-
Notifications
You must be signed in to change notification settings - Fork 15
166 lines (141 loc) · 6.36 KB
/
Copy pathrelease-draft.yml
File metadata and controls
166 lines (141 loc) · 6.36 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
name: Release – Draft
on:
workflow_dispatch: # checkov:skip=CKV_GHA_7
inputs:
bump-type:
description: |
How to bump the base version (X.Y.Z). Use `none` to keep the base unchanged
and only re-qualify an existing pre-release (e.g. rc1 -> rc2).
required: true
type: choice
options:
- patch
- minor
- major
- none
qualifier:
description: |
Optional pre-release qualifier to append, without the leading hyphen
(e.g. `rc1`, `alpha2`, `beta`). Leave blank for a stable release.
Allowed characters: alphanumerics, dot, hyphen.
required: false
type: string
default: ""
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
# The release branch push and PR creation use the GitHub App token, so GITHUB_TOKEN stays read-only.
permissions:
contents: read
pull-requests: read
jobs:
create-release-pr:
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ github.ref_name }}
fetch-depth: 0
- name: Install JDK 17
uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6
with:
distribution: "zulu"
java-version: "17"
- name: Setup Gradle
uses: gradle/actions/setup-gradle@9c971963bec38e04b3d30dcc455b5382be2fdbfb # v6.3.0
- name: Validate qualifier input
env:
QUALIFIER: ${{ github.event.inputs.qualifier }}
run: |
if [ -n "$QUALIFIER" ] && ! [[ "$QUALIFIER" =~ ^[A-Za-z0-9][A-Za-z0-9.-]*$ ]]; then
echo "::error::qualifier '$QUALIFIER' is invalid. It must start with an alphanumeric character and may only contain alphanumerics, dot, and hyphen."
exit 1
fi
- name: Get current version
id: version-file
run: |
version_from_file=$(head -n 1 VERSION)
echo "release-version=$version_from_file" >> "$GITHUB_OUTPUT"
base_version="${version_from_file%%-*}"
echo "base-version=$base_version" >> "$GITHUB_OUTPUT"
- name: Bump base version
id: bump-version
if: ${{ github.event.inputs.bump-type != 'none' }}
uses: actions-ecosystem/action-bump-semver@34e334551143a5301f38c830e44a22273c6ff5c5 # v1.0.0
with:
current_version: ${{ steps.version-file.outputs.base-version }}
level: ${{ github.event.inputs.bump-type }}
- name: Compose new version
id: compose-version
env:
CURRENT: ${{ steps.version-file.outputs.release-version }}
BUMPED: ${{ steps.bump-version.outputs.new_version }}
BASE: ${{ steps.version-file.outputs.base-version }}
BUMP_TYPE: ${{ github.event.inputs.bump-type }}
QUALIFIER: ${{ github.event.inputs.qualifier }}
run: |
if [ "$BUMP_TYPE" = "none" ]; then
new_base="$BASE"
else
new_base="$BUMPED"
fi
if [ -n "$QUALIFIER" ]; then
new_version="${new_base}-${QUALIFIER}"
else
new_version="$new_base"
fi
if [ "$new_version" = "$CURRENT" ]; then
echo "::error::Computed version '$new_version' is identical to the current VERSION. Pick a different bump-type or qualifier."
exit 1
fi
echo "new-version=$new_version" >> "$GITHUB_OUTPUT"
- name: Save bumped version to file
run: |
echo "${{ steps.compose-version.outputs.new-version }}" > VERSION
- name: Build and test
run: ./gradlew build --no-build-cache
- name: Publish SDK to Maven local (smoke test)
env:
ORG_GRADLE_PROJECT_signingInMemoryKey: ${{ secrets.MAVEN_CENTRAL_SIGNING_KEY }}
ORG_GRADLE_PROJECT_signingInMemoryKeyPassword: ${{ secrets.MAVEN_CENTRAL_SIGNING_KEY_PASSWORD }}
run: ./gradlew :sdk:publishMavenPublicationToMavenLocal -PVERSION=${{ steps.compose-version.outputs.new-version }} --no-build-cache
- name: Generate changelog entry
id: changelog
# Pinned SHA for Semgrep (no mutable @main); bump when upgrading the action.
uses: ROKT/rokt-workflows/actions/generate-changelog@c5c93e92107c520fb8b8cf71070995abdf4c403f
env:
GH_TOKEN: ${{ github.token }}
with:
version: ${{ steps.compose-version.outputs.new-version }}
repo-url: https://github.com/${{ github.repository }}
tag-prefix: v
changelog-path: CHANGELOG.md
exclude-types: chore,ci,test,build
- name: Generate a token
id: generate-token
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
with:
client-id: ${{ secrets.SDK_RELEASE_GITHUB_CLIENT_ID }}
private-key: ${{ secrets.SDK_RELEASE_GITHUB_APP_PRIVATE_KEY }}
owner: ${{ github.repository_owner }}
repositories: |
mparticle-firehose-java-sdk
- name: Create Pull Request
uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8.1.1
with:
token: ${{ steps.generate-token.outputs.token }}
commit-message: "chore: prepare release ${{ steps.compose-version.outputs.new-version }}"
branch: release-prep/${{ steps.compose-version.outputs.new-version }}
title: "chore: prepare release ${{ steps.compose-version.outputs.new-version }}"
base: ${{ github.ref_name }}
body: |
## Release ${{ steps.compose-version.outputs.new-version }}
- Version: `${{ steps.compose-version.outputs.new-version }}`
- Bump type: `${{ github.event.inputs.bump-type }}`
- Base branch: `${{ github.ref_name }}`
`VERSION` and `CHANGELOG.md` are updated. The SDK built, passed tests, and published to Maven local before this PR was opened.
## Changelog
${{ steps.changelog.outputs.release-notes }}
---
**On merge:** [Release – Publish](https://github.com/${{ github.repository }}/actions/workflows/release-publish.yml) uploads `com.mparticle:java-sdk` to the Maven Central Portal, tags `v${{ steps.compose-version.outputs.new-version }}`, and creates the GitHub release.