mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-09-30 03:43:10 +00:00
- Reusable PR review workflow (repos call via thin wrapper) - Weekly compliance audit across all org repos - Rollout script to push wrapper workflow to all repos - Uses GitHub App tokens for cross-repo auth (no PAT rotation needed)
84 lines
2.1 KiB
Bash
Executable file
84 lines
2.1 KiB
Bash
Executable file
#!/usr/bin/env bash
|
|
set -euo pipefail
|
|
|
|
ORG="Sea-Haven-Industries"
|
|
BRANCH="add-claude-review"
|
|
WORKFLOW_PATH=".github/workflows/claude-review.yaml"
|
|
COMMIT_MSG="Add Claude Code review workflow"
|
|
|
|
WORKFLOW_CONTENT='name: Claude Code Review
|
|
|
|
on:
|
|
pull_request:
|
|
types: [opened, synchronize]
|
|
|
|
permissions:
|
|
contents: read
|
|
pull-requests: write
|
|
|
|
jobs:
|
|
review:
|
|
uses: Sea-Haven-Industries/.github/.github/workflows/claude-code-review.yaml@main
|
|
secrets:
|
|
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
|
|
'
|
|
|
|
SKIP_REPOS=(".github")
|
|
|
|
should_skip() {
|
|
local repo="$1"
|
|
for skip in "${SKIP_REPOS[@]}"; do
|
|
if [[ "$repo" == "$skip" ]]; then
|
|
return 0
|
|
fi
|
|
done
|
|
return 1
|
|
}
|
|
|
|
echo "Fetching non-archived repos from $ORG..."
|
|
repos=$(gh repo list "$ORG" --no-archived --json name --jq '.[].name' --limit 100)
|
|
|
|
for repo in $repos; do
|
|
if should_skip "$repo"; then
|
|
echo "SKIP $repo (in skip list)"
|
|
continue
|
|
fi
|
|
|
|
echo ""
|
|
echo "--- $repo ---"
|
|
|
|
existing=$(gh api "repos/$ORG/$repo/contents/$WORKFLOW_PATH" --jq '.sha' 2>/dev/null || true)
|
|
if [[ -n "$existing" ]]; then
|
|
echo "SKIP $repo (workflow already exists)"
|
|
continue
|
|
fi
|
|
|
|
default_branch=$(gh api "repos/$ORG/$repo" --jq '.default_branch')
|
|
|
|
encoded=$(echo -n "$WORKFLOW_CONTENT" | base64)
|
|
|
|
gh api "repos/$ORG/$repo/git/refs" \
|
|
-f "ref=refs/heads/$BRANCH" \
|
|
-f "sha=$(gh api "repos/$ORG/$repo/git/ref/heads/$default_branch" --jq '.object.sha')" \
|
|
2>/dev/null || true
|
|
|
|
gh api "repos/$ORG/$repo/contents/$WORKFLOW_PATH" \
|
|
-X PUT \
|
|
-f "message=$COMMIT_MSG" \
|
|
-f "content=$encoded" \
|
|
-f "branch=$BRANCH" \
|
|
> /dev/null
|
|
|
|
pr_url=$(gh pr create \
|
|
--repo "$ORG/$repo" \
|
|
--base "$default_branch" \
|
|
--head "$BRANCH" \
|
|
--title "$COMMIT_MSG" \
|
|
--body "Adds a thin workflow that delegates PR reviews to the central reusable workflow in \`Sea-Haven-Industries/.github\`. Requires the \`ANTHROPIC_API_KEY\` org secret to be set." \
|
|
2>/dev/null || echo "PR already exists")
|
|
|
|
echo "DONE $repo → $pr_url"
|
|
done
|
|
|
|
echo ""
|
|
echo "Rollout complete. Review and merge the PRs, then delete the feature branches."
|