Repository navigation
ci(release): derive versions from commits, check commit messages, pin the supply chain - #17
Merged
Merged
Conversation
…efore tagging The release job now builds the binaries and the image before the tag exists, pushes the tag only after a fresh remote check, and publishes under one rule: a published artifact is reused only once proven to be this run's and is never replaced. The create-tag and cleanup-tag steps are gone; they cannot work under the immutable-tag ruleset. The required semver input is replaced by an optional version input, derived with svu when empty, and a dry_run input.
Every uses reference in the four workflows is now a full commit SHA with the version in a trailing comment, including the reusable pre-commit warm-up workflow and gha-pre-commit-reviewdog-actions v1.0.1, whose composite actions now pin their own nested actions. The warm-up workflow's nested actions are still tag-pinned upstream, and their cache writes can reach the release job; docs/release.md records that exposure and its fix. Dependabot's gomod updates now use the fix(deps) prefix, so a Go dependency bump produces a patch release.
gh-reusable-workflows v1.2.1 pins the checkout, setup-python and cache actions it runs. The warm-up job writes the master cache scope that the release job restores, so those tag-pinned actions were the last mutable ref that could reach a release. docs/release.md drops the remaining-exposure note.
6 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Release versions are now derived from Conventional Commits. The release workflow is rewritten so a failed run can be recovered under the "Immutable tags" ruleset. Commit messages are checked in CI, and the supply chain is pinned.
docs/release.md(new) explains the whole flow.Commits
build(pre-commit): theend-of-file-fixerandtrailing-whitespacehooks skiptestdata/, because theinternal/cgroup/testdatafixtures are byte-for-byte/proccaptures. The config now also documents why the commit-msg hook is installed.ci(ci): newconventional-commitsjob, on pull requests only. It runs the repo's ownconventional-pre-commithook,--force-scopeincluded, on every non-merge commit in the PR. There is no PR-title check, because squash merging is disabled.ci(release):.github/workflows/release.yamlrewritten:versionis optional; left empty, it is derived withsvu, and a range with nofeat/fix/breaking commit fails. It replaces the requiredsemverinput.dry_runis new.guardjob refuses any ref butmaster. Thetest,auditandintegrationjobs rerun the CI checks inside the release, all with Go taken fromgo.mod.:<version>tag is reused only aftergh attestation verifybinds it to this repo, this workflow and this commit. Otherwise the run stops.--clobber.:latest,:<major>and the GitHub "Latest" marker move only if the version is still the highest when each one moves. A warning fires if they end up disagreeing.SOURCE_DATE_EPOCHand a fixed-length short SHA all come from the commit.build(docker): both base images are pinned astag@sha256. Dependabot keeps them moving.ci(deps): everyuses:is pinned to a full commit SHA.gha-pre-commit-reviewdog-actionsis pinned at v1.0.1, which now pins its own nested actions. Dependabot'sgomodprefix is nowfix(deps), so Go dependency bumps produce patch releases.ci(deps): the warm-up workflow is pinned togh-reusable-workflowsv1.2.1, which pins its owncheckout,setup-pythonandcacheactions. That closes the last mutable ref that could reach the release job, through themastercache scope. This is documented indocs/release.mdunder "What the workflows trust".Follow-ups after this PR
conventional-commitshas run here, add it as a required status check on themasterruleset16797240(seedocs/release.md).masterdeployment-branch rule to thereleaseenvironment.Releasewithdry_run: true:build/docs;0.10.1: expect the full build, and no tag or image published.0.10.1) needs an explicit version.Verification done locally
pre-commitpasses on every commit. actionlint with shellcheck at style level is clean onrelease.yaml.v1.0.0tag,svu nextgives v0.10.0 (no bump), v0.10.1 after afix, and v0.11.0 after afeat.make docker-buildsucceeds with the digest-pinned bases.Pull request checklist
masterbranchmake checklocally before creating the commit and it has run successfullyWIPcommits in this PRType of changes