diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS index cd56ba3..5127995 100644 --- a/.github/CODEOWNERS +++ b/.github/CODEOWNERS @@ -1,2 +1,2 @@ # Default ownership for repository review requests. -* @HauntedMC +* @remdui diff --git a/.github/workflows/ci-lint.yml b/.github/workflows/ci-lint.yml deleted file mode 100644 index 8156b26..0000000 --- a/.github/workflows/ci-lint.yml +++ /dev/null @@ -1,45 +0,0 @@ -name: CI Lint - -on: - pull_request: - types: [opened, synchronize, reopened] - push: - branches: [main] - -concurrency: - group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} - cancel-in-progress: true - -permissions: - contents: read - packages: read - -jobs: - maven-policy: - name: Shared Maven policy - uses: HauntedMC/HauntedPlatform/.github/workflows/maven-ci.yml@v1.6.8 - with: - maven-command: ./mvnw -U -B -ntp validate - secrets: - PACKAGES_USER: ${{ secrets.HAUNTEDMC_PACKAGES_USERNAME }} - PACKAGES_TOKEN: ${{ secrets.HAUNTEDMC_PACKAGES_TOKEN }} - - shellcheck: - name: ShellCheck and release-bump smoke test - runs-on: ubuntu-24.04 - env: - PACKAGES_USER: ${{ secrets.HAUNTEDMC_PACKAGES_USERNAME }} - PACKAGES_TOKEN: ${{ secrets.HAUNTEDMC_PACKAGES_TOKEN }} - steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - name: Install pinned release CLI - env: - GH_TOKEN: ${{ github.token }} - run: gh extension install HauntedMC/gh-haunted-release --pin ed440a0a2d5ab23af30c36bb22132f8ffa0ea33f - - shell: bash - run: | - mapfile -d '' scripts < <(git ls-files -z '*.sh') - if (( ${#scripts[@]} > 0 )); then shellcheck tools/release/update-version tools/release/prepare-version.sh "${scripts[@]}"; fi - - run: ./tools/release/update-version --dry-run major diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index c39c638..375c75b 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -20,8 +20,8 @@ jobs: runs-on: ubuntu-24.04 timeout-minutes: 20 env: - PACKAGES_USER: ${{ secrets.HAUNTEDMC_PACKAGES_USERNAME }} - PACKAGES_TOKEN: ${{ secrets.HAUNTEDMC_PACKAGES_TOKEN }} + PACKAGES_USER: ${{ secrets.HAUNTEDMC_PACKAGES_USERNAME || github.actor }} + PACKAGES_TOKEN: ${{ secrets.HAUNTEDMC_PACKAGES_TOKEN || github.token }} steps: - name: Checkout uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 @@ -30,7 +30,7 @@ jobs: - name: Install pinned release CLI env: GH_TOKEN: ${{ github.token }} - run: gh extension install HauntedMC/gh-haunted-release --pin ed440a0a2d5ab23af30c36bb22132f8ffa0ea33f + run: gh extension install HauntedMC/gh-haunted-release --pin de43c102d81797001eef36fe45725744fdd22031 - name: Verify dependency version ownership run: python3 scripts/verify-version-ownership.py @@ -53,3 +53,53 @@ jobs: run: ./mvnw -U -B -ntp -Prelease install - name: Verify external BOM consumer run: bash scripts/verify-bom-consumer.sh + + maven-policy: + name: Shared Maven policy + uses: HauntedMC/HauntedPlatform/.github/workflows/maven-ci.yml@10dfbacc8515208bf3b0ee236a8c7688fda49c9e # release hardening + with: + maven-command: ./mvnw -U -B -ntp validate + secrets: + PACKAGES_USER: ${{ secrets.HAUNTEDMC_PACKAGES_USERNAME || github.actor }} + PACKAGES_TOKEN: ${{ secrets.HAUNTEDMC_PACKAGES_TOKEN || github.token }} + + shellcheck: + name: ShellCheck and release-bump smoke test + runs-on: ubuntu-24.04 + env: + PACKAGES_USER: ${{ secrets.HAUNTEDMC_PACKAGES_USERNAME || github.actor }} + PACKAGES_TOKEN: ${{ secrets.HAUNTEDMC_PACKAGES_TOKEN || github.token }} + steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + - name: Install pinned release CLI + env: + GH_TOKEN: ${{ github.token }} + run: gh extension install HauntedMC/gh-haunted-release --pin de43c102d81797001eef36fe45725744fdd22031 + - shell: bash + run: | + mapfile -d '' scripts < <(git ls-files -z '*.sh') + if (( ${#scripts[@]} > 0 )); then shellcheck tools/release/update-version tools/release/prepare-version.sh "${scripts[@]}"; fi + - run: ./tools/release/update-version --dry-run major + + ci-required: + name: ci-required + if: ${{ always() }} + needs: [test, maven-policy, shellcheck] + runs-on: ubuntu-24.04 + permissions: + contents: read + env: + CHECK_RESULTS: ${{ toJSON(needs) }} + steps: + - name: Require every validation job + run: | + python3 - <<'PYTHON' + import json + import os + results = {name: job['result'] for name, job in json.loads(os.environ['CHECK_RESULTS']).items()} + failed = {name: result for name, result in results.items() if result != 'success'} + if failed: + raise SystemExit(f'Validation did not pass: {failed}') + PYTHON diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index fbb5fef..c3a9a02 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -10,8 +10,7 @@ concurrency: cancel-in-progress: false permissions: - contents: write - packages: write + contents: read jobs: gate: @@ -28,7 +27,7 @@ jobs: - name: Install pinned release CLI env: GH_TOKEN: ${{ github.token }} - run: gh extension install HauntedMC/gh-haunted-release --pin ed440a0a2d5ab23af30c36bb22132f8ffa0ea33f + run: gh extension install HauntedMC/gh-haunted-release --pin de43c102d81797001eef36fe45725744fdd22031 - id: version name: Detect a reviewed version change env: @@ -38,6 +37,9 @@ jobs: publish: needs: gate + permissions: + contents: write + packages: write if: needs.gate.outputs.publish == 'true' runs-on: ubuntu-24.04 timeout-minutes: 45 @@ -54,7 +56,7 @@ jobs: - name: Install pinned release CLI env: GH_TOKEN: ${{ github.token }} - run: gh extension install HauntedMC/gh-haunted-release --pin ed440a0a2d5ab23af30c36bb22132f8ffa0ea33f + run: gh extension install HauntedMC/gh-haunted-release --pin de43c102d81797001eef36fe45725744fdd22031 - name: Set up JDK 25 and Maven package credentials uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1 with: @@ -76,7 +78,11 @@ jobs: run: | ./mvnw -U -B -ntp -Prelease install bash scripts/verify-bom-consumer.sh + - id: preflight + name: Inspect already published Maven coordinates + run: gh haunted-release published-state "${{ needs.gate.outputs.version }}" - name: Publish the verified reactor + if: steps.preflight.outputs.state == 'none' run: ./mvnw -U -B -ntp -DdeployAtEnd=true -Prelease deploy - name: Resolve every published artifact from a fresh Maven repository run: gh haunted-release verify-published "${{ needs.gate.outputs.version }}" @@ -84,7 +90,7 @@ jobs: run: gh release create "${{ needs.gate.outputs.tag }}" --target "$GITHUB_SHA" --title "HauntedObservability ${{ needs.gate.outputs.tag }}" --generate-notes - name: Create cross-repository GitHub App token id: app - uses: actions/create-github-app-token@v3 + uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3 with: app-id: ${{ vars.HAUNTEDMC_RELEASE_APP_ID }} private-key: ${{ secrets.HAUNTEDMC_RELEASE_APP_PRIVATE_KEY }} diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 40b4bd5..a481582 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -4,10 +4,10 @@ - Java 25 - Maven Wrapper (`./mvnw`), pinned by `.mvn/wrapper/maven-wrapper.properties` -- HauntedPlatform 1.6.10 -- FeatureFramework 2.2.0 -- DataProvider 3.4.3 -- DataRegistry 1.18.4 +- HauntedPlatform 2.0.0 +- FeatureFramework 2.2.1 +- DataProvider 3.4.5 +- DataRegistry 1.18.6 GitHub Packages credentials are required to resolve HauntedMC artifacts. Configure `PACKAGES_USER` and `PACKAGES_TOKEN`; never commit tokens or generated Maven settings containing credentials. @@ -47,7 +47,7 @@ Preview a bump without modifying the worktree: ./tools/release/update-version --dry-run major ``` -Run `./tools/release/update-version patch` (or an intentional minor/major bump) from a clean branch. The helper updates the reactor revision and timestamp and checks all module versions. Commit the changes in a reviewed PR. After merge, CI runs the release gate, publishes and resolves the package, then creates `vX.Y.Z`. +Run `./tools/release/update-version patch --pr` (or an intentional minor/major bump) from clean, current `main`. The helper prepares the revision and timestamp in an isolated worktree, checks module versions, and opens the PR. An existing branch is revalidated on retry. Merge after `ci-required` passes; the release workflow then publishes, resolves every coordinate, and creates `vX.Y.Z`. ## Pull request checklist @@ -58,3 +58,7 @@ Run `./tools/release/update-version patch` (or an intentional minor/major bump) - [ ] External BOM consumption passes. - [ ] Public API/configuration changes are documented. - [ ] No credentials, secrets, private hosts, or production-only configuration are committed. + +## Fork pull requests + +Fork PRs run with a read-only GitHub token and receive no repository package secrets. CI attempts to resolve public HauntedMC Maven packages with that token and still runs static checks. If GitHub Packages denies cross-repository access, the required Maven check cannot pass on the fork; a maintainer reviews the change and opens an upstream branch PR for full CI before merge. Never include a package token in a PR or build log. diff --git a/tools/release/README.md b/tools/release/README.md index 398a70b..ed22101 100644 --- a/tools/release/README.md +++ b/tools/release/README.md @@ -1,7 +1,9 @@ # Version updates -Install the pinned shared CLI once with `gh extension install HauntedMC/gh-haunted-release --pin v1.0.1`. This folder keeps the project-specific version adapter and its configuration. +Install the pinned shared CLI once with `gh extension install HauntedMC/gh-haunted-release --pin v1.0.3`. This folder keeps the project-specific version adapter and its configuration. -From clean, current `main`, run `./tools/release/update-version patch --pr` to prepare, commit, push, and open a reviewed PR. Omit `--pr` to prepare only a local diff; add `--dry-run` to inspect the next version without edits. The tool never merges, publishes, or tags. +If an older pinned extension is installed, run `gh extension remove haunted-release` and then the install command above. Check `gh haunted-release --version` before preparing a release. + +From clean, current `main`, run `./tools/release/update-version patch --pr` to prepare, commit, push, and open a PR from an isolated worktree. Retry the same command if PR creation fails; it checks the pushed branch again. Omit `--pr` to prepare only a local diff; add `--dry-run` to inspect the next version without edits. The tool never merges, publishes, or tags. Enabled repositories use their pull-request CI as the merge gate. diff --git a/tools/release/project.toml b/tools/release/project.toml index c35e27a..bf95d77 100644 --- a/tools/release/project.toml +++ b/tools/release/project.toml @@ -1,7 +1,7 @@ [project] name = "HauntedObservability" repository = "HauntedMC/HauntedObservability" -tool_version = "1.0.1" +tool_version = "1.0.3" mode = "bump" prepare = "tools/release/prepare-version.sh" verify = ["./mvnw", "-B", "-ntp", "verify"]