Repository navigation
feat(ci): Immutable release & Cosign - #2725
Conversation
审查者指南此 PR 将 beta 和 stable 发布流程整合为一个可手动配置且可自动触发的发布流水线。该流水线会构建 x64 和 ARM64 构件,将其暂存于不可变的 GitHub 草稿发布中,使用 Cosign 对其签名,发布该版本,并调用 MirrorChyan 集成,同时固定 CI actions 版本以确保可复现性。 不可变发布流水线的时序图sequenceDiagram
actor Maintainer
participant PR as Merged release PR
participant Trigger as release-trigger.yml
participant Publish as release-publish.yml
participant Build as reusable-build.yml
participant GitHub as GitHub Release
participant Cosign as sigstore action
participant Mirror as MirrorChyan workflows
PR->>Trigger: pull_request closed
Trigger->>Trigger: Extract version from PR title
Trigger->>Publish: gh workflow run release-publish.yml
par Build x64
Publish->>Build: reusable build configuration and x64
Build-->>Publish: Build artifact
and Build ARM64
Publish->>Build: reusable build configuration and ARM64
Build-->>Publish: Build artifact
end
Publish->>GitHub: Create or update draft release
par Sign and upload x64
Publish->>Cosign: sigstore action
Cosign-->>Publish: Signed x64 binary
Publish->>GitHub: Upload binary and signature
and Sign and upload ARM64
Publish->>Cosign: sigstore action
Cosign-->>Publish: Signed ARM64 binary
Publish->>GitHub: Upload binary and signature
end
Publish->>GitHub: Publish Draft
Publish->>Mirror: gh workflow run mirrorchyan_uploading.yml
Publish->>Mirror: gh workflow run mirrorchyan_release_note.yml
可配置发布调度的流程图flowchart TD
A[workflow_dispatch configuration version prerelease] --> B[Build x64 and ARM64]
B --> C[Create draft GitHub release]
C --> D[Rename binaries]
D --> E[Sign binaries with Cosign]
E --> F[Upload binaries and sigstore files]
F --> G[Publish draft release]
G --> H[Trigger MirrorChyan uploading]
G --> I[Trigger MirrorChyan release note]
文件级变更
提示和命令与 Sourcery 交互
自定义你的使用体验访问你的控制面板来:
获取帮助Original review guide in EnglishReviewer's GuideThis PR consolidates beta and stable publishing into a manually configurable and automatically triggerable release pipeline that builds x64 and ARM64 artifacts, stages them in an immutable draft GitHub release, signs them with Cosign, publishes the release, and invokes MirrorChyan integrations, while pinning CI actions for reproducibility. Sequence diagram for the immutable release pipelinesequenceDiagram
actor Maintainer
participant PR as Merged release PR
participant Trigger as release-trigger.yml
participant Publish as release-publish.yml
participant Build as reusable-build.yml
participant GitHub as GitHub Release
participant Cosign as sigstore action
participant Mirror as MirrorChyan workflows
PR->>Trigger: pull_request closed
Trigger->>Trigger: Extract version from PR title
Trigger->>Publish: gh workflow run release-publish.yml
par Build x64
Publish->>Build: reusable build configuration and x64
Build-->>Publish: Build artifact
and Build ARM64
Publish->>Build: reusable build configuration and ARM64
Build-->>Publish: Build artifact
end
Publish->>GitHub: Create or update draft release
par Sign and upload x64
Publish->>Cosign: sigstore action
Cosign-->>Publish: Signed x64 binary
Publish->>GitHub: Upload binary and signature
and Sign and upload ARM64
Publish->>Cosign: sigstore action
Cosign-->>Publish: Signed ARM64 binary
Publish->>GitHub: Upload binary and signature
end
Publish->>GitHub: Publish Draft
Publish->>Mirror: gh workflow run mirrorchyan_uploading.yml
Publish->>Mirror: gh workflow run mirrorchyan_release_note.yml
Flow diagram for configurable release dispatchflowchart TD
A[workflow_dispatch configuration version prerelease] --> B[Build x64 and ARM64]
B --> C[Create draft GitHub release]
C --> D[Rename binaries]
D --> E[Sign binaries with Cosign]
E --> F[Upload binaries and sigstore files]
F --> G[Publish draft release]
G --> H[Trigger MirrorChyan uploading]
G --> I[Trigger MirrorChyan release note]
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
There was a problem hiding this comment.
Hey - 我发现了 1 个问题,并给出了一些整体性的反馈:
- 在
rename_and_release这个 job 中,shell 赋值语句MRC_CHANNEL = "stable"因为在=两侧有空格而无效,会导致语法错误;应该写成MRC_CHANNEL="stable"(其他类似的赋值语句也需要相应修改)。 - 新增的
release-trigger.ymlworkflow 中调用了gh workflow run,但该 workflow 的permissions目前只授予了contents: read;你很可能需要再添加actions: write(如果需要的话,可能还要加contents: write),这样gh命令才能成功触发另一个 workflow。
给 AI Agent 的提示
请根据以下代码评审意见进行修改:
## 整体评论
- 在 `rename_and_release` 这个 job 中,shell 赋值语句 `MRC_CHANNEL = "stable"` 因为在 `=` 两侧有空格而无效,会导致语法错误;应该写成 `MRC_CHANNEL="stable"`(其他类似的赋值语句也需要相应修改)。
- 新增的 `release-trigger.yml` workflow 中调用了 `gh workflow run`,但该 workflow 的 `permissions` 目前只授予了 `contents: read`;你很可能需要再添加 `actions: write`(如果需要的话,可能还要加 `contents: write`),这样 `gh` 命令才能成功触发另一个 workflow。
## 单独评论
### 评论 1
<location path=".github/workflows/release-trigger.yml" line_range="3-12" />
<code_context>
-name: Publish (Beta)
+name: Release Beta (Actual)
permissions:
- contents: read
+ contents: write
</code_context>
<issue_to_address>
**issue (bug_risk):** 为了让 `gh workflow run` 成功执行,workflow 使用的 token 很可能需要 `actions: write` 权限。
这个 workflow 目前只设置了 `contents: write`,但 `gh workflow run` 需要 `GITHUB_TOKEN` 具备 `actions: write`(在某些配置下还需要 `workflow`)权限。请更新 `permissions` 配置块,至少包含:
```yaml
permissions:
contents: write
actions: write
```
否则 `gh workflow run` 调用很可能会因为权限不足而失败。
</issue_to_address>帮我变得更有用!请在每条评论上点击 👍 或 👎,我会根据你的反馈改进后续的评审。
Original comment in English
Hey - I've found 1 issue, and left some high level feedback:
- In the
rename_and_releasejob, the shell assignmentMRC_CHANNEL = "stable"is invalid due to the spaces around=, which will cause a syntax error; it should beMRC_CHANNEL="stable"(and similarly for any other assignments). - The new
release-trigger.ymlworkflow callsgh workflow run, but the workflow’spermissionsonly grantcontents: read; you likely need to addactions: write(and possiblycontents: writeif required) so theghcommand can successfully trigger the other workflow.
Prompt for AI Agents
Please address the comments from this code review:
## Overall Comments
- In the `rename_and_release` job, the shell assignment `MRC_CHANNEL = "stable"` is invalid due to the spaces around `=`, which will cause a syntax error; it should be `MRC_CHANNEL="stable"` (and similarly for any other assignments).
- The new `release-trigger.yml` workflow calls `gh workflow run`, but the workflow’s `permissions` only grant `contents: read`; you likely need to add `actions: write` (and possibly `contents: write` if required) so the `gh` command can successfully trigger the other workflow.
## Individual Comments
### Comment 1
<location path=".github/workflows/release-trigger.yml" line_range="3-12" />
<code_context>
-name: Publish (Beta)
+name: Release Beta (Actual)
permissions:
- contents: read
+ contents: write
</code_context>
<issue_to_address>
**issue (bug_risk):** The workflow token likely needs `actions: write` permission for `gh workflow run` to succeed.
This workflow currently only sets `contents: write`, but `gh workflow run` needs `actions: write` on `GITHUB_TOKEN` (and in some setups also `workflow`). Please update the permissions block to include at least:
```yaml
permissions:
contents: write
actions: write
```
Otherwise the `gh workflow run` call is likely to fail with insufficient permissions.
</issue_to_address>Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.
2eb6785
Add project_file and artifact_name_suffix inputs to the reusable workflow, allowing the build matrix to compile both .csproj and .vbproj targets. Artifact names now include a suffix to distinguish between language variants.
This reverts commit 85e46ae.
|
女娲,推错仓库了( |
已 revert( |
Resolved. As I don't have time to review the rest of this PR, I'm dismissing my self-review to keep the process better organized, rather than submitting an approval.
|
这个好了咩 |
|
@sourcery-ai review |
There was a problem hiding this comment.
嘿——我发现了 1 个问题
面向 AI 代理的提示
请处理本次代码审查中的评论:
## 单独评论
### 评论 1
<location path=".github/workflows/release-publish.yml" line_range="43" />
<code_context>
- permissions:
- contents: write
- runs-on: ubuntu-latest
- continue-on-error: true
- if: ${{ github.event.release.prerelease }}
- steps:
</code_context>
<issue_to_address>
**issue (bug_risk):** checkout、git-cliff 安装、变更日志生成或草稿发布创建过程中的失败会在作业级别被忽略,而下游发布作业仍可继续执行。随后,制品上传作业可能会在没有生成变更日志的情况下创建或发布版本,从而掩盖发布准备步骤失败的问题。
**触发条件:** 任何变更日志准备步骤失败时。
**建议修复:** 移除作业级别的 `continue-on-error`,仅对预期的可选变更日志失败进行明确处理;或者要求下游作业必须依赖一个成功完成的变更日志作业。
```suggestion
```
</issue_to_address>Original comment in English
Hey - I've found 1 issue
Prompt for AI Agents
Please address the comments from this code review:
## Individual Comments
### Comment 1
<location path=".github/workflows/release-publish.yml" line_range="43" />
<code_context>
- permissions:
- contents: write
- runs-on: ubuntu-latest
- continue-on-error: true
- if: ${{ github.event.release.prerelease }}
- steps:
</code_context>
<issue_to_address>
**issue (bug_risk):** A failure in checkout, git-cliff installation, changelog generation, or draft-release creation is ignored at the job level, while the downstream release jobs can continue. The artifact-upload jobs can then create or publish a release without the generated changelog, hiding a failed release-preparation step.
**Triggers:** When any changelog-preparation step fails.
**Suggested fix:** Remove job-level `continue-on-error` and handle only the intended optional changelog failure explicitly, or make downstream jobs require a successful changelog job.
```suggestion
```
</issue_to_address>Co-authored-by: sourcery-ai[bot] <58596630+sourcery-ai[bot]@users.noreply.github.com>
Support Immutable release and cosign.
Sourcery 摘要
围绕可配置的草稿版本发布,统一发布自动化流程,支持手动触发或由已合并的发布 PR 触发。
新功能:
改进:
CI:
杂项:
Original summary in English
Sourcery 总结
围绕可配置且不可变的草稿版本,统一发布自动化流程;发布可由手动操作或合并后的发布拉取请求触发。
新功能:
增强功能:
构建:
CI:
Original summary in English
Sourcery 摘要
将 beta 和 stable 发布统一到可配置、不可变的 GitHub 发布流水线中,并支持自动触发和 Cosign 签名。
新功能:
增强功能:
构建:
CI:
release-publish和release-trigger工作流替代单独的 beta 与 stable 发布工作流。杂项:
Original summary in English
Sourcery 摘要
通过可配置的不可变草稿、自动触发合并 PR 以及使用 Cosign 签名的多架构构建产物,统一发布自动化流程。
新功能:
增强功能:
构建:
CI:
Original summary in English
Sourcery 摘要
将 Beta 版和稳定版发布流程统一为可配置的、由 Cosign 签名的多架构 GitHub 发布流水线,支持草稿发布和自动触发已合并 PR。
新功能:
增强功能:
构建:
CI:
Original summary in English
Sourcery 摘要
将 Beta 版和稳定版发布流程统一为可配置的、由 Cosign 签名的多架构 GitHub 发布流水线,支持草稿发布以及自动响应已合并 PR 的触发机制。
新功能:
增强:
构建:
CI:
Original summary in English
Summary by Sourcery
Unify beta and stable releases into a configurable, Cosign-signed multi-architecture GitHub release pipeline with draft publishing and automatic merged-PR triggers.
New Features:
Enhancements:
Build:
CI:
新功能:
增强:
softprops/action-gh-release动作,并将发布管理为草稿,待最终发布。CI:
Original summary in English