Compare commits

..
32 Commits
Author SHA1 Message Date
Matt TraviandGitHub 18730e824f Merge pull request #2826 from semantic-release/renovate/major-semantic-release-monorepo 2023-06-09 16:32:02 -05:00
Matt Travi 4bf763f264 test(semantic-release-error): switched instanceof check to the native version
since the check provided by the ava assertion seems to fail beyond the context of the test
2023-06-09 16:14:46 -05:00
renovate[bot]andGitHub d259350c3e fix(deps): update dependency @semantic-release/error to v4 2023-06-07 21:29:33 +00:00
286bd67de5 chore(deps): lock file maintenance (#2825)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2023-06-05 04:23:37 +00:00
95551a0df8 chore(deps): update dependency ava to v5.3.0 (#2809)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2023-06-02 15:30:01 -05:00
4e80bab563 chore(deps): lock file maintenance (#2816)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2023-06-02 15:25:29 -05:00
5145268539 chore(deps): update dependency got to v13 (#2813)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2023-06-02 15:18:21 -05:00
Matt TraviandGitHub dd352f1044 Merge pull request #2823 from semantic-release/beta 2023-06-02 15:09:44 -05:00
Matt Travi 39410186df fix(deps): updated the beta plugins to stable versions 2023-06-02 14:30:32 -05:00
Matt Travi 4a6b31f57e fix: bump @semantic-release/commit-analyzer to v10.0.0-beta.1 2023-05-29 22:03:54 -05:00
6f19d77e54 fix: bump @semantic-release/github to 9.0.0-beta.2 (#2818)
Co-authored-by: Matt Travi <programmer@travi.org>
2023-05-29 20:47:17 -05:00
6ef4cee971 chore(deps): update dependency c8 to v7.14.0 (#2815)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2023-05-28 19:00:28 +00:00
18bd0c4904 chore(deps): lock file maintenance (#2797)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2023-05-23 07:05:08 +00:00
Matt Travi ab4fe4c3d4 refactor: leverage native async setTimeout rather than delay 2023-05-22 22:25:22 -05:00
42385d0f96 chore(deps): update dependency sinon to v15.1.0 (#2801)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2023-05-21 15:39:53 -07:00
57db31ad97 chore(deps): update dependency delay to v6 (#2803)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2023-05-21 20:14:15 +00:00
Matt TraviandGitHub fa133f2a9d ci(release): pinned the version of semantic-release (#2796) 2023-05-12 17:17:04 -05:00
4af49f3c87 chore(deps): update dependency nock to v13.3.1 (#2777)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2023-05-10 16:01:22 -05:00
Joram van den BoezemandGitHub 0d5e717fa6 docs(extending): add semantic-release-yarn to community plugins (#2790) 2023-05-10 08:40:17 -05:00
Matt Travi ee250a04db docs(gitbook): fixed reference to the installation page 2023-05-09 09:07:50 -05:00
85a31fb612 docs(npx-version): mentioned using a renovate regex manager to update the version (#2786)
Co-authored-by: HonkingGoose <34918129+HonkingGoose@users.noreply.github.com>
2023-05-09 08:02:45 -05:00
8826e524e4 chore(deps): update dependency testdouble to v3.18.0 (#2787)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2023-05-09 06:35:20 +00:00
Liran TalandGitHub f1b0801157 docs: Update README.md with npm package provenance (#2789) 2023-05-08 21:06:39 -05:00
214a376342 ci(action): pin dependencies (#2781)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2023-05-06 10:09:56 +00:00
0c6c20ee96 chore(deps): lock file maintenance (#2763)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2023-05-06 08:06:29 +00:00
420211c806 chore(deps): update dependency prettier to v2.8.8 (#2771)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2023-05-06 04:19:59 +00:00
Eric KandGitHub 0476ae58a0 docs(extending): add link to semantic-release-major-tag (#2776) 2023-05-05 16:55:09 -05:00
ac40804dc4 fix(deps): update dependency @semantic-release/release-notes-generator to v11 (#2778)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2023-04-28 17:01:24 -05:00
Matt Travi e046ece3cb ci(signatures): moved the audit step to the non-matrix stage
since older versions of npm dont support `npm audit signatures` and instead simply audit for vulnerabilities
2023-04-28 16:33:03 -05:00
Matt Travi ef998acd4d ci(dependencies): audited signatures and provenance attestations of installed packages 2023-04-21 16:41:27 -05:00
Matt Travi 278d8e6bec docs(gh-actions): captured details about publishing with provenance from an actions workflow 2023-04-21 16:01:08 -05:00
ddf4065b4e chore(deps): update dependency sinon to v15.0.4 (#2769)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2023-04-20 17:40:03 +00:00
13 changed files with 1608 additions and 1452 deletions
+7 -4
View File
@@ -18,13 +18,16 @@ jobs:
name: release
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- uses: actions/setup-node@v3
- uses: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab # v3
- uses: actions/setup-node@64ed1c7eab4cce3362f8c340dee64e5eaeef8f7c # v3
with:
cache: npm
node-version: lts/*
- run: npm ci
- run: npx semantic-release
- run: npm clean-install
- run: npm audit signatures
# pinned version updated automatically by Renovate.
# details at https://semantic-release.gitbook.io/semantic-release/usage/installation#global-installation
- run: npx semantic-release@21.0.2
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
NPM_TOKEN: ${{ secrets.SEMANTIC_RELEASE_BOT_NPM_TOKEN }}
+5 -4
View File
@@ -27,11 +27,11 @@ jobs:
timeout-minutes: 10
steps:
- uses: actions/checkout@v3
- uses: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab # v3
- run: git config --global user.name github-actions
- run: git config --global user.email github-actions@github.com
- name: Use Node.js ${{ matrix.node-version }}
uses: actions/setup-node@v3
uses: actions/setup-node@64ed1c7eab4cce3362f8c340dee64e5eaeef8f7c # v3
with:
node-version: ${{ matrix.node-version }}
cache: npm
@@ -46,10 +46,11 @@ jobs:
runs-on: ubuntu-latest
needs: test_matrix
steps:
- uses: actions/checkout@v3
- uses: actions/setup-node@v3
- uses: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab # v3
- uses: actions/setup-node@64ed1c7eab4cce3362f8c340dee64e5eaeef8f7c # v3
with:
node-version: lts/*
cache: npm
- run: npm clean-install
- run: npm audit signatures
- run: npm run lint
+1
View File
@@ -41,6 +41,7 @@ This removes the immediate connection between human emotions and version numbers
- Avoid potential errors associated with manual releases
- Support any [package managers and languages](docs/recipes/release-workflow/README.md#package-managers-and-languages) via [plugins](docs/usage/plugins.md)
- Simple and reusable configuration via [shareable configurations](docs/usage/shareable-configurations.md)
- Support for [npm package provenance](https://github.com/semantic-release/npm#npm-provenance) that promotes increased supply-chain security via signed attestations on GitHub Actions
## How does it work?
+1 -1
View File
@@ -3,7 +3,7 @@
## Usage
- [Getting started](docs/usage/getting-started.md#getting-started)
- [Installation](docs/usage/installation.md#installation)
- [Installation](docs/usage/installation.md)
- [CI Configuration](docs/usage/ci-configuration.md)
- [Configuration](docs/usage/configuration.md)
- [Plugins](docs/usage/plugins.md)
+1 -1
View File
@@ -142,7 +142,7 @@ Information related to the last release found:
| gitTag | `String` | The [Git tag](https://git-scm.com/book/en/v2/Git-Basics-Tagging) associated with the last release. |
| channel | `String` | The distribution channel on which the last release was initially made available (`undefined` for the default distribution channel). |
**Notes**: If no previous release is found, `lastRelease` will be an empty `Object`.
**Note**: If no previous release is found, `lastRelease` will be an empty `Object`.
Example:
+8
View File
@@ -174,3 +174,11 @@
- [semantic-release-coralogix](https://github.com/adobe/semantic-release-coralogix)
- `verifyConditions` Verified that required credentials are provided and API is accessible
- `publish` add a release tag to Coralogix
- [semantic-release-major-tag](https://github.com/doteric/semantic-release-major-tag)
- `success` Create major version tag, for example `v1`.
- [semantic-release-yarn](https://github.com/hongaar/semantic-release-yarn)
- **Note**: this is an alternative to the default `@semantic-release/npm` plugin and adds support for monorepos.
- `verifyConditions` Verify Yarn 2 or higher is installed, verify the presence of a NPM auth token (either in an environment variable or a `.yarnrc.yml` file) and verify the authentication method is valid.
- `prepare` Update the `package.json` version and create the package tarball.
- `addChannel` Add a tag for the release.
- `publish` Publish to the npm registry.
@@ -6,6 +6,11 @@ The [Authentication](../../usage/ci-configuration.md#authentication) environment
In this example a publish type [`NPM_TOKEN`](https://docs.npmjs.com/creating-and-viewing-authentication-tokens) is required to publish a package to the npm registry. GitHub Actions [automatically populate](https://help.github.com/en/articles/virtual-environments-for-github-actions#github_token-secret) a [`GITHUB_TOKEN`](https://help.github.com/en/articles/creating-a-personal-access-token-for-the-command-line) environment variable which can be used in Workflows.
## npm provenance
Since GitHub Actions is a [supported provider](https://docs.npmjs.com/generating-provenance-statements#provenance-limitations) for [npm provenance](https://docs.npmjs.com/generating-provenance-statements), it is recommended to enable this to increase supply-chain security for your npm packages.
Find more detail about configuring npm to publish with provenance through semantic-release [in the documentation for our npm plugin](https://github.com/semantic-release/npm#npm-provenance).
## Node project configuration
[GitHub Actions](https://github.com/features/actions) support [Workflows](https://help.github.com/en/articles/configuring-workflows), allowing to run tests on multiple Node versions and publish a release only when all test pass.
@@ -23,10 +28,19 @@ on:
push:
branches:
- master
permissions:
contents: read # for checkout
jobs:
release:
name: Release
runs-on: ubuntu-latest
permissions:
contents: write # to be able to publish a GitHub release
issues: write # to be able to comment on released issues
pull-requests: write # to be able to comment on released pull requests
id-token: write # to enable use of OIDC for npm provenance
steps:
- name: Checkout
uses: actions/checkout@v3
@@ -37,7 +51,9 @@ jobs:
with:
node-version: "lts/*"
- name: Install dependencies
run: npm ci
run: npm clean-install
- name: Verify the integrity of provenance attestations and registry signatures for installed dependencies
run: npm audit signatures
- name: Release
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+24 -5
View File
@@ -24,9 +24,28 @@ For other type of projects we recommend installing **semantic-release** directly
$ npx semantic-release
```
**Note**: For a global installation, it's recommended to specify the major **semantic-release** version to install (for example with `npx semantic-release@18`).
This way your build will not automatically use the next major **semantic-release** release that could possibly break your build.
You will have to upgrade manually when a new major version is released.
### Notes
**Note**: `npx` is a tool bundled with `npm@>=5.2.0`. It is used to conveniently install the semantic-release binary and to execute it.
See [What is npx](../support/FAQ.md#what-is-npx) for more details.
1. If you've globally installed **semantic-release** then we recommend that you set the major **semantic-release** version to install.
For example, by using `npx semantic-release@18`.
This way you control which major version of **semantic-release** is used by your build, and thus avoid breaking the build when there's a new major version of **semantic-release**.
This also means you, or a bot, must upgrade **semantic-release** when a new major version is released.
2. Pinning **semantic-release** to an exact version makes your releases even more deterministic.
But pinning also means you, or a bot, must update to newer versions of **semantic-release** more often.
3. You can use [Renovate's regex manager](https://docs.renovatebot.com/modules/manager/regex/) to get automatic updates for **semantic-release** in either of the above scenarios.
Put this in your Renovate configuration file:
```json
{
"regexManagers": [
{
"description": "Update semantic-release version used by npx",
"fileMatch": ["^\\.github/workflows/[^/]+\\.ya?ml$"],
"matchStrings": ["\\srun: npx semantic-release@(?<currentValue>.*?)\\s"],
"datasourceTemplate": "npm",
"depNameTemplate": "semantic-release"
}
]
}
```
4. `npx` is a tool bundled with `npm@>=5.2.0`. You can use it to install (and run) the **semantic-release** binary.
See [What is npx](../support/FAQ.md#what-is-npx) for more details.
+1515 -1415
View File
File diff suppressed because it is too large Load Diff
+11 -12
View File
@@ -26,11 +26,11 @@
"Matt Travi <npm@travi.org> (https://matt.travi.org/)"
],
"dependencies": {
"@semantic-release/commit-analyzer": "^9.0.2",
"@semantic-release/error": "^3.0.0",
"@semantic-release/github": "^8.0.0",
"@semantic-release/commit-analyzer": "^10.0.0",
"@semantic-release/error": "^4.0.0",
"@semantic-release/github": "^9.0.0",
"@semantic-release/npm": "^10.0.2",
"@semantic-release/release-notes-generator": "^10.0.0",
"@semantic-release/release-notes-generator": "^11.0.0",
"aggregate-error": "^4.0.1",
"cosmiconfig": "^8.0.0",
"debug": "^4.0.0",
@@ -56,24 +56,23 @@
"yargs": "^17.5.1"
},
"devDependencies": {
"ava": "5.2.0",
"c8": "7.13.0",
"ava": "5.3.0",
"c8": "7.14.0",
"clear-module": "4.1.2",
"codecov": "3.8.3",
"delay": "5.0.0",
"dockerode": "3.3.5",
"file-url": "4.0.0",
"fs-extra": "11.1.1",
"got": "12.6.0",
"got": "13.0.0",
"js-yaml": "4.1.0",
"mockserver-client": "5.15.0",
"nock": "13.3.0",
"nock": "13.3.1",
"p-retry": "5.1.2",
"prettier": "2.8.7",
"sinon": "15.0.3",
"prettier": "2.8.8",
"sinon": "15.1.0",
"stream-buffers": "3.0.2",
"tempy": "3.0.0",
"testdouble": "3.17.2"
"testdouble": "3.18.0"
},
"engines": {
"node": ">=18"
+2 -2
View File
@@ -1,9 +1,9 @@
import path, { dirname } from "node:path";
import { fileURLToPath } from "node:url";
import { setTimeout } from "node:timers/promises";
import Docker from "dockerode";
import getStream from "get-stream";
import got from "got";
import delay from "delay";
import pRetry from "p-retry";
const IMAGE = "verdaccio/verdaccio:5";
@@ -33,7 +33,7 @@ export async function start() {
});
await container.start();
await delay(4000);
await setTimeout(4000);
try {
// Wait for the registry to be ready
+13 -4
View File
@@ -1853,10 +1853,19 @@ test.serial("Throw an Error if plugin returns an unexpected value", async (t) =>
await td.replaceEsm("../lib/get-logger.js", null, () => t.context.logger);
await td.replaceEsm("env-ci", null, () => ({ isCi: true, branch: "master", isPr: false }));
const semanticRelease = (await import("../index.js")).default;
const error = await t.throwsAsync(
semanticRelease(options, { cwd, env: {}, stdout: new WritableStreamBuffer(), stderr: new WritableStreamBuffer() }),
{ instanceOf: SemanticReleaseError }
);
let error;
try {
await semanticRelease(options, {
cwd,
env: {},
stdout: new WritableStreamBuffer(),
stderr: new WritableStreamBuffer(),
});
} catch (e) {
error = e;
}
t.is(error.code, "EANALYZECOMMITSOUTPUT");
t.regex(error.details, /string/);
});
+3 -3
View File
@@ -1,11 +1,11 @@
import path from "path";
import path from "node:path";
import { setTimeout } from "node:timers/promises";
import test from "ava";
import * as td from "testdouble";
import { escapeRegExp } from "lodash-es";
import fsExtra from "fs-extra";
import { execa } from "execa";
import { WritableStreamBuffer } from "stream-buffers";
import delay from "delay";
import getAuthUrl from "../lib/get-git-auth-url.js";
import { SECRET_REPLACEMENT } from "../lib/definitions/constants.js";
@@ -295,7 +295,7 @@ test("Release patch, minor and major versions", async (t) => {
t.is(exitCode, 0);
// Wait for 3s as the change of dist-tag takes time to be reflected in the registry
await delay(3000);
await setTimeout(3000);
// Retrieve the published package from the registry and check version and gitHead
({
"dist-tags": { latest: releasedVersion },