mirror of
https://github.com/vercel/workflow.git
synced 2026-09-14 19:59:43 +08:00
3621f8d058
* ci: upgrade pnpm/action-setup to v5 and read version from package.json (#1785) * ci: upgrade pnpm/action-setup to v6 and read version from package.json Removes hardcoded pnpm version (10.14.0) from all workflows and instead reads the version from the packageManager field in package.json, so CI stays in sync with the version used locally. * ci: update setup-workflow-dev composite action to use pnpm/action-setup@v6 Also removes the pnpm-version input since the action now reads the version from package.json#packageManager. * ci: downgrade pnpm/action-setup to v5 v6 installs pnpm 11 RC/beta, which has a regression (pnpm/pnpm#11264, pnpm/action-setup#225/#227/#228) that causes 'ERR_PNPM_BROKEN_LOCKFILE: expected a single document in the stream' when the project's packageManager pins a 10.x pnpm version. v5 is the latest stable release before v6 and supports reading the version from package.json#packageManager. * ci: stop using Release App token in release workflows (#1866) The Release App has been temporarily removed. Switch the Release and Backport workflows to use the default GITHUB_TOKEN, and disable the cross-repo Front dispatch workflow until the App is restored. Also add a workflow_dispatch trigger to release.yml so the Version Packages PR can be created/updated manually (since pushes made by GITHUB_TOKEN do not trigger downstream workflow runs). * ci: use GitHub API commit mode for changesets action (#1867) The repo enforces "Commits must have verified signatures" via an org/enterprise-level ruleset, which blocks unsigned commits pushed via the Git CLI by GITHUB_TOKEN. Switching the changesets action to commitMode: github-api makes commits GPG-signed by GitHub. * Add changeset for backport * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Signed-off-by: Nathan Rajlich <n@n8.io> --------- Signed-off-by: Nathan Rajlich <n@n8.io> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
120 lines
3.9 KiB
YAML
120 lines
3.9 KiB
YAML
name: Release
|
|
|
|
on:
|
|
push:
|
|
branches:
|
|
- main
|
|
- stable
|
|
# Allow manual triggering from the Actions tab. Useful for re-running the
|
|
# release flow when a push from the default GITHUB_TOKEN (e.g. a clean
|
|
# cherry-pick from the backport workflow, or a merged "Version Packages"
|
|
# PR) does not automatically trigger this workflow.
|
|
workflow_dispatch:
|
|
|
|
concurrency: ${{ github.workflow }}-${{ github.ref }}
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
release:
|
|
name: Release
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: write
|
|
pull-requests: write
|
|
id-token: write
|
|
env:
|
|
TURBO_TOKEN: ${{ secrets.TURBO_TOKEN }}
|
|
TURBO_TEAM: ${{ vars.TURBO_TEAM }}
|
|
steps:
|
|
- name: Checkout Repo
|
|
uses: actions/checkout@v4
|
|
with:
|
|
fetch-depth: 0
|
|
|
|
- name: Configure Git identity
|
|
run: |
|
|
git config user.name "github-actions[bot]"
|
|
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
|
|
|
|
- name: Setup pnpm
|
|
uses: pnpm/action-setup@v5
|
|
|
|
- name: Setup Node.js 24.x
|
|
uses: actions/setup-node@v4
|
|
with:
|
|
node-version: 24.x
|
|
cache: "pnpm"
|
|
registry-url: 'https://registry.npmjs.org'
|
|
|
|
- name: Install Dependencies
|
|
run: pnpm install --frozen-lockfile
|
|
|
|
- name: Create Release Pull Request or Publish to npm
|
|
id: changesets
|
|
uses: changesets/action@v1
|
|
with:
|
|
version: pnpm ci:version
|
|
publish: pnpm ci:publish
|
|
createGithubReleases: false
|
|
setupGitUser: false
|
|
# Use GitHub API for GPG-signed commits (required by branch rules).
|
|
commitMode: github-api
|
|
env:
|
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
|
|
- name: Create GitHub Release
|
|
if: steps.changesets.outputs.published == 'true'
|
|
env:
|
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
PUBLISHED_PACKAGES: ${{ steps.changesets.outputs.publishedPackages }}
|
|
run: |
|
|
# Generate release notes (PUBLISHED_PACKAGES filters to only include packages from this release)
|
|
RELEASE_JSON=$(node scripts/generate-release-notes.mjs)
|
|
TAG=$(echo "$RELEASE_JSON" | jq -r '.tag')
|
|
TITLE=$(echo "$RELEASE_JSON" | jq -r '.title')
|
|
BODY=$(echo "$RELEASE_JSON" | jq -r '.body')
|
|
|
|
# Determine release flags based on branch
|
|
if [ "$GITHUB_REF_NAME" = "stable" ]; then
|
|
PRERELEASE="false"
|
|
LATEST_FLAG="--latest"
|
|
else
|
|
PRERELEASE="true"
|
|
LATEST_FLAG="--latest=false"
|
|
fi
|
|
|
|
# Check if a release with this tag already exists
|
|
if gh release view "$TAG" &>/dev/null; then
|
|
echo "Release $TAG already exists, updating..."
|
|
gh release edit "$TAG" \
|
|
--title "$TITLE" \
|
|
--notes "$BODY" \
|
|
$LATEST_FLAG \
|
|
--prerelease=$PRERELEASE
|
|
else
|
|
echo "Creating new release $TAG..."
|
|
gh release create "$TAG" \
|
|
--target "${{ github.sha }}" \
|
|
--title "$TITLE" \
|
|
--notes "$BODY" \
|
|
$LATEST_FLAG \
|
|
--prerelease=$PRERELEASE
|
|
fi
|
|
|
|
- name: Post release notes to Slack
|
|
if: steps.changesets.outputs.published == 'true'
|
|
env:
|
|
SLACK_BOT_TOKEN: ${{ secrets.SLACK_BOT_TOKEN }}
|
|
SLACK_RELEASE_CHANNEL_ID: ${{ secrets.SLACK_RELEASE_CHANNEL_ID }}
|
|
PUBLISHED_PACKAGES: ${{ steps.changesets.outputs.publishedPackages }}
|
|
run: |
|
|
if [ -z "$SLACK_BOT_TOKEN" ] || [ -z "$SLACK_RELEASE_CHANNEL_ID" ]; then
|
|
echo "Missing Slack secrets: SLACK_BOT_TOKEN and/or SLACK_RELEASE_CHANNEL_ID"
|
|
exit 1
|
|
fi
|
|
|
|
# Post to Slack via chat.postMessage (payload is chunked to Slack limits)
|
|
node scripts/generate-release-slack-payload.mjs --post
|