ci: add canary/publish split, bump actions, audit deps #29
No reviewers
Labels
No labels
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
question
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
luchaveztech/larakube-cli!29
Loading…
Reference in a new issue
No description provided.
Delete branch "feature/ci-workflow"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
CI Workflow Security & Structure Improvements
Changes
publishintocanary+publishcanarypre-release; onlyv*tags trigger stable releases. Prevents accidental production releases from every push.environment: releasegatecomposer audit--no-devto production buildsruns-on: ubuntu-latest→ubuntu-24.04actions/checkout@v4→@v7(pwn-request protection),softprops/action-gh-release@v2→@v3(Node 24), PHP 8.4 → 8.5 (current stable).Action Required
releaseGitHub Environment (Settings → Environments): required reviewers = 1, branch filter =mainGPG_PRIVATE_KEY+GPG_PASSPHRASEsecrets to thereleaseenvironmentTAP_GITHUB_TOKENsecret exists (PAT withcontents:writeonhomebrew-larakube)Testing
main→test+canaryjobs run, canary pre-release updatedv*tag →test+publish(paused atreleaseenv for approval) +tapruntestjob runsView command line instructions
Manual merge helper
Use this merge commit message when completing the merge manually.
Checkout
From your project repository, check out a new branch and test the changes.Merge
Merge the changes and update on Forgejo.Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.