From 6e04e62f2d6e374c2c5ae86f94b0eca8332a1825 Mon Sep 17 00:00:00 2001 From: Titus Kirch Date: Wed, 2 Sep 2026 13:39:26 +0200 Subject: [PATCH 1/2] feat(ci): call the release-please body instead of the last local copy MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit This was the only repo still running release-please from its own steps — the publish half already called the body, the release half did not, so the major alias logic sat here in duplicate. The workflow-level permissions block goes too: it caps every called body, and the publish jobs need id-token: write. --- .github/workflows/ci.yml | 2 +- .github/workflows/codeql.yml | 2 +- .github/workflows/fast-forward-queue.yml | 2 +- .github/workflows/promotion-pr.yml | 2 +- .github/workflows/queue-branch.yml | 2 +- .github/workflows/release-please.yml | 91 +++++------------------- 6 files changed, 23 insertions(+), 78 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 049f0a6..4945d7a 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -23,4 +23,4 @@ permissions: jobs: check: name: CI - uses: kirchDev/workflows/.github/workflows/_ci-check.yml@bec834b87a96c8c1dbf2c7cb28f774e9173e32d7 # v0.2.0 + uses: kirchDev/workflows/.github/workflows/_ci-check.yml@c4cce887e4df7cceb397bb556934e3c82bc6a69d # v0.4.0 diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 7e52e5c..a33c84f 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -20,4 +20,4 @@ jobs: packages: read actions: read contents: read - uses: kirchDev/workflows/.github/workflows/_codeql.yml@bec834b87a96c8c1dbf2c7cb28f774e9173e32d7 # v0.2.0 + uses: kirchDev/workflows/.github/workflows/_codeql.yml@c4cce887e4df7cceb397bb556934e3c82bc6a69d # v0.4.0 diff --git a/.github/workflows/fast-forward-queue.yml b/.github/workflows/fast-forward-queue.yml index d54b037..1977428 100644 --- a/.github/workflows/fast-forward-queue.yml +++ b/.github/workflows/fast-forward-queue.yml @@ -25,7 +25,7 @@ jobs: pull-requests: read checks: read statuses: read - uses: kirchDev/workflows/.github/workflows/_fast-forward-queue.yml@bec834b87a96c8c1dbf2c7cb28f774e9173e32d7 # v0.2.0 + uses: kirchDev/workflows/.github/workflows/_fast-forward-queue.yml@c4cce887e4df7cceb397bb556934e3c82bc6a69d # v0.4.0 with: pr: ${{ inputs.pr }} secrets: diff --git a/.github/workflows/promotion-pr.yml b/.github/workflows/promotion-pr.yml index 3bb50d4..a520ff6 100644 --- a/.github/workflows/promotion-pr.yml +++ b/.github/workflows/promotion-pr.yml @@ -15,4 +15,4 @@ permissions: jobs: promotion-pr: name: Promotion PR - uses: kirchDev/workflows/.github/workflows/_promotion-pr.yml@bec834b87a96c8c1dbf2c7cb28f774e9173e32d7 # v0.2.0 + uses: kirchDev/workflows/.github/workflows/_promotion-pr.yml@c4cce887e4df7cceb397bb556934e3c82bc6a69d # v0.4.0 diff --git a/.github/workflows/queue-branch.yml b/.github/workflows/queue-branch.yml index 1af8d1f..9e2c757 100644 --- a/.github/workflows/queue-branch.yml +++ b/.github/workflows/queue-branch.yml @@ -16,6 +16,6 @@ jobs: permissions: contents: read pull-requests: write - uses: kirchDev/workflows/.github/workflows/_queue-branch.yml@bec834b87a96c8c1dbf2c7cb28f774e9173e32d7 # v0.2.0 + uses: kirchDev/workflows/.github/workflows/_queue-branch.yml@c4cce887e4df7cceb397bb556934e3c82bc6a69d # v0.4.0 secrets: BWS_ACCESS_TOKEN: ${{ secrets.BWS_ACCESS_TOKEN }} diff --git a/.github/workflows/release-please.yml b/.github/workflows/release-please.yml index 1b374e8..633110d 100644 --- a/.github/workflows/release-please.yml +++ b/.github/workflows/release-please.yml @@ -10,84 +10,29 @@ on: # itself is gated to the release branch below. - dev -permissions: - contents: write - pull-requests: write - +# PERMISSIONS PER JOB, NOT PER WORKFLOW: a workflow-level block caps every +# called body, and the publish jobs need `id-token: write` for npm's Trusted +# Publishing — a cap makes the run fail at startup rather than at that step. concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: false jobs: release-please: - name: Run release-please - runs-on: ubuntu-latest + name: Release Please + # `dev` reaches this workflow for the prerelease job below; release-please + # itself only ever runs on the release branch. if: github.ref_name == 'main' - # Step outputs are invisible to other jobs, so the publish job below could - # never learn whether a release was cut without lifting them here. - outputs: - release-created: ${{ steps.release.outputs.release_created }} - tag-name: ${{ steps.release.outputs.tag_name }} - steps: - - name: Fetch Release App PEM from Bitwarden - uses: bitwarden/sm-action@1238aae8fc64b212641190a9227c8a734ab1a793 # v3.0.1 - with: - access_token: ${{ secrets.BWS_ACCESS_TOKEN }} - cloud_region: eu - secrets: | - 3a3459f0-c986-4ff3-a36b-b4550012d41e > KIRCHDEV_RELEASE_APP_PEM - - - name: Mint Release App token - id: app-token - uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0 - with: - client-id: 'Iv23li3hNqtsZ8fDlwqH' - private-key: ${{ env.KIRCHDEV_RELEASE_APP_PEM }} - - - id: release - uses: googleapis/release-please-action@45996ed1f6d02564a971a2fa1b5860e934307cf7 # v5.0.0 - with: - token: ${{ steps.app-token.outputs.token }} - config-file: release-please-config.json - manifest-file: .release-please-manifest.json - - # release-please cuts exact tags only — `v0.1.0`, never `v0`. This repo - # ships a composite action consumed as `kirchDev/gitignore-sync@`, so - # the moving alias is what lets a caller follow the v0 line without a bump - # PR for every patch — exactly how `actions/checkout@v7` behaves. - # - # FORCED ON PURPOSE. Moving a tag is normally the thing not to do, and an - # alias is the one case where moving it IS the contract: the tag names a - # major line, not a release. The exact tags it points at are never touched. - - name: Move the major alias - if: steps.release.outputs.release_created == 'true' - env: - GH_TOKEN: ${{ steps.app-token.outputs.token }} - GH_REPO: ${{ github.repository }} - TAG: ${{ steps.release.outputs.tag_name }} - SHA: ${{ steps.release.outputs.sha }} - run: | - set -euo pipefail - - if [ -z "${TAG:-}" ] || [ -z "${SHA:-}" ]; then - echo "::warning::release-please reported a release without a tag or sha — no alias moved." - exit 0 - fi - - # v1.2.3 -> v1, and 0.x keeps its own line as v0: a 0.x major is not - # stable, so callers who want it must ask for it by name. - alias="v${TAG#v}" - alias="${alias%%.*}" - - if gh api "repos/$GH_REPO/git/ref/tags/$alias" > /dev/null 2>&1; then - gh api -X PATCH "repos/$GH_REPO/git/refs/tags/$alias" \ - -f "sha=$SHA" -F force=true > /dev/null - echo "::notice::Moved $alias to $TAG ($SHA)." - else - gh api -X POST "repos/$GH_REPO/git/refs" \ - -f "ref=refs/tags/$alias" -f "sha=$SHA" > /dev/null - echo "::notice::Created $alias at $TAG ($SHA)." - fi + permissions: + contents: write + pull-requests: write + uses: kirchDev/workflows/.github/workflows/_release-please.yml@c4cce887e4df7cceb397bb556934e3c82bc6a69d # v0.4.0 + with: + # This package is consumed as `kirchDev/gitignore-sync@`, so `@v0` + # has to keep meaning "the newest v0.x.y". + major-alias: true + secrets: + BWS_ACCESS_TOKEN: ${{ secrets.BWS_ACCESS_TOKEN }} publish-release: name: Publish stable release @@ -102,7 +47,7 @@ jobs: # `build-script` is left at its default: this repo's `build` writes the npm # artifact itself. coverage-report needs `build:npm` there only because its # `build` produces an Action bundle instead. - uses: kirchDev/workflows/.github/workflows/_publish-npm.yml@bec834b87a96c8c1dbf2c7cb28f774e9173e32d7 # v0.2.0 + uses: kirchDev/workflows/.github/workflows/_publish-npm.yml@c4cce887e4df7cceb397bb556934e3c82bc6a69d # v0.4.0 with: tag-name: ${{ needs.release-please.outputs.tag-name }} @@ -122,6 +67,6 @@ jobs: permissions: contents: read id-token: write - uses: kirchDev/workflows/.github/workflows/_publish-npm.yml@bec834b87a96c8c1dbf2c7cb28f774e9173e32d7 # v0.2.0 + uses: kirchDev/workflows/.github/workflows/_publish-npm.yml@c4cce887e4df7cceb397bb556934e3c82bc6a69d # v0.4.0 with: prerelease: true From ed4d410fb044b3f71bf8f0e486e82de6e0e1b9ab Mon Sep 17 00:00:00 2001 From: Titus Kirch Date: Wed, 2 Sep 2026 13:54:32 +0200 Subject: [PATCH 2/2] fix(ci): pin the workflow bodies to v0.5.0 One pin across the estate. v0.5.0 lets the gate body install PHP, so a Laravel repo's Pint no longer forces the whole job to stay local, and it carries the Gate fix that reports a superseded run as cancelled rather than failed. --- .github/workflows/ci.yml | 2 +- .github/workflows/codeql.yml | 2 +- .github/workflows/fast-forward-queue.yml | 2 +- .github/workflows/promotion-pr.yml | 2 +- .github/workflows/queue-branch.yml | 2 +- .github/workflows/release-please.yml | 6 +++--- 6 files changed, 8 insertions(+), 8 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 4945d7a..aba28eb 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -23,4 +23,4 @@ permissions: jobs: check: name: CI - uses: kirchDev/workflows/.github/workflows/_ci-check.yml@c4cce887e4df7cceb397bb556934e3c82bc6a69d # v0.4.0 + uses: kirchDev/workflows/.github/workflows/_ci-check.yml@b7bc3408448d1c0c1266e8c5fe2788c9cf120790 # v0.5.0 diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index a33c84f..4d1b3ff 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -20,4 +20,4 @@ jobs: packages: read actions: read contents: read - uses: kirchDev/workflows/.github/workflows/_codeql.yml@c4cce887e4df7cceb397bb556934e3c82bc6a69d # v0.4.0 + uses: kirchDev/workflows/.github/workflows/_codeql.yml@b7bc3408448d1c0c1266e8c5fe2788c9cf120790 # v0.5.0 diff --git a/.github/workflows/fast-forward-queue.yml b/.github/workflows/fast-forward-queue.yml index 1977428..5be1e16 100644 --- a/.github/workflows/fast-forward-queue.yml +++ b/.github/workflows/fast-forward-queue.yml @@ -25,7 +25,7 @@ jobs: pull-requests: read checks: read statuses: read - uses: kirchDev/workflows/.github/workflows/_fast-forward-queue.yml@c4cce887e4df7cceb397bb556934e3c82bc6a69d # v0.4.0 + uses: kirchDev/workflows/.github/workflows/_fast-forward-queue.yml@b7bc3408448d1c0c1266e8c5fe2788c9cf120790 # v0.5.0 with: pr: ${{ inputs.pr }} secrets: diff --git a/.github/workflows/promotion-pr.yml b/.github/workflows/promotion-pr.yml index a520ff6..17203ed 100644 --- a/.github/workflows/promotion-pr.yml +++ b/.github/workflows/promotion-pr.yml @@ -15,4 +15,4 @@ permissions: jobs: promotion-pr: name: Promotion PR - uses: kirchDev/workflows/.github/workflows/_promotion-pr.yml@c4cce887e4df7cceb397bb556934e3c82bc6a69d # v0.4.0 + uses: kirchDev/workflows/.github/workflows/_promotion-pr.yml@b7bc3408448d1c0c1266e8c5fe2788c9cf120790 # v0.5.0 diff --git a/.github/workflows/queue-branch.yml b/.github/workflows/queue-branch.yml index 9e2c757..d8e674e 100644 --- a/.github/workflows/queue-branch.yml +++ b/.github/workflows/queue-branch.yml @@ -16,6 +16,6 @@ jobs: permissions: contents: read pull-requests: write - uses: kirchDev/workflows/.github/workflows/_queue-branch.yml@c4cce887e4df7cceb397bb556934e3c82bc6a69d # v0.4.0 + uses: kirchDev/workflows/.github/workflows/_queue-branch.yml@b7bc3408448d1c0c1266e8c5fe2788c9cf120790 # v0.5.0 secrets: BWS_ACCESS_TOKEN: ${{ secrets.BWS_ACCESS_TOKEN }} diff --git a/.github/workflows/release-please.yml b/.github/workflows/release-please.yml index 633110d..34628b7 100644 --- a/.github/workflows/release-please.yml +++ b/.github/workflows/release-please.yml @@ -26,7 +26,7 @@ jobs: permissions: contents: write pull-requests: write - uses: kirchDev/workflows/.github/workflows/_release-please.yml@c4cce887e4df7cceb397bb556934e3c82bc6a69d # v0.4.0 + uses: kirchDev/workflows/.github/workflows/_release-please.yml@b7bc3408448d1c0c1266e8c5fe2788c9cf120790 # v0.5.0 with: # This package is consumed as `kirchDev/gitignore-sync@`, so `@v0` # has to keep meaning "the newest v0.x.y". @@ -47,7 +47,7 @@ jobs: # `build-script` is left at its default: this repo's `build` writes the npm # artifact itself. coverage-report needs `build:npm` there only because its # `build` produces an Action bundle instead. - uses: kirchDev/workflows/.github/workflows/_publish-npm.yml@c4cce887e4df7cceb397bb556934e3c82bc6a69d # v0.4.0 + uses: kirchDev/workflows/.github/workflows/_publish-npm.yml@b7bc3408448d1c0c1266e8c5fe2788c9cf120790 # v0.5.0 with: tag-name: ${{ needs.release-please.outputs.tag-name }} @@ -67,6 +67,6 @@ jobs: permissions: contents: read id-token: write - uses: kirchDev/workflows/.github/workflows/_publish-npm.yml@c4cce887e4df7cceb397bb556934e3c82bc6a69d # v0.4.0 + uses: kirchDev/workflows/.github/workflows/_publish-npm.yml@b7bc3408448d1c0c1266e8c5fe2788c9cf120790 # v0.5.0 with: prerelease: true