Skip to content

Merge pull request #6 from scaleapi/ci/bandit-fetch-head-by-sha #1

Merge pull request #6 from scaleapi/ci/bandit-fetch-head-by-sha

Merge pull request #6 from scaleapi/ci/bandit-fetch-head-by-sha #1

name: Release Please
# Hand-edited from the stlc-generated template. `.github/workflows/*.yml` is
# scaffold-once, so this survives every later build -- upstream's own source cites
# exactly this PAT-to-App swap as the reason that preservation exists. Do NOT run
# `stlc build --rewrite-scaffold` without reapplying these three changes.
#
# What changed from the generated file, and why each is load-bearing:
#
# 1. App token instead of `secrets.RELEASE_PLEASE_TOKEN`, which does not exist
# and which we do not want to create -- eliminating PATs was the point of the
# App migration. It is deliberately NOT `GITHUB_TOKEN`: releases created by
# GITHUB_TOKEN do not trigger other workflows, so publish-*.yml would never
# fire and the release would stop one hop short of the registry.
#
# 2. The `npx release-please@16` CLI instead of googleapis/release-please-action.
# scale-agentex-typescript sets `allowed_actions: selected` and does not permit
# that action; the CLI needs only actions/-owned steps, which
# `github_owned_allowed: true` covers on both production repos.
#
# 3. `issues: write` on the minted token. release-please drives its
# autorelease:pending -> autorelease:tagged labels through the Issues API.
# Without it you get duplicate release pull requests. The generated file omits
# it, and the omission is silent until it bites.
#
# Requires AGENTEX_SDK_SYNC_PRIVATE_KEY (secret) and AGENTEX_SDK_SYNC_APP_ID
# (variable) on the PRODUCTION repo -- a workflow only reads secrets from the repo
# it runs in, and the guard below means that is production.
on:
push:
branches:
- main
workflow_dispatch:
permissions:
contents: read
jobs:
release-please:
# Self-routing: this file is SHA-identical on the staging trunk, where it must
# stay inert. Only production cuts releases.
if: github.repository == 'scaleapi/scale-agentex-python'
runs-on: ubuntu-latest
steps:
- name: Mint release token
id: release-token
uses: actions/create-github-app-token@v2
with:
app-id: ${{ vars.AGENTEX_SDK_SYNC_APP_ID }}
private-key: ${{ secrets.AGENTEX_SDK_SYNC_PRIVATE_KEY }}
owner: scaleapi
repositories: scale-agentex-python
permission-contents: write
permission-pull-requests: write
permission-issues: write
permission-metadata: read
- uses: actions/setup-node@v4
with:
node-version: '20'
- name: Release PR + GitHub release
env:
RP_TOKEN: ${{ steps.release-token.outputs.token }}
run: |
# release-pr opens or updates the version-bump pull request;
# github-release turns an already-merged one into the tag + GitHub Release
# that publish-pypi.yml / publish-npm.yml trigger on. Both are idempotent,
# so running the pair on every push carries a release the whole way.
#
# No checkout step is needed: release-please reads the config and manifest
# from the repo over the API.
npx --yes release-please@16 release-pr \
--token="$RP_TOKEN" --repo-url="${{ github.repository }}" \
--config-file=release-please-config.json \
--manifest-file=.release-please-manifest.json
npx --yes release-please@16 github-release \
--token="$RP_TOKEN" --repo-url="${{ github.repository }}" \
--config-file=release-please-config.json \
--manifest-file=.release-please-manifest.json