|
1 | | -name: Release |
| 1 | +name: Release Action |
2 | 2 |
|
3 | 3 | on: |
4 | 4 | workflow_dispatch: |
|
31 | 31 | with: |
32 | 32 | ref: main |
33 | 33 | fetch-depth: 0 |
34 | | - token: ${{ secrets.PAT || secrets.GITHUB_TOKEN }} |
35 | | - persist-credentials: true |
| 34 | + persist-credentials: false |
36 | 35 |
|
37 | 36 | - name: Determine version and scheme |
38 | 37 | id: version |
@@ -67,11 +66,17 @@ jobs: |
67 | 66 | fi |
68 | 67 | fi |
69 | 68 |
|
70 | | - - name: Create and push tag |
| 69 | + # Local tag is needed for changelog generation; remote ref is created via the API |
| 70 | + - name: Create tag |
71 | 71 | if: github.event_name == 'workflow_dispatch' |
| 72 | + env: |
| 73 | + GH_TOKEN: ${{ secrets.PAT || secrets.GITHUB_TOKEN }} |
| 74 | + TAG: ${{ steps.version.outputs.tag }} |
72 | 75 | run: | |
73 | | - git tag "${{ steps.version.outputs.tag }}" |
74 | | - git push origin "${{ steps.version.outputs.tag }}" |
| 76 | + git tag "$TAG" |
| 77 | + gh api "repos/${GITHUB_REPOSITORY}/git/refs" \ |
| 78 | + -f ref="refs/tags/${TAG}" \ |
| 79 | + -f sha="$(git rev-parse HEAD)" |
75 | 80 |
|
76 | 81 | - name: Get previous tag |
77 | 82 | id: previous |
@@ -116,10 +121,14 @@ jobs: |
116 | 121 | useGitmojis: false |
117 | 122 | writeToFile: true |
118 | 123 |
|
| 124 | + # Commits via the GitHub API are signed by GitHub and show as Verified |
119 | 125 | - name: Commit updated CHANGELOG |
120 | 126 | if: steps.previous.outputs.found == 'true' |
121 | | - uses: stefanzweifel/git-auto-commit-action@v7 |
| 127 | + uses: planetscale/ghcommit-action@v0.2.22 |
122 | 128 | with: |
123 | | - branch: main |
124 | 129 | commit_message: "docs: update CHANGELOG for ${{ steps.version.outputs.tag }}" |
| 130 | + repo: ${{ github.repository }} |
| 131 | + branch: main |
125 | 132 | file_pattern: CHANGELOG.md |
| 133 | + env: |
| 134 | + GITHUB_TOKEN: ${{ secrets.PAT || secrets.GITHUB_TOKEN }} |
0 commit comments