Reusable GitHub Actions workflows for the Kooker ecosystem.
Important
This repository must remain public.
GitHub's reusable workflow rules only allow private repositories to call reusable workflows
from the same repository. Cross-repository calls — even within the same org — require the
workflow source to be either public (all GitHub plans) or internal (GitHub Enterprise Cloud only).
kooker-workflows contains no secrets or proprietary code; keeping it public is safe and is the
standard pattern for shared workflow libraries.
Bumps pom.xml version on every merge to main based on the Conventional Commit prefix.
| Commit prefix | Bump | Example |
|---|---|---|
fix: |
PATCH | 1.0.0 → 1.0.1 |
feat: |
MINOR | 1.0.0 → 1.1.0 |
feat!: / BREAKING CHANGE |
MAJOR | 1.0.0 → 2.0.0 |
chore: / ci: / docs: / test: |
none | — |
Loop prevention: commits starting with chore(release): are skipped.
Inputs: none
Secrets: GITHUB_TOKEN (from secrets: inherit)
Outputs: new-version, bumped
jobs:
version-bump:
uses: duikindiesee/kooker-workflows/.github/workflows/maven-version-bump.yml@main
secrets: inheritBumps versionName and versionCode in {app-dir}/app/build.gradle based on the same Conventional Commit rules.
versionCode scheme: MAJOR×100 + MINOR×10 + PATCH (e.g. 1.2.3 → 123).
Inputs:
| Input | Required | Description |
|---|---|---|
app-dir |
✅ | Subdirectory containing the Android project |
Outputs: new-version, new-version-code, bumped
jobs:
version-bump:
uses: duikindiesee/kooker-workflows/.github/workflows/android-version-bump.yml@main
with:
app-dir: my-app
secrets: inherit
permissions:
contents: writeDetects new or modified SQL migration files in a PR. Outputs has_db_changes=true which downstream jobs use to decide whether a DB-aware version bump is needed.
Inputs:
| Input | Required | Default | Description |
|---|---|---|---|
migration-path |
❌ | src/main/resources/db/migration |
Path to Flyway migrations directory |
Outputs: has_db_changes ('true' / 'false')
jobs:
flyway-lint:
uses: duikindiesee/kooker-workflows/.github/workflows/flyway-lint.yml@main
with:
migration-path: my-module/src/main/resources/db/migrationFails a pull request before any build/package/release work begins when an in-scope Maven project's
configured release/source/target/toolchain drops below the org baseline (default 25). Two
layers: a fast offline static scan of committed pom.xml/toolchains.xml files
(scripts/check-jdk25-baseline.sh, independently unit-tested — run bash tests/check-jdk25-baseline.test.sh), then — only for a project that declares nothing of its own and
relies on parent-POM inheritance — a live mvn help:evaluate effective-configuration cross-check.
See docs/jdk25-baseline-adoption.md for the full repository
inventory, current compliance state, and the two-layer design rationale.
Inputs:
| Input | Required | Default | Description |
|---|---|---|---|
minimum-java-version |
❌ | 25 |
Minimum acceptable Java release/source/target/toolchain version |
workflows-ref |
❌ | main |
kooker-workflows ref to source the guard script from |
Outputs: result ('pass' / 'fail')
Secrets: MAVEN_PUBLISH_TOKEN — only consulted when the effective-configuration cross-check runs
(i.e. only for a project that declares nothing of its own), to resolve kooker-parent-build from
GitHub Packages. Same secret maven-version-bump.yml already uses for this.
jobs:
jdk25-guard:
uses: duikindiesee/kooker-workflows/.github/workflows/jdk25-baseline-guard.yml@main
build:
needs: jdk25-guard
# ...existing build/package job, unchanged...Tags the repo with a semver version on merge. Distinguishes DB-breaking changes (4-part version vX.Y.Z.N) from regular patches.
Inputs:
| Input | Required | Description |
|---|---|---|
has-db-changes |
✅ | Pass output of flyway-lint |
jobs:
tag:
uses: duikindiesee/kooker-workflows/.github/workflows/auto-version.yml@main
with:
has-db-changes: ${{ needs.flyway-lint.outputs.has_db_changes }}
secrets: inheritValidates that the OpenAPI spec compiles against the Spring Boot app. Fails the PR if the spec is inconsistent.
Inputs:
| Input | Required | Default |
|---|---|---|
java-version |
❌ | 21 |
jobs:
validate:
uses: duikindiesee/kooker-workflows/.github/workflows/swagger-enforce.yml@mainFor all repos in duikindiesee to consume these workflows, the org must have:
Settings → Actions → General → Actions permissions
→ Allow all actions and reusable workflows
Settings → Actions → General → Workflow permissions
→ Read and write permissions ✅
→ Allow GitHub Actions to create and approve pull requests ✅
Without read/write, maven-version-bump and android-version-bump cannot push the version bump commit back to the branch.
- Create
.github/workflows/<name>.ymlwithon: workflow_call:trigger - Document inputs, outputs, and secrets in this README
- Add the calling snippet to the consumer repo's workflow
- Open a PR — the workflow is available to all
duikindieseerepos as soon as it merges tomain
Do not make this repo private. See the note at the top for why.