Skip to content

feat(security): add a hash-based CSP and security headers to HTML pag… #35

feat(security): add a hash-based CSP and security headers to HTML pag…

feat(security): add a hash-based CSP and security headers to HTML pag… #35

Workflow file for this run

name: Auto Release
on:
push:
branches: [main]
workflow_dispatch:
inputs:
allow_major:
description: 'Cut a major release. Leave off unless a major is deliberately intended.'
type: boolean
default: false
permissions:
contents: write
jobs:
version:
name: Determine Version
runs-on: ubuntu-latest
if: "!startsWith(github.event.head_commit.message, 'chore(release):')"
outputs:
tag: ${{ steps.version.outputs.next }}
version: ${{ steps.version.outputs.version }}
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Setup pnpm
uses: pnpm/action-setup@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: '22'
cache: 'pnpm'
- name: Install Just
uses: extractions/setup-just@v2
- name: Determine next version
id: version
env:
ALLOW_MAJOR: ${{ inputs.allow_major || false }}
run: |
latest_tag=$(git describe --tags --abbrev=0 2>/dev/null || echo "v0.0.0")
echo "latest=$latest_tag" >> "$GITHUB_OUTPUT"
commits=$(git log "$latest_tag"..HEAD --pretty=format:"%s" 2>/dev/null || git log --pretty=format:"%s")
printf '%s\n' "$commits" \
| ./scripts/next-version.sh "$latest_tag" "$ALLOW_MAJOR" > version.out
cat version.out >> "$GITHUB_OUTPUT"
version=$(grep '^version=' version.out | cut -d= -f2)
bump=$(grep '^bump=' version.out | cut -d= -f2)
suppressed=$(grep '^suppressed_major=' version.out | cut -d= -f2)
rm -f version.out
echo "next=v$version" >> "$GITHUB_OUTPUT"
if [ "$suppressed" = "true" ]; then
echo "::warning::A breaking-change marker was found in the commits since $latest_tag, but automatic major bumps are disabled. Releasing v$version as a $bump instead. To cut a major, run this workflow manually with allow_major enabled."
fi
echo "Next version: v$version ($bump, from $latest_tag)"
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Update versions
run: just set-version ${{ steps.version.outputs.version }}
- name: Verify
run: |
just typecheck
just test-run
- name: Commit and tag
env:
TAG: ${{ steps.version.outputs.next }}
VERSION: ${{ steps.version.outputs.version }}
run: |
git config user.name "github-actions[bot]"
git config user.email "github-actions[bot]@users.noreply.github.com"
git add -A
git commit -m "chore(release): bump version to v$VERSION"
git tag -a "$TAG" -m "Release $TAG"
git push origin main --follow-tags
release:
name: Create Release
needs: version
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
with:
ref: ${{ needs.version.outputs.tag }}
fetch-depth: 0
- name: Generate changelog
uses: orhun/git-cliff-action@v4
id: changelog
with:
config: cliff.toml
args: --latest --strip header
env:
OUTPUT: CHANGELOG.md
- name: Create GitHub Release
uses: softprops/action-gh-release@v2
with:
tag_name: ${{ needs.version.outputs.tag }}
body: ${{ steps.changelog.outputs.content }}
draft: false
prerelease: false