Skip to content

ci(deps): bump the github-actions group with 3 updates #1340

ci(deps): bump the github-actions group with 3 updates

ci(deps): bump the github-actions group with 3 updates #1340

Workflow file for this run

name: CI
on:
push:
branches: [main]
pull_request:
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: ${{ github.ref != 'refs/heads/main' }}
# No default grant: a job added later starts with nothing rather than inheriting write
# access it never asked for.
permissions: {}
jobs:
commitlint:
name: Commitlint
runs-on: ubuntu-latest
if: "!startsWith(github.head_ref, 'release-please--')"
permissions:
contents: read
pull-requests: read
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
- uses: wagoid/commitlint-github-action@b948419dd99f3fd78a6548d48f94e3df7f6bf3ed # v6.2.1
with:
configFile: commitlint.config.cjs
commitDepth: 1
# `commitDepth: 1` lints the head commit, not the subject a squash merge gives `next`,
# which GitHub defaults to the PR title. The title goes through the same config here.
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
if: github.event_name == 'pull_request'
with:
node-version: "22"
- name: Lint the PR title (the subject a squash merge will actually use)
if: github.event_name == 'pull_request'
env:
PR_TITLE: ${{ github.event.pull_request.title }}
run: |
corepack enable
pnpm install --frozen-lockfile --ignore-scripts
printf '%s' "$PR_TITLE" | pnpm exec commitlint --config commitlint.config.cjs
release-please:
name: Release Please
runs-on: ubuntu-latest
needs: [commitlint]
if: |
always() &&
github.event_name == 'push' &&
(needs.commitlint.result == 'success' || needs.commitlint.result == 'skipped')
outputs:
release_created: ${{ steps.release.outputs.release_created }}
tag_name: ${{ steps.release.outputs.tag_name }}
version: ${{ steps.release.outputs.version }}
paths_released: ${{ steps.release.outputs.paths_released }}
steps:
- uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
id: app-token
with:
app-id: ${{ secrets.AIDD_BOT_APP_ID }}
private-key: ${{ secrets.AIDD_BOT_PRIVATE_KEY }}
- uses: googleapis/release-please-action@45996ed1f6d02564a971a2fa1b5860e934307cf7 # v5.0.0
id: release
with:
token: ${{ steps.app-token.outputs.token }}
config-file: release-please-config.json
manifest-file: .release-please-manifest.json
# `--admin` is required: the branch policy refuses a plain `gh pr merge` even for a
# bypass actor. The App token also re-fires the `push: main` and `release: published`
# workflows a GITHUB_TOKEN merge would not. Guarded on prs_created, since
# releases_created only fires on merge.
- name: Auto-merge the Release PR
if: ${{ steps.release.outputs.prs_created == 'true' }}
env:
GH_TOKEN: ${{ steps.app-token.outputs.token }}
run: gh pr merge "${{ fromJSON(steps.release.outputs.pr).number }}" --squash --admin --repo "${{ github.repository }}"
# GitHub marks whichever release is created last as "Latest", and release-please
# creates the umbrella and every plugin release in one unordered run — so a plugin
# release can outrank the marketplace version. Bare `tag_name` is the root tag, the one
# carrying the marketplace bundle, and it bumps every cycle.
- name: Pin umbrella release as latest
if: ${{ steps.release.outputs.release_created == 'true' }}
env:
GH_TOKEN: ${{ steps.app-token.outputs.token }}
run: gh release edit "${{ steps.release.outputs.tag_name }}" --latest --repo "${{ github.repository }}"
build-and-attach:
name: Build and attach marketplace
needs: [release-please]
if: needs.release-please.outputs.release_created == 'true'
runs-on: ubuntu-latest
# `gh release upload` writes a release asset, which GitHub treats as a contents change.
permissions:
contents: write
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Build clean marketplace bundle
# Self-contained, for `/plugin marketplace add ./aidd-framework-marketplace-<version>`:
# the catalog manifest and the plugins, and no framework-internal file.
run: |
VERSION="${{ needs.release-please.outputs.version }}"
STAGE_PARENT="$(mktemp -d)"
STAGE="${STAGE_PARENT}/aidd-framework-marketplace-${VERSION}"
mkdir -p "${STAGE}"
cp -R .claude-plugin "${STAGE}/"
cp -R plugins "${STAGE}/"
( cd "${STAGE_PARENT}" && zip -q -r "/tmp/aidd-framework-marketplace-${VERSION}.zip" "aidd-framework-marketplace-${VERSION}" )
- name: Attach marketplace bundle to release
env:
GH_TOKEN: ${{ github.token }}
run: |
VERSION="${{ needs.release-please.outputs.version }}"
TAG="${{ needs.release-please.outputs.tag_name }}"
gh release upload "${TAG}" \
"/tmp/aidd-framework-marketplace-${VERSION}.zip" \
--clobber
build-per-tool:
name: Build and attach per-tool distribution
needs: [release-please]
if: needs.release-please.outputs.release_created == 'true'
runs-on: ubuntu-latest
# contents: write — `gh release upload` writes a release asset.
permissions:
contents: write
strategy:
fail-fast: false
# Four marketplace plus five flat — opencode is flat-only. Mirrors the CLI golden
# snapshot matrix.
matrix:
include:
- { tool: claude, mode: marketplace }
- { tool: cursor, mode: marketplace }
- { tool: copilot, mode: marketplace }
- { tool: codex, mode: marketplace }
- { tool: claude, mode: flat }
- { tool: cursor, mode: flat }
- { tool: copilot, mode: flat }
- { tool: codex, mode: flat }
- { tool: opencode, mode: flat }
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: "22"
- name: Install pnpm
run: corepack enable
# The exact CLI this release is publishing, built from this run's own checkout: a
# published-version pin would need bumping by hand and can name a command that no
# longer exists.
- run: cd cli && pnpm install --frozen-lockfile
- run: cd cli && pnpm build
- name: Build the target-native distribution
run: |
VERSION="${{ needs.release-please.outputs.version }}"
NAME="aidd-framework-${{ matrix.tool }}-${{ matrix.mode }}-${VERSION}"
# --out must live outside --source: the CLI refuses to build when one path
# contains the other, so stage under RUNNER_TEMP rather than the repo tree.
OUT="${RUNNER_TEMP}/dist/${{ matrix.tool }}/${{ matrix.mode }}"
mkdir -p "$OUT"
node cli/dist/cli.js translate . \
--to ${{ matrix.tool }} --out "$OUT" --as ${{ matrix.mode }}
STAGE="$(mktemp -d)/${NAME}"
mkdir -p "$STAGE"
cp -R "$OUT"/. "$STAGE"/
( cd "$(dirname "$STAGE")" && zip -q -r "/tmp/${NAME}.zip" "${NAME}" )
- name: Attach per-tool distribution to release
env:
GH_TOKEN: ${{ github.token }}
run: |
VERSION="${{ needs.release-please.outputs.version }}"
TAG="${{ needs.release-please.outputs.tag_name }}"
NAME="aidd-framework-${{ matrix.tool }}-${{ matrix.mode }}-${VERSION}"
gh release upload "${TAG}" "/tmp/${NAME}.zip" --clobber
build-plugin:
name: Build and attach plugin
needs: [release-please]
if: needs.release-please.outputs.paths_released != '' && needs.release-please.outputs.paths_released != '[]'
runs-on: ubuntu-latest
# contents: write — `gh release upload` writes a release asset.
permissions:
contents: write
strategy:
fail-fast: false
matrix:
# Every plugin `marketplace.json` lists, and nothing else — asserted by
# scripts/__tests__/release-covers-every-plugin.test.js, since a plugin missing here
# is tagged with no archive and nothing else notices.
plugin:
[
aidd-context,
aidd-dev,
aidd-vcs,
aidd-pm,
aidd-orchestrator,
aidd-refine,
aidd-ui,
aidd-telemetry,
]
steps:
- name: Check if this plugin was released
id: check
run: |
PATHS='${{ needs.release-please.outputs.paths_released }}'
if echo "$PATHS" | jq -e --arg p "plugins/${{ matrix.plugin }}" 'map(. == $p) | any' > /dev/null 2>&1; then
echo "released=true" >> $GITHUB_OUTPUT
else
echo "released=false" >> $GITHUB_OUTPUT
fi
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
if: steps.check.outputs.released == 'true'
- name: Get plugin version
id: version
if: steps.check.outputs.released == 'true'
run: |
VERSION=$(jq -r '.version' "plugins/${{ matrix.plugin }}/.claude-plugin/plugin.json")
echo "version=$VERSION" >> $GITHUB_OUTPUT
- name: Build plugin bundle
if: steps.check.outputs.released == 'true'
# Self-contained: a user extracts it and installs the plugin locally.
run: |
PLUGIN="${{ matrix.plugin }}"
VERSION="${{ steps.version.outputs.version }}"
( cd plugins && zip -q -r "/tmp/${PLUGIN}-v${VERSION}.zip" "${PLUGIN}" )
- name: Attach plugin bundle to release
if: steps.check.outputs.released == 'true'
env:
GH_TOKEN: ${{ github.token }}
run: |
PLUGIN="${{ matrix.plugin }}"
VERSION="${{ steps.version.outputs.version }}"
TAG="${PLUGIN}-v${VERSION}"
gh release upload "${TAG}" \
"/tmp/${PLUGIN}-v${VERSION}.zip" \
--clobber
publish-cli:
name: Publish cli
needs: [release-please]
if: needs.release-please.outputs.paths_released != '' && contains(fromJSON(needs.release-please.outputs.paths_released), 'cli')
runs-on: ubuntu-latest
# id-token for npm's OIDC trusted publish, packages for the best-effort mirror.
permissions:
contents: read
id-token: write
packages: write
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Install pnpm
run: corepack enable
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: "22"
# No kanban install: `cli/src/` names kanban nowhere and the bundle carries none of
# its symbols.
- run: cd cli && pnpm install --frozen-lockfile
- run: cd cli && pnpm build
- name: Publish to GitHub Packages
continue-on-error: true
working-directory: cli
run: |
printf '%s\n%s\n' "@ai-driven-dev:registry=https://npm.pkg.github.com" "//npm.pkg.github.com/:_authToken=${GITHUB_TOKEN}" > .npmrc
pnpm publish --no-git-checks
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
# OIDC trusted publishing (npm CLI >= 11.5.1, Node >= 22.14.0), not a token, so no
# NPM_TOKEN secret is needed. `npm publish` and not `pnpm publish`: pnpm's OIDC support
# is unreliable, and npm's own CLI is the reference implementation for its own feature.
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: "22"
registry-url: "https://registry.npmjs.org"
- name: Publish to npm
working-directory: cli
# Pinned, not @latest: this is the release path, so an npm release breaking here
# breaks publishing. Bump by hand.
run: |
rm -f .npmrc
npm install -g npm@11.19.1
npm publish --access public