-
Notifications
You must be signed in to change notification settings - Fork 4
Tag reviewed main in release workflow #22
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
senamakel
merged 3 commits into
tinyhumansai:main
from
senamakel:tinybrowser-protected-release
Sep 25, 2026
Merged
Changes from all commits
Commits
Show all changes
3 commits
Select commit
Hold shift + click to select a range
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,68 @@ | ||
| #!/usr/bin/env bash | ||
| set -euo pipefail | ||
|
|
||
| : "${EXPECTED_VERSION:?set EXPECTED_VERSION to the merged release version}" | ||
| : "${GITHUB_OUTPUT:?set GITHUB_OUTPUT for release job outputs}" | ||
| : "${RELEASE_PACKAGE:=tinybrowser}" | ||
|
|
||
| if [[ ! "$EXPECTED_VERSION" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]; then | ||
| echo "release version must be major.minor.patch: $EXPECTED_VERSION" >&2 | ||
| exit 1 | ||
| fi | ||
| if [[ "${GITHUB_REF:-}" != refs/heads/main ]]; then | ||
| echo "release tagging is only allowed from main" >&2 | ||
| exit 1 | ||
| fi | ||
| root="$(git rev-parse --show-toplevel)" | ||
| if [[ "$(pwd -P)" != "$(cd "$root" && pwd -P)" ]]; then | ||
| echo "run release tagging from the repository root" >&2 | ||
| exit 1 | ||
| fi | ||
| if ! git diff --quiet || ! git diff --cached --quiet; then | ||
| echo "release checkout has uncommitted tracked changes" >&2 | ||
| exit 1 | ||
| fi | ||
|
|
||
| metadata="$(cargo metadata --format-version 1 --no-deps --locked)" | ||
| crate_name="$(jq -r --arg name "$RELEASE_PACKAGE" \ | ||
| '.packages[] | select(.name == $name) | .name' <<< "$metadata")" | ||
| current_version="$(jq -r --arg name "$RELEASE_PACKAGE" \ | ||
| '.packages[] | select(.name == $name) | .version' <<< "$metadata")" | ||
| if [[ "$crate_name" != "$RELEASE_PACKAGE" || "$current_version" != "$EXPECTED_VERSION" ]]; then | ||
| echo "merged $RELEASE_PACKAGE version is $current_version; expected $EXPECTED_VERSION" >&2 | ||
| exit 1 | ||
| fi | ||
|
|
||
| head_sha="$(git rev-parse HEAD)" | ||
|
senamakel marked this conversation as resolved.
|
||
| main_sha="$(git ls-remote origin refs/heads/main | awk '{print $1}')" | ||
| if [[ -z "$main_sha" || "$head_sha" != "$main_sha" ]]; then | ||
| echo "release HEAD is not the current protected main commit" >&2 | ||
| exit 1 | ||
| fi | ||
|
|
||
| tag="v${current_version}" | ||
| git fetch --tags origin | ||
| if git rev-parse --verify --quiet "refs/tags/${tag}" >/dev/null; then | ||
| if [[ "$(git cat-file -t "refs/tags/${tag}")" != tag ]]; then | ||
| echo "existing release tag $tag must be annotated" >&2 | ||
| exit 1 | ||
| fi | ||
| tagged_sha="$(git rev-list -n 1 "$tag")" | ||
|
senamakel marked this conversation as resolved.
|
||
| if [[ "$tagged_sha" != "$head_sha" ]]; then | ||
| echo "existing tag $tag points to $tagged_sha, not reviewed main $head_sha" >&2 | ||
| exit 1 | ||
| fi | ||
| echo "using existing tag $tag on reviewed main $head_sha" | ||
| else | ||
| git config user.name "github-actions[bot]" | ||
| git config user.email "41898282+github-actions[bot]@users.noreply.github.com" | ||
| git tag -a "$tag" -m "Release $tag" | ||
| git push origin "refs/tags/${tag}" | ||
| echo "created tag $tag on reviewed main $head_sha" | ||
| fi | ||
|
|
||
| { | ||
| echo "crate_name=$crate_name" | ||
| echo "next_version=$current_version" | ||
| echo "tag=$tag" | ||
| } >> "$GITHUB_OUTPUT" | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,88 @@ | ||
| #!/usr/bin/env bash | ||
| set -euo pipefail | ||
|
|
||
| script_dir="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd -P)" | ||
| scratch="$(mktemp -d)" | ||
| trap 'rm -rf "$scratch"' EXIT | ||
|
|
||
| git init -q --bare "$scratch/remote.git" | ||
| git init -q -b main "$scratch/work" | ||
| git -C "$scratch/work" config user.name "Release test" | ||
| git -C "$scratch/work" config user.email "release-test@example.invalid" | ||
| printf 'first reviewed commit\n' > "$scratch/work/source.txt" | ||
| git -C "$scratch/work" add source.txt | ||
| git -C "$scratch/work" commit -qm 'Initial reviewed source' | ||
| git -C "$scratch/work" remote add origin "$scratch/remote.git" | ||
| git -C "$scratch/work" push -q -u origin main | ||
|
|
||
| mkdir "$scratch/fakebin" | ||
| cat > "$scratch/fakebin/cargo" <<'FAKE_CARGO' | ||
| #!/usr/bin/env bash | ||
| set -euo pipefail | ||
| [[ "$1" == metadata ]] | ||
| printf '{"packages":[{"name":"tinybrowser","version":"%s"}]}\n' "$TEST_VERSION" | ||
| FAKE_CARGO | ||
| chmod +x "$scratch/fakebin/cargo" | ||
|
|
||
| run_tag() { | ||
| ( | ||
| cd "$scratch/work" | ||
| PATH="$scratch/fakebin:$PATH" \ | ||
| TEST_VERSION="${3:-0.2.2}" EXPECTED_VERSION="$1" \ | ||
| GITHUB_REF="${2:-refs/heads/main}" \ | ||
| GITHUB_OUTPUT="$scratch/outputs" RELEASE_PACKAGE=tinybrowser \ | ||
| "$script_dir/tag-reviewed-release.sh" | ||
| ) | ||
| } | ||
|
|
||
| if run_tag 0.2.3 > "$scratch/mismatch.out" 2>&1; then | ||
| echo "tagged a version that was not merged" >&2 | ||
| exit 1 | ||
| fi | ||
| grep -q 'expected 0.2.3' "$scratch/mismatch.out" | ||
| if run_tag 0.2.2 refs/heads/feature > "$scratch/branch.out" 2>&1; then | ||
| echo "tagged a non-main branch" >&2 | ||
| exit 1 | ||
| fi | ||
| grep -q 'only allowed from main' "$scratch/branch.out" | ||
|
|
||
| printf 'unreviewed local commit\n' >> "$scratch/work/source.txt" | ||
| git -C "$scratch/work" commit -qam 'Local unreviewed change' | ||
| if run_tag 0.2.2 > "$scratch/unreviewed.out" 2>&1; then | ||
| echo "tagged a commit not on protected main" >&2 | ||
| exit 1 | ||
| fi | ||
| grep -q 'not the current protected main commit' "$scratch/unreviewed.out" | ||
|
|
||
| git -C "$scratch/work" push -q origin main | ||
| reviewed_sha="$(git -C "$scratch/work" rev-parse HEAD)" | ||
| run_tag 0.2.2 > "$scratch/created.out" | ||
| [[ "$(git -C "$scratch/work" rev-list -n 1 v0.2.2)" == "$reviewed_sha" ]] | ||
| [[ "$(git -C "$scratch/work" ls-remote origin refs/heads/main | awk '{print $1}')" == "$reviewed_sha" ]] | ||
| [[ -n "$(git -C "$scratch/work" ls-remote origin refs/tags/v0.2.2)" ]] | ||
| grep -q '^next_version=0.2.2$' "$scratch/outputs" | ||
| grep -q '^tag=v0.2.2$' "$scratch/outputs" | ||
|
|
||
| run_tag 0.2.2 > "$scratch/existing.out" | ||
| grep -q 'using existing tag v0.2.2' "$scratch/existing.out" | ||
|
|
||
| git -C "$scratch/work" update-ref refs/tags/v0.2.3 HEAD | ||
| git -C "$scratch/work" push -q origin refs/tags/v0.2.3 | ||
| if run_tag 0.2.3 refs/heads/main 0.2.3 > "$scratch/lightweight.out" 2>&1; then | ||
| echo "accepted a lightweight release tag" >&2 | ||
| exit 1 | ||
| fi | ||
| grep -q 'must be annotated' "$scratch/lightweight.out" | ||
|
|
||
| printf 'later reviewed commit\n' >> "$scratch/work/source.txt" | ||
|
senamakel marked this conversation as resolved.
|
||
| git -C "$scratch/work" commit -qam 'Later reviewed source' | ||
| git -C "$scratch/work" push -q origin main | ||
| [[ "$(git -C "$scratch/work" ls-remote origin refs/heads/main | awk '{print $1}')" == \ | ||
| "$(git -C "$scratch/work" rev-parse HEAD)" ]] | ||
| if run_tag 0.2.2 > "$scratch/stale-tag.out" 2>&1; then | ||
|
senamakel marked this conversation as resolved.
|
||
| echo "accepted a tag pointing to an older commit" >&2 | ||
| exit 1 | ||
| fi | ||
| grep -q 'not reviewed main' "$scratch/stale-tag.out" | ||
|
senamakel marked this conversation as resolved.
|
||
|
|
||
| echo "reviewed release tag tests passed" | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.