Composite and Node GitHub Actions, reusable workflows and shared Renovate presets, each released under its own tag.
One repository holding the CI parts the other repositories in this account call: the actions under
actions/, the callable workflows under workflows/, and the Renovate presets and branch rulesets
under configs/.
Each directory is its own release-please component, so actions/rust/clippy and
actions/bun/setup-cached are versioned and tagged apart from each other. A tag names the component
it belongs to, as actions-<path>-vX.Y.Z or workflows-<path>-vX.Y.Z. The tables below carry the
current tag of every component and the uses: line that pins it.
Copy a uses: line from the tables below. It pins the released tag to the commit that tag points
at, and repeats the tag in a trailing comment.
Then extend the shared Renovate preset in your renovate.json:
{
"extends": ["github>TimSchoenle/actions//configs/renovate/base"]
}The preset installs a regex manager that matches exactly that shape. It also turns Renovate's
built-in github-actions manager off for this repository, so a pin written without its # tag=
comment matches nothing and never moves. The versioning regex carries the component prefix through
as its compatibility group. That is what stops a release of actions-rust-clippy being offered as
an upgrade to actions-bun-setup-cached.
The first column links to the action's directory. Its action.yaml declares the inputs and the
outputs. Where an action needs more than that, a README sits next to it.
| Action | Description | Version | Usage |
|---|---|---|---|
| Bun Setup-cached | Sets up Bun and manages dependency caching. | actions-bun-setup-cached-v1.1.11 | uses: TimSchoenle/actions/actions/bun/setup-cached@e16a1e466faf8ec751b26289c1898143a253269f # tag=actions-bun-setup-cached-v1.1.11 |
| Action | Description | Version | Usage |
|---|---|---|---|
| Close Pull Request | Closes a pull request | actions-common-close-pull-request-v1.5.3 | uses: TimSchoenle/actions/actions/common/close-pull-request@7e8fd61045447d321c5139eea8f2e2b766333f8b # tag=actions-common-close-pull-request-v1.5.3 |
| Commit Changes | Commits changes using the GitHub API to ensure verified bot commits. | actions-common-commit-changes-v1.5.3 | uses: TimSchoenle/actions/actions/common/commit-changes@7e8fd61045447d321c5139eea8f2e2b766333f8b # tag=actions-common-commit-changes-v1.5.3 |
| Common Modify YAML | A action to modify a value in a YAML file while strictly preserving comments and structure | actions-common-modify-yaml-v1.5.3 | uses: TimSchoenle/actions/actions/common/modify-yaml@7e8fd61045447d321c5139eea8f2e2b766333f8b # tag=actions-common-modify-yaml-v1.5.3 |
| Common Read YAML | A action to read a value from a YAML file using dot notation | actions-common-read-yaml-v1.3.3 | uses: TimSchoenle/actions/actions/common/read-yaml@7e8fd61045447d321c5139eea8f2e2b766333f8b # tag=actions-common-read-yaml-v1.3.3 |
| Common Readme Variables | Collect the standard README render payload — repository facts, release, toolchain and a docs index — as strict JSON for render-template | actions-common-readme-variables-v1.2.3 | uses: TimSchoenle/actions/actions/common/readme-variables@7e8fd61045447d321c5139eea8f2e2b766333f8b # tag=actions-common-readme-variables-v1.2.3 |
| Create Branch | Creates or resets a git branch using GitHub API. | actions-common-create-branch-v1.6.3 | uses: TimSchoenle/actions/actions/common/create-branch@7e8fd61045447d321c5139eea8f2e2b766333f8b # tag=actions-common-create-branch-v1.6.3 |
| Create Pull Request | Creates or updates a pull request using GitHub App authentication with optional branch reset. | actions-common-create-pull-request-v1.0.19 | uses: TimSchoenle/actions/actions/common/create-pull-request@f4fea19c7d53dee672f082bd62406b3e1e29ee3a # tag=actions-common-create-pull-request-v1.0.19 |
| Delete-Branch | Deletes a branch from a repository. Fails gracefully if the branch does not exist. | actions-common-delete-branch-v1.5.3 | uses: TimSchoenle/actions/actions/common/delete-branch@7e8fd61045447d321c5139eea8f2e2b766333f8b # tag=actions-common-delete-branch-v1.5.3 |
| Get App Git Identity | Resolves the git identity (username, email, user ID) for a GitHub App bot. | actions-common-get-app-git-identity-v1.5.3 | uses: TimSchoenle/actions/actions/common/get-app-git-identity@7e8fd61045447d321c5139eea8f2e2b766333f8b # tag=actions-common-get-app-git-identity-v1.5.3 |
| Render Template | A action to render a Handlebars template file to an output file from a JSON map of variables, deterministically | actions-common-render-template-v1.2.3 | uses: TimSchoenle/actions/actions/common/render-template@7e8fd61045447d321c5139eea8f2e2b766333f8b # tag=actions-common-render-template-v1.2.3 |
| Render Template And Commit | Renders a Handlebars template to a file and commits the result as a verified bot commit, skipping the commit when the render changed nothing. | actions-common-render-template-and-commit-v1.1.10 | uses: TimSchoenle/actions/actions/common/render-template-and-commit@f4fea19c7d53dee672f082bd62406b3e1e29ee3a # tag=actions-common-render-template-and-commit-v1.1.10 |
| Setup App Git Identity | Configures git with the identity of a GitHub App bot and outputs the bot details. | actions-common-setup-app-git-identity-v1.5.3 | uses: TimSchoenle/actions/actions/common/setup-app-git-identity@7e8fd61045447d321c5139eea8f2e2b766333f8b # tag=actions-common-setup-app-git-identity-v1.5.3 |
| Upsert Issue | Opens or updates a repository issue, updating the previous issue carrying the same identifier. | actions-common-upsert-issue-v1.1.2 | uses: TimSchoenle/actions/actions/common/upsert-issue@7e8fd61045447d321c5139eea8f2e2b766333f8b # tag=actions-common-upsert-issue-v1.1.2 |
| Upsert PR Comment | Posts a comment on a pull request, updating the previous comment carrying the same identifier. | actions-common-upsert-pr-comment-v1.1.3 | uses: TimSchoenle/actions/actions/common/upsert-pr-comment@7e8fd61045447d321c5139eea8f2e2b766333f8b # tag=actions-common-upsert-pr-comment-v1.1.3 |
| Action | Description | Version | Usage |
|---|---|---|---|
| Apply Helm Chart Updates | Applies a set of templated image updates to a Helm chart's values.yaml and bumps Chart.yaml, preserving comments and structure. Every image carries its own version and digest. | actions-helm-apply-chart-updates-v1.3.3 | uses: TimSchoenle/actions/actions/helm/apply-chart-updates@7e8fd61045447d321c5139eea8f2e2b766333f8b # tag=actions-helm-apply-chart-updates-v1.3.3 |
| Update Helm Chart Version | Updates a Helm chart's image tags, version and appVersion, then opens a Pull Request. Every image carries its own version and digest, so one call can move a chart with many services. This action requires a bot account with access to the charts repo. | actions-helm-update-chart-version-v1.6.13 | uses: TimSchoenle/actions/actions/helm/update-chart-version@7e8fd61045447d321c5139eea8f2e2b766333f8b # tag=actions-helm-update-chart-version-v1.6.13 |
| Action | Description | Version | Usage |
|---|---|---|---|
| Helper Verify-branch-name | Verify the head branch of a pull request matches a pattern and check whether it comes from a fork | actions-helper-verify-branch-name-v1.4.3 | uses: TimSchoenle/actions/actions/helper/verify-branch-name@7e8fd61045447d321c5139eea8f2e2b766333f8b # tag=actions-helper-verify-branch-name-v1.4.3 |
| Resolve Branch | Resolve the given base branch or return default branch. With optional existence check. | actions-helper-resolve-base-branch-v1.5.3 | uses: TimSchoenle/actions/actions/helper/resolve-base-branch@7e8fd61045447d321c5139eea8f2e2b766333f8b # tag=actions-helper-resolve-base-branch-v1.5.3 |
| Verify Commit Authors | Verifies that all commits in a PR are authored by a specific set of users and are signed. | actions-helper-verify-commit-authors-v1.5.3 | uses: TimSchoenle/actions/actions/helper/verify-commit-authors@7e8fd61045447d321c5139eea8f2e2b766333f8b # tag=actions-helper-verify-commit-authors-v1.5.3 |
| Action | Description | Version | Usage |
|---|---|---|---|
| Java-gradle Auto-spotless | Automatically apply spotless formatting and commit changes. | actions-java-gradle-auto-spotless-v1.1.25 | uses: TimSchoenle/actions/actions/java-gradle/auto-spotless@f4fea19c7d53dee672f082bd62406b3e1e29ee3a # tag=actions-java-gradle-auto-spotless-v1.1.25 |
| Java-Gradle default setup | Setup Java and Gradle environment for building, with opinionated default settings | actions-java-gradle-setup-base-environment-v1.2.13 | uses: TimSchoenle/actions/actions/java-gradle/setup-base-environment@7e8fd61045447d321c5139eea8f2e2b766333f8b # tag=actions-java-gradle-setup-base-environment-v1.2.13 |
| Action | Description | Version | Usage |
|---|---|---|---|
| Maintenance Auto-approve-pr | Auto approve Pull Requests with the given user ids and branches. | actions-maintenance-auto-approve-pr-v1.5.3 | uses: TimSchoenle/actions/actions/maintenance/auto-approve-pr@7e8fd61045447d321c5139eea8f2e2b766333f8b # tag=actions-maintenance-auto-approve-pr-v1.5.3 |
| Maintenance Ensure-actions-are-executed | Ensures selected checks completed successfully when they were started. | actions-maintenance-ensure-actions-are-executed-v1.5.3 | uses: TimSchoenle/actions/actions/maintenance/ensure-actions-are-executed@7e8fd61045447d321c5139eea8f2e2b766333f8b # tag=actions-maintenance-ensure-actions-are-executed-v1.5.3 |
| Action | Description | Version | Usage |
|---|---|---|---|
| Rust Auto-format | Action that runs cargo fmt and commits changes. | actions-rust-auto-format-v1.1.18 | uses: TimSchoenle/actions/actions/rust/auto-format@f4fea19c7d53dee672f082bd62406b3e1e29ee3a # tag=actions-rust-auto-format-v1.1.18 |
| Rust Cargo-check | Action that runs cargo check to verify Rust code compiles without errors. | actions-rust-cargo-check-v1.1.7 | uses: TimSchoenle/actions/actions/rust/cargo-check@88e964d440835fd99f7e9d17b4ba1b48544303ba # tag=actions-rust-cargo-check-v1.1.7 |
| Rust Clippy | Action that runs clippy to catch common mistakes and improve your Rust code. | actions-rust-clippy-v1.1.12 | uses: TimSchoenle/actions/actions/rust/clippy@7e8fd61045447d321c5139eea8f2e2b766333f8b # tag=actions-rust-clippy-v1.1.12 |
| Rust Config Contract | Action that checks a terrace-config contract, its Dockerfile LABEL block and a built image against the configuration types they claim to describe. | actions-rust-config-contract-v1.3.3 | uses: TimSchoenle/actions/actions/rust/config-contract@7e8fd61045447d321c5139eea8f2e2b766333f8b # tag=actions-rust-config-contract-v1.3.3 |
| Rust Coverage (Codecov) | Action that runs cargo llvm-cov to generate code coverage and uploads to Codecov. | actions-rust-coverage-codecov-v1.1.49 | uses: TimSchoenle/actions/actions/rust/coverage-codecov@7e8fd61045447d321c5139eea8f2e2b766333f8b # tag=actions-rust-coverage-codecov-v1.1.49 |
| Rust Test | Action that runs cargo nextest to verify Rust code passes tests. | actions-rust-test-v1.1.2 | uses: TimSchoenle/actions/actions/rust/test@e16a1e466faf8ec751b26289c1898143a253269f # tag=actions-rust-test-v1.1.2 |
| Action | Description | Version | Usage |
|---|---|---|---|
| Setup E2E Test | Sets up the environment for E2E testing: generates token, checks out test repo, and checks out actions code. | actions-test-setup-e2e-v1.2.3 | uses: TimSchoenle/actions/actions/test/setup-e2e@51bbb07f9ccf8d9f5a8de245e2d6f2812638e989 # tag=actions-test-setup-e2e-v1.2.3 |
Releasing one of these publishes it onto its tag at .github/workflows/<category>-<name>.yaml,
which is the path the uses: line resolves. Read and change the source under workflows/.
| Workflow | Description | Version | Usage |
|---|---|---|---|
| Auto Format | Reusable workflow to auto-format code by running a "bun run" script and commit changes. | workflows-maintenance-auto-bun-prettier-v1.1.35 | uses: TimSchoenle/actions/.github/workflows/maintenance-auto-bun-prettier.yaml@e43762bcca42c815ca8256c68f4fa8820786dffc # tag=workflows-maintenance-auto-bun-prettier-v1.1.35 |
| Auto-Approve & Merge Timed PRs | Reusable workflow that automatically verifies, approves, and merges Pull Requests that match a specific branch pattern and have been open for a configurable duration. It ensures all commits are signed and authored by trusted users. | workflows-maintenance-timed-auto-pr-approve-v1.2.37 | uses: TimSchoenle/actions/.github/workflows/maintenance-timed-auto-pr-approve.yaml@eeabdbd574bf75fbfb4a5eada1bb4fd690ca996a # tag=workflows-maintenance-timed-auto-pr-approve-v1.2.37 |
| Maintenance Auto-approve-renovate | Reusable workflow to auto approve Renovate PRs, this is useful to auto merge Renovate PRs which have auto-merge enabled. | workflows-maintenance-auto-approve-renovate-v1.4.25 | uses: TimSchoenle/actions/.github/workflows/maintenance-auto-approve-renovate.yaml@45c906a16a1cc301ce8f918cf0447555c5a7d6c9 # tag=workflows-maintenance-auto-approve-renovate-v1.4.25 |
| Maintenance Auto-rebase | Automatically rebases open PRs with a given label. | workflows-maintenance-auto-rebase-v1.1.7 | uses: TimSchoenle/actions/.github/workflows/maintenance-auto-rebase.yaml@112057eff67d583e17eda2b173bc5d67eb83fb4f # tag=workflows-maintenance-auto-rebase-v1.1.7 |
| Maintenance Wipe-cache | Workflow to wipe all cache entries for the given branch. | workflows-maintenance-wipe-cache-v1.1.13 | uses: TimSchoenle/actions/.github/workflows/maintenance-wipe-cache.yaml@103a601a6e8778074ac41d9dd03870d1989463b6 # tag=workflows-maintenance-wipe-cache-v1.1.13 |
The Renovate presets are consumed through extends. The ruleset files are GitHub's own export
format: download one and import it under the repository's Settings, then Rules.
Each Checkstyle ruleset lives in its own directory under configs/checkstyle/, alongside a
configs/checkstyle/_shared/ directory holding Lombok-annotation suppressions common to every
ruleset. Checkstyle's ${config_loc} is a convention property your build tool sets to a local
directory (Gradle's checkstyle.configDirectory, Maven's propertyExpansion) — it is never
derived from a remote configLocation URL — so a ruleset only resolves its suppression files, its
../_shared/ sibling included, once you vendor both directories into your project and point your
build tool's config directory at your copy of the ruleset directory.
| Config | Description |
|---|---|
| Default Branch: Default Protection Rules | Enforces standard protection rules on the default branch: requires PRs with 1 approval (squash only), signed commits, CodeQL scanning, and passing status checks. |
| Release Please Branches: Trusted Bots Only | Restricts access to release-please branches, allowing only trusted bots to create, update, or delete them, while enforcing code quality and signature requirements. |
| Release Tags: Only Allow Automatic Release Manager Bot | Enforces that only the Automatic Release Manager bot can create, update, or delete release tags. |
| Renovate Branches: Trusted Bots & Admins Only | Restricts access to Renovate branches, allowing only trusted bots (Renovate, Automatic Release Manager) and admins to manage them, while enforcing code quality and signature requirements. |
| Config | Description | Usage |
|---|---|---|
| actions | Versioning rules for all custom Github Actions defined in this repository | "extends": ["github>TimSchoenle/actions//configs/renovate/actions"] |
| base | Base configuration to handle custom versioning for all resources in this repository. | "extends": ["github>TimSchoenle/actions//configs/renovate/base"] |
| ci-automerge | Auto-merge rules for all none major Github Actions including custom actions defined in this repository. | "extends": ["github>TimSchoenle/actions//configs/renovate/ci-automerge"] |
| default | Default configuration for Renovate | "extends": ["github>TimSchoenle/actions//configs/renovate/default"] |
| workflows | Versioning rules for all custom Reusable Workflows defined in this repository | "extends": ["github>TimSchoenle/actions//configs/renovate/workflows"] |
| Config | Description | Version |
|---|---|---|
| Application | Latest Palantir Baseline Checkstyle plus strict final locals/parameters, explicit this qualification, and Lombok-annotation-aware suppressions, for application and service code. Unlike the Library ruleset, it omits DesignForExtension and JavadocMethod since this code has no public API surface to document or keep extension-safe. |
configs-checkstyle-application-v1.0.2 |
| Library | Latest Palantir Baseline Checkstyle plus strict final locals/parameters, explicit this qualification, and Lombok-annotation-aware suppressions. Enforces DesignForExtension and a strengthened JavadocMethod so every public and protected member of the library's API is documented and safe to extend. |
configs-checkstyle-library-v1.0.2 |
Vendor configs/checkstyle/application/ and configs/checkstyle/_shared/ into your project, then point your build tool's config directory (Gradle configDirectory, Maven config_loc) at your copy of configs/checkstyle/application/. Or depend on it directly via JitPack, no vendoring or config directory required:
Gradle (Kotlin DSL)
val checkstyleConfig: Configuration by configurations.creating
repositories {
maven { url = uri("https://jitpack.io") }
}
checkstyle {
toolVersion = "<your checkstyle version>"
config = resources.text.fromArchiveEntry(checkstyleConfig, "checkstyle.xml")
}
dependencies {
checkstyleConfig("de.timscho.actions:checkstyle-application:configs-checkstyle-application-v1.0.2")
checkstyle("de.timscho.actions:checkstyle-application:configs-checkstyle-application-v1.0.2")
checkstyle("com.puppycrawl.tools:checkstyle:${checkstyle.toolVersion}")
}Maven
<repositories>
<repository>
<id>jitpack.io</id>
<url>https://jitpack.io</url>
</repository>
</repositories>
<build>
<plugins>
<plugin>
<groupId>org.apache.maven.plugins</groupId>
<artifactId>maven-checkstyle-plugin</artifactId>
<configuration>
<configLocation>checkstyle.xml</configLocation>
</configuration>
<dependencies>
<dependency>
<groupId>de.timscho.actions</groupId>
<artifactId>checkstyle-application</artifactId>
<version>configs-checkstyle-application-v1.0.2</version>
</dependency>
</dependencies>
</plugin>
</plugins>
</build>Vendor configs/checkstyle/library/ and configs/checkstyle/_shared/ into your project, then point your build tool's config directory (Gradle configDirectory, Maven config_loc) at your copy of configs/checkstyle/library/. Or depend on it directly via JitPack, no vendoring or config directory required:
Gradle (Kotlin DSL)
val checkstyleConfig: Configuration by configurations.creating
repositories {
maven { url = uri("https://jitpack.io") }
}
checkstyle {
toolVersion = "<your checkstyle version>"
config = resources.text.fromArchiveEntry(checkstyleConfig, "checkstyle.xml")
}
dependencies {
checkstyleConfig("de.timscho.actions:checkstyle-library:configs-checkstyle-library-v1.0.2")
checkstyle("de.timscho.actions:checkstyle-library:configs-checkstyle-library-v1.0.2")
checkstyle("com.puppycrawl.tools:checkstyle:${checkstyle.toolVersion}")
}Maven
<repositories>
<repository>
<id>jitpack.io</id>
<url>https://jitpack.io</url>
</repository>
</repositories>
<build>
<plugins>
<plugin>
<groupId>org.apache.maven.plugins</groupId>
<artifactId>maven-checkstyle-plugin</artifactId>
<configuration>
<configLocation>checkstyle.xml</configLocation>
</configuration>
<dependencies>
<dependency>
<groupId>de.timscho.actions</groupId>
<artifactId>checkstyle-library</artifactId>
<version>configs-checkstyle-library-v1.0.2</version>
</dependency>
</dependencies>
</plugin>
</plugins>
</build>docs/ holds the two writing standards every repository in this account is held to. Other
repositories link them from their own CONTRIBUTING.md instead of keeping a copy.
| Document | Purpose |
|---|---|
| docs/readme/README.md | What a README contains and in what order, how its prose is written, the template it starts from and the CI job that keeps it rendered. |
| docs/doc-comments/README.md | What carries a doc comment and what it says, with an annex each for Rust, Java and TypeScript. |
Issues and pull requests are welcome. CONTRIBUTING.md covers the commit convention release-please reads, the interactive generators that scaffold a new action or workflow, and the checks CI runs. This file and SECURITY.md are generated. An edit to either is reverted on the next pull request.
Do not open a public issue for a vulnerability. SECURITY.md has the private reporting route and the list of supported versions.
Every action, workflow and config here is published under the terms in LICENSE.