feat(security): add a hash-based CSP and security headers to HTML pag… #35
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Auto Release | |
| on: | |
| push: | |
| branches: [main] | |
| workflow_dispatch: | |
| inputs: | |
| allow_major: | |
| description: 'Cut a major release. Leave off unless a major is deliberately intended.' | |
| type: boolean | |
| default: false | |
| permissions: | |
| contents: write | |
| jobs: | |
| version: | |
| name: Determine Version | |
| runs-on: ubuntu-latest | |
| if: "!startsWith(github.event.head_commit.message, 'chore(release):')" | |
| outputs: | |
| tag: ${{ steps.version.outputs.next }} | |
| version: ${{ steps.version.outputs.version }} | |
| steps: | |
| - uses: actions/checkout@v4 | |
| with: | |
| fetch-depth: 0 | |
| - name: Setup pnpm | |
| uses: pnpm/action-setup@v4 | |
| - name: Setup Node.js | |
| uses: actions/setup-node@v4 | |
| with: | |
| node-version: '22' | |
| cache: 'pnpm' | |
| - name: Install Just | |
| uses: extractions/setup-just@v2 | |
| - name: Determine next version | |
| id: version | |
| env: | |
| ALLOW_MAJOR: ${{ inputs.allow_major || false }} | |
| run: | | |
| latest_tag=$(git describe --tags --abbrev=0 2>/dev/null || echo "v0.0.0") | |
| echo "latest=$latest_tag" >> "$GITHUB_OUTPUT" | |
| commits=$(git log "$latest_tag"..HEAD --pretty=format:"%s" 2>/dev/null || git log --pretty=format:"%s") | |
| printf '%s\n' "$commits" \ | |
| | ./scripts/next-version.sh "$latest_tag" "$ALLOW_MAJOR" > version.out | |
| cat version.out >> "$GITHUB_OUTPUT" | |
| version=$(grep '^version=' version.out | cut -d= -f2) | |
| bump=$(grep '^bump=' version.out | cut -d= -f2) | |
| suppressed=$(grep '^suppressed_major=' version.out | cut -d= -f2) | |
| rm -f version.out | |
| echo "next=v$version" >> "$GITHUB_OUTPUT" | |
| if [ "$suppressed" = "true" ]; then | |
| echo "::warning::A breaking-change marker was found in the commits since $latest_tag, but automatic major bumps are disabled. Releasing v$version as a $bump instead. To cut a major, run this workflow manually with allow_major enabled." | |
| fi | |
| echo "Next version: v$version ($bump, from $latest_tag)" | |
| - name: Install dependencies | |
| run: pnpm install --frozen-lockfile | |
| - name: Update versions | |
| run: just set-version ${{ steps.version.outputs.version }} | |
| - name: Verify | |
| run: | | |
| just typecheck | |
| just test-run | |
| - name: Commit and tag | |
| env: | |
| TAG: ${{ steps.version.outputs.next }} | |
| VERSION: ${{ steps.version.outputs.version }} | |
| run: | | |
| git config user.name "github-actions[bot]" | |
| git config user.email "github-actions[bot]@users.noreply.github.com" | |
| git add -A | |
| git commit -m "chore(release): bump version to v$VERSION" | |
| git tag -a "$TAG" -m "Release $TAG" | |
| git push origin main --follow-tags | |
| release: | |
| name: Create Release | |
| needs: version | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| with: | |
| ref: ${{ needs.version.outputs.tag }} | |
| fetch-depth: 0 | |
| - name: Generate changelog | |
| uses: orhun/git-cliff-action@v4 | |
| id: changelog | |
| with: | |
| config: cliff.toml | |
| args: --latest --strip header | |
| env: | |
| OUTPUT: CHANGELOG.md | |
| - name: Create GitHub Release | |
| uses: softprops/action-gh-release@v2 | |
| with: | |
| tag_name: ${{ needs.version.outputs.tag }} | |
| body: ${{ steps.changelog.outputs.content }} | |
| draft: false | |
| prerelease: false |