Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -47,6 +47,6 @@ jobs:
permissions:
contents: read
id-token: write
uses: putdotio/.github/.github/workflows/frontend-release-npm.yml@8240b79dee9e0933c757bca249c82daa698d9c47 # v1.0.2
uses: putdotio/.github/.github/workflows/frontend-release-npm.yml@aebc5c2313cce5d667477d1a48d30a6f2eb4bc31 # putio-ci credential rename
Comment thread
altaywtf marked this conversation as resolved.
Comment thread
altaywtf marked this conversation as resolved.
secrets:
PUTIO_RELEASE_BOT_PRIVATE_KEY: ${{ secrets.PUTIO_RELEASE_BOT_PRIVATE_KEY }}
PUTIO_CI_APP_PRIVATE_KEY: ${{ secrets.PUTIO_CI_APP_PRIVATE_KEY }}
8 changes: 4 additions & 4 deletions docs/DISTRIBUTION.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,22 +11,22 @@ Merges to `main` are considered publishable. The CI workflow runs:

semantic-release analyzes Conventional Commits; a releasable commit publishes to npm, creates a GitHub Release, and commits the released `package.json` version back to `main` with `[skip ci]`.

The release job calls the [shared frontend release workflow](https://github.com/putdotio/.github) from `putdotio/.github`, pinned to a tagged commit; the semantic-release action and plugin pins live there. [`scan.yml`](https://github.com/putdotio/rokit/blob/main/.github/workflows/scan.yml) calls the shared frontend scan workflow from the same repository: Gitleaks, TruffleHog, Actionlint, and Zizmor on pull requests, weekly, and on manual dispatch.
The release job calls the [shared frontend release workflow](https://github.com/putdotio/.github) from `putdotio/.github`, pinned to a reviewed commit SHA; the semantic-release action and plugin pins live there. [`scan.yml`](https://github.com/putdotio/rokit/blob/main/.github/workflows/scan.yml) calls the shared frontend scan workflow from the same repository: Gitleaks, TruffleHog, Actionlint, and Zizmor on pull requests, weekly, and on manual dispatch.

## Release Credentials

The release job uses the `release` GitHub Environment with `deployment: false`.

Required protected inputs:

- `PUTIO_RELEASE_BOT_CLIENT_ID` as a repository or Environment variable
- `PUTIO_RELEASE_BOT_PRIVATE_KEY` as an Environment secret
- `PUTIO_CI_APP_CLIENT_ID` as a repository or Environment variable
- `PUTIO_CI_APP_PRIVATE_KEY` as an Environment secret

The npm package uses Trusted Publishing from GitHub Actions. On npm, configure owner `putdotio`, repository `rokit`, workflow `ci.yml`, and Environment named `release` for the package.

During the `@semantic-release/npm` publish step, npm detects the GitHub OIDC identity, mints short-lived publish credentials, and publishes provenance for the release job.

Release writes use the `putio-releaser` installation token. The default `GITHUB_TOKEN` remains read-only, and the release bot token is minted only after dependencies are installed.
Release writes use the `putio-ci` installation token. The default `GITHUB_TOKEN` remains read-only, and the release bot token is minted only after dependencies are installed.

## Package Contents

Expand Down