chore(deps): Update @posthog/mcp to 0.21.0 #411199
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Container Images CI | |
| on: | |
| pull_request: | |
| # Label-triggered builds live in container-images-label-ci.yml so a skipped | |
| # label event cannot replace this workflow's required check. | |
| types: [opened, synchronize] | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.head_ref || github.ref }} | |
| cancel-in-progress: ${{ github.event_name == 'pull_request' }} | |
| jobs: | |
| changes: | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 5 | |
| if: github.repository == 'PostHog/posthog' | |
| name: Determine need to run Docker checks | |
| permissions: | |
| contents: read | |
| pull-requests: read | |
| outputs: | |
| # The image is only consumed by ci-hobby.yml. Skip the long image build | |
| # when ci-hobby would also skip, plus on changes to inputs that can | |
| # only break inside the Docker build (workflow self-edits, frontend | |
| # lockfile bumps that ci-hobby's filter ignores). | |
| should_build: >- | |
| ${{ | |
| steps.filter.outputs.hobby == 'true' | |
| || steps.filter.outputs.build_inputs == 'true' | |
| || contains(github.event.pull_request.labels.*.name, 'hobby-preview') | |
| }} | |
| dockerignore_changed: ${{ steps.filter.outputs.dockerignore }} | |
| # Drives the Dockerfile lint job: a boolean plus the shell-escaped, space-separated | |
| # list of changed Dockerfiles to hand straight to hadolint. | |
| dockerfiles_changed: ${{ steps.filter.outputs.dockerfiles }} | |
| dockerfiles_files: ${{ steps.filter.outputs.dockerfiles_files }} | |
| steps: | |
| - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| with: | |
| sparse-checkout: .github/actions/paths-filter | |
| sparse-checkout-cone-mode: false | |
| - uses: actions/create-github-app-token@1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1 | |
| id: app-token | |
| if: github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name == github.repository | |
| with: | |
| client-id: ${{ vars.GH_APP_POSTHOG_PATHS_FILTER_APP_ID }} | |
| private-key: ${{ secrets.GH_APP_POSTHOG_PATHS_FILTER_PRIVATE_KEY }} | |
| - uses: ./.github/actions/paths-filter | |
| id: filter | |
| with: | |
| token: ${{ steps.app-token.outputs.token || github.token }} | |
| # Emit `<filter>_files` lists (shell-escaped, space-separated) so the | |
| # lint job can feed changed Dockerfiles straight to hadolint. | |
| list-files: shell | |
| filters: | | |
| # Keep `hobby:` in sync with the same-named filter in ci-hobby.yml — | |
| # drift means hobby waits for an image we never build (or vice versa). | |
| hobby: | |
| - Dockerfile | |
| - docker-compose.base.yml | |
| - docker-compose.hobby.yml | |
| - 'bin/deploy-hobby' | |
| - 'bin/hobby-ci-setup-user.py' | |
| - 'bin/hobby-ci.py' | |
| - 'bin/upgrade-hobby' | |
| - 'bin/migrate-*-hobby' | |
| - 'bin/docker' | |
| - 'bin/docker-worker' | |
| - 'bin/docker-worker-beat' | |
| - 'bin/docker-worker-celery' | |
| - 'bin/docker-server' | |
| - 'bin/celery-queues.env' | |
| - 'bin/migrate' | |
| - 'bin/migrate-check' | |
| - 'bin/posthog-node' | |
| - 'bin/hobby-installer/**' | |
| - 'docker/**' | |
| - uv.lock | |
| - .github/workflows/ci-hobby.yml | |
| # Inputs that can break inside the Docker build but aren't covered | |
| # by the `hobby:` filter — workflow self-edits, `.dockerignore` | |
| # (silently changes the build context), and `pnpm-lock.yaml` so | |
| # Renovate-style dep bumps are exercised on PR (otherwise they'd | |
| # only fail after merging). Root `package.json` carries the | |
| # `packageManager` pin the image seeds corepack from, and a pin-only | |
| # edit leaves the lockfile untouched. | |
| build_inputs: | |
| - .github/workflows/container-images-ci.yml | |
| - .github/workflows/container-images-label-ci.yml | |
| - .github/actions/build-n-cache-image/** | |
| - .dockerignore | |
| - pnpm-lock.yaml | |
| - package.json | |
| # Drives the fast PR-time guard below (models `COPY . .`, so it only reacts | |
| # to .dockerignore — Dockerfile COPY changes are covered by the image boot check). | |
| dockerignore: | |
| - .dockerignore | |
| # Drives the hadolint lint job below — the matched paths are passed straight | |
| # to hadolint via the `dockerfiles_files` output. Scoped to added|modified | |
| # so a PR that deletes a Dockerfile doesn't hand hadolint a path that no | |
| # longer exists in the tree. | |
| dockerfiles: | |
| - added|modified: | |
| - '**/Dockerfile' | |
| - '**/*.Dockerfile' | |
| - '**/Dockerfile.*' | |
| dockerignore_guard: | |
| needs: changes | |
| name: Guard against dropped image files | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 10 | |
| # Needs no secrets or docker login, so unlike the image build below it runs on fork PRs too. | |
| if: github.event_name == 'pull_request' && needs.changes.outputs.dockerignore_changed == 'true' | |
| permissions: | |
| contents: read | |
| steps: | |
| - name: Check out | |
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| - name: Fetch base ref for comparison | |
| run: git fetch --no-tags --depth=1 origin "${{ github.event.pull_request.base.sha }}" | |
| - name: Check for non-test files dropped from the image | |
| run: bin/dockerignore-drop-check "${{ github.event.pull_request.base.sha }}" | |
| posthog_build: | |
| needs: changes | |
| name: Build Docker image | |
| # run these on 4, if they're RAM constrained the FE build will fail randomly in Docker build | |
| runs-on: depot-ubuntu-24.04-4 | |
| timeout-minutes: 45 | |
| permissions: | |
| id-token: write # allow issuing OIDC tokens for this workflow run | |
| contents: read # allow at least reading the repo contents, add other permissions if necessary | |
| # Only on PostHog/posthog, as there's no docker login on forks | |
| if: github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name == github.repository && needs.changes.outputs.should_build == 'true' | |
| outputs: | |
| digest: ${{ steps.build.outputs.digest }} | |
| steps: | |
| - name: Check out | |
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| - name: Build and cache Docker image in Depot | |
| id: build | |
| uses: ./.github/actions/build-n-cache-image | |
| with: | |
| actions-id-token-request-url: ${{ env.ACTIONS_ID_TOKEN_REQUEST_URL }} | |
| push-image: ${{ github.repository == 'PostHog/posthog' }} # Don't push on forks due to lack of credentials | |
| # PR-only publish role: any branch, but can ONLY push to posthog-cloud-prs (not posthog-cloud). | |
| aws-role-to-assume: ${{ vars.AWS_ECR_POSTHOG_PRS_PUBLISH_IAM_ROLE }} | |
| dockerhub-username: ${{ secrets.DOCKERHUB_USER }} | |
| dockerhub-password: ${{ secrets.DOCKERHUB_TOKEN }} | |
| pr-number: ${{ github.event.number }} | |
| no-cache: ${{ contains(github.event.pull_request.labels.*.name, 'no-depot-docker-cache') }} | |
| - name: Container image digest | |
| env: | |
| IMAGE_DIGEST: ${{ steps.build.outputs.digest }} | |
| IMAGE_REGISTRY: ${{ steps.build.outputs.registry }} | |
| run: | | |
| echo "Image digest: $IMAGE_DIGEST" | |
| echo "## Container image built :rocket:" >> $GITHUB_STEP_SUMMARY | |
| echo "" >> $GITHUB_STEP_SUMMARY | |
| echo "**Image reference:** \`$IMAGE_REGISTRY/posthog-cloud-prs@$IMAGE_DIGEST\`" >> $GITHUB_STEP_SUMMARY | |
| echo "" >> $GITHUB_STEP_SUMMARY | |
| echo "**Image SHA:** \`${{ github.sha }}@$IMAGE_DIGEST\`" >> $GITHUB_STEP_SUMMARY | |
| echo "" >> $GITHUB_STEP_SUMMARY | |
| echo "- Commit: \`${{ github.sha }}\`" >> $GITHUB_STEP_SUMMARY | |
| echo "- Digest: \`$IMAGE_DIGEST\`" >> $GITHUB_STEP_SUMMARY | |
| lint: | |
| needs: changes | |
| name: Lint changed Dockerfiles | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 5 | |
| permissions: | |
| contents: read | |
| steps: | |
| - name: Check out | |
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| # Changed-Dockerfile list comes from the shared paths-filter in `changes`, so no | |
| # second changed-files action or full-history checkout. The job still always runs | |
| # (only the hadolint step is gated) to keep its required-check status reporting. | |
| - name: Lint changed Dockerfile(s) with Hadolint | |
| if: needs.changes.outputs.dockerfiles_changed == 'true' | |
| uses: jbergstroem/hadolint-gh-action@2b00b87f8a56783930b6a4749837d7c45c567ff2 # v1.13.0 | |
| with: | |
| dockerfile: '${{ needs.changes.outputs.dockerfiles_files }}' |