mirror of
https://github.com/jackwener/OpenCLI.git
synced 2026-09-14 18:25:42 +08:00
515ce75f3b
* chore(ci): add Dependabot for npm and GitHub Actions updates - Weekly npm dependency updates with PR limit of 10 - Weekly GitHub Actions version updates with PR limit of 5 - Conventional commit prefixes (chore(deps), chore(ci)) * ci: add security audit workflow - Run npm audit on push/PR and weekly schedule - Fail on high-severity vulnerabilities using audit-ci - Only audit production dependencies * ci: add release-please for automated changelog and versioning - Auto-generate CHANGELOG.md from Conventional Commits - Create version bump PRs on push to main - Works alongside existing release.yml for npm publish * ci: add concurrency controls and Node.js version matrix - Add concurrency groups to ci, e2e-headed, security workflows to cancel duplicate runs on the same branch - Test unit tests across Node 18/20/22 with fail-fast: false - Update test step name to show Node version * chore: bump minimum Node.js version from 18 to 20 - Update engines.node in package.json to >=20.0.0 - Update prerequisites in README.md and README.zh-CN.md - Remove Node 18 from CI test matrix * review: fix release token and prod-only audit scope * docs: align Node 20 troubleshooting guidance --------- Co-authored-by: jackwener <jakevingoo@gmail.com>
26 lines
602 B
YAML
26 lines
602 B
YAML
name: Release Please
|
|
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
|
|
permissions:
|
|
contents: write
|
|
pull-requests: write
|
|
|
|
jobs:
|
|
release-please:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Ensure release-please token is configured
|
|
run: |
|
|
if [ -z "${{ secrets.RELEASE_PLEASE_TOKEN }}" ]; then
|
|
echo "RELEASE_PLEASE_TOKEN secret is required so release PRs can trigger downstream CI workflows." >&2
|
|
exit 1
|
|
fi
|
|
|
|
- uses: googleapis/release-please-action@v4
|
|
with:
|
|
release-type: node
|
|
token: ${{ secrets.RELEASE_PLEASE_TOKEN }}
|