Skip to content

chore(deps): Update @posthog/mcp to 0.21.0 #411199

chore(deps): Update @posthog/mcp to 0.21.0

chore(deps): Update @posthog/mcp to 0.21.0 #411199

name: Container Images CI
on:
pull_request:
# Label-triggered builds live in container-images-label-ci.yml so a skipped
# label event cannot replace this workflow's required check.
types: [opened, synchronize]
concurrency:
group: ${{ github.workflow }}-${{ github.head_ref || github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
jobs:
changes:
runs-on: ubuntu-24.04
timeout-minutes: 5
if: github.repository == 'PostHog/posthog'
name: Determine need to run Docker checks
permissions:
contents: read
pull-requests: read
outputs:
# The image is only consumed by ci-hobby.yml. Skip the long image build
# when ci-hobby would also skip, plus on changes to inputs that can
# only break inside the Docker build (workflow self-edits, frontend
# lockfile bumps that ci-hobby's filter ignores).
should_build: >-
${{
steps.filter.outputs.hobby == 'true'
|| steps.filter.outputs.build_inputs == 'true'
|| contains(github.event.pull_request.labels.*.name, 'hobby-preview')
}}
dockerignore_changed: ${{ steps.filter.outputs.dockerignore }}
# Drives the Dockerfile lint job: a boolean plus the shell-escaped, space-separated
# list of changed Dockerfiles to hand straight to hadolint.
dockerfiles_changed: ${{ steps.filter.outputs.dockerfiles }}
dockerfiles_files: ${{ steps.filter.outputs.dockerfiles_files }}
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
sparse-checkout: .github/actions/paths-filter
sparse-checkout-cone-mode: false
- uses: actions/create-github-app-token@1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1
id: app-token
if: github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name == github.repository
with:
client-id: ${{ vars.GH_APP_POSTHOG_PATHS_FILTER_APP_ID }}
private-key: ${{ secrets.GH_APP_POSTHOG_PATHS_FILTER_PRIVATE_KEY }}
- uses: ./.github/actions/paths-filter
id: filter
with:
token: ${{ steps.app-token.outputs.token || github.token }}
# Emit `<filter>_files` lists (shell-escaped, space-separated) so the
# lint job can feed changed Dockerfiles straight to hadolint.
list-files: shell
filters: |
# Keep `hobby:` in sync with the same-named filter in ci-hobby.yml —
# drift means hobby waits for an image we never build (or vice versa).
hobby:
- Dockerfile
- docker-compose.base.yml
- docker-compose.hobby.yml
- 'bin/deploy-hobby'
- 'bin/hobby-ci-setup-user.py'
- 'bin/hobby-ci.py'
- 'bin/upgrade-hobby'
- 'bin/migrate-*-hobby'
- 'bin/docker'
- 'bin/docker-worker'
- 'bin/docker-worker-beat'
- 'bin/docker-worker-celery'
- 'bin/docker-server'
- 'bin/celery-queues.env'
- 'bin/migrate'
- 'bin/migrate-check'
- 'bin/posthog-node'
- 'bin/hobby-installer/**'
- 'docker/**'
- uv.lock
- .github/workflows/ci-hobby.yml
# Inputs that can break inside the Docker build but aren't covered
# by the `hobby:` filter — workflow self-edits, `.dockerignore`
# (silently changes the build context), and `pnpm-lock.yaml` so
# Renovate-style dep bumps are exercised on PR (otherwise they'd
# only fail after merging). Root `package.json` carries the
# `packageManager` pin the image seeds corepack from, and a pin-only
# edit leaves the lockfile untouched.
build_inputs:
- .github/workflows/container-images-ci.yml
- .github/workflows/container-images-label-ci.yml
- .github/actions/build-n-cache-image/**
- .dockerignore
- pnpm-lock.yaml
- package.json
# Drives the fast PR-time guard below (models `COPY . .`, so it only reacts
# to .dockerignore — Dockerfile COPY changes are covered by the image boot check).
dockerignore:
- .dockerignore
# Drives the hadolint lint job below — the matched paths are passed straight
# to hadolint via the `dockerfiles_files` output. Scoped to added|modified
# so a PR that deletes a Dockerfile doesn't hand hadolint a path that no
# longer exists in the tree.
dockerfiles:
- added|modified:
- '**/Dockerfile'
- '**/*.Dockerfile'
- '**/Dockerfile.*'
dockerignore_guard:
needs: changes
name: Guard against dropped image files
runs-on: ubuntu-24.04
timeout-minutes: 10
# Needs no secrets or docker login, so unlike the image build below it runs on fork PRs too.
if: github.event_name == 'pull_request' && needs.changes.outputs.dockerignore_changed == 'true'
permissions:
contents: read
steps:
- name: Check out
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Fetch base ref for comparison
run: git fetch --no-tags --depth=1 origin "${{ github.event.pull_request.base.sha }}"
- name: Check for non-test files dropped from the image
run: bin/dockerignore-drop-check "${{ github.event.pull_request.base.sha }}"
posthog_build:
needs: changes
name: Build Docker image
# run these on 4, if they're RAM constrained the FE build will fail randomly in Docker build
runs-on: depot-ubuntu-24.04-4
timeout-minutes: 45
permissions:
id-token: write # allow issuing OIDC tokens for this workflow run
contents: read # allow at least reading the repo contents, add other permissions if necessary
# Only on PostHog/posthog, as there's no docker login on forks
if: github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name == github.repository && needs.changes.outputs.should_build == 'true'
outputs:
digest: ${{ steps.build.outputs.digest }}
steps:
- name: Check out
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Build and cache Docker image in Depot
id: build
uses: ./.github/actions/build-n-cache-image
with:
actions-id-token-request-url: ${{ env.ACTIONS_ID_TOKEN_REQUEST_URL }}
push-image: ${{ github.repository == 'PostHog/posthog' }} # Don't push on forks due to lack of credentials
# PR-only publish role: any branch, but can ONLY push to posthog-cloud-prs (not posthog-cloud).
aws-role-to-assume: ${{ vars.AWS_ECR_POSTHOG_PRS_PUBLISH_IAM_ROLE }}
dockerhub-username: ${{ secrets.DOCKERHUB_USER }}
dockerhub-password: ${{ secrets.DOCKERHUB_TOKEN }}
pr-number: ${{ github.event.number }}
no-cache: ${{ contains(github.event.pull_request.labels.*.name, 'no-depot-docker-cache') }}
- name: Container image digest
env:
IMAGE_DIGEST: ${{ steps.build.outputs.digest }}
IMAGE_REGISTRY: ${{ steps.build.outputs.registry }}
run: |
echo "Image digest: $IMAGE_DIGEST"
echo "## Container image built :rocket:" >> $GITHUB_STEP_SUMMARY
echo "" >> $GITHUB_STEP_SUMMARY
echo "**Image reference:** \`$IMAGE_REGISTRY/posthog-cloud-prs@$IMAGE_DIGEST\`" >> $GITHUB_STEP_SUMMARY
echo "" >> $GITHUB_STEP_SUMMARY
echo "**Image SHA:** \`${{ github.sha }}@$IMAGE_DIGEST\`" >> $GITHUB_STEP_SUMMARY
echo "" >> $GITHUB_STEP_SUMMARY
echo "- Commit: \`${{ github.sha }}\`" >> $GITHUB_STEP_SUMMARY
echo "- Digest: \`$IMAGE_DIGEST\`" >> $GITHUB_STEP_SUMMARY
lint:
needs: changes
name: Lint changed Dockerfiles
runs-on: ubuntu-24.04
timeout-minutes: 5
permissions:
contents: read
steps:
- name: Check out
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
# Changed-Dockerfile list comes from the shared paths-filter in `changes`, so no
# second changed-files action or full-history checkout. The job still always runs
# (only the hadolint step is gated) to keep its required-check status reporting.
- name: Lint changed Dockerfile(s) with Hadolint
if: needs.changes.outputs.dockerfiles_changed == 'true'
uses: jbergstroem/hadolint-gh-action@2b00b87f8a56783930b6a4749837d7c45c567ff2 # v1.13.0
with:
dockerfile: '${{ needs.changes.outputs.dockerfiles_files }}'