Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ permissions:

env:
# The Ervisio release whose manifest validator is used.
ERVISIO_REF: v0.5.0
ERVISIO_REF: v0.6.2

jobs:
build:
Expand Down
90 changes: 23 additions & 67 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
@@ -1,77 +1,33 @@
# Publishes a release when a version tag is pushed:
#
# git tag -a v1.2.0 -m "1.2.0" && git push origin v1.2.0
#
# The tag must equal the version in plugin/manifest.json and package.json.
# Assets: <id>-<version>.tar.gz (one top folder <id>/, unsigned manifest) and
# <id>-<version>.tar.gz.sha256. The Ervisio plugin registry (Ervisio/plugins)
# picks the release up, reviews it, signs it with the Ervisio team key and
# lists it in the marketplace. No secrets are needed here.
# Release: Actions > Release > Run workflow, choose patch, minor or major
# (and optionally type the release notes). The version, CHANGELOG.md, the tag
# and the GitHub release are done for you, then the Ervisio registry is told;
# a version that asks for no new permissions is in the marketplace minutes
# later. Pushing a vX.Y.Z tag yourself still works.
# The steps live in Ervisio/plugin-sdk (.github/workflows/plugin-release.yml).
name: Release

on:
workflow_dispatch:
inputs:
bump:
description: 'Which part of the version goes up'
type: choice
options: [patch, minor, major]
default: patch
notes:
description: 'Release notes (empty: the commit subjects since the last release)'
type: string
required: false
push:
tags: ['v*.*.*']

permissions:
contents: read

env:
ERVISIO_REF: v0.5.0
contents: write

jobs:
release:
runs-on: ubuntu-24.04
permissions:
contents: write
env:
TAG: ${{ github.ref_name }}
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: 24
- name: Install
run: if [ -f package-lock.json ]; then npm ci; else npm install; fi
- name: Build
run: npm run build
- name: Pack (checks tag = manifest version = package.json version)
run: npm run pack
- uses: actions/checkout@v4
with:
repository: Ervisio/ervisio
ref: ${{ env.ERVISIO_REF }}
path: .ervisio-core
- uses: actions/setup-go@v5
with:
go-version-file: .ervisio-core/server/go.mod
cache: false
- name: Validate the manifest (Ervisio's own checks, throwaway key)
run: |
(cd .ervisio-core/server && CGO_ENABLED=0 go build -o "$RUNNER_TEMP/plugin-sign" ./internal/modules/plugins/cmd/plugin-sign)
id="$(node -p "require('./plugin/manifest.json').id")"
version="$(node -p "require('./plugin/manifest.json').version")"
echo "ID=$id" >> "$GITHUB_ENV"; echo "VERSION=$version" >> "$GITHUB_ENV"
(cd dist && sha256sum -c "$id-$version.tar.gz.sha256")
V="$RUNNER_TEMP/validate"; mkdir -p "$V"
tar -xzf "dist/$id-$version.tar.gz" -C "$V"
test "$(ls "$V")" = "$id"
if [ -n "$(find "$V" ! -type f ! -type d)" ]; then echo "links or special files in the tarball"; exit 1; fi
pub="$("$RUNNER_TEMP/plugin-sign" -genkey "$RUNNER_TEMP/throwaway.key" | sed -n 's/^public key: //p')"
"$RUNNER_TEMP/plugin-sign" -key "$RUNNER_TEMP/throwaway.key" "$V/$id"
"$RUNNER_TEMP/plugin-sign" -verify -pub "$pub" "$V/$id"
rm -f "$RUNNER_TEMP/throwaway.key"
- name: Release notes (CHANGELOG.md section of this version)
run: |
notes="$RUNNER_TEMP/notes.md"
awk -v v="$VERSION" '
/^## / { if (p) exit; h=$0; sub(/^## +\[?v?/, "", h); gsub(/\]/, " ", h); split(h, a, /[ \t(]+/); if (a[1] == v) { p=1; next } }
p { print }' CHANGELOG.md > "$notes"
if ! grep -q '[^[:space:]]' "$notes"; then echo "::error::CHANGELOG.md has no section for $VERSION"; exit 1; fi
cat "$notes"
- name: Publish
env:
GH_TOKEN: ${{ github.token }}
run: |
gh release create "$TAG" --verify-tag --title "$ID $VERSION" --notes-file "$RUNNER_TEMP/notes.md" \
"dist/$ID-$VERSION.tar.gz" "dist/$ID-$VERSION.tar.gz.sha256"
uses: Ervisio/plugin-sdk/.github/workflows/plugin-release.yml@main
with:
bump: ${{ github.event_name == 'workflow_dispatch' && inputs.bump || '' }}
notes: ${{ inputs.notes }}
secrets: inherit
15 changes: 5 additions & 10 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -61,16 +61,11 @@ The SDK types, the React shim and the Vite preset come from

## Releasing

1. Set the version in `plugin/manifest.json` and `package.json`, add a `## X.Y.Z` section to `CHANGELOG.md` (say
when a release asks for new permissions, and why).
2. Commit, then `git tag -a vX.Y.Z -m "X.Y.Z" && git push origin vX.Y.Z`.
3. The release workflow builds, validates the manifest with Ervisio's own validator and publishes
`docker-X.Y.Z.tar.gz` and its `.sha256` (unsigned).
4. The Ervisio plugin registry, [Ervisio/plugins](https://github.com/Ervisio/plugins), picks the release up within a
few hours and opens a pull request with the permission changes; a maintainer can run its "Sync" workflow by hand
for a faster pickup. After review and merge the registry signs the plugin and publishes it in the catalog.

This repository holds no secrets and never signs anything.
On GitHub: **Actions › Release › Run workflow**, choose `patch`, `minor` or `major`, optionally type the release notes
(empty: the commit subjects since the last release), and run it. The workflow bumps the version, writes the
`CHANGELOG.md` section, tags, builds, validates and releases, then tells the Ervisio registry: an update that asks for
no new permissions is in the marketplace a few minutes later. The steps live in
[Ervisio/plugin-sdk](https://github.com/Ervisio/plugin-sdk/blob/main/docs/publishing.md).

## How it fits together

Expand Down
Loading