ci: release weekly from git history with git-cliff instead of release-please - #93
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Replaces release-please with a weekly release job that works from the git log. This removes release PRs entirely: they were pushed with
GITHUB_TOKEN, so the required CI checks never ran on them and they could not be merged without an admin bypass.How it works (
release.yml, Tuesdays 17:00 UTC + manual)orhun/git-cliff-actionv4.9.1, pinned) computes the next version and release notes from conventional commits since the lastv*tag.pnpm/setupinstalls pnpm and Node.js in one step, then build,pnpm version --no-git-tag-version,pnpm publish(npm trusted publishing via OIDC), andgh release create vX.Y.Zwith the generated notes. Nothing is committed back tomain.dry-run: true: compute the version and notes (shown in the job summary), build, and runpnpm publish --dry-run.Why
pnpm publishinstead ofnpm publish: the Node.js runtime installed bypnpm/setuponly linksnode, sonpmresolves to the runner image npm 10.9.8, which cannot do trusted publishing (needs 11.5.1+). pnpm 12 publishes natively with OIDC and automatic provenance (same setup pnpm uses for its own releases).Release rules (
cliff.toml)feat→ minor,!/BREAKING CHANGE→ major, everything else → patch.feat,fix,perf,refactor,docsandchoreare included in the release notes;ci,build,test,styleare skipped..github/,.devcontainer/,website/orcliff.tomldo not count, so GitHub Actions bumps do not cut npm releases.Other changes
release-please-config.jsonand.release-please-manifest.json.CHANGELOG.mdis frozen with a pointer to GitHub Releases; the README links there too.package.jsonversionin the repo is no longer bumped; the published package gets the right version at publish time.Verification
Dry run on this branch: run 36631399518 computed
v1.0.1(57chorecommits sincev1.0.0touching shipped files), built the package, obtained the npm OIDC token, and stopped atSkip publishing @forward-software/qrcodets@1.0.1 (dry run). The first real run after merge will release 1.0.1.