镜像站点 · 本页由第三方 GitHub 只读镜像提供,非 GitHub 官方站点,不接受任何登录或凭据输入。前往 github.com
Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
210 changes: 186 additions & 24 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -27,6 +27,12 @@ on:
- latest
- experimental
- snapshot
snapit_comment_id:
description: 'PR comment requesting a snapshot (set automatically by /snapit)'
type: string
snapit_sha:
description: 'PR commit to publish (set automatically by /snapit)'
type: string

concurrency:
group: changeset-${{ github.head_ref || github.run_id }}
Expand All @@ -37,53 +43,209 @@ env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}

jobs:
# Snapit job - runs when /snapit comment is made on a PR
# npm rejects issue_comment OIDC tokens, so comments only request a separate run.
snapit:
name: Snapit
name: Request snapshot
if: ${{ github.event_name == 'issue_comment' && github.event.issue.pull_request && github.event.comment.body == '/snapit' }}
runs-on: ubuntu-latest
timeout-minutes: 5
permissions:
actions: write
contents: read
pull-requests: write
steps:
- name: Request a snapshot release
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1
with:
script: |
const {comment, issue, repository} = context.payload;
try {
const {data: collaborator} = await github.rest.repos.getCollaboratorPermissionLevel({
...context.repo,
username: comment.user.login,
});
if (!['write', 'admin'].includes(collaborator.permission)) {
throw new Error('Only users with write permission to the repository can run /snapit.');
}

const {data: pullRequest} = await github.rest.pulls.get({
...context.repo,
pull_number: issue.number,
});
if (pullRequest.state !== 'open') {
throw new Error('Snapshots can only be requested for open pull requests.');
}
if (pullRequest.head.repo?.full_name !== repository.full_name) {
throw new Error('/snapit is not supported on pull requests from forked repositories.');
}

await github.rest.actions.createWorkflowDispatch({
...context.repo,
workflow_id: 'release.yml',
ref: repository.default_branch,
inputs: {
tag: 'snapshot',
snapit_comment_id: String(comment.id),
snapit_sha: pullRequest.head.sha,
},
});
await github.rest.reactions.createForIssueComment({
...context.repo,
comment_id: comment.id,
content: 'eyes',
}).catch((error) => core.warning(`Snapshot requested, but the reaction failed: ${error.message}`));
core.info(`Requested a snapshot for PR #${issue.number} at ${pullRequest.head.sha}.`);
} catch (error) {
core.setFailed(error.message);
await github.rest.issues.createComment({
...context.repo,
issue_number: issue.number,
body: `Unable to request a snapshot: ${error.message}`,
});
}

snapshot-release:
name: Publish PR snapshot
if: ${{ github.event_name == 'workflow_dispatch' && (inputs.snapit_comment_id != '' || inputs.snapit_sha != '') }}
runs-on: ubuntu-latest
permissions:
contents: read
pull-requests: write
id-token: write
steps:
# WARNING: DO NOT RUN ANY CUSTOM LOCAL SCRIPT BEFORE RUNNING THE SNAPIT ACTION
# This action can be executed by 3rd party users and it should not be able to run arbitrary code from a PR.
- name: Checkout current branch
- name: Validate snapshot request
id: request
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1
with:
script: |
const {tag, snapit_comment_id: commentId, snapit_sha: sha} = context.payload.inputs;
if (
tag !== 'snapshot' ||
!/^[1-9]\d*$/.test(commentId) ||
!Number.isSafeInteger(Number(commentId)) ||
!/^[a-f0-9]{40}$/.test(sha)
) {
throw new Error('A snapshot request requires a comment ID and a full PR commit SHA.');
}

// Recheck the original request before checking out or executing any PR code.
const {data: comment} = await github.rest.issues.getComment({
...context.repo,
comment_id: Number(commentId),
});
if (comment.body !== '/snapit') {
throw new Error('The requesting comment must contain /snapit.');
}
const {data: collaborator} = await github.rest.repos.getCollaboratorPermissionLevel({
...context.repo,
username: comment.user.login,
});
if (!['write', 'admin'].includes(collaborator.permission)) {
throw new Error('Only users with write permission to the repository can run /snapit.');
}

const issueUrlPrefix = `https://github.com/proxy/api.github.com/repos/${context.repo.owner}/${context.repo.repo}/issues/`;
const pullRequestNumber = Number(comment.issue_url.slice(issueUrlPrefix.length));
if (
!comment.issue_url.startsWith(issueUrlPrefix) ||
!Number.isSafeInteger(pullRequestNumber) ||
pullRequestNumber < 1
) {
throw new Error('The requesting comment must belong to a PR in this repository.');
}
const {data: pullRequest} = await github.rest.pulls.get({
...context.repo,
pull_number: pullRequestNumber,
});
// Keep enough context to report failures for an authorized request.
core.setOutput('pull_request', pullRequestNumber);
core.setOutput('comment_id', comment.id);
core.setOutput('requester', comment.user.login);
core.setOutput('sha', sha);
if (
pullRequest.state !== 'open' ||
pullRequest.head.repo?.full_name !== `${context.repo.owner}/${context.repo.repo}`
) {
throw new Error('Snapshots require an open PR from this repository.');
}
if (pullRequest.head.sha !== sha) {
throw new Error('The PR changed after the request. Post /snapit again to publish the current commit.');
}

- name: Checkout PR commit
uses: actions/checkout@v6
with:
ref: ${{ steps.request.outputs.sha }}
fetch-depth: 0
persist-credentials: false
- name: Setup deps
uses: ./.github/actions/setup-cli-deps
with:
node-version: 24.12.0
- name: Force snapshot changeset
run: "mv .changeset/force-snapshot-build.md.ignore .changeset/force-snapshot-build.md"
- name: Create snapshot version
uses: Shopify/snapit@2a7ca29133cfeb2c8703654d54bc6dbc565caa69 # registry-and-package-manager
with:
comment_is_global: 'true'
comment_packages: '@shopify/cli'
comment_suffix: "
> [!CAUTION]

> After installing, validate the version by running `shopify version` in your terminal.

> If the versions don't match, you might have multiple global instances installed.

> Use `which shopify` to find out which one you are running and uninstall it."
comment_command_flags: '--@shopify:registry=https://registry.npmjs.org'
build_script: "node bin/update-cli-kit-version.js && pnpm nx run-many --target=bundle --all --skip-nx-cache --output-style=stream && pnpm refresh-manifests"
- name: Publish snapshot
id: publish
run: |
pnpm release snapshot
VERSION=$(node -p "require('./packages/cli/package.json').version")
echo "version=$VERSION" >> "$GITHUB_OUTPUT"
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
NPM_TOKEN: ''
NPM_CONFIG_PROVENANCE: true
SHOPIFY_CLI_BUILD_REPO: ${{ github.repository }}
- name: Report snapshot result
if: ${{ always() && steps.request.outputs.pull_request != '' }}
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1
env:
SNAPSHOT_OUTCOME: ${{ steps.publish.outcome }}
SNAPSHOT_VERSION: ${{ steps.publish.outputs.version }}
SNAPSHOT_PR: ${{ steps.request.outputs.pull_request }}
SNAPSHOT_COMMENT: ${{ steps.request.outputs.comment_id }}
SNAPSHOT_REQUESTER: ${{ steps.request.outputs.requester }}
SNAPSHOT_SHA: ${{ steps.request.outputs.sha }}
with:
script: |
const {
SNAPSHOT_OUTCOME: outcome,
SNAPSHOT_VERSION: version,
SNAPSHOT_REQUESTER: requester,
SNAPSHOT_SHA: sha,
} = process.env;
const runUrl = `https://github.com/${context.repo.owner}/${context.repo.repo}/actions/runs/${context.runId}`;
const published = outcome === 'success';
const body = published
? [
`🫰✨ **Thanks @${requester}! Your snapshot has been published to npm.**`,
`Built from \`${sha}\`. [Workflow run](${runUrl}).`,
'Test the snapshot by installing your package globally:',
[
'```bash',
`pnpm i -g --@shopify:registry=https://registry.npmjs.org @shopify/cli@${version}`,
'```',
].join('\n'),
[
'> [!CAUTION]',
'> After installing, validate the version by running `shopify version` in your terminal.',
"> If the versions don't match, you might have multiple global instances installed.",
'> Use `which shopify` to find out which one you are running and uninstall it.',
].join('\n'),
].join('\n\n')
: `The snapshot requested by @${requester} for \`${sha}\` could not be published. [View the workflow run](${runUrl}).`;
await github.rest.issues.createComment({
...context.repo,
issue_number: Number(process.env.SNAPSHOT_PR),
body,
});
await github.rest.reactions.createForIssueComment({
...context.repo,
comment_id: Number(process.env.SNAPSHOT_COMMENT),
content: published ? 'rocket' : 'confused',
});

# Changeset release job - runs on push to main or stable branches
changeset-release:
name: Changeset Release
if: ${{ github.event_name == 'push' || (github.event_name == 'workflow_dispatch' && github.event.inputs.tag == '') }}
if: ${{ github.event_name == 'push' || (github.event_name == 'workflow_dispatch' && github.event.inputs.tag == '' && inputs.snapit_comment_id == '' && inputs.snapit_sha == '') }}
runs-on: ubuntu-latest
permissions:
contents: write
Expand Down Expand Up @@ -187,7 +349,7 @@ jobs:
# Manual/Cron release job - runs on schedule or manual trigger with tag
manual-cron-release:
name: Manual & Cron Release
if: ${{ github.event_name == 'schedule' || (github.event_name == 'workflow_dispatch' && github.event.inputs.tag != '') }}
if: ${{ github.event_name == 'schedule' || (github.event_name == 'workflow_dispatch' && github.event.inputs.tag != '' && inputs.snapit_comment_id == '' && inputs.snapit_sha == '') }}
runs-on: ubuntu-latest
permissions:
contents: read
Expand Down
Loading