Skip to content

release: v2.0.4 - #33

Closed
cldmv-bot[bot] wants to merge 7 commits into
masterfrom
release/v2.0.1
Closed

cldmv-bot[bot] wants to merge 7 commits into
masterfrom
release/v2.0.1

Conversation

@cldmv-bot

@cldmv-bot cldmv-bot Bot commented Sep 9, 2025

Copy link
Copy Markdown
Contributor

🚀 What's Changed

💥 Breaking Changes

  • release!: complete v2.0.0 architectural rewrite with AsyncLocalStorage and universal module support (7e8285d)

✨ Features

No new features

🐛 Bug Fixes

No bug fixes

🔧 Other Changes

  • ci(release): Fix the release detection logic in workflow (176afd3)
  • chore(tests): remove deprecated test scripts for doclet processing (e337498)
  • release: v2.0.1 - Fix workflow authentication and GPG signing (c1f6778)

👥 Contributors

@Shinrai Shinrai closed this Sep 9, 2025
@Shinrai
Shinrai deleted the release/v2.0.1 branch September 9, 2025 22:45
Comment on lines +31 to +76
uses: CLDMV/.github/.github/workflows/release.yml@v1
with:
package_name: "@cldmv/slothlet" # Required: Your NPM package name
debug: ${{ github.event_name == 'workflow_dispatch' && inputs.debug || false }}
# skip_matrix_tests: ${{ github.event_name == 'workflow_dispatch' && inputs.skip_matrix_tests || false }}

# Node.js Version Configuration (choose one approach)
# Option 1: Single Node.js version (simple)
# node_version: "lts/*" # Single Node.js version to test (default: lts/*)
# skip_matrix_tests: true # Use this with node_version (default: false)

# Option 2: Matrix testing (comprehensive) - DEFAULT BEHAVIOR
min_node_version: "16.4" # Minimum Node.js version for matrix testing (default: 20)
# max_node_major: "22" # Maximum Node.js major version (default: 22)

# Package & Build Configuration
# package_manager: "npm" # Package manager - npm or yarn (default: npm)
test_command: "npm test" # Command to run tests (default: npm test)
build_command: "npm run build:ci" # Command to build package (default: npm run build:ci)

# Release Configuration
# version_bump: "" # Type of version bump: patch, minor, major. Leave empty for auto-detection from commit message (default: "")
# version: "" # Specific version - auto-calculated if not provided (default: "")
# is_prerelease: false # Whether this is a prerelease (default: false)
# release_source_only: false # Create source-only release, no package assets (default: false)
# create_documentation: true # Create/update VERSION_TAGS.md (default: true)

# Test Control Options
# skip_performance_tests: false # Skip performance tests during CI (default: false)
# skip_matrix_tests: false # Skip matrix testing, use single version (default: false)

# Authentication & Bot Configuration
# The workflow supports automatic App token detection for enhanced permissions and proper attribution:
# - WITH App secrets: Operations attributed to CLDMV bot, enhanced permissions for workflow repositories
# - WITHOUT App secrets: Falls back to GitHub Actions bot with standard permissions
# To set up App authentication, add these secrets to your repository settings:
secrets:
NPM_TOKEN: ${{ secrets.NPM_TOKEN }}
# Optional: CLDMV Bot credentials for enhanced permissions and proper attribution
# If not provided, will use default GITHUB_TOKEN with GitHub Actions bot attribution
BOT_APP_ID: ${{ secrets.CLDMV_BOT_APP_ID }}
BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }}
TAGGER_NAME: ${{ secrets.CLDMV_BOT_NAME }}
TAGGER_EMAIL: ${{ secrets.CLDMV_BOT_EMAIL }}
GPG_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_GPG_PRIVATE_KEY }}
GPG_PASSPHRASE: ${{ secrets.CLDMV_BOT_GPG_PASSPHRASE }}

Check warning

Code scanning / CodeQL

Workflow does not contain permissions Medium

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {}

Copilot Autofix

AI about 1 year ago

To remediate the issue, add a permissions block specifying the least necessary privileges. This is typically done either at the workflow root or under the job—in this case, either above jobs: or under create-release-pr:. Since the workflow only calls a reusable workflow for release PR creation, the likely minimal required scope is contents: read and pull-requests: write (since releasing may require creating PRs and reading repo contents). If the downstream workflow requires broader permissions, you should set only those privileges that are strictly necessary. The update should be at the root, affecting all jobs (since there is only one job), and must not interfere with secrets or other functionality.

Specifically:

  • Insert a permissions: block after the name: key (line 7).
  • Use least privilege recommended for release PRs:
    permissions:
      contents: read
      pull-requests: write

No additional imports or dependency updates are needed.


Suggested changeset 1
.github/workflows/release.yml

Autofix patch

Autofix patch
Run the following command in your local git repository to apply this patch
cat << 'EOF' | git apply
diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml
--- a/.github/workflows/release.yml
+++ b/.github/workflows/release.yml
@@ -5,6 +5,9 @@
 # and uses smart commit analysis to determine if a release should be created.
 #
 name: 🚀 Create Release PR
+permissions:
+  contents: read
+  pull-requests: write
 
 on:
   push:
EOF
@@ -5,6 +5,9 @@
# and uses smart commit analysis to determine if a release should be created.
#
name: 🚀 Create Release PR
permissions:
contents: read
pull-requests: write

on:
push:
Copilot is powered by AI and may make mistakes. Always verify output.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants