Skip to content

Update NVIDIA driver versions #23

Update NVIDIA driver versions

Update NVIDIA driver versions #23

name: Update NVIDIA driver versions
on:
# NVIDIA Unix driver releases are infrequent so a weekly check is plenty.
schedule:
- cron: "0 14 * * 1"
workflow_dispatch:
permissions:
contents: write
pull-requests: write
jobs:
refresh:
name: Open PR if NVIDIA versions changed
runs-on:
group: Self Hosted
labels: edera-16
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
- name: checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v4
- name: scrape upstream and rewrite config.yaml
run: python3 ./hack/build/refresh-nvidia-versions.py
- name: generate cultivator token
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
id: generate-token
with:
app-id: "${{ secrets.EDERA_CULTIVATION_APP_ID }}"
private-key: "${{ secrets.EDERA_CULTIVATION_APP_PRIVATE_KEY }}"
# Scope the minted token to only what create-pull-request needs:
# push the branch (contents) and open/update the PR (pull-requests).
permission-contents: write
permission-pull-requests: write
# Uses the GitHub API path under the hood so commits are auto-signed
# with the web-flow key (the repo enforces "Verified signatures", which
# blocks plain `git push` from GITHUB_TOKEN). The action is idempotent:
# repeated runs on the same branch update the existing PR.
- name: open PR if config.yaml changed
uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8.1.1
with:
token: ${{ steps.generate-token.outputs.token }}
sign-commits: true
branch: auto/refresh-nvidia
base: main
add-paths: config.yaml
commit-message: "chore: bump NVIDIA driver versions from upstream"
title: "chore: bump NVIDIA driver versions"
body: |
Automated refresh from https://www.nvidia.com/en-us/drivers/unix/.
Review the diff in `config.yaml` and confirm the bumped image tags
build cleanly before merging.
delete-branch: true