feat(ci): pass the notes boundary to GoReleaser, and make promotion strict

minor or major, nothing else. A manual patch would republish an identical
commit under the next patch number, and a version typed by hand is the one
way to get a release that does not follow from the tag before it.

Claude-Session: https://claude.ai/code/session_01ShuAy8q8ZfPi8KHxwc8JpQ
This commit is contained in:
pj committed 2026-08-16 15:16:13 +05:30
1 parent a45f645309
commit 83015d89f0
2 files changed
+16 -22

No files matched your search

+9 -14
View File
@@ -12,10 +12,6 @@ on:
description: Which part of MAJOR.MINOR.PATCH to advance description: Which part of MAJOR.MINOR.PATCH to advance
type: string type: string
default: patch default: patch
version:
description: Release this version outright, overriding the bump
type: string
default: ""
sha: sha:
description: >- description: >-
The commit to release. Empty means the commit the last release was cut The commit to release. Empty means the commit the last release was cut
@@ -49,6 +45,7 @@ jobs:
outputs: outputs:
version: ${{ steps.next.outputs.version }} version: ${{ steps.next.outputs.version }}
tag: ${{ steps.next.outputs.tag }} tag: ${{ steps.next.outputs.tag }}
previous_tag: ${{ steps.next.outputs.previous_tag }}
steps: steps:
- uses: actions/checkout@v7 - uses: actions/checkout@v7
with: with:
@@ -60,7 +57,6 @@ jobs:
run: .github/scripts/next-version.sh run: .github/scripts/next-version.sh
env: env:
BUMP: ${{ inputs.bump }} BUMP: ${{ inputs.bump }}
VERSION: ${{ inputs.version }}
# A promotion re-cuts the commit that is already released, so it needs no # A promotion re-cuts the commit that is already released, so it needs no
# ci run of its own: that commit is only tagged because ci went green on # ci run of its own: that commit is only tagged because ci went green on
@@ -141,18 +137,10 @@ jobs:
- name: Publish @sanderling/spec to npm - name: Publish @sanderling/spec to npm
if: steps.published.outputs.publish == 'true' if: steps.published.outputs.publish == 'true'
working-directory: pkg/spec working-directory: pkg/spec
# A pre-release is tagged `next` so `npm install @sanderling/spec` keeps run: npm publish --access public
# resolving the latest stable.
run: |
if [[ "$VERSION" == *-* ]]; then
npm publish --access public --tag next
else
npm publish --access public
fi
# The publish credential is scoped to the one step that publishes rather # The publish credential is scoped to the one step that publishes rather
# than to the job, so no other step runs with it in reach. # than to the job, so no other step runs with it in reach.
env: env:
VERSION: ${{ needs.tag.outputs.version }}
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
cli: cli:
@@ -196,6 +184,12 @@ jobs:
- name: Build sidecar JAR - name: Build sidecar JAR
run: make sidecar run: make sidecar
# GoReleaser reaches back to the release before this one on its own, which
# is right for a patch and wrong for a milestone: a promotion tags a commit
# that is already tagged, so the notes would cover the single merge that
# produced the last patch. GORELEASER_PREVIOUS_TAG moves that boundary back
# to the last release at this one's level, and an empty value leaves
# GoReleaser on its own default, which is what a patch passes.
- name: Publish the sanderling CLI to GitHub Releases - name: Publish the sanderling CLI to GitHub Releases
uses: goreleaser/goreleaser-action@f06c13b6b1a9625abc9e6e439d9c05a8f2190e94 # v7.2.3 uses: goreleaser/goreleaser-action@f06c13b6b1a9625abc9e6e439d9c05a8f2190e94 # v7.2.3
with: with:
@@ -203,3 +197,4 @@ jobs:
args: release --clean args: release --clean
env: env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
GORELEASER_PREVIOUS_TAG: ${{ needs.tag.outputs.previous_tag }}
+7 -8
View File
@@ -2,26 +2,26 @@ name: release
# Promotes the last release to a milestone. ci cuts a patch on every merge, so # Promotes the last release to a milestone. ci cuts a patch on every merge, so
# the released versions run 0.1.4, 0.1.5, 0.1.6; this marks the one you have # the released versions run 0.1.4, 0.1.5, 0.1.6; this marks the one you have
# been running as 0.2.0 and publishes it under that name. # been running as 0.2.0 and publishes it under that name. The release notes
# reach back over every patch being consolidated.
# #
# It runs no checks of its own and needs none. The commit it releases is the one # It runs no checks of its own and needs none. The commit it releases is the one
# the last release was cut from, and that commit only carries a tag because a # the last release was cut from, and that commit only carries a tag because a
# whole ci run went green on it. # whole ci run went green on it.
#
# There is no box to type a version into. The two entries below are the only two
# things a promotion can mean, and a version named by hand is the one way to get
# a release that does not follow from the tag before it.
on: on:
workflow_dispatch: workflow_dispatch:
inputs: inputs:
bump: bump:
description: Which part of MAJOR.MINOR.PATCH to advance description: Consolidate the patches since the last release at this level
type: choice type: choice
options: options:
- minor - minor
- major - major
- patch
default: minor default: minor
version:
description: Release this version outright, e.g. 1.0.0 or 1.0.0-rc1. Overrides the bump.
type: string
required: false
permissions: permissions:
contents: read contents: read
@@ -36,6 +36,5 @@ jobs:
contents: write contents: write
with: with:
bump: ${{ inputs.bump }} bump: ${{ inputs.bump }}
version: ${{ inputs.version }}
secrets: secrets:
NPM_TOKEN: ${{ secrets.NPM_TOKEN }} NPM_TOKEN: ${{ secrets.NPM_TOKEN }}