Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions .github/PULL_REQUEST_TEMPLATE.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,10 @@

---

Tag the title with `[major]`, `[minor]`, or `[patch]` to control the version bump. Defaults to `[patch]` if untagged.

---

## Linked issue (if any)
- Fixes #<issue-number>
<!-- If this PR does not fully fix the issue, use "Refs #<issue-number>" -->
Expand Down
136 changes: 0 additions & 136 deletions .github/workflows/deploy.yml

This file was deleted.

138 changes: 138 additions & 0 deletions .github/workflows/release-publish.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,138 @@
name: Publish Release

on:
pull_request:
types:
- closed

permissions:
contents: read

jobs:
cleanup-abandoned:
name: Delete abandoned release branch
if: >
github.event.pull_request.merged == false &&
startsWith(github.event.pull_request.head.ref, 'release/prep-')
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- name: Delete release branch
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
gh api -X DELETE "repos/${{ github.repository }}/git/refs/heads/${{ github.event.pull_request.head.ref }}" \
|| echo "Branch already gone, nothing to do."

deploy:
name: Tag and deploy to Maven Central
if: >
github.event.pull_request.merged == true &&
github.event.pull_request.base.ref == 'develop' &&
startsWith(github.event.pull_request.head.ref, 'release/prep-')
runs-on: ubuntu-latest
environment: deployment
permissions:
contents: write
outputs:
tag_name: ${{ steps.tag.outputs.tag_name }}
steps:
- name: Checkout develop
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
token: ${{ secrets.AUTO_MERGE_PAT }}
ref: develop
fetch-depth: 0

- name: Setup Java
uses: actions/setup-java@1bcf9fb12cf4aa7d266a90ae39939e61372fe520 # v5.4.0
with:
distribution: adopt
java-package: jdk
java-version: 17
server-id: central # must match the serverId configured for the nexus-staging-maven-plugin
server-username: MAVEN_USERNAME # Env var that holds the central publisher user name
server-password: MAVEN_CENTRAL_TOKEN # Env var that holds the central publisher user token
gpg-private-key: ${{ secrets.GPG_PRIVATE_KEY }} # Substituted with the value stored in the referenced secret
gpg-passphrase: MAVEN_GPG_PASSPHRASE # Env var that holds the key's passphrase

- name: Tag the just-merged release version
id: tag
run: |
set -euo pipefail
git config --global user.email "${{ github.actor }}@users.noreply.github.com"
git config --global user.name "${{ github.actor }}"

# develop's tip now holds whatever version the merged release PR brought in
CURRENT_VERSION=$(mvn -q -ntp org.apache.maven.plugins:maven-help-plugin:2.1.1:evaluate -Dexpression=project.version -DforceStdout)
TAG_NAME="v$CURRENT_VERSION"

git tag -a "$TAG_NAME" -m "version $CURRENT_VERSION"
git push origin "$TAG_NAME"

echo "tag_name=$TAG_NAME" >> "$GITHUB_OUTPUT"

- name: Deploy on Maven Central
run: |
# -U force updates just to make sure we are using latest dependencies
# -B Batch mode (do not ask for user input), just in case
# -D activate a profile via the release property (and disable defined submodules that should not be deployed)
mvn -U -B -ntp clean deploy -Drelease -DskipTests
env:
MAVEN_USERNAME: ${{ secrets.SONATYPE_USER }}
MAVEN_CENTRAL_TOKEN: ${{ secrets.SONATYPE_PW }}
MAVEN_GPG_PASSPHRASE: ${{ secrets.GPG_PRIVATE_KEY_PASSPHRASE }}

- name: Create GitHub release
run: |
gh release create "${{ steps.tag.outputs.tag_name }}" --title "${{ steps.tag.outputs.tag_name }}" --generate-notes
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}

bump-develop:
name: Advance develop to next SNAPSHOT
needs: deploy
runs-on: ubuntu-latest
permissions:
contents: read
steps:
- name: Checkout develop
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
token: ${{ secrets.AUTO_MERGE_PAT }}
ref: develop
fetch-depth: 0

- name: Setup Java
uses: actions/setup-java@1bcf9fb12cf4aa7d266a90ae39939e61372fe520 # v5.4.0
with:
distribution: zulu
java-version: '17'
cache: 'maven'

- name: Bump to next SNAPSHOT and open auto-merge PR
env:
GH_TOKEN: ${{ secrets.AUTO_MERGE_PAT }}
run: |
set -euo pipefail
git config --global user.email "${{ github.actor }}@users.noreply.github.com"
git config --global user.name "${{ github.actor }}"

BRANCH="chore/next-snapshot-${{ github.run_id }}"
git checkout -b "$BRANCH"

# Bumps forward from the version that was just released (develop's current tip), e.g. 2.4.0 -> 2.4.1-SNAPSHOT
mvn -B -ntp versions:set versions:commit -DnextSnapshot
git ls-files | grep 'pom.xml$' | xargs git add
git commit --allow-empty -am "prepare next development iteration"
git push origin "$BRANCH"

gh pr create \
-B develop \
-H "$BRANCH" \
-t "Prepare next development iteration after ${{ needs.deploy.outputs.tag_name }}" \
-b "Advances develop's SNAPSHOT version following the ${{ needs.deploy.outputs.tag_name }} release."

PR_NUMBER=$(gh pr view "$BRANCH" --json number -q .number)
gh pr merge "$PR_NUMBER" --auto --merge --delete-branch
96 changes: 96 additions & 0 deletions .github/workflows/release-refresh.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,96 @@
name: Refresh release branch from develop

on:
issue_comment:
types:
- created

permissions:
contents: read

concurrency:
group: release-refresh-${{ github.event.issue.number }}
cancel-in-progress: true

jobs:
refresh:
name: Rebase release branch onto develop
if: github.event.issue.pull_request != null
runs-on: ubuntu-latest
permissions:
contents: read
pull-requests: read
issues: write
steps:
- name: Check command, target branch and commenter permission
id: check
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
COMMENT_BODY: ${{ github.event.comment.body }}
COMMENTER: ${{ github.event.comment.user.login }}
PR_NUMBER: ${{ github.event.issue.number }}
run: |
set -euo pipefail
BODY_TRIMMED=$(echo "$COMMENT_BODY" | tr -d '[:space:]' | tr '[:upper:]' '[:lower:]')

case "$BODY_TRIMMED" in
/refresh|/rebase|/update) ;;
*)
echo "Comment is not a refresh command, ignoring."
echo "proceed=false" >> "$GITHUB_OUTPUT"
exit 0
;;
esac

HEAD_REF=$(gh pr view "$PR_NUMBER" --json headRefName -q .headRefName)
if [[ "$HEAD_REF" != release/prep-* ]]; then
echo "Not a release PR (head ref '$HEAD_REF'), ignoring."
echo "proceed=false" >> "$GITHUB_OUTPUT"
exit 0
fi

PERMISSION=$(gh api "repos/${{ github.repository }}/collaborators/$COMMENTER/permission" -q .permission)
if [[ "$PERMISSION" != "admin" && "$PERMISSION" != "write" ]]; then
echo "$COMMENTER lacks write access ($PERMISSION), ignoring command."
echo "proceed=false" >> "$GITHUB_OUTPUT"
exit 0
fi

echo "proceed=true" >> "$GITHUB_OUTPUT"
echo "head_ref=$HEAD_REF" >> "$GITHUB_OUTPUT"

- name: React to comment
if: steps.check.outputs.proceed == 'true'
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
gh api "repos/${{ github.repository }}/issues/comments/${{ github.event.comment.id }}/reactions" -f content='+1'

- name: Checkout release branch
if: steps.check.outputs.proceed == 'true'
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
token: ${{ secrets.AUTO_MERGE_PAT }} # default GITHUB_TOKEN is blocked by branch protection
ref: ${{ steps.check.outputs.head_ref }}
fetch-depth: 0

- name: Rebase release branch onto develop
Comment thread
swissiety marked this conversation as resolved.
Dismissed
id: rebase
if: steps.check.outputs.proceed == 'true'
run: |
set -euo pipefail
git config --global user.email "${{ github.actor }}@users.noreply.github.com"
git config --global user.name "${{ github.actor }}"

git fetch origin develop
# release branch holds exactly one commit (the version bump, possibly amended by
# release-title-sync) - rebasing replays it on top of develop so it's the last commit again.
git rebase origin/develop
git push --force origin HEAD:"${{ steps.check.outputs.head_ref }}"
Comment thread
github-advanced-security[bot] marked this conversation as resolved.
Fixed

- name: Report rebase conflict
if: steps.check.outputs.proceed == 'true' && failure()
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
gh pr comment "${{ github.event.issue.number }}" --body "Rebase onto \`develop\` hit conflicts and needs manual resolution."
Loading
Loading