-
Notifications
You must be signed in to change notification settings - Fork 56
139 lines (122 loc) · 4.59 KB
/
Copy pathrelease.yml
File metadata and controls
139 lines (122 loc) · 4.59 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
name: Release
on:
push:
branches: [main]
workflow_dispatch:
# Serialize every release run (beta, promote, stable) so a main-push beta
# release and a dispatched stable promotion can never mutate main/release
# concurrently. cancel-in-progress stays false: a running release must finish.
# Caveat: GitHub keeps only the newest *pending* run per group, so if a beta
# push lands while a stable run is still queued, the queued stable run is
# cancelled - re-run the promote dispatch in that case.
concurrency:
group: release-pipeline
cancel-in-progress: false
permissions:
id-token: write
contents: write
issues: write
pull-requests: write
actions: write
jobs:
beta:
if: github.event_name == 'push'
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: 22
- name: Sync release tags into main
run: |
git config user.name "github-actions[bot]"
git config user.email "github-actions[bot]@users.noreply.github.com"
if git rev-parse --verify origin/release >/dev/null 2>&1; then
RELEASE_AHEAD=$(git rev-list --count HEAD..origin/release)
if [ "$RELEASE_AHEAD" -gt 0 ]; then
echo "Release branch is $RELEASE_AHEAD commits ahead of main, merging..."
node scripts/release-sync.js release-to-main origin/release
git push https://x-access-token:${GITHUB_TOKEN}@github.com/${{ github.repository }}.git main
fi
fi
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- name: Install dependencies
run: npm ci
- name: Run semantic-release (beta)
run: npx semantic-release
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
NPM_TOKEN: ${{ secrets.NPM_TOKEN }}
promote:
if: github.event_name == 'workflow_dispatch' && github.ref == 'refs/heads/main'
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: 22
- name: Merge main to release
run: |
git config user.name "github-actions[bot]"
git config user.email "github-actions[bot]@users.noreply.github.com"
git show main:scripts/release-sync.js > "$RUNNER_TEMP/release-sync.js"
git checkout release
node "$RUNNER_TEMP/release-sync.js" promote main
git push https://x-access-token:${GITHUB_TOKEN}@github.com/${{ github.repository }}.git release
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- name: Trigger stable release
run: gh workflow run release.yml --ref release
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
stable:
if: github.event_name == 'workflow_dispatch' && github.ref == 'refs/heads/release'
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: 0
persist-credentials: false
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: 22
- name: Install dependencies
run: npm ci
- name: Run semantic-release (stable)
run: npx semantic-release --branches release
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
NPM_TOKEN: ${{ secrets.NPM_TOKEN }}
# Refresh origin/main immediately before merging and retry on a lost
# race: the checkout at job start goes stale while semantic-release
# runs, and direct pushes to main (PR merges) can land at any moment
# even with the workflow-level concurrency group.
- name: Merge release back to main
run: |
git config user.name "github-actions[bot]"
git config user.email "github-actions[bot]@users.noreply.github.com"
for attempt in 1 2 3; do
git fetch origin main
git checkout -B main origin/main
node scripts/release-sync.js release-to-main release
if git push https://x-access-token:${GITHUB_TOKEN}@github.com/${{ github.repository }}.git main; then
exit 0
fi
echo "Push to main rejected (branch advanced during merge), retrying ($attempt/3)..."
sleep 10
done
echo "Failed to merge release back to main after 3 attempts" >&2
exit 1
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}