From 12a4272ac49441816eaa7669aed0ff2a361e195f Mon Sep 17 00:00:00 2001 From: woensug-choi Date: Wed, 23 Sep 2026 15:50:02 +0900 Subject: [PATCH] ci: fix runtime, permission, and formatting annotations --- .github/workflows/docker-amd64.yml | 10 ++-- .github/workflows/docker-arm64v8.yml | 8 +-- .github/workflows/docker-pr-publish.yml | 12 ++-- .github/workflows/lint.yml | 58 +++++++++---------- .github/workflows/pages.yml | 56 ++++++++++++++++++ .../config/mavros/mavros.yaml | 1 + 6 files changed, 100 insertions(+), 45 deletions(-) create mode 100644 .github/workflows/pages.yml diff --git a/.github/workflows/docker-amd64.yml b/.github/workflows/docker-amd64.yml index c9382f67..a15f8fe3 100644 --- a/.github/workflows/docker-amd64.yml +++ b/.github/workflows/docker-amd64.yml @@ -42,21 +42,21 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@v4 + uses: actions/checkout@v7.0.1 - name: Set up Docker Buildx - uses: docker/setup-buildx-action@v3 + uses: docker/setup-buildx-action@v4.4.1 - name: Log in to Docker Hub if: github.event_name != 'pull_request' - uses: docker/login-action@v4 + uses: docker/login-action@v4.6.0 with: username: ${{ secrets.DOCKERHUB_USERNAME }} password: ${{ secrets.DOCKERHUB_TOKEN }} - name: Docker metadata id: meta - uses: docker/metadata-action@v5 + uses: docker/metadata-action@v6.2.0 with: images: ${{ env.IMAGE_NAME }} tags: | @@ -66,7 +66,7 @@ jobs: type=semver,pattern={{major}}.{{minor}} - name: Build Docker image - uses: docker/build-push-action@v5 + uses: docker/build-push-action@v7.4.0 with: context: . push: ${{ github.event_name != 'pull_request' }} diff --git a/.github/workflows/docker-arm64v8.yml b/.github/workflows/docker-arm64v8.yml index 192ddff1..70252a75 100644 --- a/.github/workflows/docker-arm64v8.yml +++ b/.github/workflows/docker-arm64v8.yml @@ -48,10 +48,10 @@ jobs: echo "DOCKER_CONFIG=$docker_config" >> "$GITHUB_ENV" - name: Checkout repository - uses: actions/checkout@v4 + uses: actions/checkout@v7.0.1 - name: Set up Docker Buildx - uses: docker/setup-buildx-action@v3 + uses: docker/setup-buildx-action@v4.4.1 with: # On a macOS launchd runner, the docker-container driver can try to # open Docker Desktop's interactive Keychain credential helper. @@ -83,7 +83,7 @@ jobs: - name: Docker metadata id: meta - uses: docker/metadata-action@v5 + uses: docker/metadata-action@v6.2.0 with: images: ${{ env.IMAGE_NAME }} tags: | @@ -91,7 +91,7 @@ jobs: type=ref,event=pr - name: Build Docker image - uses: docker/build-push-action@v5 + uses: docker/build-push-action@v7.4.0 with: context: . push: ${{ github.event_name != 'pull_request' }} diff --git a/.github/workflows/docker-pr-publish.yml b/.github/workflows/docker-pr-publish.yml index 0cfe46bd..1b5c8f8b 100644 --- a/.github/workflows/docker-pr-publish.yml +++ b/.github/workflows/docker-pr-publish.yml @@ -42,7 +42,7 @@ jobs: steps: - name: Verify current PR and successful builds for both architectures id: builds - uses: actions/github-script@v7 + uses: actions/github-script@v9.0.0 with: script: | const repo = context.repo; @@ -107,16 +107,16 @@ jobs: sudo apt-get install -y --no-install-recommends skopeo - name: Set up Docker Buildx - uses: docker/setup-buildx-action@v3 + uses: docker/setup-buildx-action@v4.4.1 - name: Log in to Docker Hub - uses: docker/login-action@v4 + uses: docker/login-action@v4.6.0 with: username: ${{ secrets.DOCKERHUB_USERNAME }} password: ${{ secrets.DOCKERHUB_TOKEN }} - name: Download AMD64 image from its verified build - uses: actions/download-artifact@v4 + uses: actions/download-artifact@v8.0.1 with: name: dave-pr-image-amd64 path: ${{ runner.temp }}/amd64 @@ -133,7 +133,7 @@ jobs: rm -- "$archive" - name: Download ARM64 image from its verified build - uses: actions/download-artifact@v4 + uses: actions/download-artifact@v8.0.1 with: name: dave-pr-image-arm64 path: ${{ runner.temp }}/arm64 @@ -150,7 +150,7 @@ jobs: rm -- "$archive" - name: Check that the PR still points to this revision - uses: actions/github-script@v7 + uses: actions/github-script@v9.0.0 with: script: | const {data: pr} = await github.rest.pulls.get({ diff --git a/.github/workflows/lint.yml b/.github/workflows/lint.yml index 640fdefd..d633ad8f 100644 --- a/.github/workflows/lint.yml +++ b/.github/workflows/lint.yml @@ -10,62 +10,59 @@ on: pull_request: types: [opened, synchronize, reopened] -jobs: - # ament_lint: - # runs-on: ubuntu-latest - # container: - # image: rostooling/setup-ros-docker:ubuntu-resolute-ros-lyrical-desktop-latest - # options: -u root - # strategy: - # fail-fast: false - # matrix: - # linter: [flake8, mypy, pep8, xmllint] - # steps: - # - uses: actions/checkout@v2 - # - uses: ros-tooling/action-ros-lint@master - # with: - # linter: ${{ matrix.linter }} - # package-name: . +permissions: + contents: read +jobs: run-linters: name: Run Linters for Code Format Check - runs-on: ubuntu-24.04 + runs-on: ubuntu-26.04 steps: - name: Check out Git repository - uses: actions/checkout@v3 + uses: actions/checkout@v7.0.1 - name: Set up Python 3.12 - uses: actions/setup-python@v1 + uses: actions/setup-python@v7.0.0 with: python-version: 3.12 - name: Install Python dependencies - run: pip install black flake8 cmakelang + # Match the formatter versions used by .pre-commit-config.yaml. + run: >- + python -m pip install black==24.10.0 flake8==7.1.1 + clang-format==19.1.6 cmakelang==0.6.13 yamllint==1.35.1 - name: Install system lint dependencies run: | sudo apt-get update - sudo apt-get install -y clang-format libxml2-utils + sudo apt-get install -y libxml2-utils - - name: Run Linters for python and C++ - uses: wearerequired/lint-action@v2 - with: - black: true - black_args: --line-length 100 - flake8: true - flake8_args: --max-line-length=100 - clang_format: true + - name: Check Python formatting + run: black --check --diff --line-length 99 --exclude tools/code_check . + + - name: Lint Python + if: ${{ !cancelled() }} + run: flake8 --ignore=E203,W503,E501 --exclude=tools/code_check . + + - name: Check C and C++ formatting + if: ${{ !cancelled() }} + run: | + git ls-files -z '*.c' '*.cc' '*.cpp' '*.h' '*.hpp' '*.m' '*.mm' | \ + xargs -0 -r clang-format --dry-run --Werror --fallback-style=none - name: Run XML Linter for URDF, SDF, Xacro, XML files + if: ${{ !cancelled() }} run: | find . \( -iname '*.urdf' -o -iname '*.sdf' -o -iname '*.xacro' \ -o -iname '*.xml' -o -iname '*.launch' -o -iname '*.world' \) -print0 | xargs -0 xmllint --noout - name: Run ShellCheck - uses: ludeeus/action-shellcheck@master + if: ${{ !cancelled() }} + uses: ludeeus/action-shellcheck@2.0.0 - name: Run Yamllint on YAML and .launch files + if: ${{ !cancelled() }} run: | find . \( -iname '*.yml' -o -iname '*.yaml' \) -print0 | xargs -0 yamllint -d "{ extends: default, @@ -76,4 +73,5 @@ jobs: }" - name: Lint CMake files + if: ${{ !cancelled() }} run: find . \( -iname 'CMakeLists.txt' -o -iname '*.cmake' \) -print0 | xargs -0 cmake-lint diff --git a/.github/workflows/pages.yml b/.github/workflows/pages.yml new file mode 100644 index 00000000..cf0df750 --- /dev/null +++ b/.github/workflows/pages.yml @@ -0,0 +1,56 @@ +--- +name: Build and deploy Pages + +# After merging, select Settings > Pages > Source > GitHub Actions to retire +# GitHub's generated legacy workflow and its uneditable action versions. +# yamllint disable-line rule:truthy +on: + push: + branches: [ros2] + pull_request: + branches: [ros2] + workflow_dispatch: + +permissions: + contents: read + +concurrency: + group: pages-${{ github.event.pull_request.number || github.ref }} + cancel-in-progress: false + +jobs: + build: + runs-on: ubuntu-26.04 + permissions: + contents: read + pages: read + steps: + - name: Check out repository + uses: actions/checkout@v7.0.1 + + - name: Configure Pages + uses: actions/configure-pages@v6.0.0 + + - name: Build the existing Jekyll site from the repository root + uses: actions/jekyll-build-pages@v1.0.13 + with: + source: ./ + destination: ./_site + + - name: Upload Pages artifact + uses: actions/upload-pages-artifact@v5.0.0 + + deploy: + if: github.event_name != 'pull_request' && github.ref == 'refs/heads/ros2' + needs: build + runs-on: ubuntu-26.04 + permissions: + pages: write + id-token: write + environment: + name: github-pages + url: ${{ steps.deployment.outputs.page_url }} + steps: + - name: Deploy Pages + id: deployment + uses: actions/deploy-pages@v5.0.1 diff --git a/models/dave_robot_models/config/mavros/mavros.yaml b/models/dave_robot_models/config/mavros/mavros.yaml index 0e0de031..a3ea5c74 100644 --- a/models/dave_robot_models/config/mavros/mavros.yaml +++ b/models/dave_robot_models/config/mavros/mavros.yaml @@ -1,3 +1,4 @@ +--- mavros: ros__parameters: system_id: 255