diff --git a/.github/workflows/build-private-images-ghcr.yml b/.github/workflows/build-private-images-ghcr.yml index 66e53bc0aea5..fbf3f25df16e 100644 --- a/.github/workflows/build-private-images-ghcr.yml +++ b/.github/workflows/build-private-images-ghcr.yml @@ -38,7 +38,7 @@ jobs: uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3.12.0 - name: Login to GitHub Container Registry - uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3.7.0 + uses: docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 # v4.1.0 with: registry: ghcr.io username: ${{ github.actor }} diff --git a/.github/workflows/build-public-images-ghcr.yml b/.github/workflows/build-public-images-ghcr.yml index fc8ce42b287a..61f951bbfc6a 100644 --- a/.github/workflows/build-public-images-ghcr.yml +++ b/.github/workflows/build-public-images-ghcr.yml @@ -40,7 +40,7 @@ jobs: uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3.12.0 - name: Login to GitHub Container Registry - uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3.7.0 + uses: docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 # v4.1.0 with: registry: ghcr.io username: ${{ github.actor }} @@ -48,7 +48,7 @@ jobs: - name: Build id: docker_build - uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6.19.2 + uses: docker/build-push-action@d08e5c354a6adb9ed34480a06d141179aa583294 # v7.0.0 with: labels: ${{ steps.meta.outputs.labels }} outputs: type=image,name=${{ env.GHCR_REPO }},push-by-digest=true,name-canonical=true,push=true @@ -68,7 +68,7 @@ jobs: touch "${{ runner.temp }}/digests/${digest#sha256:}" - name: Upload digest - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6.0.0 + uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0 with: name: digests-${{ env.PLATFORM_PAIR }} path: ${{ runner.temp }}/digests/* @@ -91,13 +91,13 @@ jobs: steps: - name: Download digests - uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7.0.0 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: path: ${{ runner.temp }}/digests pattern: digests-* merge-multiple: true - - uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3.7.0 + - uses: docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 # v4.1.0 with: registry: ghcr.io username: ${{ github.actor }} diff --git a/.github/workflows/codespell.yml b/.github/workflows/codespell.yml index 8c82c2a9b84b..076ffb6c2952 100644 --- a/.github/workflows/codespell.yml +++ b/.github/workflows/codespell.yml @@ -3,7 +3,7 @@ name: Check spelling on: pull_request: push: - branches: [ master ] + branches: [ master, 'v*-psf' ] merge_group: jobs: @@ -15,4 +15,4 @@ jobs: with: check_filenames: true ignore_words_file: .codespellignore - path: lib test extra + path: lib test extra diff --git a/.github/workflows/elixir.yml b/.github/workflows/elixir.yml index 94187aff2809..7a1bfb98d047 100644 --- a/.github/workflows/elixir.yml +++ b/.github/workflows/elixir.yml @@ -3,7 +3,7 @@ name: Elixir CI on: pull_request: push: - branches: [master, stable] + branches: [master, stable, 'v*-psf'] merge_group: concurrency: @@ -53,10 +53,11 @@ jobs: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: fetch-depth: 0 + filter: blob:none - uses: marocchino/tool-versions-action@18a164fa2b0db1cc1edf7305fcb17ace36d1c306 # v1.2.0 id: versions - - uses: erlef/setup-beam@ee09b1e59bb240681c382eb1f0abc6a04af72764 # v1.23.0 + - uses: erlef/setup-beam@fc68ffb90438ef2936bbb3251622353b3dcb2f93 # v1.24.0 with: elixir-version: ${{ steps.versions.outputs.elixir }} otp-version: ${{ steps.versions.outputs.erlang }} @@ -73,10 +74,10 @@ jobs: key: ${{ env.MIX_ENV }}-${{ env.CACHE_VERSION }}-${{ github.head_ref || github.ref }}-${{ hashFiles('**/mix.lock') }} restore-keys: | ${{ env.MIX_ENV }}-${{ env.CACHE_VERSION }}-${{ github.head_ref || github.ref }}- - ${{ env.MIX_ENV }}-${{ env.CACHE_VERSION }}-refs/heads/master- + ${{ env.MIX_ENV }}-${{ env.CACHE_VERSION }}-refs/heads/${{ github.base_ref || github.event.repository.default_branch }}- - name: Check for changes in tracker/** - uses: dorny/paths-filter@de90cc6fb38fc0963ad72b210f1f284cd68cea36 # v3.0.2 + uses: dorny/paths-filter@fbd0ab8f3e69293af611ebaee6363fc25e6d187d # v4.0.1 id: changes with: filters: | @@ -152,11 +153,12 @@ jobs: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: fetch-depth: 0 + filter: blob:none - uses: marocchino/tool-versions-action@18a164fa2b0db1cc1edf7305fcb17ace36d1c306 # v1.2.0 id: versions - - uses: erlef/setup-beam@ee09b1e59bb240681c382eb1f0abc6a04af72764 # v1.23.0 + - uses: erlef/setup-beam@fc68ffb90438ef2936bbb3251622353b3dcb2f93 # v1.24.0 with: elixir-version: ${{ steps.versions.outputs.elixir }} otp-version: ${{ steps.versions.outputs.erlang }} @@ -174,7 +176,7 @@ jobs: key: e2e-${{ env.MIX_ENV }}-${{ env.CACHE_VERSION }}-${{ github.head_ref || github.ref }}-${{ hashFiles('**/mix.lock') }} restore-keys: | e2e-${{ env.MIX_ENV }}-${{ env.CACHE_VERSION }}-${{ github.head_ref || github.ref }}- - e2e-${{ env.MIX_ENV }}-${{ env.CACHE_VERSION }}-refs/heads/master- + e2e-${{ env.MIX_ENV }}-${{ env.CACHE_VERSION }}-refs/heads/${{ github.base_ref || github.event.repository.default_branch }}- - name: Cache E2E dependencies and Playwright browsers uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4 @@ -189,7 +191,7 @@ jobs: playwright-${{ runner.os }}- - name: Check for changes in tracker/** - uses: dorny/paths-filter@de90cc6fb38fc0963ad72b210f1f284cd68cea36 # v3.0.2 + uses: dorny/paths-filter@fbd0ab8f3e69293af611ebaee6363fc25e6d187d # v4.0.1 id: changes with: filters: | @@ -225,7 +227,7 @@ jobs: - name: Upload E2E blob report to GitHub Actions Artifacts if: ${{ !cancelled() }} - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6.0.0 + uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0 with: name: e2e-blob-report-${{ matrix.shardIndex }} path: e2e/blob-report @@ -247,7 +249,7 @@ jobs: run: npm --prefix ./e2e ci - name: Download blob reports from GitHub Actions Artifacts - uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7.0.0 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: path: all-e2e-blob-reports pattern: e2e-blob-report-* @@ -266,11 +268,12 @@ jobs: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: fetch-depth: 0 + filter: blob:none - uses: marocchino/tool-versions-action@18a164fa2b0db1cc1edf7305fcb17ace36d1c306 # v1.2.0 id: versions - - uses: erlef/setup-beam@ee09b1e59bb240681c382eb1f0abc6a04af72764 # v1.23.0 + - uses: erlef/setup-beam@fc68ffb90438ef2936bbb3251622353b3dcb2f93 # v1.24.0 with: elixir-version: ${{ steps.versions.outputs.elixir }} otp-version: ${{ steps.versions.outputs.erlang }} @@ -284,11 +287,13 @@ jobs: key: static-${{ env.MIX_ENV }}-${{ env.CACHE_VERSION }}-${{ github.head_ref || github.ref }}-${{ hashFiles('**/mix.lock') }} restore-keys: | static-${{ env.MIX_ENV }}-${{ env.CACHE_VERSION }}-${{ github.head_ref || github.ref }}- - static-${{ env.MIX_ENV }}-${{ env.CACHE_VERSION }}-refs/heads/master- + static-${{ env.MIX_ENV }}-${{ env.CACHE_VERSION }}-refs/heads/${{ github.base_ref || github.event.repository.default_branch }}- - run: mix deps.get - run: mix compile --warnings-as-errors --all-warnings - run: mix format --check-formatted - run: mix deps.unlock --check-unused - - run: mix credo diff --from-git-merge-base origin/master + - run: mix credo diff --from-git-merge-base "$BASE_REF" + env: + BASE_REF: ${{ github.event.pull_request.base.sha || github.event.merge_group.base_sha || format('origin/{0}', github.event.repository.default_branch) }} - run: mix dialyzer diff --git a/.github/workflows/migrations-validation.yml b/.github/workflows/migrations-validation.yml index 3f3681c31ee3..29d84e84b3d1 100644 --- a/.github/workflows/migrations-validation.yml +++ b/.github/workflows/migrations-validation.yml @@ -12,7 +12,7 @@ jobs: runs-on: ubuntu-latest steps: - - uses: dorny/paths-filter@de90cc6fb38fc0963ad72b210f1f284cd68cea36 # v3.0.2 + - uses: dorny/paths-filter@fbd0ab8f3e69293af611ebaee6363fc25e6d187d # v4.0.1 id: changes with: list-files: json diff --git a/.github/workflows/node.yml b/.github/workflows/node.yml index 323934633e7f..777cdc01571b 100644 --- a/.github/workflows/node.yml +++ b/.github/workflows/node.yml @@ -2,7 +2,7 @@ name: NPM CI on: push: - branches: [master, stable] + branches: [master, stable, 'v*-psf'] pull_request: merge_group: diff --git a/.github/workflows/publish-docs.yml b/.github/workflows/publish-docs.yml index 9f73c53274a1..c079965b216c 100644 --- a/.github/workflows/publish-docs.yml +++ b/.github/workflows/publish-docs.yml @@ -23,13 +23,12 @@ jobs: steps: - name: Checkout uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - - name: Read .tool-versions uses: marocchino/tool-versions-action@18a164fa2b0db1cc1edf7305fcb17ace36d1c306 # v1.2.0 id: versions - name: Set up Elixir - uses: erlef/setup-beam@ee09b1e59bb240681c382eb1f0abc6a04af72764 # v1.23.0 + uses: erlef/setup-beam@fc68ffb90438ef2936bbb3251622353b3dcb2f93 # v1.24.0 with: elixir-version: ${{steps.versions.outputs.elixir}} otp-version: ${{ steps.versions.outputs.erlang}} @@ -46,7 +45,7 @@ jobs: - name: Install Mix dependencies run: mix deps.get - + - name: Build documentation run: mix docs diff --git a/.github/workflows/terraform-e2e.yml b/.github/workflows/terraform-e2e.yml index 717f5d6f9a14..8aba6bfea699 100644 --- a/.github/workflows/terraform-e2e.yml +++ b/.github/workflows/terraform-e2e.yml @@ -30,7 +30,7 @@ jobs: uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - name: Setup Terraform - uses: hashicorp/setup-terraform@b9cd54a3c349d3f38e8881555d616ced269862dd # v3.1.2 + uses: hashicorp/setup-terraform@5e8dbf3c6d9deaf4193ca7a8fb23f2ac83bb6c85 # v4.0.0 with: cli_config_credentials_token: ${{ secrets.TF_CLOUD_CHECKLY_API_TOKEN }} diff --git a/.github/workflows/tracker-script-update.yml b/.github/workflows/tracker-script-update.yml index fc9f589cb98b..7b61cb87480b 100644 --- a/.github/workflows/tracker-script-update.yml +++ b/.github/workflows/tracker-script-update.yml @@ -22,21 +22,20 @@ jobs: token: ${{ secrets.PLAUSIBLE_BOT_GITHUB_TOKEN }} fetch-depth: 1 - - name: Checkout master for comparison + - name: Checkout PR base for comparison uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: - ref: master - path: master-branch + ref: ${{ github.event.pull_request.base.sha || github.event.repository.default_branch }} + path: base-branch - name: Install jq and clickhouse-local run: | - sudo apt-get install apt-transport-https ca-certificates dirmngr - sudo apt-key adv --keyserver hkp://keyserver.ubuntu.com:80 --recv 8919F6BD2B48D754 - echo "deb https://packages.clickhouse.com/deb stable main" | sudo tee \ - /etc/apt/sources.list.d/clickhouse.list + curl -fsSL 'https://packages.clickhouse.com/rpm/lts/repodata/repomd.xml.key' \ + | sudo gpg --batch --yes --dearmor -o /usr/share/keyrings/clickhouse-archive-keyring.gpg + echo "deb [signed-by=/usr/share/keyrings/clickhouse-archive-keyring.gpg] https://packages.clickhouse.com/deb stable main" \ + | sudo tee /etc/apt/sources.list.d/clickhouse.list sudo apt-get update - - sudo apt-get install jq clickhouse-server -y + sudo apt-get install -y jq clickhouse-server - name: Compare and increment tracker_script_version id: increment @@ -45,21 +44,21 @@ jobs: # Get current version from PR branch PR_VERSION=$(jq '.tracker_script_version' package.json) - # Get version from master, default to 0 if not present - MASTER_VERSION=$(jq '.tracker_script_version // 0' ../master-branch/tracker/package.json) + # Get version from the PR base, default to 0 if not present + BASE_VERSION=$(jq '.tracker_script_version // 0' ../base-branch/tracker/package.json) echo "PR tracker_script_version: $PR_VERSION" - echo "Master tracker_script_version: $MASTER_VERSION" + echo "Base tracker_script_version: $BASE_VERSION" # Calculate new version NEW_VERSION=$((PR_VERSION + 1)) # Check version conditions - if [ $PR_VERSION -lt $MASTER_VERSION ]; then - echo "::error::PR tracker tracker_script_version ($PR_VERSION) is less than master ($MASTER_VERSION) and cannot be incremented." - echo "::error::Rebase or merge master into your PR to fix this." + if [ $PR_VERSION -lt $BASE_VERSION ]; then + echo "::error::PR tracker tracker_script_version ($PR_VERSION) is less than the PR base ($BASE_VERSION) and cannot be incremented." + echo "::error::Rebase or merge the base branch into your PR to fix this." exit 1 - elif [ $NEW_VERSION -eq $((MASTER_VERSION + 1)) ]; then + elif [ $NEW_VERSION -eq $((BASE_VERSION + 1)) ]; then echo "Incrementing version from $PR_VERSION to $NEW_VERSION" jq ".tracker_script_version = $NEW_VERSION" package.json > package.json.tmp mv package.json.tmp package.json @@ -82,9 +81,9 @@ jobs: - name: Compile tracker code run: | - cd master-branch/tracker + cd base-branch/tracker npm install - node compile.js --suffix master + node compile.js --suffix base cp ../priv/tracker/js/plausible* ../../priv/tracker/js/ cd ../../tracker @@ -95,7 +94,7 @@ jobs: id: analyze run: | cd tracker - OUT=$(node compiler/analyze-sizes.js --baselineSuffix master --currentSuffix pr) + OUT=$(node compiler/analyze-sizes.js --baselineSuffix base --currentSuffix pr) # Set multiline output echo "sizes<> $GITHUB_OUTPUT echo "$OUT" >> $GITHUB_OUTPUT @@ -122,7 +121,7 @@ jobs: - name: Get changed files id: changelog_changed - uses: tj-actions/changed-files@e0021407031f5be11a464abee9a0776171c79891 + uses: tj-actions/changed-files@22103cc46bda19c2b464ffe86db46df6922fd323 with: files: | tracker/npm_package/CHANGELOG.md diff --git a/.github/workflows/tracker.yml b/.github/workflows/tracker.yml index af929babfddc..cd3f69df8cc9 100644 --- a/.github/workflows/tracker.yml +++ b/.github/workflows/tracker.yml @@ -49,7 +49,7 @@ jobs: run: npm --prefix ./tracker test -- --shard=${{ matrix.shardIndex }}/${{ matrix.shardTotal }} --reporter=blob - name: Upload blob report to GitHub Actions Artifacts if: ${{ !cancelled() }} - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6.0.0 + uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0 with: name: blob-report-${{ matrix.shardIndex }} path: tracker/blob-report @@ -70,7 +70,7 @@ jobs: run: npm --prefix ./tracker ci - name: Download blob reports from GitHub Actions Artifacts - uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7.0.0 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: path: all-blob-reports pattern: blob-report-* diff --git a/CHANGELOG.md b/CHANGELOG.md index 88e9fb9dd67c..3dc2d3b21fac 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -17,6 +17,7 @@ All notable changes to this project will be documented in this file. ### Changed +- Restore upstream ancestry, reconcile CE v3.2.1 without changing PSF application code, and prepare CI and deployment instructions for the `v3.2.1-psf` branch. - Keybind hints are hidden on smaller screens - Site index is sortable alphanumerically and by traffic @@ -27,6 +28,12 @@ All notable changes to this project will be documented in this file. - Fixed issue with all non-interactive events being counted as interactive - Fixed countries map countries staying highlighted on Chrome +## v3.2.1 - 2026-05-12 + +### Removed + +- Removed phoenix storybook dependency + ## v3.2.0 - 2026-01-16 ### Added diff --git a/README.md b/README.md index f6983fe9abd4..3635b730e49c 100644 --- a/README.md +++ b/README.md @@ -4,13 +4,18 @@ This is the Python Software Foundation's fork of [Plausible Analytics](https://p running at [analytics.python.org](https://analytics.python.org). It tracks traffic across PSF infrastructure sites with privacy-friendly, cookie-free analytics. -The fork adds a few things on top of upstream Plausible CE: +The fork adds: - A custom landing page at `/` with links to public dashboards - Unix domain socket support for Cabotage deployments - PSF-specific Procfile and Dockerfile configuration +- ClickHouse migration and replication settings for the PSF database topology +- Google API and GA4 import adjustments -We try to sync with [upstream](https://github.com/plausible/analytics) periodically. -PSF-specific changes live on the `v3.0.1-psf` branch. +The deployment branch for this baseline is `v3.2.1-psf`, incorporating upstream +[v3.2.1](https://github.com/plausible/analytics/releases/tag/v3.2.1). +The name identifies the latest incorporated CE release, not an unmodified release +tree: this fork also retains the previously imported upstream `master` snapshot +`dc51b4cc9c7107d9bed63fbe594c7c81fe702238` and subsequent PSF changes. ## Examples of Public Dashboards @@ -44,8 +49,9 @@ The landing page at `/` is a static HTML file at `landing/index.html`. It gets baked into the Docker image and served by the Phoenix app through `PageController`. Logged-in users get redirected to `/sites` as usual. -To edit the landing page, change `landing/index.html` and push to `v3.0.1-psf`. -The next image build and deploy picks it up. +To edit the landing page, change `landing/index.html` and open a PR against the +deployment branch. Merge only after CI passes; Cabotage builds from its configured +branch. ## Local Development @@ -105,7 +111,20 @@ This runs on [Cabotage](https://github.com/cabotage/cabotage-app), the PSF's Paa - `web` — the Plausible Phoenix app, binds to a unix socket via `HTTPS_UDS` - `release` — runs database migrations on deploy -Image builds happen automatically from the `v3.0.1-psf` branch. To deploy, trigger a build and deploy through the Cabotage UI. +Cabotage builds from its configured deployment branch. The transition from +`v3.0.1-psf` to `v3.2.1-psf` requires an explicit operator cutover; merging code or +editing this README does not change Cabotage's branch setting. + +After the reconciliation PR passes CI and is merged **with a merge commit**: + +1. Pause automatic deployment while changing branch references. +2. Rename the deployment branch from `v3.0.1-psf` to `v3.2.1-psf`, keeping its + reviewed history. Update GitHub's default branch and applicable branch rules. +3. Change Cabotage's tracked branch to `v3.2.1-psf`, then resume automatic deployment. +4. Build and deploy through Cabotage. Verify the deployed source commit and image + digest, migration completion, and application health. + +Before this cutover, production continues to track the existing branch. ### Storybook security update @@ -117,17 +136,31 @@ If credentials were disclosed or compromise is suspected, rotate or revoke all s ## Upstream Sync -This fork tracks `plausible/analytics:master` as the `upstream` remote. - -```bash -git fetch upstream -git checkout v3.0.1-psf -git merge upstream/master -# resolve any conflicts in PSF-specific files -git push -``` - -PSF-specific changes are minimal (landing page, PageController, unix socket patch, Procfile/Dockerfile) so conflicts are rare. +Track published upstream CE release tags, not the moving `master` branch. +For each release, create a review branch from the current PSF deployment branch +and merge the selected upstream tag into it. Keep the PSF and previously imported +upstream changes unless a reviewed migration deliberately replaces them. + +The reconciliation to v3.2.1 restores the ancestry lost when PR #2 was +squash-merged: original merge `ec3f81de488b7aa9a6dcffc03cb9b33bcb53cda1` +has the same tree as squash commit `2d3391215fd26fe3a4a2e54c083e4ffb5ebe7b60`. +The ancestry repair preserves the current PSF tree, then incorporates the +upstream v3.2.1 tag. + +**Use merge commits for upstream synchronization PRs, including this ancestry +repair. Do not squash or rebase them.** A repository administrator must enable +merge commits before merging if the repository only permits squash merges. + +Review the landing page and controller, Unix socket configuration, Dockerfile and +Procfile, ClickHouse migrations and replication paths, Google API/GA4 import +adjustments, Storybook removal, and MinIO test setup during every synchronization. +Preserve applied migration history; do not reset the fork to a stock release tree. + +Require CI and a production-image build before merging. If migrations change, +validate them against a restored database copy before production deployment. +After review, rename the deployment branch to `v-psf` and update +GitHub, Cabotage, and these instructions together. Record the upstream tag, PSF +commit, and deployed image digest for each deployment. ## License