diff --git a/.github/actions/setup-vp/action.yml b/.github/actions/setup-vp/action.yml deleted file mode 100644 index 9a13455..0000000 --- a/.github/actions/setup-vp/action.yml +++ /dev/null @@ -1,30 +0,0 @@ -name: Setup Vite+ -description: Set up the repo-pinned Vite+ runtime - -inputs: - node-version-file: - description: Node version file to pass to setup-vp - required: false - default: .node-version - cache: - description: Restore and save package-manager dependencies for this job - required: false - default: "true" - -runs: - using: composite - steps: - - name: Read Vite+ version - id: versions - shell: bash - run: | - version=$(sed -n 's/^ vite-plus: //p' pnpm-workspace.yaml) - test -n "$version" - echo "vite-plus-version=${version}" >> "$GITHUB_OUTPUT" - - - name: Set up Vite+ - uses: voidzero-dev/setup-vp@2dec1e33f4ab2c6d5bce1b0c4607961bb1a3f7a1 # v1.12.0 - with: - version: ${{ steps.versions.outputs.vite-plus-version }} - node-version-file: ${{ inputs.node-version-file }} - cache: ${{ inputs.cache }} diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 1a8d45e..a92ce0e 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -4,6 +4,8 @@ updates: directory: / schedule: interval: monthly + cooldown: + default-days: 1 groups: actions-patch-minor: update-types: ["patch", "minor"] diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index bd7ac24..78fa22e 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -28,8 +28,9 @@ jobs: persist-credentials: false - name: Set up Vite+ - uses: ./.github/actions/setup-vp + uses: voidzero-dev/setup-vp@3754dd7dbdb32bd8f6d28b6043de13ad3a75f21f # v1.21.1 with: + run-install: false node-version-file: ".node-version" cache: true @@ -41,84 +42,11 @@ jobs: release: if: github.event_name == 'push' && github.ref == 'refs/heads/main' && !contains(github.event.head_commit.message, '[skip ci]') - name: Release vref needs: - verify - runs-on: ubuntu-latest # npm Trusted Publishing rejects self-hosted runners - timeout-minutes: 20 - concurrency: - group: release-${{ github.repository }}-main - cancel-in-progress: false - environment: - name: release - deployment: false permissions: contents: read id-token: write - - steps: - - name: Create release bot token - id: release-bot - uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0 - with: - client-id: ${{ vars.PUTIO_RELEASE_BOT_CLIENT_ID }} - private-key: ${{ secrets.PUTIO_RELEASE_BOT_PRIVATE_KEY }} - permission-contents: write - permission-issues: write - permission-pull-requests: write - - - name: Resolve release bot identity - id: release-bot-identity - shell: bash - env: - GH_TOKEN: ${{ steps.release-bot.outputs.token }} - APP_SLUG: ${{ steps.release-bot.outputs.app-slug }} - run: | - set -euo pipefail - user_id="$(gh api "/users/${APP_SLUG}%5Bbot%5D" --jq .id)" - if [[ ! "$user_id" =~ ^[0-9]+$ ]]; then - echo "failed to resolve numeric bot user id for ${APP_SLUG}[bot]" >&2 - exit 1 - fi - echo "user_id=${user_id}" >> "$GITHUB_OUTPUT" - - - name: Check out repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - fetch-depth: 0 - persist-credentials: false - - - name: Set up Vite+ - uses: ./.github/actions/setup-vp - with: - node-version-file: ".node-version" - cache: false - - - name: Install dependencies - run: vp install - - - name: Build release artifacts - run: vp run build - - - name: Configure release bot remote - run: git remote set-url origin "https://x-access-token:${RELEASE_BOT_TOKEN}@github.com/${GITHUB_REPOSITORY}.git" - env: - RELEASE_BOT_TOKEN: ${{ steps.release-bot.outputs.token }} - - - name: Release package - uses: cycjimmy/semantic-release-action@b12c8f6015dc215fe37bc154d4ad456dd3833c90 # v6.0.0 - with: - extra_plugins: | - @semantic-release/commit-analyzer@13.0.1 - @semantic-release/release-notes-generator@14.1.1 - @semantic-release/npm@13.1.5 - @semantic-release/github@12.0.8 - @semantic-release/git@10.0.1 - conventional-changelog-conventionalcommits@9.3.1 - env: - GITHUB_TOKEN: ${{ steps.release-bot.outputs.token }} - NPM_CONFIG_PROVENANCE: "true" - GIT_AUTHOR_NAME: ${{ steps.release-bot.outputs.app-slug }}[bot] - GIT_AUTHOR_EMAIL: ${{ steps.release-bot-identity.outputs.user_id }}+${{ steps.release-bot.outputs.app-slug }}[bot]@users.noreply.github.com - GIT_COMMITTER_NAME: ${{ steps.release-bot.outputs.app-slug }}[bot] - GIT_COMMITTER_EMAIL: ${{ steps.release-bot-identity.outputs.user_id }}+${{ steps.release-bot.outputs.app-slug }}[bot]@users.noreply.github.com + uses: putdotio/.github/.github/workflows/frontend-release-npm.yml@6694b278a64e6884b6518176dd2b008774ca6979 # v1.0.1 + secrets: + PUTIO_RELEASE_BOT_PRIVATE_KEY: ${{ secrets.PUTIO_RELEASE_BOT_PRIVATE_KEY }} diff --git a/.github/workflows/scan.yml b/.github/workflows/scan.yml new file mode 100644 index 0000000..5cbaa93 --- /dev/null +++ b/.github/workflows/scan.yml @@ -0,0 +1,19 @@ +name: Scan + +on: + pull_request: + schedule: + - cron: "41 6 * * 1" + workflow_dispatch: + +permissions: {} + +concurrency: + group: scan-${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true + +jobs: + scan: + permissions: + contents: read + uses: putdotio/.github/.github/workflows/frontend-scan.yml@6694b278a64e6884b6518176dd2b008774ca6979 # v1.0.1 diff --git a/.github/zizmor.yml b/.github/zizmor.yml new file mode 100644 index 0000000..54af406 --- /dev/null +++ b/.github/zizmor.yml @@ -0,0 +1,8 @@ +rules: + dependabot-cooldown: + config: + days: 1 + unpinned-uses: + config: + policies: + "*": hash-pin diff --git a/docs/DISTRIBUTION.md b/docs/DISTRIBUTION.md index b98304f..81e6200 100644 --- a/docs/DISTRIBUTION.md +++ b/docs/DISTRIBUTION.md @@ -10,6 +10,8 @@ Merges to `main` are publishable. Those two links are absolute because neither file ships in the tarball, where a relative link would dead-end. +The release job calls the [shared frontend release workflow](https://github.com/putdotio/.github/blob/main/frontend/README.md) from `putdotio/.github`, pinned to a tagged commit; the semantic-release action and plugin pins live there. [`scan.yml`](https://github.com/putdotio/vref/blob/main/.github/workflows/scan.yml) calls the shared frontend scan workflow from the same repository: Gitleaks, TruffleHog, Actionlint, and Zizmor on pull requests, weekly, and on manual dispatch. + Release expectations: - npm package: `@putdotio/vref`, public access