Skip to content

fix: keep release plan logs concise (#164) #31

fix: keep release plan logs concise (#164)

fix: keep release plan logs concise (#164) #31

# SPDX-FileCopyrightText: 2026 LibreCode coop and contributors
# SPDX-License-Identifier: AGPL-3.0-or-later
name: Publish github-workflows
on:
push:
branches:
- main
paths:
- VERSION
- '.github/workflows/repository-release.yml'
workflow_dispatch:
permissions:
contents: write
concurrency:
group: release
cancel-in-progress: false
jobs:
release:
name: Publish versioned release
if: github.ref == 'refs/heads/main'
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
persist-credentials: false
- name: Read and validate version
id: version
shell: bash
run: |
set -euo pipefail
version="$(tr -d '[:space:]' < VERSION)"
if ! [[ "$version" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]; then
echo "VERSION must use MAJOR.MINOR.PATCH" >&2
exit 1
fi
echo "version=$version" >> "$GITHUB_OUTPUT"
echo "tag=v$version" >> "$GITHUB_OUTPUT"
- name: Run project checks
run: |
python3 -m unittest discover -s tests -p 'test_*.py'
python3 scripts/sync_upstream.py check upstream/sources.json
python3 scripts/render_upstream.py check upstream/templates.json
python3 scripts/check_workflow_policy.py
- name: Publish GitHub release
env:
GH_TOKEN: ${{ github.token }}
TAG: ${{ steps.version.outputs.tag }}
shell: bash
run: |
set -euo pipefail
if gh release view "$TAG" --repo "$GITHUB_REPOSITORY" >/dev/null 2>&1; then
echo "Release $TAG already exists; nothing to do."
exit 0
fi
gh release create "$TAG" --repo "$GITHUB_REPOSITORY" --target "$GITHUB_SHA" --title "$TAG" --generate-notes