Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
18730e824f | ||
|
|
4bf763f264 | ||
|
|
d259350c3e | ||
|
|
286bd67de5 | ||
|
|
95551a0df8 | ||
|
|
4e80bab563 | ||
|
|
5145268539 | ||
|
|
dd352f1044 | ||
|
|
39410186df | ||
|
|
4a6b31f57e | ||
|
|
6f19d77e54 | ||
|
|
6ef4cee971 | ||
|
|
18bd0c4904 | ||
|
|
ab4fe4c3d4 | ||
|
|
42385d0f96 | ||
|
|
57db31ad97 | ||
|
|
fa133f2a9d | ||
|
|
4af49f3c87 | ||
|
|
0d5e717fa6 | ||
|
|
ee250a04db | ||
|
|
85a31fb612 | ||
|
|
8826e524e4 | ||
|
|
f1b0801157 | ||
|
|
214a376342 | ||
|
|
0c6c20ee96 | ||
|
|
420211c806 | ||
|
|
0476ae58a0 | ||
|
|
ac40804dc4 | ||
|
|
e046ece3cb | ||
|
|
ef998acd4d | ||
|
|
278d8e6bec | ||
|
|
ddf4065b4e |
@@ -18,13 +18,16 @@ jobs:
|
||||
name: release
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v3
|
||||
- uses: actions/setup-node@v3
|
||||
- uses: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab # v3
|
||||
- uses: actions/setup-node@64ed1c7eab4cce3362f8c340dee64e5eaeef8f7c # v3
|
||||
with:
|
||||
cache: npm
|
||||
node-version: lts/*
|
||||
- run: npm ci
|
||||
- run: npx semantic-release
|
||||
- run: npm clean-install
|
||||
- run: npm audit signatures
|
||||
# pinned version updated automatically by Renovate.
|
||||
# details at https://semantic-release.gitbook.io/semantic-release/usage/installation#global-installation
|
||||
- run: npx semantic-release@21.0.2
|
||||
env:
|
||||
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
NPM_TOKEN: ${{ secrets.SEMANTIC_RELEASE_BOT_NPM_TOKEN }}
|
||||
|
||||
@@ -27,11 +27,11 @@ jobs:
|
||||
timeout-minutes: 10
|
||||
|
||||
steps:
|
||||
- uses: actions/checkout@v3
|
||||
- uses: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab # v3
|
||||
- run: git config --global user.name github-actions
|
||||
- run: git config --global user.email github-actions@github.com
|
||||
- name: Use Node.js ${{ matrix.node-version }}
|
||||
uses: actions/setup-node@v3
|
||||
uses: actions/setup-node@64ed1c7eab4cce3362f8c340dee64e5eaeef8f7c # v3
|
||||
with:
|
||||
node-version: ${{ matrix.node-version }}
|
||||
cache: npm
|
||||
@@ -46,10 +46,11 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
needs: test_matrix
|
||||
steps:
|
||||
- uses: actions/checkout@v3
|
||||
- uses: actions/setup-node@v3
|
||||
- uses: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab # v3
|
||||
- uses: actions/setup-node@64ed1c7eab4cce3362f8c340dee64e5eaeef8f7c # v3
|
||||
with:
|
||||
node-version: lts/*
|
||||
cache: npm
|
||||
- run: npm clean-install
|
||||
- run: npm audit signatures
|
||||
- run: npm run lint
|
||||
|
||||
@@ -41,6 +41,7 @@ This removes the immediate connection between human emotions and version numbers
|
||||
- Avoid potential errors associated with manual releases
|
||||
- Support any [package managers and languages](docs/recipes/release-workflow/README.md#package-managers-and-languages) via [plugins](docs/usage/plugins.md)
|
||||
- Simple and reusable configuration via [shareable configurations](docs/usage/shareable-configurations.md)
|
||||
- Support for [npm package provenance](https://github.com/semantic-release/npm#npm-provenance) that promotes increased supply-chain security via signed attestations on GitHub Actions
|
||||
|
||||
## How does it work?
|
||||
|
||||
|
||||
+1
-1
@@ -3,7 +3,7 @@
|
||||
## Usage
|
||||
|
||||
- [Getting started](docs/usage/getting-started.md#getting-started)
|
||||
- [Installation](docs/usage/installation.md#installation)
|
||||
- [Installation](docs/usage/installation.md)
|
||||
- [CI Configuration](docs/usage/ci-configuration.md)
|
||||
- [Configuration](docs/usage/configuration.md)
|
||||
- [Plugins](docs/usage/plugins.md)
|
||||
|
||||
@@ -142,7 +142,7 @@ Information related to the last release found:
|
||||
| gitTag | `String` | The [Git tag](https://git-scm.com/book/en/v2/Git-Basics-Tagging) associated with the last release. |
|
||||
| channel | `String` | The distribution channel on which the last release was initially made available (`undefined` for the default distribution channel). |
|
||||
|
||||
**Notes**: If no previous release is found, `lastRelease` will be an empty `Object`.
|
||||
**Note**: If no previous release is found, `lastRelease` will be an empty `Object`.
|
||||
|
||||
Example:
|
||||
|
||||
|
||||
@@ -174,3 +174,11 @@
|
||||
- [semantic-release-coralogix](https://github.com/adobe/semantic-release-coralogix)
|
||||
- `verifyConditions` Verified that required credentials are provided and API is accessible
|
||||
- `publish` add a release tag to Coralogix
|
||||
- [semantic-release-major-tag](https://github.com/doteric/semantic-release-major-tag)
|
||||
- `success` Create major version tag, for example `v1`.
|
||||
- [semantic-release-yarn](https://github.com/hongaar/semantic-release-yarn)
|
||||
- **Note**: this is an alternative to the default `@semantic-release/npm` plugin and adds support for monorepos.
|
||||
- `verifyConditions` Verify Yarn 2 or higher is installed, verify the presence of a NPM auth token (either in an environment variable or a `.yarnrc.yml` file) and verify the authentication method is valid.
|
||||
- `prepare` Update the `package.json` version and create the package tarball.
|
||||
- `addChannel` Add a tag for the release.
|
||||
- `publish` Publish to the npm registry.
|
||||
|
||||
@@ -6,6 +6,11 @@ The [Authentication](../../usage/ci-configuration.md#authentication) environment
|
||||
|
||||
In this example a publish type [`NPM_TOKEN`](https://docs.npmjs.com/creating-and-viewing-authentication-tokens) is required to publish a package to the npm registry. GitHub Actions [automatically populate](https://help.github.com/en/articles/virtual-environments-for-github-actions#github_token-secret) a [`GITHUB_TOKEN`](https://help.github.com/en/articles/creating-a-personal-access-token-for-the-command-line) environment variable which can be used in Workflows.
|
||||
|
||||
## npm provenance
|
||||
|
||||
Since GitHub Actions is a [supported provider](https://docs.npmjs.com/generating-provenance-statements#provenance-limitations) for [npm provenance](https://docs.npmjs.com/generating-provenance-statements), it is recommended to enable this to increase supply-chain security for your npm packages.
|
||||
Find more detail about configuring npm to publish with provenance through semantic-release [in the documentation for our npm plugin](https://github.com/semantic-release/npm#npm-provenance).
|
||||
|
||||
## Node project configuration
|
||||
|
||||
[GitHub Actions](https://github.com/features/actions) support [Workflows](https://help.github.com/en/articles/configuring-workflows), allowing to run tests on multiple Node versions and publish a release only when all test pass.
|
||||
@@ -23,10 +28,19 @@ on:
|
||||
push:
|
||||
branches:
|
||||
- master
|
||||
|
||||
permissions:
|
||||
contents: read # for checkout
|
||||
|
||||
jobs:
|
||||
release:
|
||||
name: Release
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
contents: write # to be able to publish a GitHub release
|
||||
issues: write # to be able to comment on released issues
|
||||
pull-requests: write # to be able to comment on released pull requests
|
||||
id-token: write # to enable use of OIDC for npm provenance
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v3
|
||||
@@ -37,7 +51,9 @@ jobs:
|
||||
with:
|
||||
node-version: "lts/*"
|
||||
- name: Install dependencies
|
||||
run: npm ci
|
||||
run: npm clean-install
|
||||
- name: Verify the integrity of provenance attestations and registry signatures for installed dependencies
|
||||
run: npm audit signatures
|
||||
- name: Release
|
||||
env:
|
||||
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
|
||||
@@ -24,9 +24,28 @@ For other type of projects we recommend installing **semantic-release** directly
|
||||
$ npx semantic-release
|
||||
```
|
||||
|
||||
**Note**: For a global installation, it's recommended to specify the major **semantic-release** version to install (for example with `npx semantic-release@18`).
|
||||
This way your build will not automatically use the next major **semantic-release** release that could possibly break your build.
|
||||
You will have to upgrade manually when a new major version is released.
|
||||
### Notes
|
||||
|
||||
**Note**: `npx` is a tool bundled with `npm@>=5.2.0`. It is used to conveniently install the semantic-release binary and to execute it.
|
||||
See [What is npx](../support/FAQ.md#what-is-npx) for more details.
|
||||
1. If you've globally installed **semantic-release** then we recommend that you set the major **semantic-release** version to install.
|
||||
For example, by using `npx semantic-release@18`.
|
||||
This way you control which major version of **semantic-release** is used by your build, and thus avoid breaking the build when there's a new major version of **semantic-release**.
|
||||
This also means you, or a bot, must upgrade **semantic-release** when a new major version is released.
|
||||
2. Pinning **semantic-release** to an exact version makes your releases even more deterministic.
|
||||
But pinning also means you, or a bot, must update to newer versions of **semantic-release** more often.
|
||||
3. You can use [Renovate's regex manager](https://docs.renovatebot.com/modules/manager/regex/) to get automatic updates for **semantic-release** in either of the above scenarios.
|
||||
Put this in your Renovate configuration file:
|
||||
```json
|
||||
{
|
||||
"regexManagers": [
|
||||
{
|
||||
"description": "Update semantic-release version used by npx",
|
||||
"fileMatch": ["^\\.github/workflows/[^/]+\\.ya?ml$"],
|
||||
"matchStrings": ["\\srun: npx semantic-release@(?<currentValue>.*?)\\s"],
|
||||
"datasourceTemplate": "npm",
|
||||
"depNameTemplate": "semantic-release"
|
||||
}
|
||||
]
|
||||
}
|
||||
```
|
||||
4. `npx` is a tool bundled with `npm@>=5.2.0`. You can use it to install (and run) the **semantic-release** binary.
|
||||
See [What is npx](../support/FAQ.md#what-is-npx) for more details.
|
||||
|
||||
Generated
+1515
-1415
File diff suppressed because it is too large
Load Diff
+11
-12
@@ -26,11 +26,11 @@
|
||||
"Matt Travi <npm@travi.org> (https://matt.travi.org/)"
|
||||
],
|
||||
"dependencies": {
|
||||
"@semantic-release/commit-analyzer": "^9.0.2",
|
||||
"@semantic-release/error": "^3.0.0",
|
||||
"@semantic-release/github": "^8.0.0",
|
||||
"@semantic-release/commit-analyzer": "^10.0.0",
|
||||
"@semantic-release/error": "^4.0.0",
|
||||
"@semantic-release/github": "^9.0.0",
|
||||
"@semantic-release/npm": "^10.0.2",
|
||||
"@semantic-release/release-notes-generator": "^10.0.0",
|
||||
"@semantic-release/release-notes-generator": "^11.0.0",
|
||||
"aggregate-error": "^4.0.1",
|
||||
"cosmiconfig": "^8.0.0",
|
||||
"debug": "^4.0.0",
|
||||
@@ -56,24 +56,23 @@
|
||||
"yargs": "^17.5.1"
|
||||
},
|
||||
"devDependencies": {
|
||||
"ava": "5.2.0",
|
||||
"c8": "7.13.0",
|
||||
"ava": "5.3.0",
|
||||
"c8": "7.14.0",
|
||||
"clear-module": "4.1.2",
|
||||
"codecov": "3.8.3",
|
||||
"delay": "5.0.0",
|
||||
"dockerode": "3.3.5",
|
||||
"file-url": "4.0.0",
|
||||
"fs-extra": "11.1.1",
|
||||
"got": "12.6.0",
|
||||
"got": "13.0.0",
|
||||
"js-yaml": "4.1.0",
|
||||
"mockserver-client": "5.15.0",
|
||||
"nock": "13.3.0",
|
||||
"nock": "13.3.1",
|
||||
"p-retry": "5.1.2",
|
||||
"prettier": "2.8.7",
|
||||
"sinon": "15.0.3",
|
||||
"prettier": "2.8.8",
|
||||
"sinon": "15.1.0",
|
||||
"stream-buffers": "3.0.2",
|
||||
"tempy": "3.0.0",
|
||||
"testdouble": "3.17.2"
|
||||
"testdouble": "3.18.0"
|
||||
},
|
||||
"engines": {
|
||||
"node": ">=18"
|
||||
|
||||
@@ -1,9 +1,9 @@
|
||||
import path, { dirname } from "node:path";
|
||||
import { fileURLToPath } from "node:url";
|
||||
import { setTimeout } from "node:timers/promises";
|
||||
import Docker from "dockerode";
|
||||
import getStream from "get-stream";
|
||||
import got from "got";
|
||||
import delay from "delay";
|
||||
import pRetry from "p-retry";
|
||||
|
||||
const IMAGE = "verdaccio/verdaccio:5";
|
||||
@@ -33,7 +33,7 @@ export async function start() {
|
||||
});
|
||||
|
||||
await container.start();
|
||||
await delay(4000);
|
||||
await setTimeout(4000);
|
||||
|
||||
try {
|
||||
// Wait for the registry to be ready
|
||||
|
||||
+13
-4
@@ -1853,10 +1853,19 @@ test.serial("Throw an Error if plugin returns an unexpected value", async (t) =>
|
||||
await td.replaceEsm("../lib/get-logger.js", null, () => t.context.logger);
|
||||
await td.replaceEsm("env-ci", null, () => ({ isCi: true, branch: "master", isPr: false }));
|
||||
const semanticRelease = (await import("../index.js")).default;
|
||||
const error = await t.throwsAsync(
|
||||
semanticRelease(options, { cwd, env: {}, stdout: new WritableStreamBuffer(), stderr: new WritableStreamBuffer() }),
|
||||
{ instanceOf: SemanticReleaseError }
|
||||
);
|
||||
|
||||
let error;
|
||||
try {
|
||||
await semanticRelease(options, {
|
||||
cwd,
|
||||
env: {},
|
||||
stdout: new WritableStreamBuffer(),
|
||||
stderr: new WritableStreamBuffer(),
|
||||
});
|
||||
} catch (e) {
|
||||
error = e;
|
||||
}
|
||||
t.is(error.code, "EANALYZECOMMITSOUTPUT");
|
||||
t.regex(error.details, /string/);
|
||||
});
|
||||
|
||||
|
||||
@@ -1,11 +1,11 @@
|
||||
import path from "path";
|
||||
import path from "node:path";
|
||||
import { setTimeout } from "node:timers/promises";
|
||||
import test from "ava";
|
||||
import * as td from "testdouble";
|
||||
import { escapeRegExp } from "lodash-es";
|
||||
import fsExtra from "fs-extra";
|
||||
import { execa } from "execa";
|
||||
import { WritableStreamBuffer } from "stream-buffers";
|
||||
import delay from "delay";
|
||||
|
||||
import getAuthUrl from "../lib/get-git-auth-url.js";
|
||||
import { SECRET_REPLACEMENT } from "../lib/definitions/constants.js";
|
||||
@@ -295,7 +295,7 @@ test("Release patch, minor and major versions", async (t) => {
|
||||
t.is(exitCode, 0);
|
||||
|
||||
// Wait for 3s as the change of dist-tag takes time to be reflected in the registry
|
||||
await delay(3000);
|
||||
await setTimeout(3000);
|
||||
// Retrieve the published package from the registry and check version and gitHead
|
||||
({
|
||||
"dist-tags": { latest: releasedVersion },
|
||||
|
||||
Reference in New Issue
Block a user