Skip to content

ci(deps): bump github/codeql-action/analyze from 4.37.6 to 4.37.9 #39

ci(deps): bump github/codeql-action/analyze from 4.37.6 to 4.37.9

ci(deps): bump github/codeql-action/analyze from 4.37.6 to 4.37.9 #39

name: Release post-merge
# Runs after a merge to main. Two responsibilities:
# 1. auto-tag — read the new version and push a vX.Y.Z tag, idempotently.
# 2. back-merge — if the merge came from a hotfix/* branch, open a tracking
# issue reminding maintainers to back-merge into staging.
on:
push:
branches: [main]
pull_request:
types: [closed]
branches: [main]
permissions:
contents: write # push tags
issues: write # open back-merge tracking issue
pull-requests: read
# Serialize tag-creation across overlapping pushes to main so two workflow runs
# can't race on the same tag.
concurrency:
group: release-post-merge-${{ github.ref }}
cancel-in-progress: false
jobs:
auto-tag:
name: Tag main HEAD as vX.Y.Z
if: github.event_name == 'push'
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
- name: Read version from plugin.json
id: ver
shell: bash
run: |
set -euo pipefail
VERSION=$(jq -r '.version' plugins/winui/agent-plugin/plugin.json)
if [[ ! "$VERSION" =~ ^[0-9]+\.[0-9]+\.[0-9]+(-[0-9A-Za-z.-]+)?$ ]]; then
echo "::error::plugin.json version '$VERSION' is not valid semver. Refusing to tag."
exit 1
fi
echo "version=$VERSION" >> "$GITHUB_OUTPUT"
echo "tag=v$VERSION" >> "$GITHUB_OUTPUT"
- name: Create and push tag (idempotent, SHA-checked)
env:
TAG: ${{ steps.ver.outputs.tag }}
GH_TOKEN: ${{ github.token }}
shell: bash
run: |
set -euo pipefail
# Fetch any tags we don't have locally so the existence check is honest.
git fetch --tags origin --quiet
# If the tag exists locally OR on the remote, verify it points at the
# current main HEAD. Same SHA = idempotent success. Different SHA = loud
# failure (we will NOT silently overwrite or accept a misplaced tag).
REMOTE_LINE=$(git ls-remote --tags origin "refs/tags/$TAG" || true)
if git rev-parse --verify --quiet "refs/tags/$TAG^{}" >/dev/null || [[ -n "$REMOTE_LINE" ]]; then
EXISTING_SHA=""
if git rev-parse --verify --quiet "refs/tags/$TAG^{}" >/dev/null; then
EXISTING_SHA=$(git rev-parse "refs/tags/$TAG^{}")
else
# Annotated tag from remote — peel via fetch to a temp ref.
git fetch origin "refs/tags/$TAG:refs/tags/$TAG" --quiet || true
EXISTING_SHA=$(git rev-parse "refs/tags/$TAG^{}" 2>/dev/null || echo "")
fi
if [[ "$EXISTING_SHA" == "$GITHUB_SHA" ]]; then
echo "::notice::Tag $TAG already points at $GITHUB_SHA — nothing to do."
exit 0
fi
echo "::error::Tag $TAG already exists at $EXISTING_SHA but main HEAD is $GITHUB_SHA."
echo "::error::Refusing to overwrite. Investigate: did someone create the tag manually, or did a previous release of this same version land at a different commit?"
exit 1
fi
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git tag -a "$TAG" -m "Release $TAG"
git push origin "$TAG"
echo "::notice::Tagged $GITHUB_SHA as $TAG."
back-merge-reminder:
name: Back-merge reminder for hotfix
runs-on: ubuntu-latest
# Fires when a PR from a hotfix/* branch is merged into main. Using the PR
# event (not the push commit message) avoids false negatives from squash
# merges that drop the branch name.
if: >
github.event_name == 'pull_request' &&
github.event.pull_request.merged == true &&
startsWith(github.event.pull_request.head.ref, 'hotfix/')
steps:
- name: Open tracking issue
env:
GH_TOKEN: ${{ github.token }}
PR_NUMBER: ${{ github.event.pull_request.number }}
PR_TITLE: ${{ github.event.pull_request.title }}
HEAD_REF: ${{ github.event.pull_request.head.ref }}
MERGE_SHA: ${{ github.event.pull_request.merge_commit_sha }}
shell: bash
run: |
set -euo pipefail
TITLE="Back-merge hotfix into staging (#$PR_NUMBER: $HEAD_REF)"
BODY=$(cat <<EOF
Hotfix PR #$PR_NUMBER ('$PR_TITLE') merged into \`main\` at $MERGE_SHA.
Per [CONTRIBUTING.md § Back-merge path](../blob/main/CONTRIBUTING.md#back-merge-path),
this commit must be back-merged into \`staging\` immediately so the fix is
not lost on the next release.
To do this:
\`\`\`
git fetch origin
git checkout -b backmerge/hotfix-${HEAD_REF#hotfix/} origin/staging
git merge origin/main
git push -u origin backmerge/hotfix-${HEAD_REF#hotfix/}
gh pr create --base staging --head backmerge/hotfix-${HEAD_REF#hotfix/}
\`\`\`
The branch **must** be named \`backmerge/*\` — the \`version-sync\` CI
check skips that prefix.
The \`staging-up-to-date-with-main\` CI check will block all new feature
PRs until this back-merge happens.
EOF
)
gh issue create \
--title "$TITLE" \
--body "$BODY" \
--label "release-process" \
|| echo "::warning::Could not open tracking issue (label may not exist; safe to ignore — the staging-up-to-date check will still block feature PRs)."