & 0 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,12 @@ Use `make` to see available commands for building, testing, and formatting.
`make check-rust` requires `cargo-hack` 0.6.45. The Rust check and test targets require the
Hyperscan development library so they can check every Cargo feature.

## Publishing and downstream dependency bumps

- `.github/workflows/publish-crate.yml` calls the reusable `trigger_pr.yml` only after successful publication on `main`
- The dispatch checks that the exact published version is available and not yanked in the crates.io index, then sends `crate_version`, `commit_author`, and `pr_url` to `ddoghq/sds-shared-library` via `repository_dispatch/create_pr`.
- The protected environment's trigger GitHub App must have access to `ddoghq/sds-shared-library` with Contents: write. HTTP errors fail the workflow.

## Code Quality Requirements

- **Warnings are errors:** CI runs with `RUSTFLAGS="-D warnings"`
Expand Down
Loading