Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
28 changes: 28 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
version: 2
updates:
- package-ecosystem: npm
directory: /
# The default branch is next. Omit target-branch so security groups apply too.
schedule:
interval: weekly
day: monday
open-pull-requests-limit: 5
commit-message:
prefix: "fix(*)"
groups:
security:
applies-to: security-updates
patterns: ["*"]
development:
dependency-type: development
update-types: [minor, patch]
versioning-strategy: increase
- package-ecosystem: github-actions
directory: /
schedule:
interval: weekly
commit-message:
prefix: ci
groups:
actions:
patterns: ["*"]
6 changes: 3 additions & 3 deletions .github/workflows/e2e-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,11 +18,11 @@ on:
default: 'next'

permissions:
contents: write
id-token: write
contents: read

jobs:
e2e:
if: github.ref == 'refs/heads/next'
name: E2E (${{ matrix.e2e-project }}, Node ${{ matrix.node-version }})
runs-on: ubuntu-latest
strategy:
Expand All @@ -34,7 +34,7 @@ jobs:
- name: Checkout
uses: actions/checkout@v4
with:
ref: ${{ inputs.target_branch }}
ref: next
fetch-depth: 0

- name: Setup Node ${{ matrix.node-version }}
Expand Down
174 changes: 32 additions & 142 deletions .github/workflows/release-preview.yml
Original file line number Diff line number Diff line change
@@ -1,165 +1,55 @@
name: Release Preview

on:
workflow_dispatch:
inputs:
release_type:
description: 'Release Type'
description: Release type to preview locally
type: choice
options:
- 'prerelease'
- 'graduate'
- 'auto'
options: [prerelease, graduate, auto]
default: auto
required: true
default: 'auto'
preid:
description: 'Prerelease ID (for prerelease type)'
description: Prerelease identifier
type: choice
options:
- 'next'
- 'rc'
- 'alpha'
- 'beta'
- 'dev'
required: false
default: 'next'

options: [dev, next, rc, alpha, beta]
default: next
required: true
permissions:
contents: read

jobs:
preview:
name: Preview Release
if: github.ref == 'refs/heads/next'
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- uses: actions/checkout@v4
with:
ref: next
fetch-depth: 0
persist-credentials: false

- name: Setup Node
uses: actions/setup-node@v4
with:
node-version: '22.x'

- name: Install pnpm
uses: pnpm/action-setup@v4
- uses: pnpm/action-setup@v4
with:
version: 9.15.4

- name: Install dependencies
run: pnpm install --frozen-lockfile

- name: Install conventional-changelog-cli
run: npm install -g conventional-changelog-cli

- name: Config Git
run: |
git config --global user.email "preview@contractual.dev"
git config --global user.name "Release Preview Bot"

- name: Show Changed Packages
run: |
echo "## Changed Packages" >> $GITHUB_STEP_SUMMARY
echo "" >> $GITHUB_STEP_SUMMARY
echo "Packages that have changed since last release:" >> $GITHUB_STEP_SUMMARY
echo "" >> $GITHUB_STEP_SUMMARY
npx lerna changed --json 2>/dev/null | jq -r '.[] | "- **\(.name)** (current: `v\(.version)`)"' >> $GITHUB_STEP_SUMMARY || echo "No changed packages" >> $GITHUB_STEP_SUMMARY

- name: Preview Versions (Prerelease)
if: ${{ inputs.release_type == 'prerelease' }}
run: |
npx lerna version prerelease --yes \
--preid ${{ inputs.preid }} \
--no-git-tag-version \
--no-push \
--allow-branch next

- name: Preview Versions (Graduate)
if: ${{ inputs.release_type == 'graduate' }}
run: |
npx lerna version --yes \
--conventional-graduate \
--no-git-tag-version \
--no-push \
--allow-branch next

- name: Preview Versions (Auto - Conventional Commits)
if: ${{ inputs.release_type == 'auto' }}
run: |
npx lerna version --yes \
--conventional-commits \
--no-git-tag-version \
--no-push \
--allow-branch next

- name: Generate Version Summary
run: |
echo "" >> $GITHUB_STEP_SUMMARY
echo "## Proposed Versions" >> $GITHUB_STEP_SUMMARY
echo "" >> $GITHUB_STEP_SUMMARY
echo "**Release Type:** \`${{ inputs.release_type }}\`" >> $GITHUB_STEP_SUMMARY
if [ "${{ inputs.release_type }}" = "prerelease" ]; then
echo "**Prerelease ID:** \`${{ inputs.preid }}\`" >> $GITHUB_STEP_SUMMARY
fi
echo "" >> $GITHUB_STEP_SUMMARY
npx lerna ls --json | jq -r '.[] | "- **\(.name)** -> `v\(.version)`"' >> $GITHUB_STEP_SUMMARY

- name: Show Git Diff
run: |
echo "" >> $GITHUB_STEP_SUMMARY
echo "## Package.json Changes" >> $GITHUB_STEP_SUMMARY
echo "" >> $GITHUB_STEP_SUMMARY
echo '```diff' >> $GITHUB_STEP_SUMMARY
git diff packages/*/package.json | head -100 >> $GITHUB_STEP_SUMMARY
echo '```' >> $GITHUB_STEP_SUMMARY

- name: Generate Changelog Preview
run: |
echo "" >> $GITHUB_STEP_SUMMARY
echo "## Changelog Preview" >> $GITHUB_STEP_SUMMARY
echo "" >> $GITHUB_STEP_SUMMARY

npx lerna exec --concurrency 1 --stream -- \
'conventional-changelog --preset angular --release-count 1 \
--commit-path $PWD --pkg $PWD/package.json' 2>/dev/null | \
sed 's/^[^:]*: //' >> $GITHUB_STEP_SUMMARY || echo "No changelog entries generated" >> $GITHUB_STEP_SUMMARY

- name: Show Conventional Commit Analysis
run: |
echo "" >> $GITHUB_STEP_SUMMARY
echo "## Commit Analysis" >> $GITHUB_STEP_SUMMARY
echo "" >> $GITHUB_STEP_SUMMARY

breaking=$(git log --oneline --no-merges $(git describe --tags --abbrev=0 2>/dev/null || echo HEAD~50)..HEAD 2>/dev/null | grep -c "!" || echo "0")
features=$(git log --oneline --no-merges $(git describe --tags --abbrev=0 2>/dev/null || echo HEAD~50)..HEAD 2>/dev/null | grep -c "^[a-z0-9]* feat" || echo "0")
fixes=$(git log --oneline --no-merges $(git describe --tags --abbrev=0 2>/dev/null || echo HEAD~50)..HEAD 2>/dev/null | grep -c "^[a-z0-9]* fix" || echo "0")

echo "- **Breaking Changes**: $breaking" >> $GITHUB_STEP_SUMMARY
echo "- **Features**: $features" >> $GITHUB_STEP_SUMMARY
echo "- **Fixes**: $fixes" >> $GITHUB_STEP_SUMMARY
echo "" >> $GITHUB_STEP_SUMMARY

if [ "$breaking" -gt 0 ]; then
echo "**This release contains breaking changes!**" >> $GITHUB_STEP_SUMMARY
fi

- name: Cleanup
if: always()
run: |
git reset --hard HEAD
git clean -fd

- name: Summary Footer
run: |
echo "" >> $GITHUB_STEP_SUMMARY
echo "---" >> $GITHUB_STEP_SUMMARY
echo "" >> $GITHUB_STEP_SUMMARY
echo "**This is a preview only.** No changes have been committed or pushed." >> $GITHUB_STEP_SUMMARY
echo "" >> $GITHUB_STEP_SUMMARY
echo "To proceed with this release:" >> $GITHUB_STEP_SUMMARY
echo "1. Run **Prepare Release** workflow" >> $GITHUB_STEP_SUMMARY
echo "2. Then run **Publish Packages** workflow" >> $GITHUB_STEP_SUMMARY
- uses: actions/setup-node@v4
with:
node-version: 22
# Deliberately do not read or write caches in release workflows.
- run: pnpm install --frozen-lockfile
- name: Preview versions without commits, tags, or publication
env:
RELEASE_TYPE: ${{ inputs.release_type }}
PREID: ${{ inputs.preid }}
run: |
case "$PREID" in dev|next|rc|alpha|beta) ;; *) exit 1 ;; esac
args=(--yes --no-git-tag-version --no-push --no-commit-hooks --allow-branch next)
case "$RELEASE_TYPE" in
prerelease) pnpm exec lerna version prerelease --preid "$PREID" "${args[@]}" ;;
graduate) pnpm exec lerna version --conventional-graduate "${args[@]}" ;;
auto) pnpm exec lerna version --conventional-commits "${args[@]}" ;;
*) exit 1 ;;
esac
- name: Summarize local preview
run: |
echo '## Proposed versions (preview only)' >> "$GITHUB_STEP_SUMMARY"
pnpm exec lerna ls --json | jq -r '.[] | "- **\(.name)**: \(.version)"' >> "$GITHUB_STEP_SUMMARY"
echo 'No commits, tags, or packages were published. Ask Omer before preparing or publishing a release.' >> "$GITHUB_STEP_SUMMARY"
25 changes: 25 additions & 0 deletions .github/workflows/security-audit.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
name: Dependency security audit
on:
pull_request:
branches: [next]
push:
branches: [next]
schedule:
- cron: '30 6 * * 1'
permissions:
contents: read
jobs:
audit:
name: Dependency audit
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
persist-credentials: false
- uses: pnpm/action-setup@v4
with:
version: 9.15.4
- uses: actions/setup-node@v4
with:
node-version: 22
- run: pnpm audit --audit-level low
89 changes: 12 additions & 77 deletions .github/workflows/set-coverage.yml
Original file line number Diff line number Diff line change
@@ -1,93 +1,28 @@
name: Test & Coverage
on:
push:
branches:
- master

branches: [next]
permissions:
id-token: write
contents: read
checks: write

jobs:
test:
name: Test
runs-on: ubuntu-latest
strategy:
matrix:
project: ['cli', 'governance', 'changesets', 'json-schema-differ', 'types']
steps:
- name: Checkout
uses: actions/checkout@v4

- name: Setup Node
uses: actions/setup-node@v4
- uses: actions/checkout@v4
with:
node-version: '22.x'

- uses: actions/cache@v4
with:
path: '**/node_modules'
key: ${{ runner.os }}-modules-${{ hashFiles('**/pnpm-lock.yaml') }}

- name: Install pnpm
uses: pnpm/action-setup@v4
persist-credentials: false
- uses: pnpm/action-setup@v4
with:
version: 9.15.4

- name: Install dependencies
run: pnpm install --frozen-lockfile

- name: Build
run: pnpm build

- name: Create Coverage Directory
run: mkdir -p ${{ github.workspace }}/coverage

- name: Test
run: pnpm lerna run test --scope @contractual/${{ matrix.project }} --stream
continue-on-error: true
env:
COVERAGE_DIR: ${{ github.workspace }}/coverage
COVERAGE_FILE: coverage-${{ matrix.project }}.xml

- name: Upload Report to Codecov
- uses: actions/setup-node@v4
with:
node-version: 22
- run: pnpm install --frozen-lockfile
- run: pnpm build
- run: pnpm exec vitest run --coverage
- name: Upload report to Codecov
uses: codecov/codecov-action@v4
with:
name: codecov-umbrella
flags: ${{ matrix.project }}
token: ${{ secrets.CODECOV_TOKEN }}
fail_ci_if_error: false
files: ${{ github.workspace }}/coverage/coverage-${{ matrix.project }}.xml
verbose: true

e2e:
name: E2E Tests
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4

- name: Setup Node
uses: actions/setup-node@v4
with:
node-version: '22.x'

- uses: actions/cache@v4
with:
path: '**/node_modules'
key: ${{ runner.os }}-modules-${{ hashFiles('**/pnpm-lock.yaml') }}

- name: Install pnpm
uses: pnpm/action-setup@v4
with:
version: 9.15.4

- name: Install dependencies
run: pnpm install --frozen-lockfile

- name: Build
run: pnpm build

- name: Run E2E Tests
run: pnpm test:e2e
files: coverage/cobertura-coverage.xml
2 changes: 1 addition & 1 deletion e2e/cli-basic/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
},
"devDependencies": {
"@types/node": "^22.10.2",
"vitest": "^3.0.3",
"vitest": "^4.1.11",
"typescript": "~5.7.2"
},
"scripts": {
Expand Down
2 changes: 1 addition & 1 deletion e2e/cli-lifecycle/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
},
"devDependencies": {
"@types/node": "^22.10.2",
"vitest": "^3.0.3",
"vitest": "^4.1.11",
"typescript": "~5.7.2",
"yaml": "^2.8.2"
},
Expand Down
Loading
Loading