-
Notifications
You must be signed in to change notification settings - Fork 0
Add GitHub Actions workflow for 3D Skyline generation #2
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| @@ -0,0 +1,34 @@ | ||||||||||||||||||
| name: Generate 3D Contribution Skyline | ||||||||||||||||||
|
|
||||||||||||||||||
| on: | ||||||||||||||||||
| schedule: | ||||||||||||||||||
| - cron: '0 0 * * *' | ||||||||||||||||||
| workflow_dispatch: | ||||||||||||||||||
|
|
||||||||||||||||||
| permissions: | ||||||||||||||||||
| contents: write | ||||||||||||||||||
|
|
||||||||||||||||||
| jobs: | ||||||||||||||||||
| build: | ||||||||||||||||||
| runs-on: ubuntu-latest | ||||||||||||||||||
| steps: | ||||||||||||||||||
| - name: Checkout repo | ||||||||||||||||||
| uses: actions/checkout@v3 | ||||||||||||||||||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🩺 Stability & Availability | 🟠 Major | ⚡ Quick win 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
gh api repos/actions/checkout/releases/latest --jq '.tag_name'
rg -n -C 2 'actions/checkout@|runs-on:' .github/workflowsRepository: ElonCoding/ElonCoding Length of output: 984 🌐 Web query:
💡 Result: GitHub Actions has removed support for older Node.js runtimes as they reached their end-of-life (EOL). The removal of Node.js 12 and Node.js 16 followed established deprecation cycles, requiring users and action maintainers to upgrade their dependencies to newer, supported versions [1][2][3]. Summary of Node.js Runtime Deprecations in GitHub Actions: Node.js 12: Support was removed from GitHub Actions runners on August 14, 2023, following a deprecation process that began in 2022 [2][4][5]. Node.js 16: After reaching EOL, Node.js 16 was removed from GitHub Actions runners on November 12, 2024 [1][3]. Node.js 20: Following the EOL of Node.js 20 in April 2026, it was removed from GitHub runner images by May 2026, with defaults migrated to Node.js 22 [6]. Impact on Citations:
🌐 Web query:
💡 Result: The Citations:
🌐 Web query:
💡 Result: GitHub announced that Node.js 16 would reach its end-of-life on the Actions runner on November 12, 2024 [1]. From this date forward, Node.js 16 was no longer included in the GitHub-hosted runners, and users were required to migrate their actions to Node.js 20 to avoid workflow disruption [1]. While the general end-of-life date for the runner was set for November 12, 2024 [1], the specific removal dates from various runner images varied slightly: - Ubuntu 24.04: Node.js 16 was removed on October 21, 2024 [2]. - Ubuntu 20.04 and 22.04: Node.js 16 was scheduled for removal on November 18, 2024 [3]. This transition was part of a larger deprecation process that began earlier in 2024 [4]. By late 2024, GitHub had completed the transition to Node.js 20 as the required runtime for GitHub Actions [1]. Citations:
Replace the unsupported checkout action.
🧰 Tools🪛 actionlint (1.7.12)[error] 16-16: the runner of "actions/checkout@v3" action is too old to run on GitHub Actions. update the action's version to fix this issue (action) 🪛 zizmor (1.29.0)[warning] 15-16: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false (artipacked) 🤖 Prompt for AI AgentsSource: Linters/SAST tools |
||||||||||||||||||
|
|
||||||||||||||||||
| - name: Generate Skyline | ||||||||||||||||||
| uses: Platane/snk@v3 | ||||||||||||||||||
| with: | ||||||||||||||||||
| github_user_name: ElonCoding | ||||||||||||||||||
| outputs: | | ||||||||||||||||||
| output/profile-3d-contrib/profile-night-rainbow.svg | ||||||||||||||||||
|
|
||||||||||||||||||
| - name: Commit and Push SVG | ||||||||||||||||||
| env: | ||||||||||||||||||
| TOKEN: ${{ secrets.GITHUB_TOKEN }} | ||||||||||||||||||
| run: | | ||||||||||||||||||
| git config --global user.name 'ElonCoding' | ||||||||||||||||||
| git config --global user.email 'sharmaparikshit405@gmail.com' | ||||||||||||||||||
|
Comment on lines
+29
to
+30
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win Use a bot identity for generated commits. The workflow records Proposed fix- git config --global user.name 'ElonCoding'
- git config --global user.email 'sharmaparikshit405@gmail.com'
+ git config user.name 'github-actions[bot]'
+ git config user.email '41898282+github-actions[bot]`@users.noreply.github.com`'📝 Committable suggestion
Suggested change
🤖 Prompt for AI Agents |
||||||||||||||||||
| git add output || echo "Nothing to add" | ||||||||||||||||||
| git commit -m "🛰️ Update 3D Skyline graph" || echo "Nothing to commit" | ||||||||||||||||||
|
Comment on lines
+31
to
+32
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🩺 Stability & Availability | 🟠 Major | ⚡ Quick win Do not hide staging and commit failures.
Proposed fix- git add output || echo "Nothing to add"
- git commit -m "🛰️ Update 3D Skyline graph" || echo "Nothing to commit"
+ git add output
+ if git diff --cached --quiet; then
+ echo "Nothing to commit"
+ exit 0
+ fi
+ git commit -m "🛰️ Update 3D Skyline graph"📝 Committable suggestion
Suggested change
🤖 Prompt for AI Agents |
||||||||||||||||||
| git remote set-url origin https://x-access-token:${TOKEN}@github.com/${{ github.repository }}.git | ||||||||||||||||||
| git push origin HEAD:main | ||||||||||||||||||
|
Comment on lines
+25
to
+34
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🩺 Stability & Availability | 🟠 Major | ⚡ Quick win 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
echo "== candidate file =="
if [ -f .github/workflows/3d.yml ]; then
nl -ba .github/workflows/3d.yml | sed -n '1,80p'
else
echo ".github/workflows/3d.yml not found"
fi
echo
echo "== all workflow files =="
git ls-files '.github/workflows/*' | sort
echo
echo "== concurrency declarations in workflows =="
rg -n "concurrency:|cancel-in-progress|schedule:|workflow_dispatch" .github/workflows || trueRepository: ElonCoding/ElonCoding Length of output: 220 🏁 Script executed: #!/bin/bash
set -u
echo "== candidate file =="
if [ -f .github/workflows/3d.yml ]; then
awk '{printf "%6d %s\n", NR, $0}' .github/workflows/3d.yml | sed -n '1,100p'
else
echo ".github/workflows/3d.yml not found"
fi
echo
echo "== all workflow files =="
git ls-files '.github/workflows/*' | sort
echo
echo "== concurrency declarations in workflows =="
grep -RInE 'concurrency:|cancel-in-progress|schedule:|workflow_dispatch' .github/workflows || trueRepository: ElonCoding/ElonCoding Length of output: 1713 Serialize skyline runs before pushing. This workflow runs on both schedule and manual dispatch, but it has no workflow-level concurrency control. Concurrent runs can commit from the same base and make one 🤖 Prompt for AI Agents |
||||||||||||||||||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
Repository: ElonCoding/ElonCoding
Length of output: 2135
🌐 Web query:
actions/checkout v3 ref input default pull_request branch event default branch💡 Result:
For the actions/checkout action (including version v3), the ref input behaves according to the following logic: When checking out the repository that triggered the workflow, the ref input defaults to the reference or SHA associated with that event [1][2]. If it is not triggered by an event, or in cases where the reference is not automatically determined, it defaults to the repository's default branch [1][2]. Regarding the pull_request event specifically: By default, actions/checkout checks out a merge commit that represents the merge between the pull request branch and the base branch, rather than the pull request head commit itself [3][4]. Because this merge commit is a detached HEAD, users who specifically want to work with the branch head or a different reference must explicitly set the ref input, for example by using ${{ github.head_ref }} [5][6]. In the context of the pull_request_target event, the action defaults to the base repository's default branch for security reasons, as this event runs in a context that has access to secrets [3].
Citations:
🌐 Web query:
GitHub Actions workflow_dispatch inputs branch ref checkout default branch💡 Result:
To use the workflow_dispatch trigger with custom inputs and handle branch references or default branch checkouts in GitHub Actions, observe the following requirements and behaviors. Workflow Trigger Requirements The workflow_dispatch event trigger only functions when the workflow file is present on the repository's default branch [1][2]. If you attempt to trigger it manually via the GitHub UI or API while the workflow file exists only on a non-default branch, the workflow will not be available to run [2][3]. Handling Branch References When you manually trigger a workflow via the GitHub UI, you can select the branch or tag to run against. When using the GitHub CLI (gh) or REST API, you must specify the branch/ref explicitly using the --ref flag or the ref request parameter [2]. Checkout Behavior The actions/checkout action is responsible for cloning your code into the runner [4]. Its behavior regarding the branch is as follows: - By default, if the ref input is omitted, actions/checkout checks out the reference (branch, tag, or SHA) that triggered the workflow [4][5]. - If you have manually triggered the workflow on a specific branch (e.g., feature-branch), actions/checkout will default to that branch [4]. - If you specifically require the default branch regardless of what triggered the workflow, you must explicitly set the ref input in your checkout step: - uses: actions/checkout@v7 with: ref: main # Replace 'main' with your actual default branch name Summary of Workflow Dispatch inputs - Inputs are defined in the workflow file under on.workflow_dispatch.inputs and are accessible within the workflow via the inputs context (or github.event.inputs) [1]. - These inputs are independent of the branch reference [1]. Whether you run the workflow on the default branch or a feature branch, the same set of inputs will be available to the workflow [1]. If you are using third-party actions like benc-uk/workflow-dispatch to trigger workflows across different repositories, you may need to explicitly pass the ref input to ensure the target workflow operates on the correct branch, especially if the target repository has a different default branch than the caller [6][7].
Citations:
Checkout
mainbefore pushing tomain.workflow_dispatchcan run this workflow from a non-default branch. With norefinput,actions/checkoutchecks out the selected branch, but the final command still pushes that branch’sHEADtomain. Set the checkout ref explicitly so every run builds and commits frommain.Proposed fix
- name: Checkout repo uses: actions/checkout@v3 + with: + ref: main📝 Committable suggestion
🧰 Tools
🪛 actionlint (1.7.12)
[error] 16-16: the runner of "actions/checkout@v3" action is too old to run on GitHub Actions. update the action's version to fix this issue
(action)
🪛 zizmor (1.29.0)
[warning] 15-16: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
🤖 Prompt for AI Agents
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
Repository: ElonCoding/ElonCoding
Length of output: 219
🏁 Script executed:
Repository: ElonCoding/ElonCoding
Length of output: 1454
🌐 Web query:
actions/checkout persist-credentials default true local Git configuration persist-credentials false💡 Result:
The persist-credentials input for the GitHub Actions checkout action (actions/checkout) determines whether the repository's authentication token or SSH key is configured in the local Git configuration [1][2]. The default value for persist-credentials is true [1][2]. When set to true (the default), the action configures the authentication credentials into the local Git configuration, which allows your workflow steps to run authenticated Git commands (such as git fetch or git push) automatically [1][3]. The action ensures these credentials are removed during the post-job cleanup process [1][4]. When you set persist-credentials to false, the action will not configure these credentials in the local Git configuration [1][2]. This is an optional setting used to opt-out of this behavior [1][5]. Note: While there have been discussions and community requests to change this default to false to further reduce the risk of credential exposure, the current authoritative configuration in the official actions/checkout repository maintains the default value as true [1][6][2]. Recent security improvements have been implemented to store these credentials in a separate file under $RUNNER_TEMP rather than directly in.git/config, while still allowing git commands to work seamlessly without requiring workflow changes [3][7].
Citations:
🌐 Web query:
Platane/snk v3 GitHub Action Docker entrypoint script source💡 Result:
The Platane/snk v3 GitHub Action does not use a traditional entrypoint script file. Instead, the Docker container is configured to run a specific command directly [1]. As specified in the project's Dockerfile, the container uses the following instruction to execute the application: CMD ["bun", "/action-release/index.js"] The Docker container environment is built using Bun, and the entry point for the action's logic is the JavaScript file located at /action-release/index.js [1]. This file contains the bundled code generated during the project's build process [1]. Users do not need to interact with this entrypoint file directly, as it is managed automatically by the GitHub Action's Docker configuration [2][1].
Citations:
🌐 Web query:
Platane/snk v3 github.com/Dockerfile CMD bun /action-release/index.js action.yml Docker run uses Dockerfile💡 Result:
Platane/snk is a popular GitHub Action that generates an animated snake game visualization based on a user's GitHub contribution graph [1][2]. The action supports both GIF and SVG output formats [1][3]. Regarding the specific components you mentioned: Dockerfile and CMD: The project uses a Dockerfile that leverages the bun runtime (specifically oven/bun) [4]. The final image is configured with the command CMD ["bun", "/action-release/index.js"], which executes the main action logic upon container startup [4]. action.yml: The action definition file (action.yml) specifies that the action runs using a docker container [5]. It points to a specific image reference (image: docker://platane/snk@sha256:...) to ensure a consistent, versioned execution environment [5]. Usage: Users can invoke this action in their GitHub workflow files using the syntax - uses: Platane/snk@v3 [1][6]. For users who only require SVG output and prefer a faster, non-Docker implementation, the project also provides a secondary action: uses: Platane/snk/svg-only@v3 [3][7].
Citations:
Limit
GITHUB_TOKENexposure to the final push.actions/checkoutpersists the token in local Git credentials by default. The followingPlatane/snk@v3Docker container step can access the checked-out workspace, and the commit/push step later also writes the token into theoriginURL. Disable persisted credentials at checkout and authenticate only the finalgit pushwith a command-scopedhttp.extraheaderheader.Proposed fix
- name: Checkout repo uses: actions/checkout@v3 with: + persist-credentials: false ... - git remote set-url origin https://x-access-token:${TOKEN}`@github.com/`${{ github.repository }}.git - git push origin HEAD:main + git -c "http.extraheader=AUTHORIZATION: bearer ${TOKEN}" push origin HEAD:main🧰 Tools
🪛 actionlint (1.7.12)
[error] 16-16: the runner of "actions/checkout@v3" action is too old to run on GitHub Actions. update the action's version to fix this issue
(action)
🪛 zizmor (1.29.0)
[warning] 15-16: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
🤖 Prompt for AI Agents
Source: Linters/SAST tools