Files
opensourcepos/.github/workflows/build-release.yml
T
jekkos 2da95e33b6 chore(release): unified git-cliff release workflow (changelog + tag + optional bump) (#4711)
* chore: unified release workflow (git-cliff changelog + tag + optional bump)

- cliff.toml: git-cliff config (commit.author.name, Weblate/version-bump excluded)
- release.yml: replaces the 'Release Version Bump' workflow with a single
  workflow that cuts the current release (changelog + tag + draft release)
  and optionally bumps App.php to the next dev version
- build-release.yml: add official-release job (draft GitHub Release with
  changelog + assets, triggered by tag push)

Supersedes the 'changelog only' scope: this now also handles tagging,
draft release, and the version bump in one place.

* fix(release): fail fast when a tag does not match the App.php version

Catches a manually-pushed mismatched tag before building, so a draft
release is never created without its archive.

* fix(release): move env block to step level (was inside run shell script)

The env: key was dedented into the run: | literal block, so the shell
would try to execute 'env:' as a command and abort the build.
2026-09-24 20:49:51 +02:00

314 lines
10 KiB
YAML

name: Build and Release
on:
push:
branches:
- '**'
tags:
- '[0-9]+.[0-9]+.[0-9]+'
pull_request:
branches:
- master
concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
build:
name: Build
runs-on: ubuntu-22.04
outputs:
version: ${{ steps.version.outputs.version }}
version-tag: ${{ steps.version.outputs.version-tag }}
short-sha: ${{ steps.version.outputs.short-sha }}
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Setup PHP
uses: shivammathur/setup-php@v2
with:
php-version: '8.2'
extensions: intl, mbstring, mysqli, gd, bcmath, zip
coverage: none
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: '20'
- name: Get composer cache directory
run: echo "COMPOSER_CACHE_FILES_DIR=$(composer config cache-files-dir)" >> $GITHUB_ENV
- name: Cache composer dependencies
uses: actions/cache@v4
with:
path: ${{ env.COMPOSER_CACHE_FILES_DIR }}
key: ${{ runner.os }}-composer-${{ hashFiles('**/composer.lock') }}
restore-keys: |
${{ runner.os }}-composer-
- name: Get npm cache directory
run: echo "NPM_CACHE_DIR=$(npm config get cache)" >> $GITHUB_ENV
- name: Cache npm dependencies
uses: actions/cache@v4
with:
path: ${{ env.NPM_CACHE_DIR }}
key: ${{ runner.os }}-node-${{ hashFiles('**/package-lock.json') }}
restore-keys: |
${{ runner.os }}-node-
- name: Install composer dependencies
run: composer install --no-dev --optimize-autoloader
- name: Install npm dependencies
run: npm ci
- name: Install gulp globally
run: npm install -g gulp-cli
- name: Get version info
id: version
run: |
VERSION=$(grep "application_version" app/Config/App.php | sed "s/.*= '\(.*\)';/\1/g")
BRANCH=$(echo "${GITHUB_REF#refs/heads/}" | sed 's/feature\///' | tr '/' '_')
TAG=$(echo "${GITHUB_TAG:-$BRANCH}" | tr '/' '_')
SHORT_SHA=$(git rev-parse --short=6 HEAD)
echo "version=$VERSION" >> $GITHUB_OUTPUT
echo "version-tag=$VERSION-$BRANCH-$SHORT_SHA" >> $GITHUB_OUTPUT
echo "short-sha=$SHORT_SHA" >> $GITHUB_OUTPUT
echo "branch=$BRANCH" >> $GITHUB_OUTPUT
env:
GITHUB_TAG: ${{ github.ref_name }}
- name: Validate release tag
if: startsWith(github.ref, 'refs/tags/')
run: |
# The ZIP below is named from App.php, while the draft-release job
# globs by the tag name. A manually-pushed tag that does not match
# App.php would silently produce a draft release with no archive, so
# fail fast instead.
if [ "${GITHUB_REF_NAME}" != "${{ steps.version.outputs.version }}" ]; then
echo "::error::tag ${GITHUB_REF_NAME} does not match App.php version ${{ steps.version.outputs.version }}"
exit 1
fi
- name: Create .env file
run: |
cp .env.example .env
sed -i 's/production/development/g' .env
- name: Update commit hash
run: |
SHORT_SHA="${{ steps.version.outputs.short-sha }}"
sed -i "s/commit_sha1 = 'dev'/commit_sha1 = '$SHORT_SHA'/g" app/Config/OSPOS.php
- name: Build frontend assets
run: npm run build
- name: Create distribution archives
run: |
set -euo pipefail
gulp compress
VERSION="${{ steps.version.outputs.version }}"
SHORT_SHA="${{ steps.version.outputs.short-sha }}"
mv dist/opensourcepos.tar "dist/opensourcepos.$VERSION.$SHORT_SHA.tar"
mv dist/opensourcepos.zip "dist/opensourcepos.$VERSION.$SHORT_SHA.zip"
- name: Upload build artifacts
uses: actions/upload-artifact@v4
with:
name: dist-${{ steps.version.outputs.short-sha }}
path: dist/
retention-days: 7
- name: Upload build context for Docker
uses: actions/upload-artifact@v4
with:
name: build-context-${{ steps.version.outputs.short-sha }}
path: |
.
!.git
!node_modules
include-hidden-files: true
retention-days: 1
docker:
name: Build Docker Image
runs-on: ubuntu-22.04
needs: build
if: github.event_name == 'push'
steps:
- name: Download build context
uses: actions/download-artifact@v4
with:
name: build-context-${{ needs.build.outputs.short-sha }}
path: .
- name: Set up QEMU
uses: docker/setup-qemu-action@v3
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Login to Docker Hub
uses: docker/login-action@v3
with:
username: ${{ secrets.DOCKER_USERNAME }}
password: ${{ secrets.DOCKER_PASSWORD }}
- name: Determine Docker tags
id: tags
run: |
REGISTRY="${{ secrets.DOCKER_USERNAME }}/opensourcepos"
SHA="${{ needs.build.outputs.short-sha }}"
if [[ "$GITHUB_REF" == refs/tags/* ]]; then
VERSION="${GITHUB_REF#refs/tags/}"
echo "tags=${REGISTRY}:${VERSION},${REGISTRY}:latest" >> "$GITHUB_OUTPUT"
elif [[ "$GITHUB_REF" == refs/heads/master ]]; then
echo "tags=${REGISTRY}:master,${REGISTRY}:${SHA}" >> "$GITHUB_OUTPUT"
else
BRANCH="${GITHUB_REF#refs/heads/}"
BRANCH="$(printf '%s' "$BRANCH" | LC_ALL=C tr -c 'A-Za-z0-9_.-' '_')"
BRANCH="${BRANCH:0:$((128 - ${#SHA} - 1))}"
[[ "$BRANCH" == [-.]* ]] && BRANCH="_${BRANCH:1}"
echo "tags=${REGISTRY}:${BRANCH}-${SHA}" >> "$GITHUB_OUTPUT"
fi
env:
GITHUB_REF: ${{ github.ref }}
- name: Build and push Docker images
uses: docker/build-push-action@v5
with:
context: .
target: ospos
platforms: linux/amd64,linux/arm64
push: true
tags: ${{ steps.tags.outputs.tags }}
unstable-release:
name: Create Unstable Release
needs: build
runs-on: ubuntu-22.04
if: github.event_name == 'push' && github.ref == 'refs/heads/master'
permissions:
contents: write
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Download build artifacts
uses: actions/download-artifact@v4
with:
name: dist-${{ needs.build.outputs.short-sha }}
path: dist/
- name: Get version info
id: version
run: |
VERSION="${{ needs.build.outputs.version }}"
SHORT_SHA=$(git rev-parse --short=6 HEAD)
echo "version=$VERSION" >> $GITHUB_OUTPUT
echo "short-sha=$SHORT_SHA" >> $GITHUB_OUTPUT
- name: Create/Update unstable release
uses: softprops/action-gh-release@v2
with:
tag_name: unstable
name: Unstable OpenSourcePOS
body: |
This is a build of the latest master which might contain bugs. Use at your own risk.
Check the releases section for the latest official release.
files: |
dist/opensourcepos.${{ steps.version.outputs.version }}.${{ steps.version.outputs.short-sha }}.zip
prerelease: true
draft: false
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
official-release:
name: Create Official Release (Draft)
needs: [build, docker]
runs-on: ubuntu-22.04
if: github.event_name == 'push' && startsWith(github.ref, 'refs/tags/')
permissions:
contents: write
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Download build artifacts
uses: actions/download-artifact@v4
with:
name: dist-${{ needs.build.outputs.short-sha }}
path: dist/
- name: Build release notes
run: |
VERSION="${GITHUB_REF_NAME}"
# Extract this version's changelog section (header + entries) from CHANGELOG.md.
SECTION=$(awk -v v="$VERSION" '
$0 ~ "^## \\[" v "\\] - " {insec=1; print; next}
insec && $0 ~ "^## \\[" {insec=0; next}
insec {print}
' CHANGELOG.md)
if [ -z "$SECTION" ]; then
echo "WARNING: no changelog section found for $VERSION"
SECTION="Changelog section for ${VERSION} is not present in CHANGELOG.md."
fi
{
echo "## Upgrade instructions"
echo ""
echo "**Docker:**"
echo ""
echo '```bash'
echo "docker pull ${{ secrets.DOCKER_USERNAME }}/opensourcepos:${VERSION}"
echo "docker compose -f docker-compose.nginx.yml up -d"
echo '```'
echo ""
echo "**Existing installation:** download one of the archives below, extract it over your current install, and run any new database migrations."
echo ""
echo "---"
echo ""
echo "$SECTION"
} > /tmp/release_notes.md
echo "=== release notes (first 12 lines) ==="
head -12 /tmp/release_notes.md
env:
GITHUB_REF_NAME: ${{ github.ref_name }}
- name: Create draft release
run: |
VERSION="${GITHUB_REF_NAME}"
ZIP=$(ls dist/opensourcepos."${VERSION}".*.zip 2>/dev/null | head -1)
if [ -n "$ZIP" ]; then
gh release create "$VERSION" \
--draft \
--title "OpenSourcePOS ${VERSION}" \
--notes-file /tmp/release_notes.md \
"$ZIP"
else
gh release create "$VERSION" \
--draft \
--title "OpenSourcePOS ${VERSION}" \
--notes-file /tmp/release_notes.md
fi
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
GITHUB_REF_NAME: ${{ github.ref_name }}