Skip to content

Commit b3c42fb

Browse files
committed
fix(ci): push to release branch and rebase-merge via PR
The main-protection ruleset bypass actors (github-actions[bot] / EtienneLescot) do not apply to direct pushes from workflow tokens or PATs. Open a PR on a release branch and rebase-merge it via the PAT instead; the merge respects the ruleset while the bypass for EtienneLescot satisfies the review requirement.
1 parent 1c5b9df commit b3c42fb

2 files changed

Lines changed: 55 additions & 8 deletions

File tree

‎.github/workflows/prerelease.yml‎

Lines changed: 28 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -83,22 +83,46 @@ jobs:
8383
echo "package.json version:"
8484
grep '"version"' package.json
8585
86-
- name: Commit package.json bump
86+
- name: Commit package.json bump on a release branch
8787
env:
8888
TOKEN: ${{ secrets.OPENSCREEN_RELEASE_TOKEN }}
89+
PRERELEASE: ${{ steps.version.outputs.prerelease }}
8990
run: |
9091
set -euo pipefail
9192
git config user.name "github-actions[bot]"
9293
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
94+
# The main-protection ruleset forbids direct pushes to main from workflow tokens.
95+
# Push to a release branch and merge via PR instead (merge via PAT bypasses as EtienneLescot).
96+
BRANCH="release/v${PRERELEASE}"
97+
git checkout -b "$BRANCH"
9398
git add package.json
94-
git commit -m "chore(release): bump to ${{ steps.version.outputs.prerelease }} [skip ci]"
95-
git push
99+
git commit -m "chore(release): bump to ${PRERELEASE} [skip ci]"
100+
git push "https://x-access-token:${TOKEN}@github.com/${GITHUB_REPOSITORY}.git" "$BRANCH"
101+
102+
- name: Open PR and rebase-merge into main
103+
env:
104+
TOKEN: ${{ secrets.OPENSCREEN_RELEASE_TOKEN }}
105+
PRERELEASE: ${{ steps.version.outputs.prerelease }}
106+
run: |
107+
set -euo pipefail
108+
BRANCH="release/v${PRERELEASE}"
109+
gh pr create \
110+
--base main \
111+
--head "$BRANCH" \
112+
--title "chore(release): bump to ${PRERELEASE}" \
113+
--body "Automated version bump from the prerelease workflow. Rebase-merged via PAT; bypass applies because EtienneLescot is a ruleset bypass actor." \
114+
--token "$TOKEN" \
115+
--repo "$GITHUB_REPOSITORY"
116+
PR_NUMBER=$(gh pr list --head "$BRANCH" --state open --json number -q '.[0].number' --repo "$GITHUB_REPOSITORY" --token "$TOKEN")
117+
gh pr merge "$PR_NUMBER" --rebase --delete-branch-remote \
118+
--token "$TOKEN" \
119+
--repo "$GITHUB_REPOSITORY"
96120
97121
- name: Push RC tag
98122
env:
99123
TOKEN: ${{ secrets.OPENSCREEN_RELEASE_TOKEN }}
100124
RC_TAG: ${{ steps.version.outputs.rc_tag }}
101-
run: git push origin "$RC_TAG"
125+
run: git push "https://x-access-token:${TOKEN}@github.com/${GITHUB_REPOSITORY}.git" "$RC_TAG"
102126

103127
- name: Announce RC on Discord (#rc-testing)
104128
if: success()

‎.github/workflows/promote.yml‎

Lines changed: 27 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -67,22 +67,45 @@ jobs:
6767
echo "package.json version:"
6868
grep '"version"' package.json
6969
70-
- name: Commit package.json bump
70+
- name: Commit package.json bump on a release branch
7171
env:
7272
TOKEN: ${{ secrets.OPENSCREEN_RELEASE_TOKEN }}
73+
STABLE_VERSION: ${{ steps.version.outputs.stable_version }}
7374
run: |
7475
set -euo pipefail
7576
git config user.name "github-actions[bot]"
7677
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
78+
# Push to a release branch and merge via PR (rebase) so the ruleset PR review rule is respected.
79+
BRANCH="release/v${STABLE_VERSION}"
80+
git checkout -b "$BRANCH"
7781
git add package.json
78-
git commit -m "chore(release): bump to ${{ steps.version.outputs.stable_version }} [skip ci]"
79-
git push
82+
git commit -m "chore(release): bump to ${STABLE_VERSION} [skip ci]"
83+
git push "https://x-access-token:${TOKEN}@github.com/${GITHUB_REPOSITORY}.git" "$BRANCH"
84+
85+
- name: Open PR and rebase-merge into main
86+
env:
87+
TOKEN: ${{ secrets.OPENSCREEN_RELEASE_TOKEN }}
88+
STABLE_VERSION: ${{ steps.version.outputs.stable_version }}
89+
run: |
90+
set -euo pipefail
91+
BRANCH="release/v${STABLE_VERSION}"
92+
gh pr create \
93+
--base main \
94+
--head "$BRANCH" \
95+
--title "chore(release): bump to ${STABLE_VERSION}" \
96+
--body "Automated version bump from the promote workflow. Rebase-merged via PAT; bypass applies because EtienneLescot is a ruleset bypass actor." \
97+
--token "$TOKEN" \
98+
--repo "$GITHUB_REPOSITORY"
99+
PR_NUMBER=$(gh pr list --head "$BRANCH" --state open --json number -q '.[0].number' --repo "$GITHUB_REPOSITORY" --token "$TOKEN")
100+
gh pr merge "$PR_NUMBER" --rebase --delete-branch-remote \
101+
--token "$TOKEN" \
102+
--repo "$GITHUB_REPOSITORY"
80103
81104
- name: Push stable tag
82105
env:
83106
TOKEN: ${{ secrets.OPENSCREEN_RELEASE_TOKEN }}
84107
STABLE_TAG: ${{ steps.version.outputs.stable_tag }}
85-
run: git push origin "$STABLE_TAG"
108+
run: git push "https://x-access-token:${TOKEN}@github.com/${GITHUB_REPOSITORY}.git" "$STABLE_TAG"
86109

87110
- name: Announce stable on Discord
88111
if: success()

0 commit comments

Comments
 (0)