Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
27 changes: 26 additions & 1 deletion .github/workflows/publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ on:
workflow_dispatch:

permissions:
contents: read
contents: write
id-token: write

jobs:
Expand All @@ -24,3 +24,28 @@ jobs:
run: python -m build
- name: Publish to PyPI
uses: pypa/gh-action-pypi-publish@release/v1

# Move floating major tag v0 → this release commit (v0.x.y only).
# Exact pins (@v0.4.0) remain preferred; @v0 is convenience and may break.
retag-v0:
if: >
github.event_name == 'release' &&
startsWith(github.event.release.tag_name, 'v0.')
needs: publish
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- uses: actions/checkout@v7
with:
fetch-depth: 0
ref: ${{ github.event.release.tag_name }}
- name: Force-update floating v0 tag
env:
RELEASE_TAG: ${{ github.event.release.tag_name }}
run: |
set -euo pipefail
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git tag -f v0 "$RELEASE_TAG"
git push origin refs/tags/v0 --force
39 changes: 34 additions & 5 deletions docs/github-action.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,12 +12,31 @@ askmy-stack/tool-semantics/.github/actions/compare
## Versioning the Action

Pin the composite Action to a **release tag** (or commit SHA) so consumer CI stays
reproducible. Tags follow the package version (`v0.4.0`, …). A floating major pin
such as `@v0` is fine once a `v0` moving tag exists; prefer an exact tag for
production workflows.
reproducible. Tags follow the package version (`v0.4.0`, …).

`@main` tracks the tip of the default branch and **may break** without notice —
use it only for local experiments.
| Pin | Stability | When to use |
| --- | --- | --- |
| `@v0.4.0` (exact) | Fixed | **Preferred** for production workflows |
| `@v0` (floating major) | Moves on each `v0.x.y` release | Convenience; still receives breaking 0.x changes |
| `@main` | Tip of default branch | Local experiments only — **may break** without notice |

### Maintaining the floating `@v0` tag

On every `v0.x.y` GitHub Release, move the lightweight `v0` tag to the same
commit as the exact version tag (force-update). The `Publish to PyPI` workflow
does this automatically after a successful release publish when the tag name
matches `v0.*`.

Maintainer one-liner (if you need to repair the tag outside CI):

```bash
git fetch origin tag v0.4.0
git tag -f v0 v0.4.0
git push origin refs/tags/v0 --force
```

`@v0` can still receive **breaking 0.x** changes — prefer `@v0.4.0` (or newer
exact tags) when reproducibility matters.

After each GitHub Release, the tagged tree includes this composite Action, so
`uses: askmy-stack/tool-semantics/.github/actions/compare@vX.Y.Z` resolves from
Expand Down Expand Up @@ -45,6 +64,7 @@ jobs:
run: |
pip install "tool-semantics==0.4.0"
tool-semantics capture manifests/candidate.json -o .tool-semantics/candidate.json
# Preferred: exact release pin
- uses: askmy-stack/tool-semantics/.github/actions/compare@v0.4.0
with:
baseline: .tool-semantics/baselines/github.json
Expand All @@ -54,6 +74,15 @@ jobs:
upload-artifacts: "true"
```

Convenience pin (receives breaking 0.x updates):

```yaml
- uses: askmy-stack/tool-semantics/.github/actions/compare@v0
with:
baseline: .tool-semantics/baselines/github.json
candidate: .tool-semantics/candidate.json
```

## Inputs

| Input | Required | Default | Description |
Expand Down