CodeCharta + DependaCharta snapshot
Source: workflows/universal-codecharta.yml
Runner: ubuntu-latest
Usage
jobs:
codecharta--dependacharta-snapshot:
uses: futuredapp/.github/.github/workflows/universal-codecharta.yml@2.7.0
with:
data_repo: '...'
picker_base_url: '...'
secrets:
CODEBASE_ARCHITECTURES_TOKEN: ${{ secrets.CODEBASE_ARCHITECTURES_TOKEN }}
Inputs
| Name | Type | Required | Default | Description |
|---|---|---|---|---|
stack |
string |
No | multi |
Stack profile (swift |
project_name |
string |
No | — | Override for the data-repo folder name. Defaults to the consumer's repository name (github.event.repository.name), so a workflow running in a repo named my-app publishes to projects/my-app/. |
data_repo |
string |
Yes | — | <owner>/<name> of the data repository that stores published snapshots and the manifest the picker reads. Provided by the consumer so this public workflow doesn't hardcode a specific (potentially private) repo name. |
picker_base_url |
string |
Yes | — | Base URL of the picker UI. Used to compose links in the PR comment (CodeCharta studio, DependaCharta visualizer, delta view). |
file_extensions |
string |
No | — | Optional override for ccsh -fe= (comma-separated extensions like kt,swift). When set, supersedes the stack profile's default. |
tokei_types |
string |
No | — | Optional override for tokei --type (comma-separated language names like Kotlin,Swift). When set, supersedes the stack profile's default. |
extra_excludes |
string |
No | — | Comma-separated patterns appended to ccsh -e= and tokei --exclude. Use for repo-specific noise (vendored dirs, generated folders, etc.). |
backfill |
boolean |
No | False |
When true (workflow_dispatch only), routes execution to the backfill job instead of the generate/cleanup pair. |
pr_limit |
string |
No | 20 |
Max number of first-parent merges to walk in backfill mode. Larger values produce more historical snapshots at proportionally higher cost. The 60-min job timeout caps this in practice around ~100. |
dependacharta_image_base |
string |
No | ghcr.io/futuredapp/dependacharta-swift |
Fully-qualified image reference without tag. Defaults to the Futured fork (covers Swift + the upstream languages). Override to maibornwolff/dependacharta-analysis (Docker Hub, public) when the Swift parser isn't needed and a public registry is preferable — e.g. consumer repos outside the futuredapp GHCR access boundary. Pair with a matching dependacharta_image_tag. |
dependacharta_image_tag |
string |
No | fork-v0.2.1 |
Tag on the DependaCharta image (paired with dependacharta_image_base). Default targets the Futured fork; if you switch the base to upstream maibornwolff/dependacharta-analysis, also set this to a matching upstream tag (e.g. 0.25.0). Pin per release of this workflow; floating tags (e.g. latest) break reproducibility. |
Secrets
| Name | Required | Description |
|---|---|---|
CODEBASE_ARCHITECTURES_TOKEN |
Yes | Fine-grained PAT or GitHub App token with Contents: read+write on the data repo (see data_repo input). The publish jobs use it to clone the data repo and push commits. |