ci(semantic-release): auto versioning via semantic-release

- .releaserc.json: commit-analyzer + release-notes-generator + changelog
  + exec (prepare) + git + github plugins.
- .semrel/prepare.mjs: syncs next release version into package.json AND
  flake.nix before the release commit — guarantees a fresh Nix store path
  on every deploy (fixes the trap where a source change without a version
  bump reused the same store path and CI silently deployed stale code).
- release.yml: runs semantic-release on main push (GITHUB_TOKEN,
  isolated /tmp/sr-tools install so package.json/bun.lock stay clean).
- Release commit (no [skip ci]) triggers deploy.yml → auto build+deploy.
- Baseline tag v1.1.1 backfilled at current HEAD.
This commit is contained in:
asepharyana
2026-09-06 00:36:01 +07:00
parent 9743fbf4b7
commit f16161d38a
3 changed files with 106 additions and 0 deletions
+43
View File
@@ -0,0 +1,43 @@
name: Semantic Release
on:
push:
branches: [main]
permissions:
contents: write
id-token: write
concurrency:
group: release
cancel-in-progress: false
jobs:
release:
if: github.actor != 'dependabot[bot]'
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v7
with:
fetch-depth: 0
# semantic-release needs the full history + tags to analyse commits
persist-credentials: true
- uses: oven-sh/setup-bun@v2
with:
bun-version: "1.3.14"
- name: Install semantic-release (isolated, no package.json pollution)
run: |
npm install --prefix /tmp/sr-tools \
semantic-release@^24 \
@semantic-release/changelog@^6 \
@semantic-release/exec@^6 \
@semantic-release/git@^10
echo "/tmp/sr-tools/node_modules/.bin" >> "$GITHUB_PATH"
- name: Run semantic-release
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: semantic-release