mirror of
https://github.com/toeverything/AFFiNE.git
synced 2026-08-02 18:09:58 +08:00
1f58173800
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/checkout](https://redirect.github.com/actions/checkout) | action | major | `v6` → `v7` | --- ### Release Notes <details> <summary>actions/checkout (actions/checkout)</summary> ### [`v7.0.1`](https://redirect.github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v701) [Compare Source](https://redirect.github.com/actions/checkout/compare/v7.0.0...v7.0.1) - Bump github/codeql-action from 3 to 4 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2475](https://redirect.github.com/actions/checkout/pull/2475) - Bump actions/setup-node from 4 to 6 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2477](https://redirect.github.com/actions/checkout/pull/2477) - Bump docker/build-push-action from 6.5.0 to 7.2.0 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2478](https://redirect.github.com/actions/checkout/pull/2478) - Bump docker/login-action from 3.3.0 to 4.2.0 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2479](https://redirect.github.com/actions/checkout/pull/2479) - Bump actions/checkout from 6 to 7 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2488](https://redirect.github.com/actions/checkout/pull/2488) - Bump actions/upload-artifact from 4 to 7 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2476](https://redirect.github.com/actions/checkout/pull/2476) - eslint 9 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2474](https://redirect.github.com/actions/checkout/pull/2474) - Bump the minor-actions-dependencies group with 2 updates by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2499](https://redirect.github.com/actions/checkout/pull/2499) - skip running unsafe pr check if input is default by [@​aiqiaoy](https://redirect.github.com/aiqiaoy) in [#​2518](https://redirect.github.com/actions/checkout/pull/2518) - trim only ascii whitespace for branch by [@​aiqiaoy](https://redirect.github.com/aiqiaoy) in [#​2521](https://redirect.github.com/actions/checkout/pull/2521) - escape values passed to --unset by [@​aiqiaoy](https://redirect.github.com/aiqiaoy) in [#​2530](https://redirect.github.com/actions/checkout/pull/2530) ### [`v7.0.0`](https://redirect.github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v700) [Compare Source](https://redirect.github.com/actions/checkout/compare/v7.0.0...v7.0.0) - Block checking out fork PR for pull\_request\_target and workflow\_run by [@​aiqiaoy](https://redirect.github.com/aiqiaoy) in [#​2454](https://redirect.github.com/actions/checkout/pull/2454) - Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the minor-actions-dependencies group across 1 directory by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2458](https://redirect.github.com/actions/checkout/pull/2458) - Bump flatted from 3.3.1 to 3.4.2 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2460](https://redirect.github.com/actions/checkout/pull/2460) - Bump js-yaml from 4.1.0 to 4.2.0 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2461](https://redirect.github.com/actions/checkout/pull/2461) - Bump [@​actions/core](https://redirect.github.com/actions/core) and [@​actions/tool-cache](https://redirect.github.com/actions/tool-cache) and Remove uuid by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2459](https://redirect.github.com/actions/checkout/pull/2459) - upgrade module to esm and update dependencies by [@​aiqiaoy](https://redirect.github.com/aiqiaoy) in [#​2463](https://redirect.github.com/actions/checkout/pull/2463) - Bump the minor-npm-dependencies group across 1 directory with 3 updates by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2462](https://redirect.github.com/actions/checkout/pull/2462) ### [`v7`](https://redirect.github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v700) [Compare Source](https://redirect.github.com/actions/checkout/compare/v6.1.0...v7.0.0) - Block checking out fork PR for pull\_request\_target and workflow\_run by [@​aiqiaoy](https://redirect.github.com/aiqiaoy) in [#​2454](https://redirect.github.com/actions/checkout/pull/2454) - Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the minor-actions-dependencies group across 1 directory by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2458](https://redirect.github.com/actions/checkout/pull/2458) - Bump flatted from 3.3.1 to 3.4.2 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2460](https://redirect.github.com/actions/checkout/pull/2460) - Bump js-yaml from 4.1.0 to 4.2.0 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2461](https://redirect.github.com/actions/checkout/pull/2461) - Bump [@​actions/core](https://redirect.github.com/actions/core) and [@​actions/tool-cache](https://redirect.github.com/actions/tool-cache) and Remove uuid by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2459](https://redirect.github.com/actions/checkout/pull/2459) - upgrade module to esm and update dependencies by [@​aiqiaoy](https://redirect.github.com/aiqiaoy) in [#​2463](https://redirect.github.com/actions/checkout/pull/2463) - Bump the minor-npm-dependencies group across 1 directory with 3 updates by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2462](https://redirect.github.com/actions/checkout/pull/2462) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zLjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC4zLjIiLCJ0YXJnZXRCcmFuY2giOiJjYW5hcnkiLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
212 lines
7.0 KiB
YAML
212 lines
7.0 KiB
YAML
name: Release
|
|
|
|
on:
|
|
schedule:
|
|
- cron: '0 9 * * *'
|
|
|
|
workflow_dispatch:
|
|
inputs:
|
|
web:
|
|
description: 'Release Web?'
|
|
required: true
|
|
type: boolean
|
|
default: false
|
|
desktop_macos:
|
|
description: 'Desktop - macOS'
|
|
required: true
|
|
type: boolean
|
|
default: false
|
|
desktop_windows:
|
|
description: 'Desktop - Windows'
|
|
required: true
|
|
type: boolean
|
|
default: false
|
|
desktop_linux:
|
|
description: 'Desktop - Linux'
|
|
required: true
|
|
type: boolean
|
|
default: false
|
|
mobile:
|
|
description: 'Release Mobile?'
|
|
required: true
|
|
type: boolean
|
|
default: false
|
|
ios-app-version:
|
|
description: 'iOS App Store Version (Optional, use tag version if empty)'
|
|
required: false
|
|
type: string
|
|
|
|
permissions:
|
|
contents: write
|
|
pull-requests: write
|
|
actions: write
|
|
id-token: write
|
|
packages: write
|
|
security-events: write
|
|
attestations: write
|
|
issues: write
|
|
|
|
jobs:
|
|
prepare:
|
|
name: Prepare
|
|
runs-on: ubuntu-latest
|
|
outputs:
|
|
APP_VERSION: ${{ steps.prepare.outputs.APP_VERSION }}
|
|
GIT_SHORT_HASH: ${{ steps.prepare.outputs.GIT_SHORT_HASH }}
|
|
BUILD_TYPE: ${{ steps.prepare.outputs.BUILD_TYPE }}
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
- name: Prepare Release
|
|
id: prepare
|
|
uses: ./.github/actions/prepare-release
|
|
|
|
canary-gate:
|
|
name: Canary Gate
|
|
runs-on: ubuntu-latest
|
|
needs:
|
|
- prepare
|
|
outputs:
|
|
SHOULD_RELEASE: ${{ steps.decide.outputs.SHOULD_RELEASE }}
|
|
LAST_CANARY_TAG: ${{ steps.decide.outputs.LAST_CANARY_TAG }}
|
|
LAST_CANARY_SHA: ${{ steps.decide.outputs.LAST_CANARY_SHA }}
|
|
steps:
|
|
- name: Decide whether to release
|
|
id: decide
|
|
uses: actions/github-script@v9
|
|
with:
|
|
script: |
|
|
const buildType = '${{ needs.prepare.outputs.BUILD_TYPE }}'
|
|
if (buildType !== 'canary') {
|
|
core.setOutput('SHOULD_RELEASE', 'true')
|
|
return
|
|
}
|
|
|
|
const owner = context.repo.owner
|
|
const repo = context.repo.repo
|
|
const currentSha = context.sha
|
|
const canaryTagRe = /^v\d+\.\d+\.\d+-canary\.[0-9a-f]+$/i
|
|
|
|
let page = 1
|
|
const perPage = 100
|
|
let lastCanary = null
|
|
|
|
while (!lastCanary && page <= 10) {
|
|
const { data } = await github.rest.repos.listTags({
|
|
owner,
|
|
repo,
|
|
per_page: perPage,
|
|
page,
|
|
})
|
|
|
|
for (const tag of data) {
|
|
if (canaryTagRe.test(tag.name)) {
|
|
lastCanary = tag
|
|
break
|
|
}
|
|
}
|
|
|
|
if (data.length < perPage) break
|
|
page++
|
|
}
|
|
|
|
if (!lastCanary) {
|
|
core.warning('No canary tags found; proceeding with canary release.')
|
|
core.setOutput('SHOULD_RELEASE', 'true')
|
|
return
|
|
}
|
|
|
|
core.setOutput('LAST_CANARY_TAG', lastCanary.name)
|
|
core.setOutput('LAST_CANARY_SHA', lastCanary.commit.sha)
|
|
|
|
const shouldRelease = lastCanary.commit.sha !== currentSha
|
|
core.info(`Latest canary tag ${lastCanary.name} -> ${lastCanary.commit.sha}; current ${currentSha}; should_release=${shouldRelease}`)
|
|
core.setOutput('SHOULD_RELEASE', shouldRelease ? 'true' : 'false')
|
|
|
|
cloud:
|
|
name: Release Cloud
|
|
if: ${{ inputs.web || github.event_name != 'workflow_dispatch' }}
|
|
needs:
|
|
- prepare
|
|
uses: ./.github/workflows/release-cloud.yml
|
|
secrets: inherit
|
|
with:
|
|
build-type: ${{ needs.prepare.outputs.BUILD_TYPE }}
|
|
app-version: ${{ needs.prepare.outputs.APP_VERSION }}
|
|
git-short-hash: ${{ needs.prepare.outputs.GIT_SHORT_HASH }}
|
|
|
|
image:
|
|
name: Release Docker Image
|
|
if: ${{ needs.canary-gate.outputs.SHOULD_RELEASE == 'true' }}
|
|
runs-on: ubuntu-latest
|
|
needs:
|
|
- prepare
|
|
- canary-gate
|
|
- cloud
|
|
steps:
|
|
- uses: trstringer/manual-approval@v1
|
|
if: ${{ needs.prepare.outputs.BUILD_TYPE == 'stable' }}
|
|
name: Wait for approval
|
|
with:
|
|
secret: ${{ secrets.GITHUB_TOKEN }}
|
|
approvers: darkskygit
|
|
minimum-approvals: 1
|
|
fail-on-denial: true
|
|
issue-title: Please confirm to release docker image
|
|
issue-body: |
|
|
Env: ${{ needs.prepare.outputs.BUILD_TYPE }}
|
|
Candidate: ghcr.io/toeverything/affine:${{ needs.prepare.outputs.BUILD_TYPE }}-${{ needs.prepare.outputs.GIT_SHORT_HASH }}
|
|
Tag: ghcr.io/toeverything/affine:${{ needs.prepare.outputs.BUILD_TYPE }}
|
|
|
|
> comment with "approve", "approved", "lgtm", "yes" to approve
|
|
> comment with "deny", "denied", "no" to deny
|
|
|
|
- name: Login to GitHub Container Registry
|
|
uses: docker/login-action@v3
|
|
with:
|
|
registry: ghcr.io
|
|
logout: false
|
|
username: ${{ github.actor }}
|
|
password: ${{ secrets.GITHUB_TOKEN }}
|
|
- name: Set up Docker Buildx
|
|
uses: docker/setup-buildx-action@v3
|
|
- name: Tag Image
|
|
run: |
|
|
docker buildx imagetools create --tag ghcr.io/toeverything/affine:${{needs.prepare.outputs.BUILD_TYPE}} ghcr.io/toeverything/affine:${{needs.prepare.outputs.BUILD_TYPE}}-${{needs.prepare.outputs.GIT_SHORT_HASH}}
|
|
docker buildx imagetools create --tag ghcr.io/toeverything/affine:${{needs.prepare.outputs.APP_VERSION}} ghcr.io/toeverything/affine:${{needs.prepare.outputs.BUILD_TYPE}}-${{needs.prepare.outputs.GIT_SHORT_HASH}}
|
|
|
|
desktop:
|
|
name: Release Desktop
|
|
if: >-
|
|
${{
|
|
(github.event_name != 'workflow_dispatch' && needs.canary-gate.outputs.SHOULD_RELEASE == 'true') ||
|
|
inputs.desktop_macos ||
|
|
inputs.desktop_windows ||
|
|
inputs.desktop_linux
|
|
}}
|
|
needs:
|
|
- prepare
|
|
- canary-gate
|
|
uses: ./.github/workflows/release-desktop.yml
|
|
secrets: inherit
|
|
with:
|
|
build-type: ${{ needs.prepare.outputs.BUILD_TYPE }}
|
|
app-version: ${{ needs.prepare.outputs.APP_VERSION }}
|
|
git-short-hash: ${{ needs.prepare.outputs.GIT_SHORT_HASH }}
|
|
desktop_macos: ${{ github.event_name != 'workflow_dispatch' || inputs.desktop_macos }}
|
|
desktop_windows: ${{ github.event_name != 'workflow_dispatch' || inputs.desktop_windows }}
|
|
desktop_linux: ${{ github.event_name != 'workflow_dispatch' || inputs.desktop_linux }}
|
|
require-windows-signing: ${{ needs.prepare.outputs.BUILD_TYPE == 'stable' || (github.event_name == 'workflow_dispatch' && inputs.desktop_windows) }}
|
|
|
|
mobile:
|
|
name: Release Mobile
|
|
if: ${{ inputs.mobile }}
|
|
needs:
|
|
- prepare
|
|
uses: ./.github/workflows/release-mobile.yml
|
|
secrets: inherit
|
|
with:
|
|
build-type: ${{ needs.prepare.outputs.BUILD_TYPE }}
|
|
app-version: ${{ needs.prepare.outputs.APP_VERSION }}
|
|
git-short-hash: ${{ needs.prepare.outputs.GIT_SHORT_HASH }}
|
|
ios-app-version: ${{ inputs.ios-app-version }}
|