From c50456d7df0c3331d3e77a3fe988376dd3bc7e3b Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Martin=20Bru=C5=BEina?= Date: Sat, 3 Oct 2026 09:24:38 +0200 Subject: [PATCH] feat!: remove the reusable semantic release workflow --- .github/workflows/semantic-release.yaml | 80 ------------------------- README.md | 35 +---------- 2 files changed, 1 insertion(+), 114 deletions(-) delete mode 100644 .github/workflows/semantic-release.yaml diff --git a/.github/workflows/semantic-release.yaml b/.github/workflows/semantic-release.yaml deleted file mode 100644 index 6c7dcaa..0000000 --- a/.github/workflows/semantic-release.yaml +++ /dev/null @@ -1,80 +0,0 @@ ---- -name: Semantic Release -on: - workflow_call: - inputs: - GH_SEM_REL_APP_ID: - type: string - required: false - description: GitHub App ID used to create the GitHub App token. - semantic_release_plugins: - type: string - required: false - description: Space-separated list of additional semantic-release plugins to install. - secrets: - GH_SEM_REL_APP_PEM_FILE: - required: false - -concurrency: - group: release-${{ github.ref }} - cancel-in-progress: false - -jobs: - release: - name: Release - runs-on: ubuntu-latest - permissions: - contents: write - issues: write - pull-requests: write - steps: - - name: Create GitHub App token - uses: actions/create-github-app-token@v3 - id: gh-app-token - if: inputs.GH_SEM_REL_APP_ID != '' - with: - app-id: ${{ inputs.GH_SEM_REL_APP_ID }} - private-key: ${{ secrets.GH_SEM_REL_APP_PEM_FILE }} - repositories: ${{ github.repository }} - permission-contents: write - permission-issues: write - permission-pull-requests: write - - name: Checkout repository - uses: actions/checkout@v7 - with: - token: ${{ steps.gh-app-token.outputs.token || secrets.GITHUB_TOKEN }} - fetch-depth: 0 - persist-credentials: true - - name: Set up Node.js - uses: actions/setup-node@v7 - with: - node-version: 'lts/*' - - name: Install Semantic Release # zizmor: ignore[adhoc-packages] lockfiles are not committed by design - env: - SEMANTIC_RELEASE_PLUGINS: ${{ inputs.semantic_release_plugins }} - run: | - read -ra plugins <<< "$SEMANTIC_RELEASE_PLUGINS" - npm install --ignore-scripts semantic-release conventional-changelog-conventionalcommits@9 @semantic-release/changelog @semantic-release/git "${plugins[@]}" - - name: Verify Semantic Release - run: npm audit signatures - - name: Run Semantic Release - env: - GITHUB_TOKEN: ${{ steps.gh-app-token.outputs.token || secrets.GITHUB_TOKEN }} - run: npx semantic-release - - name: Move major tags - if: ${{ !cancelled() }} - shell: bash - run: | - git fetch --force --prune --prune-tags origin - re='^(v(0|[1-9][0-9]*))\.(0|[1-9][0-9]*)\.(0|[1-9][0-9]*)(\+[0-9A-Za-z.-]+)?$' - declare -A latest=() - while read -r tag; do - [[ $tag =~ $re ]] && latest[${BASH_REMATCH[1]}]=$tag - done < <(git tag --list 'v*.*.*' --merged HEAD --sort=v:refname) - for major in "${!latest[@]}"; do - tag=${latest[$major]} - [ "$(git rev-parse -q --verify "refs/tags/$major^{commit}")" = "$(git rev-parse "$tag^{commit}")" ] && continue - git rev-parse -q --verify "refs/tags/$major" >/dev/null && ! git merge-base --is-ancestor "refs/tags/$major^{commit}" "$tag^{commit}" && continue - git tag --force "$major" "$tag" - git push --force origin "refs/tags/$major" - done diff --git a/README.md b/README.md index fbe0107..4eb01c2 100644 --- a/README.md +++ b/README.md @@ -1,21 +1,16 @@ # GitHub Actions and Workflows -Reusable GitHub Actions workflows forming the CI baseline for every BruzIT repository: semantic-release versioning and MegaLinter linting. +Reusable GitHub Actions and workflows forming the CI baseline for every BruzIT repository: semantic-release versioning and MegaLinter linting. ## Features - [Semantic Release Action](#semantic-release-composite-action) -- [Semantic Release Workflow](#reusable-semantic-release-workflow) - [MegaLinter Workflow](#reusable-megalinter-workflow) ### Semantic Release Composite Action [Semantic Release composite action](semantic-release/action.yaml) using the Conventional Commits preset to automate versioning, tags with SemVer and major tag, generates [GitHub releases](https://github.com/bruzit/github-actions-and-workflows/releases), and updates the [CHANGELOG](CHANGELOG.md). It checks out the repository with the GitHub App token, so the changelog commit and the major tags are pushed as the GitHub App; without `app-id` it uses `GITHUB_TOKEN`. -### Reusable Semantic Release Workflow - -Reusable [Semantic Release workflow](.github/workflows/semantic-release.yaml), similar to the [Semantic Release Action](#semantic-release-composite-action). - ### Reusable MegaLinter Workflow Reusable [MegaLinter workflow](.github/workflows/megalinter.yaml) linting pull requests with the `terraform` flavor, auto-committing fixable findings. Linters run with MegaLinter's default rules, except zizmor, whose [`zizmor.yaml`](zizmor.yaml) allows tag-pinned actions. @@ -91,34 +86,6 @@ To create a GitHub App and a GitHub App Installation: Configure Semantic Release in the repository, for example like this repository's [`.releaserc.yaml`](.releaserc.yaml). -### Use Semantic Release Workflow - -Similar to [Use Semantic Release Action](#use-semantic-release-action), with the reusable workflow: - -```yaml ---- -name: Semantic Release - -on: - push: - branches: - - main - -jobs: - release: - name: Release - uses: bruzit/github-actions-and-workflows/.github/workflows/semantic-release.yaml@v0 - permissions: - contents: write - issues: write - pull-requests: write - with: - GH_SEM_REL_APP_ID: ${{ vars.GH_SEM_REL_APP_ID }} - semantic_release_plugins: "@semantic-release/exec" # OPTIONAL Space-separated list of additional semantic-release plugins to install. - secrets: - GH_SEM_REL_APP_PEM_FILE: ${{ secrets.GH_SEM_REL_APP_PEM_FILE }} -``` - ### Use MegaLinter Workflow Create `.github/workflows/megalinter.yaml`: