Skip to content

ci: release weekly from git history with git-cliff instead of release-please - #93

Merged
panz3r merged 5 commits into
mainfrom
ci/weekly-release
Sep 29, 2026
Merged

panz3r merged 5 commits into
mainfrom
ci/weekly-release

Conversation

@panz3r

@panz3r panz3r commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

Replaces release-please with a weekly release job that works from the git log. This removes release PRs entirely: they were pushed with GITHUB_TOKEN, so the required CI checks never ran on them and they could not be merged without an admin bypass.

How it works (release.yml, Tuesdays 17:00 UTC + manual)

  1. git-cliff (orhun/git-cliff-action v4.9.1, pinned) computes the next version and release notes from conventional commits since the last v* tag.
  2. If nothing is releasable (no notes, or the tag already exists) the job stops.
  3. Otherwise: pnpm/setup installs pnpm and Node.js in one step, then build, pnpm version --no-git-tag-version, pnpm publish (npm trusted publishing via OIDC), and gh release create vX.Y.Z with the generated notes. Nothing is committed back to main.
  4. A published version is skipped on rerun, so a failed run can be retried safely.
  5. Manual runs accept dry-run: true: compute the version and notes (shown in the job summary), build, and run pnpm publish --dry-run.

Why pnpm publish instead of npm publish: the Node.js runtime installed by pnpm/setup only links node, so npm resolves to the runner image npm 10.9.8, which cannot do trusted publishing (needs 11.5.1+). pnpm 12 publishes natively with OIDC and automatic provenance (same setup pnpm uses for its own releases).

Release rules (cliff.toml)

  • feat → minor, ! / BREAKING CHANGE → major, everything else → patch.
  • feat, fix, perf, refactor, docs and chore are included in the release notes; ci, build, test, style are skipped.
  • Changes that only touch .github/, .devcontainer/, website/ or cliff.toml do not count, so GitHub Actions bumps do not cut npm releases.

Other changes

  • Remove release-please-config.json and .release-please-manifest.json.
  • CHANGELOG.md is frozen with a pointer to GitHub Releases; the README links there too.
  • package.json version in the repo is no longer bumped; the published package gets the right version at publish time.

Verification

Dry run on this branch: run 36631399518 computed v1.0.1 (57 chore commits since v1.0.0 touching shipped files), built the package, obtained the npm OIDC token, and stopped at Skip publishing @forward-software/qrcodets@1.0.1 (dry run). The first real run after merge will release 1.0.1.

@panz3r
panz3r merged commit 762f50a into main Sep 29, 2026
6 checks passed
@panz3r
panz3r deleted the ci/weekly-release branch September 29, 2026 21:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant