From d78d25e178f9e76a1d831c7e9210042e2db42489 Mon Sep 17 00:00:00 2001 From: Dave Wilding Date: Sat, 19 Sep 2026 01:25:48 +0800 Subject: [PATCH 1/5] ci: add checkout to create-draft job --- .github/workflows/release.yaml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index 8adb0d3..aaf25ae 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -84,6 +84,9 @@ jobs: contents: write pull-requests: read steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false - name: Install uv uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 - name: Create draft release From 9bbdf0b25a4fd69d51d0f0972c7184309ee746d8 Mon Sep 17 00:00:00 2001 From: Dave Wilding Date: Sat, 19 Sep 2026 01:45:26 +0800 Subject: [PATCH 2/5] ci: remove unnecessary --repo flags from create-draft --- .github/scripts/write_release_notes.py | 15 +-------------- .github/workflows/release.yaml | 9 ++++----- 2 files changed, 5 insertions(+), 19 deletions(-) diff --git a/.github/scripts/write_release_notes.py b/.github/scripts/write_release_notes.py index af55f6c..987e6bf 100644 --- a/.github/scripts/write_release_notes.py +++ b/.github/scripts/write_release_notes.py @@ -15,18 +15,7 @@ def gh(*args: str) -> str: def latest_tag() -> str: - return gh( - "release", - "list", - "--repo", - os.environ["GITHUB_REPOSITORY"], - "-L", - "1", - "--json", - "tagName", - "-q", - ".[0].tagName", - ) + return gh("release", "list", "-L", "1", "--json", "tagName", "-q", ".[0].tagName") def merged_prs() -> list[dict]: @@ -36,8 +25,6 @@ def merged_prs() -> list[dict]: prs = gh( "pr", "list", - "--repo", - repo, "--state", "merged", "--base", diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index aaf25ae..eba947e 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -91,11 +91,10 @@ jobs: uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 - name: Create draft release id: draft - env: - VERSION: ${{ needs.check-version.outputs.version }} - GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} - REPO: ${{ github.repository }} run: | set -euo pipefail notes="$(uv run --script .github/scripts/write_release_notes.py "$VERSION")" - gh release create "$VERSION" --repo "$REPO" --draft --target main --notes "$notes" + gh release create "$VERSION" --draft --target main --notes "$notes" + env: + VERSION: ${{ needs.check-version.outputs.version }} + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} From 7e63874759b12ef3bd67ec2c052432d40ec1c282 Mon Sep 17 00:00:00 2001 From: Dave Wilding Date: Sat, 19 Sep 2026 01:49:30 +0800 Subject: [PATCH 3/5] ci: move env: before run: for consistency --- .github/workflows/release.yaml | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index eba947e..831562a 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -28,6 +28,8 @@ jobs: uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 - name: Check version id: check + env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} run: | set -euo pipefail version="$(uvx --from "$PWD" gimmegit --version)" @@ -40,8 +42,6 @@ jobs: fi fi echo "release=$release" >> "$GITHUB_OUTPUT" - env: - GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} wait-checks: runs-on: ubuntu-latest @@ -91,10 +91,10 @@ jobs: uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 - name: Create draft release id: draft + env: + VERSION: ${{ needs.check-version.outputs.version }} + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} run: | set -euo pipefail notes="$(uv run --script .github/scripts/write_release_notes.py "$VERSION")" gh release create "$VERSION" --draft --target main --notes "$notes" - env: - VERSION: ${{ needs.check-version.outputs.version }} - GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} From ac749ef5d78f8b4b8c5ca62280c4c4041bf3ed9f Mon Sep 17 00:00:00 2001 From: Dave Wilding Date: Sat, 19 Sep 2026 01:51:55 +0800 Subject: [PATCH 4/5] ci: move env: before run: in zizmor workflow --- .github/workflows/zizmor.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/zizmor.yaml b/.github/workflows/zizmor.yaml index cfdd789..fd47d3a 100644 --- a/.github/workflows/zizmor.yaml +++ b/.github/workflows/zizmor.yaml @@ -21,9 +21,9 @@ jobs: - name: Install uv uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 - name: Run zizmor - run: uv run zizmor --format=sarif . > workflows.sarif env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} # Avoid rate limits for zizmor's "online" checks. + run: uv run zizmor --format=sarif . > workflows.sarif - name: Upload SARIF file uses: github/codeql-action/upload-sarif@db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28 # v4.37.8 with: From 857a79480d0f19ac82d198c9b76b550c6a52878b Mon Sep 17 00:00:00 2001 From: Dave Wilding Date: Sat, 19 Sep 2026 07:09:39 +0800 Subject: [PATCH 5/5] ci: add checkout to wait-checks and remove REPO --- .github/workflows/release.yaml | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index 831562a..dc6c0b8 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -53,21 +53,23 @@ jobs: outputs: release: ${{ steps.wait.outputs.release }} steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false - name: Wait for checks id: wait env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} - REPO: ${{ github.repository }} run: | set -euo pipefail sha="${{ github.sha }}" release=false # Wait for all other workflow runs on this SHA to complete. - other_runs="$(gh run list --repo "$REPO" --branch main --limit 50 --json databaseId,headSha --jq ".[] | select(.headSha == \"${sha}\") | .databaseId")" + other_runs="$(gh run list --branch main --limit 50 --json databaseId,headSha --jq ".[] | select(.headSha == \"${sha}\") | .databaseId")" other_runs="$(echo "$other_runs" | grep -v "${{ github.run_id }}" || true)" all_passed=true for run in $other_runs; do - if ! gh run watch "$run" --repo "$REPO" --exit-status >/dev/null 2>&1; then + if ! gh run watch "$run" --exit-status >/dev/null 2>&1; then all_passed=false fi done