-
Notifications
You must be signed in to change notification settings - Fork 78
130 lines (125 loc) · 5.15 KB
/
Copy pathdispatch_release.yml
File metadata and controls
130 lines (125 loc) · 5.15 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
# Generated by reflex-release; do not edit by hand.
# Re-run `uvx reflex-release@0.1.0a4 sync` after changing [tool.reflex-release] in
# pyproject.toml. `uvx reflex-release@0.1.0a4 sync --check` fails when this file drifts.
name: Dispatch release
# Kicks off a release by materializing news fragments into the selected
# packages' CHANGELOG.md files at the next version — the changelogs are the
# source of truth for publishing (see release_from_changelog.yml, which builds
# any changelog version that has no git tag yet and uploads it once the pypi
# environment deployment is approved).
#
# Selecting no package auto-selects the ones to release: those with pending
# news fragments — or, for release-from-prerelease, those whose changelog is
# topped by an alpha (the train's fragments are already consumed). Lockstep
# groups share one checkbox: their members only ever release together.
#
# The package list is generated from [tool.reflex-release] — after adding or
# removing a package, re-run `uvx reflex-release@0.1.0a4 sync`.
#
# Prerelease actions (new-prerelease-*, continued-prerelease) write alpha
# versions and push them straight to an r/pre-<date> branch
# (continued prereleases push back to the r/pre-* branch the
# workflow was dispatched on); alphas build immediately and upload after pypi
# environment approval — no PR review involved. To pull new work into a
# prerelease train, merge main into the branch, then dispatch
# continued-prerelease on it.
#
# Release actions (release-*) open a pull request with the changelog changes
# instead — reviewing and merging that PR is how final versions land for
# publishing. The PR targets main, or the r/hotfix/**
# branch the workflow was dispatched on (hotfix branches may publish final
# versions directly). release-from-prerelease collapses the accumulated alpha
# sections into the single final-version section, so alpha headings never
# appear in a published final changelog.
#
# Materializing changelogs never publishes by itself: every upload — alphas
# included — additionally requires approval by the `pypi` environment's
# required reviewers (see publish.yml).
#
# REQUIRED CONFIGURATION:
# - The `pypi` environment must have required reviewers (asserted, fail
# closed, by publish.yml).
# - "Allow GitHub Actions to create and approve pull requests" must be enabled
# in the repo's Actions settings for release-* actions to open PRs.
# - Branch protection on main should require review; merging a
# release PR is what lands final versions for publishing.
# - Recommended: a ruleset restricting who can create/push
# r/pre-**, r/hotfix/** and
# release/** branches to maintainers plus the github-actions[bot]
# app (this workflow pushes as github-actions[bot] via GITHUB_TOKEN).
on:
workflow_dispatch:
inputs:
action:
description: "Release action"
required: true
type: choice
# default is continued-prerelease to prevent accidental releases.
default: continued-prerelease
options:
- new-prerelease-patch
- new-prerelease-minor
- new-prerelease-major
- continued-prerelease
- release-from-prerelease
- release-post
- release-patch
- release-minor
- release-major
xy:
description: "xy"
type: boolean
default: false
permissions:
contents: read
concurrency:
group: dispatch-release-${{ github.ref }}
cancel-in-progress: false
jobs:
materialize:
runs-on: ubuntu-latest
permissions:
contents: write
pull-requests: write
actions: write
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
fetch-tags: true
fetch-depth: 0
persist-credentials: false
- uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0
- name: Plan versions
id: plan
env:
ACTION: ${{ inputs.action }}
# Each unselected package contributes an empty string, so selecting
# nothing leaves PACKAGES blank and the planner auto-selects.
PACKAGES: >-
${{ inputs.xy && 'xy' || '' }}
shell: bash
run: uvx reflex-release@0.1.0a4 plan
- name: Materialize changelogs
env:
ACTION: ${{ inputs.action }}
RELEASES_JSON: ${{ steps.plan.outputs.releases }}
shell: bash
run: uvx reflex-release@0.1.0a4 materialize
- name: Push prerelease branch
if: ${{ !startsWith(inputs.action, 'release-') }}
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
ACTION: ${{ inputs.action }}
REF_NAME: ${{ github.ref_name }}
RELEASES_JSON: ${{ steps.plan.outputs.releases }}
shell: bash
run: uvx reflex-release@0.1.0a4 push-prerelease
- name: Open release pull request
if: ${{ startsWith(inputs.action, 'release-') }}
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
ACTION: ${{ inputs.action }}
REF_NAME: ${{ github.ref_name }}
RELEASES_JSON: ${{ steps.plan.outputs.releases }}
shell: bash
run: uvx reflex-release@0.1.0a4 open-release-pr