Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/devlens-live-integration.yml
Original file line number Diff line number Diff line change
Expand Up @@ -66,7 +66,7 @@ jobs:
assert set(report["scores"]) == dimensions
assert all(0 <= int(v) <= 100 for v in report["scores"].values())
assert os.environ["BADGE"].startswith("https://img.shields.io/badge/")
assert report["action_version"] == "2.0.0"
assert report["action_version"] == "2.0.8"

print(f"Live DevLens integration passed: {score}/100")

Expand Down
82 changes: 46 additions & 36 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,9 +7,9 @@ on:
workflow_dispatch:
inputs:
tag:
description: 'Version tag to create (e.g. v2.0.3)'
description: 'Version tag to create (e.g. v2.0.8)'
required: true
default: 'v2.0.3'
default: 'v2.0.8'

env:
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true
Expand Down Expand Up @@ -37,7 +37,6 @@ jobs:
env:
EVENT_NAME: ${{ github.event_name }}
INPUT_TAG: ${{ github.event.inputs.tag }}
REF_NAME: ${{ github.ref_name }}
BEFORE_SHA: ${{ github.event.before }}
HEAD_SHA: ${{ github.sha }}
run: |
Expand Down Expand Up @@ -89,35 +88,6 @@ jobs:
echo "should_release=$SHOULD_RELEASE" >> "$GITHUB_OUTPUT"
echo "tag=$TAG" >> "$GITHUB_OUTPUT"

- name: Create or reuse versioned release tag
if: steps.release.outputs.should_release == 'true'
env:
RELEASE_TAG: ${{ steps.release.outputs.tag }}
shell: bash
run: |
set -euo pipefail
git config user.name "github-actions[bot]"
git config user.email "github-actions[bot]@users.noreply.github.com"

git fetch --tags --force origin
if git rev-parse --verify --quiet "refs/tags/$RELEASE_TAG" >/dev/null; then
echo "Release tag already exists and will be reused: $RELEASE_TAG"
else
git tag -a "$RELEASE_TAG" HEAD -m "Release $RELEASE_TAG"
git push origin "$RELEASE_TAG"
echo "Created release tag: $RELEASE_TAG"
fi

- name: Checkout release tag
if: steps.release.outputs.should_release == 'true'
env:
RELEASE_TAG: ${{ steps.release.outputs.tag }}
shell: bash
run: |
set -euo pipefail
git fetch --tags --force origin
git checkout --detach "$RELEASE_TAG"

- name: Pre-release static validation
if: steps.release.outputs.should_release == 'true'
shell: bash
Expand Down Expand Up @@ -170,6 +140,47 @@ jobs:

print(f"Release preflight passed: {score}/100; action version {action_version}")

- name: Validate versioned tag state
if: steps.release.outputs.should_release == 'true'
env:
RELEASE_TAG: ${{ steps.release.outputs.tag }}
HEAD_SHA: ${{ github.sha }}
shell: bash
run: |
set -euo pipefail
git fetch --tags --force origin
if git rev-parse --verify --quiet "refs/tags/$RELEASE_TAG" >/dev/null; then
TAG_SHA="$(git rev-list -n 1 "$RELEASE_TAG^{commit}")"
if [[ "$TAG_SHA" != "$HEAD_SHA" ]]; then
echo "Existing versioned tag $RELEASE_TAG points to $TAG_SHA, not release candidate $HEAD_SHA."
echo "Versioned release tags are immutable; bump the Action version before releasing new content."
exit 1
fi
echo "Existing versioned tag is already anchored to this release candidate: $RELEASE_TAG"
else
echo "Versioned release tag does not exist yet: $RELEASE_TAG"
fi

- name: Create versioned release tag
if: steps.release.outputs.should_release == 'true'
env:
RELEASE_TAG: ${{ steps.release.outputs.tag }}
HEAD_SHA: ${{ github.sha }}
shell: bash
run: |
set -euo pipefail
git config user.name "github-actions[bot]"
git config user.email "github-actions[bot]@users.noreply.github.com"

git fetch --tags --force origin
if git rev-parse --verify --quiet "refs/tags/$RELEASE_TAG" >/dev/null; then
echo "Release tag already exists at the validated candidate: $RELEASE_TAG"
Comment on lines +176 to +177

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Recheck the tag target before accepting it

If RELEASE_TAG is created after the earlier Validate versioned tag state step but before this fetch (for example, by a concurrently dispatched run on a different ref or a manual tag push), this branch accepts it without comparing its peeled commit to HEAD_SHA. The following v2 update then resolves and promotes that foreign tag, and the release is published, even though the current preflight validated different source; repeat the SHA check here (or make validation and creation atomic) before proceeding.

Useful? React with 👍 / 👎.

else
git tag -a "$RELEASE_TAG" "$HEAD_SHA" -m "Release $RELEASE_TAG"
git push origin "$RELEASE_TAG"
echo "Created release tag: $RELEASE_TAG"
fi

- name: Update floating v2 tag
if: steps.release.outputs.should_release == 'true'
env:
Expand All @@ -181,8 +192,7 @@ jobs:
git config user.email "github-actions[bot]@users.noreply.github.com"

git fetch --tags --force origin
git checkout --detach "$RELEASE_TAG"
git tag -fa v2 -m "Floating tag v2 -> $RELEASE_TAG"
git tag -fa v2 -m "Floating tag v2 -> $RELEASE_TAG" "$RELEASE_TAG"
git push origin v2 --force

- name: Publish GitHub Release
Expand All @@ -202,9 +212,9 @@ jobs:
- Zero hosted service dependency

### Usage
\`\`\`yaml
```yaml
- uses: SamoTech/devlens@v2
\`\`\`
```
draft: false
prerelease: false
env:
Expand Down
2 changes: 1 addition & 1 deletion scripts/devlens.py
Original file line number Diff line number Diff line change
Expand Up @@ -162,7 +162,7 @@ def dim_bar(score):
badge_url = (f"https://img.shields.io/badge/DevLens%20Health-{health}%2F100"
f"-{badge_color(health)}?style={BADGE_STYLE}&logo=github")

report = {"repo":REPO_NAME,"score_model":"action-v2-9d","action_version":"2.0.7","health_score":health,"scores":scores,
report = {"repo":REPO_NAME,"score_model":"action-v2-9d","action_version":"2.0.8","health_score":health,"scores":scores,
"badge_url":badge_url,"generated_at":now.isoformat()}

print(json.dumps(report, indent=2))
Expand Down
Loading