From 5bc17416804a270bfe59c082f8c907d69e633105 Mon Sep 17 00:00:00 2001 From: Bret Comnes Date: Thu, 3 Sep 2026 17:14:13 -0700 Subject: [PATCH 1/3] Add go-bump release workflow --- .github/workflows/release.yml | 59 +++++++++++++++++++++++++++++++++++ CONTRIBUTING.md | 15 +++++++++ go.mod | 2 ++ 3 files changed, 76 insertions(+) create mode 100644 .github/workflows/release.yml diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml new file mode 100644 index 0000000..65d2f2f --- /dev/null +++ b/.github/workflows/release.yml @@ -0,0 +1,59 @@ +name: release + +on: + workflow_dispatch: + inputs: + version-type: + description: Version bump + required: true + type: choice + options: + - patch + - minor + - major + - premajor + - preminor + - prepatch + - prerelease + - custom + new-version: + description: Explicit semantic version for custom, such as 2.5.0 (no leading v) + required: false + type: string + +permissions: + contents: write + +concurrency: + group: goversion-release + cancel-in-progress: false + +jobs: + release: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v7 + with: + ref: ${{ github.event.repository.default_branch }} + fetch-depth: 0 + persist-credentials: false + + - uses: actions/setup-go@v7 + with: + go-version-file: go.mod + check-latest: true + + - run: make all + + - id: release + uses: bcomnes/go-bump@f6b52f1871e4298407bff134904f1fa46d9b55db # v0.0.1 + with: + version-type: ${{ inputs.version-type }} + new-version: ${{ inputs.new-version }} + github-token: ${{ github.token }} + pre-publish: make all + + - name: Release summary + env: + RELEASE_TAG: ${{ steps.release.outputs.release-tag }} + run: echo "Published $RELEASE_TAG" diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index e8c09d1..a690650 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -14,3 +14,18 @@ - Aim for 100% test coverage. - Questions are welcome! However, unless there is an official support contract in place, support is not guaranteed. - Contributors reserve the right to walk away from the project at any time, with or without notice. + +## Releasing + +The repository registers its own main package as a Go tool so the checked-out source provides the same local release workflow consumers use: + +```console +go tool github.com/bcomnes/goversion/v2 -dry patch +go tool github.com/bcomnes/goversion/v2 patch +make all +go tool github.com/bcomnes/goversion/v2 publish +``` + +For hosted releases, manually dispatch `.github/workflows/release.yml` and select a version directive. +The workflow runs the full suite, invokes the immutable `go-bump v0.0.1` action, validates the exact release commit through `make all`, and delegates Git refs, GitHub Release creation, and Go proxy verification back to `goversion publish`. +Explicit custom versions omit the leading `v`, for example `2.5.0`. diff --git a/go.mod b/go.mod index 25d1d65..b5fca41 100644 --- a/go.mod +++ b/go.mod @@ -3,3 +3,5 @@ module github.com/bcomnes/goversion/v2 go 1.25.0 require golang.org/x/mod v0.40.0 + +tool github.com/bcomnes/goversion/v2 From 2c645297448836b8f8dc99f1b3b1cac9f4af1579 Mon Sep 17 00:00:00 2001 From: Bret Comnes Date: Thu, 3 Sep 2026 17:17:02 -0700 Subject: [PATCH 2/3] Use trusted go-bump major reference --- .github/workflows/release.yml | 2 +- CONTRIBUTING.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 65d2f2f..13f9725 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -46,7 +46,7 @@ jobs: - run: make all - id: release - uses: bcomnes/go-bump@f6b52f1871e4298407bff134904f1fa46d9b55db # v0.0.1 + uses: bcomnes/go-bump@v0 with: version-type: ${{ inputs.version-type }} new-version: ${{ inputs.new-version }} diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index a690650..f4ca911 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -27,5 +27,5 @@ go tool github.com/bcomnes/goversion/v2 publish ``` For hosted releases, manually dispatch `.github/workflows/release.yml` and select a version directive. -The workflow runs the full suite, invokes the immutable `go-bump v0.0.1` action, validates the exact release commit through `make all`, and delegates Git refs, GitHub Release creation, and Go proxy verification back to `goversion publish`. +The workflow runs the full suite, invokes the trusted moving `go-bump v0` action reference, validates the exact release commit through `make all`, and delegates Git refs, GitHub Release creation, and Go proxy verification back to `goversion publish`. Explicit custom versions omit the leading `v`, for example `2.5.0`. From ee46691ef8a8cf8095ca6965acb8adc2a0cfa4ed Mon Sep 17 00:00:00 2001 From: Bret Comnes Date: Thu, 3 Sep 2026 17:20:06 -0700 Subject: [PATCH 3/3] Allow moving refs for bcomnes actions --- .github/zizmor.yml | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/.github/zizmor.yml b/.github/zizmor.yml index 897ea90..40bb83f 100644 --- a/.github/zizmor.yml +++ b/.github/zizmor.yml @@ -8,5 +8,7 @@ rules: # Official GitHub actions and CodeQL use major tags for compatible security updates. "actions/*": ref-pin "github/codeql-action/*": ref-pin - # Require immutable references for every third-party action. + # First-party bcomnes actions use moving major references for compatible updates. + "bcomnes/*": ref-pin + # Require immutable references for every other third-party action. "*": hash-pin