dispatch.mjs dispatches deploy.yml via workflow_dispatch, which requires actions: write. Without it the success hook hit HTTP 403 (Resource not accessible by integration), same trap as the mytheclipse pipeline, and the auto deploy never ran for v1.2.1.
45 lines
1.1 KiB
YAML
45 lines
1.1 KiB
YAML
name: Semantic Release
|
|
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
workflow_dispatch:
|
|
|
|
permissions:
|
|
contents: write
|
|
actions: write
|
|
id-token: write
|
|
|
|
concurrency:
|
|
group: release
|
|
cancel-in-progress: false
|
|
|
|
jobs:
|
|
release:
|
|
if: github.actor != 'dependabot[bot]'
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v7
|
|
with:
|
|
fetch-depth: 0
|
|
# semantic-release needs the full history + tags to analyse commits
|
|
persist-credentials: true
|
|
|
|
- uses: oven-sh/setup-bun@v2
|
|
with:
|
|
bun-version: "1.3.14"
|
|
|
|
- name: Install semantic-release (isolated, no package.json pollution)
|
|
run: |
|
|
npm install --prefix /tmp/sr-tools \
|
|
semantic-release@^24 \
|
|
@semantic-release/changelog@^6 \
|
|
@semantic-release/exec@^6 \
|
|
@semantic-release/git@^10
|
|
echo "/tmp/sr-tools/node_modules/.bin" >> "$GITHUB_PATH"
|
|
|
|
- name: Run semantic-release
|
|
env:
|
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
run: semantic-release |