ci(deps): bump the github-actions group with 3 updates #1340
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: ${{ github.ref != 'refs/heads/main' }} | |
| # No default grant: a job added later starts with nothing rather than inheriting write | |
| # access it never asked for. | |
| permissions: {} | |
| jobs: | |
| commitlint: | |
| name: Commitlint | |
| runs-on: ubuntu-latest | |
| if: "!startsWith(github.head_ref, 'release-please--')" | |
| permissions: | |
| contents: read | |
| pull-requests: read | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| fetch-depth: 0 | |
| - uses: wagoid/commitlint-github-action@b948419dd99f3fd78a6548d48f94e3df7f6bf3ed # v6.2.1 | |
| with: | |
| configFile: commitlint.config.cjs | |
| commitDepth: 1 | |
| # `commitDepth: 1` lints the head commit, not the subject a squash merge gives `next`, | |
| # which GitHub defaults to the PR title. The title goes through the same config here. | |
| - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| if: github.event_name == 'pull_request' | |
| with: | |
| node-version: "22" | |
| - name: Lint the PR title (the subject a squash merge will actually use) | |
| if: github.event_name == 'pull_request' | |
| env: | |
| PR_TITLE: ${{ github.event.pull_request.title }} | |
| run: | | |
| corepack enable | |
| pnpm install --frozen-lockfile --ignore-scripts | |
| printf '%s' "$PR_TITLE" | pnpm exec commitlint --config commitlint.config.cjs | |
| release-please: | |
| name: Release Please | |
| runs-on: ubuntu-latest | |
| needs: [commitlint] | |
| if: | | |
| always() && | |
| github.event_name == 'push' && | |
| (needs.commitlint.result == 'success' || needs.commitlint.result == 'skipped') | |
| outputs: | |
| release_created: ${{ steps.release.outputs.release_created }} | |
| tag_name: ${{ steps.release.outputs.tag_name }} | |
| version: ${{ steps.release.outputs.version }} | |
| paths_released: ${{ steps.release.outputs.paths_released }} | |
| steps: | |
| - uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0 | |
| id: app-token | |
| with: | |
| app-id: ${{ secrets.AIDD_BOT_APP_ID }} | |
| private-key: ${{ secrets.AIDD_BOT_PRIVATE_KEY }} | |
| - uses: googleapis/release-please-action@45996ed1f6d02564a971a2fa1b5860e934307cf7 # v5.0.0 | |
| id: release | |
| with: | |
| token: ${{ steps.app-token.outputs.token }} | |
| config-file: release-please-config.json | |
| manifest-file: .release-please-manifest.json | |
| # `--admin` is required: the branch policy refuses a plain `gh pr merge` even for a | |
| # bypass actor. The App token also re-fires the `push: main` and `release: published` | |
| # workflows a GITHUB_TOKEN merge would not. Guarded on prs_created, since | |
| # releases_created only fires on merge. | |
| - name: Auto-merge the Release PR | |
| if: ${{ steps.release.outputs.prs_created == 'true' }} | |
| env: | |
| GH_TOKEN: ${{ steps.app-token.outputs.token }} | |
| run: gh pr merge "${{ fromJSON(steps.release.outputs.pr).number }}" --squash --admin --repo "${{ github.repository }}" | |
| # GitHub marks whichever release is created last as "Latest", and release-please | |
| # creates the umbrella and every plugin release in one unordered run — so a plugin | |
| # release can outrank the marketplace version. Bare `tag_name` is the root tag, the one | |
| # carrying the marketplace bundle, and it bumps every cycle. | |
| - name: Pin umbrella release as latest | |
| if: ${{ steps.release.outputs.release_created == 'true' }} | |
| env: | |
| GH_TOKEN: ${{ steps.app-token.outputs.token }} | |
| run: gh release edit "${{ steps.release.outputs.tag_name }}" --latest --repo "${{ github.repository }}" | |
| build-and-attach: | |
| name: Build and attach marketplace | |
| needs: [release-please] | |
| if: needs.release-please.outputs.release_created == 'true' | |
| runs-on: ubuntu-latest | |
| # `gh release upload` writes a release asset, which GitHub treats as a contents change. | |
| permissions: | |
| contents: write | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - name: Build clean marketplace bundle | |
| # Self-contained, for `/plugin marketplace add ./aidd-framework-marketplace-<version>`: | |
| # the catalog manifest and the plugins, and no framework-internal file. | |
| run: | | |
| VERSION="${{ needs.release-please.outputs.version }}" | |
| STAGE_PARENT="$(mktemp -d)" | |
| STAGE="${STAGE_PARENT}/aidd-framework-marketplace-${VERSION}" | |
| mkdir -p "${STAGE}" | |
| cp -R .claude-plugin "${STAGE}/" | |
| cp -R plugins "${STAGE}/" | |
| ( cd "${STAGE_PARENT}" && zip -q -r "/tmp/aidd-framework-marketplace-${VERSION}.zip" "aidd-framework-marketplace-${VERSION}" ) | |
| - name: Attach marketplace bundle to release | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| run: | | |
| VERSION="${{ needs.release-please.outputs.version }}" | |
| TAG="${{ needs.release-please.outputs.tag_name }}" | |
| gh release upload "${TAG}" \ | |
| "/tmp/aidd-framework-marketplace-${VERSION}.zip" \ | |
| --clobber | |
| build-per-tool: | |
| name: Build and attach per-tool distribution | |
| needs: [release-please] | |
| if: needs.release-please.outputs.release_created == 'true' | |
| runs-on: ubuntu-latest | |
| # contents: write — `gh release upload` writes a release asset. | |
| permissions: | |
| contents: write | |
| strategy: | |
| fail-fast: false | |
| # Four marketplace plus five flat — opencode is flat-only. Mirrors the CLI golden | |
| # snapshot matrix. | |
| matrix: | |
| include: | |
| - { tool: claude, mode: marketplace } | |
| - { tool: cursor, mode: marketplace } | |
| - { tool: copilot, mode: marketplace } | |
| - { tool: codex, mode: marketplace } | |
| - { tool: claude, mode: flat } | |
| - { tool: cursor, mode: flat } | |
| - { tool: copilot, mode: flat } | |
| - { tool: codex, mode: flat } | |
| - { tool: opencode, mode: flat } | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| node-version: "22" | |
| - name: Install pnpm | |
| run: corepack enable | |
| # The exact CLI this release is publishing, built from this run's own checkout: a | |
| # published-version pin would need bumping by hand and can name a command that no | |
| # longer exists. | |
| - run: cd cli && pnpm install --frozen-lockfile | |
| - run: cd cli && pnpm build | |
| - name: Build the target-native distribution | |
| run: | | |
| VERSION="${{ needs.release-please.outputs.version }}" | |
| NAME="aidd-framework-${{ matrix.tool }}-${{ matrix.mode }}-${VERSION}" | |
| # --out must live outside --source: the CLI refuses to build when one path | |
| # contains the other, so stage under RUNNER_TEMP rather than the repo tree. | |
| OUT="${RUNNER_TEMP}/dist/${{ matrix.tool }}/${{ matrix.mode }}" | |
| mkdir -p "$OUT" | |
| node cli/dist/cli.js translate . \ | |
| --to ${{ matrix.tool }} --out "$OUT" --as ${{ matrix.mode }} | |
| STAGE="$(mktemp -d)/${NAME}" | |
| mkdir -p "$STAGE" | |
| cp -R "$OUT"/. "$STAGE"/ | |
| ( cd "$(dirname "$STAGE")" && zip -q -r "/tmp/${NAME}.zip" "${NAME}" ) | |
| - name: Attach per-tool distribution to release | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| run: | | |
| VERSION="${{ needs.release-please.outputs.version }}" | |
| TAG="${{ needs.release-please.outputs.tag_name }}" | |
| NAME="aidd-framework-${{ matrix.tool }}-${{ matrix.mode }}-${VERSION}" | |
| gh release upload "${TAG}" "/tmp/${NAME}.zip" --clobber | |
| build-plugin: | |
| name: Build and attach plugin | |
| needs: [release-please] | |
| if: needs.release-please.outputs.paths_released != '' && needs.release-please.outputs.paths_released != '[]' | |
| runs-on: ubuntu-latest | |
| # contents: write — `gh release upload` writes a release asset. | |
| permissions: | |
| contents: write | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| # Every plugin `marketplace.json` lists, and nothing else — asserted by | |
| # scripts/__tests__/release-covers-every-plugin.test.js, since a plugin missing here | |
| # is tagged with no archive and nothing else notices. | |
| plugin: | |
| [ | |
| aidd-context, | |
| aidd-dev, | |
| aidd-vcs, | |
| aidd-pm, | |
| aidd-orchestrator, | |
| aidd-refine, | |
| aidd-ui, | |
| aidd-telemetry, | |
| ] | |
| steps: | |
| - name: Check if this plugin was released | |
| id: check | |
| run: | | |
| PATHS='${{ needs.release-please.outputs.paths_released }}' | |
| if echo "$PATHS" | jq -e --arg p "plugins/${{ matrix.plugin }}" 'map(. == $p) | any' > /dev/null 2>&1; then | |
| echo "released=true" >> $GITHUB_OUTPUT | |
| else | |
| echo "released=false" >> $GITHUB_OUTPUT | |
| fi | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| if: steps.check.outputs.released == 'true' | |
| - name: Get plugin version | |
| id: version | |
| if: steps.check.outputs.released == 'true' | |
| run: | | |
| VERSION=$(jq -r '.version' "plugins/${{ matrix.plugin }}/.claude-plugin/plugin.json") | |
| echo "version=$VERSION" >> $GITHUB_OUTPUT | |
| - name: Build plugin bundle | |
| if: steps.check.outputs.released == 'true' | |
| # Self-contained: a user extracts it and installs the plugin locally. | |
| run: | | |
| PLUGIN="${{ matrix.plugin }}" | |
| VERSION="${{ steps.version.outputs.version }}" | |
| ( cd plugins && zip -q -r "/tmp/${PLUGIN}-v${VERSION}.zip" "${PLUGIN}" ) | |
| - name: Attach plugin bundle to release | |
| if: steps.check.outputs.released == 'true' | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| run: | | |
| PLUGIN="${{ matrix.plugin }}" | |
| VERSION="${{ steps.version.outputs.version }}" | |
| TAG="${PLUGIN}-v${VERSION}" | |
| gh release upload "${TAG}" \ | |
| "/tmp/${PLUGIN}-v${VERSION}.zip" \ | |
| --clobber | |
| publish-cli: | |
| name: Publish cli | |
| needs: [release-please] | |
| if: needs.release-please.outputs.paths_released != '' && contains(fromJSON(needs.release-please.outputs.paths_released), 'cli') | |
| runs-on: ubuntu-latest | |
| # id-token for npm's OIDC trusted publish, packages for the best-effort mirror. | |
| permissions: | |
| contents: read | |
| id-token: write | |
| packages: write | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - name: Install pnpm | |
| run: corepack enable | |
| - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| node-version: "22" | |
| # No kanban install: `cli/src/` names kanban nowhere and the bundle carries none of | |
| # its symbols. | |
| - run: cd cli && pnpm install --frozen-lockfile | |
| - run: cd cli && pnpm build | |
| - name: Publish to GitHub Packages | |
| continue-on-error: true | |
| working-directory: cli | |
| run: | | |
| printf '%s\n%s\n' "@ai-driven-dev:registry=https://npm.pkg.github.com" "//npm.pkg.github.com/:_authToken=${GITHUB_TOKEN}" > .npmrc | |
| pnpm publish --no-git-checks | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| # OIDC trusted publishing (npm CLI >= 11.5.1, Node >= 22.14.0), not a token, so no | |
| # NPM_TOKEN secret is needed. `npm publish` and not `pnpm publish`: pnpm's OIDC support | |
| # is unreliable, and npm's own CLI is the reference implementation for its own feature. | |
| - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| node-version: "22" | |
| registry-url: "https://registry.npmjs.org" | |
| - name: Publish to npm | |
| working-directory: cli | |
| # Pinned, not @latest: this is the release path, so an npm release breaking here | |
| # breaks publishing. Bump by hand. | |
| run: | | |
| rm -f .npmrc | |
| npm install -g npm@11.19.1 | |
| npm publish --access public |