mirror of
https://github.com/Matysh/houseplan-card
synced 2026-09-29 03:09:36 +00:00
Три воркфлоу висели на одном событии `release: published` и бежали параллельно. Анонс выигрывал эту гонку всегда: проверять ему нечего. 12.09 стабильную v1.75.0 объявили в канале в ту же минуту, когда гейт отказал — Full Performance был красный (#537), E2E после него не выполнялся вовсе, ассеты не выкладывались. Подписчики получили сообщение о релизе, страница которого осталась без `houseplan-card.js`. Триггер события снят: у анонса остаются кнопка проверки связи и вызов из воркфлоу. `release.yml` зовёт его после джобы выкладки (`needs: build`), то есть красный гейт или несостоявшаяся выкладка сообщения не рождают. Путь беты не тронут — `publish-prerelease.yml` звал анонс сам и раньше. Мёртвая ветка чтения события из шага убрана вместе с триггером: тело берётся из заметок ветки тега, как в вызове из беты. Issue: #538 User-Visible: no
143 lines
6.8 KiB
YAML
Executable File
143 lines
6.8 KiB
YAML
Executable File
name: "Релиз: ассеты после зелёной проверки"
|
|
on:
|
|
release:
|
|
types: [published]
|
|
permissions:
|
|
contents: write
|
|
actions: read
|
|
jobs:
|
|
# AUD-159B7-02: publishing a GitHub Release used to BE the gate — this
|
|
# workflow only built and uploaded, so an asset shipped while both Validate
|
|
# runs for the very same commit were red. The asset now waits for a green
|
|
# Validate of the EXACT commit the tag points at, and is withheld otherwise.
|
|
#
|
|
# Needs a push with a token that has the `workflow` scope (the ordinary
|
|
# Personal Access Token used for `git push` refuses workflow file updates).
|
|
gate:
|
|
name: "Гейт: зелёная Проверка точного SHA тега"
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
with:
|
|
ref: ${{ github.event.release.tag_name }}
|
|
fetch-depth: 0
|
|
- uses: actions/setup-node@v7
|
|
with: { node-version: 22 }
|
|
- name: Require a green Validate for this exact commit
|
|
env:
|
|
GH_TOKEN: ${{ github.token }}
|
|
REPO: ${{ github.repository }}
|
|
TAG: ${{ github.event.release.tag_name }}
|
|
run: |
|
|
set -euo pipefail
|
|
# HEAD is the peeled commit even when TAG is annotated. Do not trust
|
|
# target_commitish (it may be a branch name) or an event-context SHA.
|
|
SHA=$(git rev-parse HEAD)
|
|
echo "release tag: $TAG; exact commit: $SHA"
|
|
# #479: тяжёлые job Validate идут только на коммите с трейлером
|
|
# `Release:`; без него зелёный Validate прогона без смоков не доказывает.
|
|
if ! git log -1 --format=%B "$SHA" | grep -Eq '^Release:[[:space:]]*v?[0-9]+\.[0-9]+\.[0-9]+'; then
|
|
echo "::error::$SHA has no Release: trailer — Validate ran without the heavy gates (#479)"
|
|
exit 1
|
|
fi
|
|
node scripts/release-gate.mjs "$SHA"
|
|
- name: Require full performance for a stable release
|
|
if: ${{ !github.event.release.prerelease }}
|
|
env:
|
|
GH_TOKEN: ${{ github.token }}
|
|
REPO: ${{ github.repository }}
|
|
run: |
|
|
set -euo pipefail
|
|
SHA=$(git rev-parse HEAD)
|
|
node scripts/release-gate.mjs "$SHA" --workflow=performance.yml --label="Полные бенчмарки производительности"
|
|
# #514: the only check on a real Home Assistant. houseplan-e2e installs
|
|
# the release's houseplan.zip — the bytes HACS ships — into HA in docker
|
|
# and walks the sidebar page, dashboards, roles, PDF, restart and the
|
|
# stable→tag upgrade. A red, missing or cancelled run withholds the
|
|
# assets exactly like Full Performance. Cross-repository dispatch needs a
|
|
# token with Actions: write on houseplan-e2e; HP_PROCESS_TOKEN (classic,
|
|
# repo scope) has it, E2E_DISPATCH_TOKEN is the fallback for a
|
|
# fine-grained token.
|
|
- name: Require green E2E on a real Home Assistant for a stable release
|
|
if: ${{ !github.event.release.prerelease }}
|
|
env:
|
|
GH_TOKEN: ${{ secrets.E2E_DISPATCH_TOKEN || secrets.HP_PROCESS_TOKEN }}
|
|
TAG: ${{ github.event.release.tag_name }}
|
|
run: node scripts/e2e-gate.mjs --tag="$TAG"
|
|
build:
|
|
name: Сборка бандла и загрузка ассетов
|
|
needs: gate
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
with:
|
|
ref: ${{ github.event.release.tag_name }}
|
|
- uses: actions/setup-node@v7
|
|
with: { node-version: 22 }
|
|
- run: npm ci && npm run build
|
|
- name: Verify compositor frame continuity for a stable release
|
|
if: ${{ !github.event.release.prerelease }}
|
|
run: |
|
|
npx playwright install --with-deps chromium
|
|
node scripts/bundle-sync.mjs
|
|
npm run continuity:screencast
|
|
- name: Upload failed continuity frames
|
|
if: ${{ failure() && !github.event.release.prerelease }}
|
|
uses: actions/upload-artifact@v7
|
|
with:
|
|
name: continuity-screencast
|
|
path: artifacts/continuity-screencast
|
|
- name: Verify the complete committed frontend tree
|
|
run: |
|
|
node scripts/bundle-tree.mjs dist custom_components/houseplan/frontend
|
|
test -s dist/houseplan-card.js
|
|
test -s dist/houseplan-panel.js
|
|
- name: Attach card to release
|
|
uses: softprops/action-gh-release@v3
|
|
with:
|
|
files: dist/houseplan-card.js
|
|
announce:
|
|
# #538: анонс — последнее звено, а не параллельное. Пока он висел на самом
|
|
# событии `release: published`, он обгонял гейт: 12.09 v1.75.0 объявили в
|
|
# канале в ту же минуту, когда проверка отказала выкладывать ассеты.
|
|
# `needs: build` означает, что молчание — это тоже ответ: красный гейт или
|
|
# несостоявшаяся выкладка сообщения не рождают.
|
|
name: Оповещение о релизе после выкладки
|
|
needs: build
|
|
uses: ./.github/workflows/announce.yml
|
|
with:
|
|
reusable: true
|
|
tag: ${{ github.event.release.tag_name }}
|
|
release_name: ${{ github.event.release.name }}
|
|
url: ${{ github.event.release.html_url }}
|
|
prerelease: ${{ github.event.release.prerelease }}
|
|
ref: ${{ github.event.release.tag_name }}
|
|
secrets: inherit
|
|
hacs-discovery:
|
|
name: HACS-видимость пре-релиза (порядок бет)
|
|
# HACS 2.0.x takes the first prerelease in GitHub's response instead of
|
|
# sorting SemVer. A valid asset can therefore be invisible to beta users
|
|
# (beta.10 appeared after beta.9). Keep the release asset, but
|
|
# make that distribution failure impossible to miss in the release run.
|
|
if: ${{ github.event.release.prerelease }}
|
|
needs: build
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Verify the published tag is the prerelease HACS will discover
|
|
uses: actions/github-script@v9
|
|
with:
|
|
script: |
|
|
const releases = await github.paginate(github.rest.repos.listReleases, {
|
|
owner: context.repo.owner,
|
|
repo: context.repo.repo,
|
|
per_page: 100,
|
|
});
|
|
const first = releases.find((r) => r.prerelease && !r.draft);
|
|
const expected = context.payload.release.tag_name;
|
|
if (first?.tag_name !== expected) {
|
|
core.setFailed(
|
|
`HACS prerelease discovery is stale: GitHub returns ${first?.tag_name ?? 'none'} before ${expected}. ` +
|
|
`Use an rc/new version line or correct the release ordering before announcing the update.`,
|
|
);
|
|
}
|