diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 5c10d6d..d42838e 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -12,7 +12,7 @@ permissions: env: # The Ervisio release whose manifest validator is used. - ERVISIO_REF: v0.5.0 + ERVISIO_REF: v0.6.2 jobs: build: diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 12b0aa6..b05fbda 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -1,77 +1,33 @@ -# Publishes a release when a version tag is pushed: -# -# git tag -a v1.2.0 -m "1.2.0" && git push origin v1.2.0 -# -# The tag must equal the version in plugin/manifest.json and package.json. -# Assets: -.tar.gz (one top folder /, unsigned manifest) and -# -.tar.gz.sha256. The Ervisio plugin registry (Ervisio/plugins) -# picks the release up, reviews it, signs it with the Ervisio team key and -# lists it in the marketplace. No secrets are needed here. +# Release: Actions > Release > Run workflow, choose patch, minor or major +# (and optionally type the release notes). The version, CHANGELOG.md, the tag +# and the GitHub release are done for you, then the Ervisio registry is told; +# a version that asks for no new permissions is in the marketplace minutes +# later. Pushing a vX.Y.Z tag yourself still works. +# The steps live in Ervisio/plugin-sdk (.github/workflows/plugin-release.yml). name: Release on: + workflow_dispatch: + inputs: + bump: + description: 'Which part of the version goes up' + type: choice + options: [patch, minor, major] + default: patch + notes: + description: 'Release notes (empty: the commit subjects since the last release)' + type: string + required: false push: tags: ['v*.*.*'] permissions: - contents: read - -env: - ERVISIO_REF: v0.5.0 + contents: write jobs: release: - runs-on: ubuntu-24.04 - permissions: - contents: write - env: - TAG: ${{ github.ref_name }} - steps: - - uses: actions/checkout@v4 - - uses: actions/setup-node@v4 - with: - node-version: 24 - - name: Install - run: if [ -f package-lock.json ]; then npm ci; else npm install; fi - - name: Build - run: npm run build - - name: Pack (checks tag = manifest version = package.json version) - run: npm run pack - - uses: actions/checkout@v4 - with: - repository: Ervisio/ervisio - ref: ${{ env.ERVISIO_REF }} - path: .ervisio-core - - uses: actions/setup-go@v5 - with: - go-version-file: .ervisio-core/server/go.mod - cache: false - - name: Validate the manifest (Ervisio's own checks, throwaway key) - run: | - (cd .ervisio-core/server && CGO_ENABLED=0 go build -o "$RUNNER_TEMP/plugin-sign" ./internal/modules/plugins/cmd/plugin-sign) - id="$(node -p "require('./plugin/manifest.json').id")" - version="$(node -p "require('./plugin/manifest.json').version")" - echo "ID=$id" >> "$GITHUB_ENV"; echo "VERSION=$version" >> "$GITHUB_ENV" - (cd dist && sha256sum -c "$id-$version.tar.gz.sha256") - V="$RUNNER_TEMP/validate"; mkdir -p "$V" - tar -xzf "dist/$id-$version.tar.gz" -C "$V" - test "$(ls "$V")" = "$id" - if [ -n "$(find "$V" ! -type f ! -type d)" ]; then echo "links or special files in the tarball"; exit 1; fi - pub="$("$RUNNER_TEMP/plugin-sign" -genkey "$RUNNER_TEMP/throwaway.key" | sed -n 's/^public key: //p')" - "$RUNNER_TEMP/plugin-sign" -key "$RUNNER_TEMP/throwaway.key" "$V/$id" - "$RUNNER_TEMP/plugin-sign" -verify -pub "$pub" "$V/$id" - rm -f "$RUNNER_TEMP/throwaway.key" - - name: Release notes (CHANGELOG.md section of this version) - run: | - notes="$RUNNER_TEMP/notes.md" - awk -v v="$VERSION" ' - /^## / { if (p) exit; h=$0; sub(/^## +\[?v?/, "", h); gsub(/\]/, " ", h); split(h, a, /[ \t(]+/); if (a[1] == v) { p=1; next } } - p { print }' CHANGELOG.md > "$notes" - if ! grep -q '[^[:space:]]' "$notes"; then echo "::error::CHANGELOG.md has no section for $VERSION"; exit 1; fi - cat "$notes" - - name: Publish - env: - GH_TOKEN: ${{ github.token }} - run: | - gh release create "$TAG" --verify-tag --title "$ID $VERSION" --notes-file "$RUNNER_TEMP/notes.md" \ - "dist/$ID-$VERSION.tar.gz" "dist/$ID-$VERSION.tar.gz.sha256" + uses: Ervisio/plugin-sdk/.github/workflows/plugin-release.yml@main + with: + bump: ${{ github.event_name == 'workflow_dispatch' && inputs.bump || '' }} + notes: ${{ inputs.notes }} + secrets: inherit diff --git a/README.md b/README.md index f1a9bcd..f520fa1 100644 --- a/README.md +++ b/README.md @@ -61,16 +61,11 @@ The SDK types, the React shim and the Vite preset come from ## Releasing -1. Set the version in `plugin/manifest.json` and `package.json`, add a `## X.Y.Z` section to `CHANGELOG.md` (say - when a release asks for new permissions, and why). -2. Commit, then `git tag -a vX.Y.Z -m "X.Y.Z" && git push origin vX.Y.Z`. -3. The release workflow builds, validates the manifest with Ervisio's own validator and publishes - `docker-X.Y.Z.tar.gz` and its `.sha256` (unsigned). -4. The Ervisio plugin registry, [Ervisio/plugins](https://github.com/Ervisio/plugins), picks the release up within a - few hours and opens a pull request with the permission changes; a maintainer can run its "Sync" workflow by hand - for a faster pickup. After review and merge the registry signs the plugin and publishes it in the catalog. - -This repository holds no secrets and never signs anything. +On GitHub: **Actions › Release › Run workflow**, choose `patch`, `minor` or `major`, optionally type the release notes +(empty: the commit subjects since the last release), and run it. The workflow bumps the version, writes the +`CHANGELOG.md` section, tags, builds, validates and releases, then tells the Ervisio registry: an update that asks for +no new permissions is in the marketplace a few minutes later. The steps live in +[Ervisio/plugin-sdk](https://github.com/Ervisio/plugin-sdk/blob/main/docs/publishing.md). ## How it fits together