Skip to content

ci: release weekly from git history with git-cliff instead of release-please - #418

Merged
panz3r merged 1 commit into
mainfrom
ci/weekly-release
Sep 29, 2026
Merged

panz3r merged 1 commit into
mainfrom
ci/weekly-release

Conversation

@panz3r

@panz3r panz3r commented Sep 29, 2026

Copy link
Copy Markdown
Member

Same release setup as qrcodets (forwardsoftware/qrcodets#93, first release v1.0.1 published this way). It replaces release-please and the weekly merge-release-pr job, which could not work: release PRs are pushed with GITHUB_TOKEN, so required checks never run on them, and dispatched CI runs do not count as required checks.

How it works (release.yml, Tuesdays 17:00 UTC + manual)

  1. git-cliff (orhun/git-cliff-action v4.9.1, pinned) computes the next version and release notes from conventional commits since the last v* tag.
  2. If nothing is releasable (no notes, or the tag already exists) the job stops.
  3. Otherwise: pnpm/setup (pnpm + Node.js latest), build, pnpm version --no-git-tag-version, pnpm publish --publish-wait-timeout 600000 (npm trusted publishing via OIDC, waits until the version is installable), then gh release create vX.Y.Z with the generated notes. Nothing is committed back to main.
  4. A published version is skipped on rerun, so a failed run can be retried safely.
  5. Manual runs accept dry-run: true: compute the version and notes (job summary), build, and run pnpm publish --dry-run.

pnpm publish is used instead of npm publish because the Node.js runtime from pnpm/setup only links node, leaving the runner image npm 10.9.8 on PATH, which cannot do trusted publishing. pnpm 12 does OIDC and provenance natively.

Release rules (cliff.toml)

  • feat → minor, ! / BREAKING CHANGE → major, everything else → patch.
  • feat, fix, perf, refactor, docs and chore are included in the release notes; ci, build, test, style are skipped.
  • Changes that only touch .github/, .devcontainer/, .vscode/ or cliff.toml do not count, so GitHub Actions bumps do not cut npm releases.

Other changes

  • Remove release-please-config.json and .release-please-manifest.json.
  • CHANGELOG.md is frozen with a pointer to GitHub Releases; the README links there too.
  • package.json version in the repo is no longer bumped (stays 6.0.4); the published package gets the right version at publish time.

Verification

Dry run on this branch: run 36632556257 computed v6.0.5 (10 chore commits since v6.0.4), built the CLI, obtained the npm OIDC token, and stopped at Skip publishing @forward-software/react-native-toolbox@6.0.5 (dry run).

@panz3r
panz3r merged commit fd7bb74 into main Sep 29, 2026
11 checks passed
@panz3r
panz3r deleted the ci/weekly-release branch September 29, 2026 21:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant