diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml new file mode 100644 index 0000000..13f9725 --- /dev/null +++ b/.github/workflows/release.yml @@ -0,0 +1,59 @@ +name: release + +on: + workflow_dispatch: + inputs: + version-type: + description: Version bump + required: true + type: choice + options: + - patch + - minor + - major + - premajor + - preminor + - prepatch + - prerelease + - custom + new-version: + description: Explicit semantic version for custom, such as 2.5.0 (no leading v) + required: false + type: string + +permissions: + contents: write + +concurrency: + group: goversion-release + cancel-in-progress: false + +jobs: + release: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v7 + with: + ref: ${{ github.event.repository.default_branch }} + fetch-depth: 0 + persist-credentials: false + + - uses: actions/setup-go@v7 + with: + go-version-file: go.mod + check-latest: true + + - run: make all + + - id: release + uses: bcomnes/go-bump@v0 + with: + version-type: ${{ inputs.version-type }} + new-version: ${{ inputs.new-version }} + github-token: ${{ github.token }} + pre-publish: make all + + - name: Release summary + env: + RELEASE_TAG: ${{ steps.release.outputs.release-tag }} + run: echo "Published $RELEASE_TAG" diff --git a/.github/zizmor.yml b/.github/zizmor.yml index 897ea90..40bb83f 100644 --- a/.github/zizmor.yml +++ b/.github/zizmor.yml @@ -8,5 +8,7 @@ rules: # Official GitHub actions and CodeQL use major tags for compatible security updates. "actions/*": ref-pin "github/codeql-action/*": ref-pin - # Require immutable references for every third-party action. + # First-party bcomnes actions use moving major references for compatible updates. + "bcomnes/*": ref-pin + # Require immutable references for every other third-party action. "*": hash-pin diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index e8c09d1..f4ca911 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -14,3 +14,18 @@ - Aim for 100% test coverage. - Questions are welcome! However, unless there is an official support contract in place, support is not guaranteed. - Contributors reserve the right to walk away from the project at any time, with or without notice. + +## Releasing + +The repository registers its own main package as a Go tool so the checked-out source provides the same local release workflow consumers use: + +```console +go tool github.com/bcomnes/goversion/v2 -dry patch +go tool github.com/bcomnes/goversion/v2 patch +make all +go tool github.com/bcomnes/goversion/v2 publish +``` + +For hosted releases, manually dispatch `.github/workflows/release.yml` and select a version directive. +The workflow runs the full suite, invokes the trusted moving `go-bump v0` action reference, validates the exact release commit through `make all`, and delegates Git refs, GitHub Release creation, and Go proxy verification back to `goversion publish`. +Explicit custom versions omit the leading `v`, for example `2.5.0`. diff --git a/go.mod b/go.mod index 25d1d65..b5fca41 100644 --- a/go.mod +++ b/go.mod @@ -3,3 +3,5 @@ module github.com/bcomnes/goversion/v2 go 1.25.0 require golang.org/x/mod v0.40.0 + +tool github.com/bcomnes/goversion/v2