This repository contains GitHub Action workflows that are shared across repos in the withastro GitHub org.
Warning
These workflows are not designed for use outside of thewithastroGitHub org.
This workflow posts a celebratory message in a Discord channel of your choice for each commit. For example:
🎊 Merged! Houston (Bot):
[ci] release (#232)
Featuring contributions by github-actions[bot]! 🌟
Create a new Discord webhook and add the URL to your repository secrets as DISCORD_WEBHOOK_CONGRATS.
name: Congratsbot
on:
push:
branches: [main]
jobs:
congrats:
if: ${{ github.repository_owner == 'withastro' }}
uses: withastro/automation/.github/workflows/congratsbot.yml@<commit-sha> # vX.Y.Z
secrets:
DISCORD_WEBHOOK: ${{ secrets.DISCORD_WEBHOOK_CONGRATS }}You can customize the emojis and co-author message templates to give your repository its own personality. You can set these under with in your job:
jobs:
congrats:
if: ${{ github.repository_owner == 'withastro' }}
uses: withastro/automation/.github/workflows/congratsbot.yml@<commit-sha> # vX.Y.Z
with:
EMOJIS: 🤖,👻,😱
COAUTHOR_TEMPLATES: >
[
"Woahhh, <names> really gave us a fright! 🎃",
"We weren’t sure what we were doing until <names> showed up. 🤝"
]
secrets:
DISCORD_WEBHOOK: ${{ secrets.DISCORD_WEBHOOK_CONGRATS }}default: 🎉,🎊,🧑🚀,🥳,🙌,🚀
A comma-delimited set of emojis. Each congrats bot message will pick one at random for the start of the message.
default: see congratsbot.yml
A JSON array of co-author recognition templates.
Each template should contain the <names> placeholder to be replaced by the names of one or more co-authors for this commit.
(Ignored for commits without any co-authors.)
When writing congrats messages, remember that <names> could be one, two, or more names. So, create messages that can work for both a single co-author and for several people, for example, "This PR was made even better by <names>!"
This workflow runs a repository’s code formatting tooling (e.g. Prettier). It needs the FREDKBOT_GITHUB_TOKEN to be passed as a secrets parameter to be able to commits any resulting changes directly.
name: Format
on:
workflow_dispatch:
push:
branches:
- main
jobs:
prettier:
if: github.repository_owner == 'withastro'
uses: withastro/automation/.github/workflows/format.yml@<commit-sha> # vX.Y.Z
with:
# Set command to this repository’s package script that runs Prettier
command: 'format:ci'
secrets:
FREDKBOT_GITHUB_TOKEN: ${{ secrets.FREDKBOT_GITHUB_TOKEN }}This workflow deploys a Cloudflare Worker to production on pushes, and on pull requests uploads the build output and PR metadata for cloudflare-deploy-preview.yml to publish a preview. It requires a CLOUDFLARE_API_TOKEN secret and a wrangler.jsonc whose name matches the Worker.
name: Deploy
on:
push:
branches: [main]
pull_request:
permissions: {}
jobs:
deploy:
if: github.repository_owner == 'withastro'
permissions:
contents: read
uses: withastro/automation/.github/workflows/cloudflare-deploy.yml@<commit-sha> # vX.Y.Z
with:
preview-domain: previews.my-worker.astro.build
artifact-paths: |
dist/
worker.js
wrangler.jsonc
# Optional build setup, omit for a repo with no build step:
node-version: '24.18.0'
install-command: 'pnpm install'
build-command: 'pnpm build'
secrets:
CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}See the workflow inputs for the full list of options.
This workflow publishes a Cloudflare Worker preview for a pull request and comments the preview URL. It runs from the trusted base-repo context (via workflow_run) so it can deploy fork PRs safely without exposing the token. Use it alongside cloudflare-deploy.yml.
name: Deploy Preview
on:
workflow_run:
workflows: ['Deploy']
types: [completed]
permissions: {}
jobs:
deploy-preview:
if: github.repository_owner == 'withastro'
permissions:
pull-requests: write
uses: withastro/automation/.github/workflows/cloudflare-deploy-preview.yml@<commit-sha> # vX.Y.Z
with:
worker-name: my-worker
secrets:
CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}GitHub doesn't give fork pull requests access to secrets, so the two workflows split the work:
Deployruns on the PR without the token. It only builds and uploads the result as an artifact — it never deploys.Deploy Previewthen runs onworkflow_run, using the workflow file from your default branch with the token. It only downloads that artifact and publishes the preview — it never runs the fork's code.
So the untrusted side never sees the token, and the trusted side never runs untrusted code.
To publish a new release of the reusable workflows:
- Merge the desired changes to main.
- Review the automatically generated draft release.
- Update the release tag and title if needed.
- Publish the release.