Skip to content

Build site

Build site #31

Workflow file for this run

# This file is part of Eisenberg Family Depression Center Open Source Hub (DepressionCenter.github.io repository).
# build-site.yml - Rebuild the static site from the GitHub API and commit the result.
# Author(s): Gabriel Mongefranco.
# Created: 2026-09-01
# Last Modified: 2026-09-02
# Summary: Runs scripts/build_site.py once a night and after template or style changes, then
# commits the generated pages so GitHub Pages serves finished HTML.
# Notes: See README file for documentation and full license information.
# Website: https://code.depressioncenter.org/
#
# This workflow uses no GitHub Actions at all. Every step is a plain shell command: git clones
# the repository, and the runner's preinstalled Python 3 runs the build. The University of
# Michigan enterprise restricts which actions may run, currently allowing those published by
# GitHub and those owned by the organization, but not the wider marketplace. Depending on no
# action keeps this workflow running whatever that policy is set to. Before adding a "uses:"
# line, confirm the action is GitHub-published or organization-owned.
#
# Copyright (c) 2026 The Regents of the University of Michigan
# Licensed under the GNU General Public License v3.0 or later.
# See <https://www.gnu.org/licenses/>.
name: Build site
on:
# 07:30 UTC is 03:30 in Michigan during daylight saving time and 02:30 otherwise.
schedule:
- cron: '30 7 * * *'
# Rebuild when the source of the site changes, but never in response to the workflow's own
# commit. Pushes made with GITHUB_TOKEN do not start workflows, and these paths hold only
# generated files, so a rebuild cannot trigger another rebuild.
push:
branches: [main]
paths-ignore:
- 'index.html'
- 'repos/**'
- 'data/readme/**'
- 'data/repos.json'
- 'data/build-cache.json'
- 'images/repo-previews/remote/**'
- 'sitemap.xml'
- 'llms.txt'
- 'llms.html'
- 'docs/**'
- '*.md'
workflow_dispatch:
permissions:
contents: write
concurrency:
group: build-site
cancel-in-progress: false
jobs:
build:
# Forks have no reason to publish to this repository and cannot push to it.
if: github.repository == 'DepressionCenter/DepressionCenter.github.io'
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- name: Check out the repository
# The repository is public, so cloning needs no credentials. Only the push at the end
# is authenticated.
run: |
set -euo pipefail
git clone --depth 1 --branch "$GITHUB_REF_NAME" \
"https://github.com/${GITHUB_REPOSITORY}.git" .
git log -1 --format='Starting from %h %s'
- name: Install dependencies
# Ubuntu runners ship Python 3 and pip. A virtual environment keeps the install clear
# of the system packages that Ubuntu marks as externally managed.
run: |
set -euo pipefail
python3 --version
python3 -m venv .venv
.venv/bin/python -m pip install --quiet --disable-pip-version-check --upgrade pip
.venv/bin/python -m pip install --quiet --disable-pip-version-check -r requirements.txt
- name: Check the build's own tests
run: .venv/bin/python scripts/test_build_site.py
- name: Build the site
# The token is issued automatically for this run. It only raises the API rate limit
# from 60 to 1000 requests an hour; no secret needs to be created or stored.
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: .venv/bin/python scripts/build_site.py
- name: Commit the generated files
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
set -euo pipefail
if [ -z "$(git status --porcelain)" ]; then
echo "No content changed; nothing to publish."
exit 0
fi
git status --short
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
# The helper reads the token from the environment at push time, so it is never
# written into .git/config and never appears in a command line.
git config credential.helper \
'!f() { echo username=x-access-token; echo "password=$GITHUB_TOKEN"; }; f'
git add -A
git commit -m "Rebuild site from the GitHub API"
git push origin "HEAD:${GITHUB_REF_NAME}"