Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -1,2 +1,2 @@
# Default ownership for repository review requests.
* @HauntedMC
* @remdui
45 changes: 0 additions & 45 deletions .github/workflows/ci-lint.yml

This file was deleted.

56 changes: 53 additions & 3 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,8 +20,8 @@ jobs:
runs-on: ubuntu-24.04
timeout-minutes: 20
env:
PACKAGES_USER: ${{ secrets.HAUNTEDMC_PACKAGES_USERNAME }}
PACKAGES_TOKEN: ${{ secrets.HAUNTEDMC_PACKAGES_TOKEN }}
PACKAGES_USER: ${{ secrets.HAUNTEDMC_PACKAGES_USERNAME || github.actor }}
PACKAGES_TOKEN: ${{ secrets.HAUNTEDMC_PACKAGES_TOKEN || github.token }}
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
Expand All @@ -30,7 +30,7 @@ jobs:
- name: Install pinned release CLI
env:
GH_TOKEN: ${{ github.token }}
run: gh extension install HauntedMC/gh-haunted-release --pin ed440a0a2d5ab23af30c36bb22132f8ffa0ea33f
run: gh extension install HauntedMC/gh-haunted-release --pin de43c102d81797001eef36fe45725744fdd22031
- name: Verify dependency version ownership
run: python3 scripts/verify-version-ownership.py

Expand All @@ -53,3 +53,53 @@ jobs:
run: ./mvnw -U -B -ntp -Prelease install
- name: Verify external BOM consumer
run: bash scripts/verify-bom-consumer.sh

maven-policy:
name: Shared Maven policy
uses: HauntedMC/HauntedPlatform/.github/workflows/maven-ci.yml@10dfbacc8515208bf3b0ee236a8c7688fda49c9e # release hardening
with:
maven-command: ./mvnw -U -B -ntp validate
secrets:
PACKAGES_USER: ${{ secrets.HAUNTEDMC_PACKAGES_USERNAME || github.actor }}
PACKAGES_TOKEN: ${{ secrets.HAUNTEDMC_PACKAGES_TOKEN || github.token }}

shellcheck:
name: ShellCheck and release-bump smoke test
runs-on: ubuntu-24.04
env:
PACKAGES_USER: ${{ secrets.HAUNTEDMC_PACKAGES_USERNAME || github.actor }}
PACKAGES_TOKEN: ${{ secrets.HAUNTEDMC_PACKAGES_TOKEN || github.token }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Install pinned release CLI
env:
GH_TOKEN: ${{ github.token }}
run: gh extension install HauntedMC/gh-haunted-release --pin de43c102d81797001eef36fe45725744fdd22031
- shell: bash
run: |
mapfile -d '' scripts < <(git ls-files -z '*.sh')
if (( ${#scripts[@]} > 0 )); then shellcheck tools/release/update-version tools/release/prepare-version.sh "${scripts[@]}"; fi
- run: ./tools/release/update-version --dry-run major

ci-required:
name: ci-required
if: ${{ always() }}
needs: [test, maven-policy, shellcheck]
runs-on: ubuntu-24.04
permissions:
contents: read
env:
CHECK_RESULTS: ${{ toJSON(needs) }}
steps:
- name: Require every validation job
run: |
python3 - <<'PYTHON'
import json
import os
results = {name: job['result'] for name, job in json.loads(os.environ['CHECK_RESULTS']).items()}
failed = {name: result for name, result in results.items() if result != 'success'}
if failed:
raise SystemExit(f'Validation did not pass: {failed}')
PYTHON
16 changes: 11 additions & 5 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,8 +10,7 @@ concurrency:
cancel-in-progress: false

permissions:
contents: write
packages: write
contents: read

jobs:
gate:
Expand All @@ -28,7 +27,7 @@ jobs:
- name: Install pinned release CLI
env:
GH_TOKEN: ${{ github.token }}
run: gh extension install HauntedMC/gh-haunted-release --pin ed440a0a2d5ab23af30c36bb22132f8ffa0ea33f
run: gh extension install HauntedMC/gh-haunted-release --pin de43c102d81797001eef36fe45725744fdd22031
- id: version
name: Detect a reviewed version change
env:
Expand All @@ -38,6 +37,9 @@ jobs:

publish:
needs: gate
permissions:
contents: write
packages: write
if: needs.gate.outputs.publish == 'true'
runs-on: ubuntu-24.04
timeout-minutes: 45
Expand All @@ -54,7 +56,7 @@ jobs:
- name: Install pinned release CLI
env:
GH_TOKEN: ${{ github.token }}
run: gh extension install HauntedMC/gh-haunted-release --pin ed440a0a2d5ab23af30c36bb22132f8ffa0ea33f
run: gh extension install HauntedMC/gh-haunted-release --pin de43c102d81797001eef36fe45725744fdd22031
- name: Set up JDK 25 and Maven package credentials
uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1
with:
Expand All @@ -76,15 +78,19 @@ jobs:
run: |
./mvnw -U -B -ntp -Prelease install
bash scripts/verify-bom-consumer.sh
- id: preflight
name: Inspect already published Maven coordinates
run: gh haunted-release published-state "${{ needs.gate.outputs.version }}"
- name: Publish the verified reactor
if: steps.preflight.outputs.state == 'none'
run: ./mvnw -U -B -ntp -DdeployAtEnd=true -Prelease deploy
- name: Resolve every published artifact from a fresh Maven repository
run: gh haunted-release verify-published "${{ needs.gate.outputs.version }}"
- name: Create the release tag only after publication is resolvable
run: gh release create "${{ needs.gate.outputs.tag }}" --target "$GITHUB_SHA" --title "HauntedObservability ${{ needs.gate.outputs.tag }}" --generate-notes
- name: Create cross-repository GitHub App token
id: app
uses: actions/create-github-app-token@v3
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3
with:
app-id: ${{ vars.HAUNTEDMC_RELEASE_APP_ID }}
private-key: ${{ secrets.HAUNTEDMC_RELEASE_APP_PRIVATE_KEY }}
Expand Down
14 changes: 9 additions & 5 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,10 +4,10 @@

- Java 25
- Maven Wrapper (`./mvnw`), pinned by `.mvn/wrapper/maven-wrapper.properties`
- HauntedPlatform 1.6.10
- FeatureFramework 2.2.0
- DataProvider 3.4.3
- DataRegistry 1.18.4
- HauntedPlatform 2.0.0
- FeatureFramework 2.2.1
- DataProvider 3.4.5
- DataRegistry 1.18.6

GitHub Packages credentials are required to resolve HauntedMC artifacts. Configure `PACKAGES_USER` and `PACKAGES_TOKEN`; never commit tokens or generated Maven settings containing credentials.

Expand Down Expand Up @@ -47,7 +47,7 @@ Preview a bump without modifying the worktree:
./tools/release/update-version --dry-run major
```

Run `./tools/release/update-version patch` (or an intentional minor/major bump) from a clean branch. The helper updates the reactor revision and timestamp and checks all module versions. Commit the changes in a reviewed PR. After merge, CI runs the release gate, publishes and resolves the package, then creates `vX.Y.Z`.
Run `./tools/release/update-version patch --pr` (or an intentional minor/major bump) from clean, current `main`. The helper prepares the revision and timestamp in an isolated worktree, checks module versions, and opens the PR. An existing branch is revalidated on retry. Merge after `ci-required` passes; the release workflow then publishes, resolves every coordinate, and creates `vX.Y.Z`.

## Pull request checklist

Expand All @@ -58,3 +58,7 @@ Run `./tools/release/update-version patch` (or an intentional minor/major bump)
- [ ] External BOM consumption passes.
- [ ] Public API/configuration changes are documented.
- [ ] No credentials, secrets, private hosts, or production-only configuration are committed.

## Fork pull requests

Fork PRs run with a read-only GitHub token and receive no repository package secrets. CI attempts to resolve public HauntedMC Maven packages with that token and still runs static checks. If GitHub Packages denies cross-repository access, the required Maven check cannot pass on the fork; a maintainer reviews the change and opens an upstream branch PR for full CI before merge. Never include a package token in a PR or build log.
6 changes: 4 additions & 2 deletions tools/release/README.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,9 @@
# Version updates

Install the pinned shared CLI once with `gh extension install HauntedMC/gh-haunted-release --pin v1.0.1`. This folder keeps the project-specific version adapter and its configuration.
Install the pinned shared CLI once with `gh extension install HauntedMC/gh-haunted-release --pin v1.0.3`. This folder keeps the project-specific version adapter and its configuration.

From clean, current `main`, run `./tools/release/update-version patch --pr` to prepare, commit, push, and open a reviewed PR. Omit `--pr` to prepare only a local diff; add `--dry-run` to inspect the next version without edits. The tool never merges, publishes, or tags.
If an older pinned extension is installed, run `gh extension remove haunted-release` and then the install command above. Check `gh haunted-release --version` before preparing a release.

From clean, current `main`, run `./tools/release/update-version patch --pr` to prepare, commit, push, and open a PR from an isolated worktree. Retry the same command if PR creation fails; it checks the pushed branch again. Omit `--pr` to prepare only a local diff; add `--dry-run` to inspect the next version without edits. The tool never merges, publishes, or tags.

Enabled repositories use their pull-request CI as the merge gate.
2 changes: 1 addition & 1 deletion tools/release/project.toml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
[project]
name = "HauntedObservability"
repository = "HauntedMC/HauntedObservability"
tool_version = "1.0.1"
tool_version = "1.0.3"
mode = "bump"
prepare = "tools/release/prepare-version.sh"
verify = ["./mvnw", "-B", "-ntp", "verify"]
Expand Down
Loading