* chore: replace GH_ACCESS_TOKEN with GitHub App token Replace personal access token (GH_ACCESS_TOKEN) with GitHub App token generation using actions/create-github-app-token@v1 for improved security. Updated workflows: - draft-release.yml - post-release.yml - cleanup.yml - cleanup-report.yml - publish-report.yml - i18n.yml Benefits: - Short-lived tokens (1 hour) vs long-lived PATs - Fine-grained, scoped permissions - Not tied to individual user accounts - Better audit trail Required setup: - Create a GitHub App with contents:write permission - Install the app on calcom/cal.com and calcom/test-results-2 - Add RELEASE_APP_ID and RELEASE_APP_PRIVATE_KEY secrets Co-Authored-By: alex@cal.com <me@alexvanandel.com> * chore: rename secrets to CI_CAL_APP_ID and CI_CAL_APP_PRIVATE_KEY Co-Authored-By: alex@cal.com <me@alexvanandel.com> * chore: use reusable workflow from calcom-ci-secrets for token generation This isolates the GitHub App private key in a separate repository, ensuring that compromised actions in cal.com can only access short-lived tokens, not the key itself. Co-Authored-By: alex@cal.com <me@alexvanandel.com> * chore: use explicit secret passing instead of secrets: inherit Only pass the two required secrets (CI_CAL_APP_ID, CI_CAL_APP_PRIVATE_KEY) to the reusable workflow instead of inheriting all secrets. Co-Authored-By: alex@cal.com <me@alexvanandel.com> * chore: remove secrets block - using environment secrets from calcom-ci-secrets Secrets are now loaded from the ci-github-app environment in calcom-ci-secrets, so cal.com workflows no longer need to pass them. Co-Authored-By: alex@cal.com <me@alexvanandel.com> * chore: revert to explicit secret passing Environment secrets in cross-repo reusable workflows don't work as expected. Secrets must be passed explicitly from the caller repository. Co-Authored-By: alex@cal.com <me@alexvanandel.com> * chore: generate GitHub App token directly in workflows Remove dependency on calcom-ci-secrets reusable workflow. Token generation is now inline using actions/create-github-app-token pinned to SHA 7e473efe3cb98aa54f8d4bac15400b15fad77d94 (v2.2.0). Co-Authored-By: alex@cal.com <me@alexvanandel.com> --------- Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> Co-authored-by: Anik Dhabal Babu <81948346+anikdhabal@users.noreply.github.com>
74 lines
2.3 KiB
YAML
74 lines
2.3 KiB
YAML
name: Draft release
|
|
run-name: Draft release ${{ inputs.next_version }}
|
|
|
|
on:
|
|
workflow_dispatch:
|
|
inputs:
|
|
next_version:
|
|
required: true
|
|
type: string
|
|
description: 'Version name'
|
|
|
|
permissions:
|
|
contents: write
|
|
|
|
jobs:
|
|
draft_release:
|
|
runs-on: ubuntu-latest
|
|
|
|
steps:
|
|
- name: Generate GitHub App token
|
|
id: generate-token
|
|
uses: actions/create-github-app-token@7e473efe3cb98aa54f8d4bac15400b15fad77d94
|
|
with:
|
|
app-id: ${{ secrets.CI_CAL_APP_ID }}
|
|
private-key: ${{ secrets.CI_CAL_APP_PRIVATE_KEY }}
|
|
repositories: 'cal.com'
|
|
|
|
- name: Checkout code
|
|
uses: actions/checkout@v4
|
|
with:
|
|
fetch-depth: 0
|
|
ref: 'main'
|
|
token: ${{ steps.generate-token.outputs.token }}
|
|
|
|
- name: Configure git
|
|
run: |
|
|
# Define authorized users and their emails using organization secret
|
|
# Expected format: JSON object with username -> email mapping
|
|
# Example: {"zomars": "zomars@cal.com", "peer": "peer@cal.com", "username3": "email3@cal.com"}
|
|
USER_EMAILS='${{ secrets.RELEASE_USER_EMAILS }}'
|
|
|
|
# Extract email for the triggering user
|
|
USER_EMAIL=$(echo "$USER_EMAILS" | jq -r --arg user "${{ github.actor }}" '.[$user] // empty')
|
|
|
|
# Fail if user is not authorized or not in mapping
|
|
if [ -z "$USER_EMAIL" ] || [ "$USER_EMAIL" = "null" ]; then
|
|
echo "Error: User '${{ github.actor }}' is not authorized to run the release workflow."
|
|
echo "Only authorized team members can trigger releases."
|
|
echo "Contact your administrator to be added to the authorized users list."
|
|
exit 1
|
|
fi
|
|
|
|
git config --local user.email "$USER_EMAIL"
|
|
git config --local user.name "${{ github.actor }}"
|
|
|
|
- uses: ./.github/actions/yarn-install
|
|
|
|
- name: Bump version
|
|
run: |
|
|
cd apps/web
|
|
yarn version ${{ inputs.next_version }}
|
|
|
|
- name: Commit changes
|
|
run: |
|
|
git add .
|
|
git commit -m "chore: release v${{ inputs.next_version }}"
|
|
git push
|
|
|
|
- name: Draft release
|
|
run: gh release create v$VERSION --generate-notes --draft
|
|
env:
|
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
VERSION: ${{ inputs.next_version }}
|