Repository navigation
feat: heal and track urllib.request calls (#45) #34
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Prepare release | |
| # Conventional commits accumulate in one rolling release PR. Merging that PR | |
| # updates src/mnfst/version.py; publish.yml then builds and publishes exactly | |
| # that committed version through PyPI trusted publishing. | |
| on: | |
| push: | |
| branches: [main] | |
| workflow_dispatch: | |
| concurrency: | |
| group: release-prepare | |
| cancel-in-progress: true | |
| permissions: | |
| contents: write | |
| issues: write | |
| pull-requests: write | |
| jobs: | |
| prepare: | |
| runs-on: ubuntu-latest | |
| env: | |
| HAS_APP: ${{ secrets.APP_ID != '' && secrets.APP_PRIVATE_KEY != '' }} | |
| steps: | |
| - name: Generate GitHub App token | |
| id: app-token | |
| if: env.HAS_APP == 'true' | |
| uses: actions/create-github-app-token@67018539274d69449ef7c02e8e71183d1719ab42 # v2.1.4 | |
| with: | |
| app-id: ${{ secrets.APP_ID }} | |
| private-key: ${{ secrets.APP_PRIVATE_KEY }} | |
| - name: Note default token fallback | |
| if: env.HAS_APP != 'true' | |
| # Pull requests created by GITHUB_TOKEN do not start pull_request | |
| # workflows. publish.yml still reruns the full package checks. | |
| run: echo "::notice::APP_ID and APP_PRIVATE_KEY are unavailable; using GITHUB_TOKEN for the release PR." | |
| - name: Open or update release PR | |
| uses: googleapis/release-please-action@45996ed1f6d02564a971a2fa1b5860e934307cf7 # v5.0.0 | |
| with: | |
| token: ${{ steps.app-token.outputs.token || github.token }} | |