From 4b26c454a0edaeaefc62f4ac247a042287c69c86 Mon Sep 17 00:00:00 2001 From: samuelburnham <45365069+samuelburnham@users.noreply.github.com> Date: Thu, 1 Oct 2026 15:57:32 -0400 Subject: [PATCH] ci: update nixpkgs and flake-parts weekly; schedule on Eastern time A weekly update-flake-lock run moves nixpkgs and flake-parts to their latest revisions and opens a PR against dev, on a fixed branch so a still-open PR is updated in place. Downstream flakes follow this one for nixpkgs, so this is the one place that pin advances; they pick it up when lean-update bumps their lean4-nix input on the next Lean release. The PR is opened with GITHUB_TOKEN, so CI runs once a maintainer reopens it. The toolchain update and repo-sync schedules move from UTC to Eastern time, matching the other repositories' workflows. --- .github/workflows/repo-sync.yml | 5 ++-- .github/workflows/update-flake-lock.yml | 36 +++++++++++++++++++++++++ .github/workflows/update.yml | 3 ++- 3 files changed, 41 insertions(+), 3 deletions(-) create mode 100644 .github/workflows/update-flake-lock.yml diff --git a/.github/workflows/repo-sync.yml b/.github/workflows/repo-sync.yml index d0ac0c1..f5fdeeb 100644 --- a/.github/workflows/repo-sync.yml +++ b/.github/workflows/repo-sync.yml @@ -1,9 +1,10 @@ -# Pull upstream changes from lenianiva/lean4-nix daily at 12am UTC +# Pull upstream changes from lenianiva/lean4-nix daily at midnight name: Repo sync on: schedule: - - cron: "0 0 * * *" + - cron: "0 0 * * *" + timezone: America/New_York workflow_dispatch: permissions: {} diff --git a/.github/workflows/update-flake-lock.yml b/.github/workflows/update-flake-lock.yml new file mode 100644 index 0000000..9d42ccc --- /dev/null +++ b/.github/workflows/update-flake-lock.yml @@ -0,0 +1,36 @@ +# Move nixpkgs and flake-parts to their latest revisions once a week and open +# a PR against dev. Downstream flakes follow this one for nixpkgs, so this is +# the one place that pin advances; they pick it up when lean-update bumps +# their lean4-nix input on the next Lean release. +name: Update flake inputs + +on: + schedule: + # Weekly on Monday at midnight + - cron: "0 0 * * 1" + timezone: America/New_York + workflow_dispatch: + +permissions: + contents: write + pull-requests: write + +jobs: + update: + name: Update flake.lock + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + - uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1 + with: + github_access_token: ${{ github.token }} + # A fixed branch name means a still-open PR is updated in place rather + # than a second one opened. The PR is opened with GITHUB_TOKEN, so CI + # runs once a maintainer closes and reopens it. + - uses: DeterminateSystems/update-flake-lock@da03c0f078bc4b2c37ee4f7e072d34bf8f188bb3 # v29 + with: + branch: update/flake-lock + commit-msg: "chore: Update flake inputs" + pr-title: "chore: Update flake inputs" diff --git a/.github/workflows/update.yml b/.github/workflows/update.yml index e202698..9968cd0 100644 --- a/.github/workflows/update.yml +++ b/.github/workflows/update.yml @@ -4,8 +4,9 @@ name: Update toolchain on: schedule: - # Daily at 00:00 UTC + # Daily at midnight - cron: "0 0 * * *" + timezone: America/New_York workflow_dispatch: permissions: