From 6064ce6b4dc4529b37fe3befbe9fd0319fd4c3ce Mon Sep 17 00:00:00 2001 From: TheMeinerLP Date: Fri, 21 Aug 2026 19:16:04 +0200 Subject: [PATCH 1/4] chore(ci): adopt shared workflows and central Renovate preset - moved .github/renovate.json to renovate.json - renovate.json -> central preset (coincoffer-maintainers) - security.yml (Trivy + CycloneDX SBOM) - build-pr.yml (gradle-build-pr, Java 17, run-tests: false) - close_invalid_prs.yml (replaced hand-rolled job) - pinned reusable workflows to v2.8.1 (close_invalid_prs.yml) --- .github/renovate.json | 15 ------- .github/workflows/build-pr.yml | 19 +++++++++ .github/workflows/close_invalid_prs.yml | 12 ++---- .github/workflows/security.yml | 55 +++++++++++++++++++++++++ renovate.json | 8 ++++ 5 files changed, 86 insertions(+), 23 deletions(-) delete mode 100644 .github/renovate.json create mode 100644 .github/workflows/build-pr.yml create mode 100644 .github/workflows/security.yml create mode 100644 renovate.json diff --git a/.github/renovate.json b/.github/renovate.json deleted file mode 100644 index bc75430..0000000 --- a/.github/renovate.json +++ /dev/null @@ -1,15 +0,0 @@ -{ - "$schema": "https://docs.renovatebot.com/renovate-schema.json", - "extends": [ - "config:recommended", - ":semanticCommitsDisabled" - ], - "ignoreDeps": [], - "labels": [ - "Renovate" - ], - "rebaseWhen": "conflicted", - "schedule": [ - "on the first day of the month" - ] -} diff --git a/.github/workflows/build-pr.yml b/.github/workflows/build-pr.yml new file mode 100644 index 0000000..881176a --- /dev/null +++ b/.github/workflows/build-pr.yml @@ -0,0 +1,19 @@ +name: Build PR + +on: + pull_request: + +permissions: + contents: read + checks: write + pull-requests: write + +jobs: + build: + # Shared org build: Temurin toolchain, 3-OS matrix, tests and coverage. + uses: OneLiteFeatherNET/workflows/.github/workflows/gradle-build-pr.yml@v2.8.1 + with: + java-version: "17" + java-distribution: "temurin" + run-tests: false + secrets: inherit diff --git a/.github/workflows/close_invalid_prs.yml b/.github/workflows/close_invalid_prs.yml index 03b5e82..bd99444 100644 --- a/.github/workflows/close_invalid_prs.yml +++ b/.github/workflows/close_invalid_prs.yml @@ -2,13 +2,9 @@ name: Close invalid PRs on: pull_request_target: - types: [ opened ] + types: [opened] jobs: - run: - if: ${{ github.repository != github.event.pull_request.head.repo.full_name && github.head_ref == 'master' }} - runs-on: ubuntu-latest - steps: - - uses: superbrothers/close-pull-request@v3 - with: - comment: "Please do not open pull requests from the `develop` branch, create a new branch instead." \ No newline at end of file + close: + uses: OneLiteFeatherNET/workflows/.github/workflows/close-invalid-prs.yml@v2.8.1 + secrets: inherit diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml new file mode 100644 index 0000000..e295875 --- /dev/null +++ b/.github/workflows/security.yml @@ -0,0 +1,55 @@ +name: Security + +# Trivy vulnerability gate plus a CycloneDX SBOM of the repository. Self-contained +# on purpose: it needs no build tool and no registry credentials, so it is the +# baseline security gate for every repository regardless of language. +on: + pull_request: + push: + branches: [main] + schedule: + - cron: "37 3 * * 1" + workflow_dispatch: +permissions: + contents: read + security-events: write + +jobs: + trivy: + name: Trivy scan + uses: OneLiteFeatherNET/workflows/.github/workflows/security-scan.yml@v2.8.1 + with: + scan-type: "fs" + scanners: "vuln,secret" + severity: "CRITICAL,HIGH" + # Report-only for now, so adopting this does not turn CI red on day one. + fail-on-findings: false + upload-sarif: true + secrets: inherit + + sbom: + name: CycloneDX SBOM + runs-on: ubuntu-latest + permissions: + contents: read + steps: + - name: Checkout + uses: actions/checkout@v6 + + - name: Generate SBOM + uses: aquasecurity/trivy-action@v0.36.0 + with: + scan-type: fs + scan-ref: . + format: cyclonedx + output: bom.json + # An SBOM is an inventory, not a finding list - never fail on it. + exit-code: '0' + + - name: Upload SBOM + uses: actions/upload-artifact@v4 + with: + name: sbom-cyclonedx + path: bom.json + if-no-files-found: error + retention-days: 90 diff --git a/renovate.json b/renovate.json new file mode 100644 index 0000000..f16b987 --- /dev/null +++ b/renovate.json @@ -0,0 +1,8 @@ +{ + "$schema": "https://docs.renovatebot.com/renovate-schema.json", + "extends": [ + "github>OneLiteFeatherNET/renovate:default(OneLiteFeatherNET/coincoffer-maintainers)", + "github>OneLiteFeatherNET/renovate:paper" + ], + "ignoreDeps": [] +} From a6f56aacfb145544bcba2838157933c6a1f592ab Mon Sep 17 00:00:00 2001 From: TheMeinerLP Date: Fri, 21 Aug 2026 20:25:51 +0200 Subject: [PATCH 2/4] chore(ci): add release-please, PR linting and release SBOMs - pr-lint.yml - commitlint.config.mjs - release-please simple mode, bootstrapped at 1.0.1 - release-please.yml with SBOM attached to the release --- .github/workflows/pr-lint.yml | 17 ++++++++++ .github/workflows/release-please.yml | 48 ++++++++++++++++++++++++++++ .release-please-manifest.json | 3 ++ commitlint.config.mjs | 3 ++ release-please-config.json | 12 +++++++ 5 files changed, 83 insertions(+) create mode 100644 .github/workflows/pr-lint.yml create mode 100644 .github/workflows/release-please.yml create mode 100644 .release-please-manifest.json create mode 100644 commitlint.config.mjs create mode 100644 release-please-config.json diff --git a/.github/workflows/pr-lint.yml b/.github/workflows/pr-lint.yml new file mode 100644 index 0000000..759b37b --- /dev/null +++ b/.github/workflows/pr-lint.yml @@ -0,0 +1,17 @@ +name: PR Lint + +# Conventional Commits on the PR title and every commit on the branch. +# release-please parses those commit types to decide the version bump and to +# build the changelog - a non-conventional commit silently produces neither. +on: + pull_request: + types: [opened, edited, synchronize, reopened] + +permissions: + contents: read + pull-requests: read + +jobs: + lint: + uses: OneLiteFeatherNET/workflows/.github/workflows/pr-lint.yml@v2.8.1 + secrets: inherit diff --git a/.github/workflows/release-please.yml b/.github/workflows/release-please.yml new file mode 100644 index 0000000..6e0e1ca --- /dev/null +++ b/.github/workflows/release-please.yml @@ -0,0 +1,48 @@ +name: Release + +# release-please collects Conventional Commits into a release PR; merging it +# tags the version and cuts the GitHub release. Everything that has to happen +# for a release is chained into this same run on purpose: release-please tags +# with GITHUB_TOKEN, and a tag pushed that way does NOT start a separate +# `on: push: tags` workflow. +on: + push: + branches: [main] + workflow_dispatch: +permissions: + contents: write + pull-requests: write + +jobs: + release-please: + uses: OneLiteFeatherNET/workflows/.github/workflows/release-please.yml@v2.8.1 + secrets: inherit + + sbom: + name: Attach SBOM to release + needs: release-please + if: needs.release-please.outputs.release_created == 'true' + runs-on: ubuntu-latest + permissions: + contents: write + steps: + - name: Checkout + uses: actions/checkout@v6 + with: + ref: ${{ needs.release-please.outputs.tag_name }} + + - name: Generate CycloneDX SBOM + uses: aquasecurity/trivy-action@v0.36.0 + with: + scan-type: fs + scan-ref: . + format: cyclonedx + output: bom.json + # An SBOM is an inventory, not a finding list - never fail on it. + exit-code: '0' + + - name: Attach SBOM to the release + env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + TAG: ${{ needs.release-please.outputs.tag_name }} + run: gh release upload "$TAG" bom.json --clobber diff --git a/.release-please-manifest.json b/.release-please-manifest.json new file mode 100644 index 0000000..8d7e5f1 --- /dev/null +++ b/.release-please-manifest.json @@ -0,0 +1,3 @@ +{ + ".": "1.0.1" +} diff --git a/commitlint.config.mjs b/commitlint.config.mjs new file mode 100644 index 0000000..0616fb9 --- /dev/null +++ b/commitlint.config.mjs @@ -0,0 +1,3 @@ +export default { + extends: ['@commitlint/config-conventional'], +}; diff --git a/release-please-config.json b/release-please-config.json new file mode 100644 index 0000000..93826b4 --- /dev/null +++ b/release-please-config.json @@ -0,0 +1,12 @@ +{ + "$schema": "https://raw.githubusercontent.com/googleapis/release-please/main/schemas/config.json", + "release-type": "simple", + "include-component-in-tag": false, + "include-v-in-tag": true, + "packages": { + ".": { + "package-name": "CoinCoffer", + "changelog-path": "CHANGELOG.md" + } + } +} From e536d44d552c7e541acc553fe080554a5211f95f Mon Sep 17 00:00:00 2001 From: TheMeinerLP Date: Fri, 21 Aug 2026 20:27:15 +0200 Subject: [PATCH 3/4] chore(release): move publishing into the release-please run release-please tags with GITHUB_TOKEN, and a tag pushed that way does not start an `on: push: tags` workflow - so the previous publish would never have fired on a release. The same commands now run as a job in the release-please run, gated on release_created, with the version taken from the release-please output. --- .github/workflows/publish.yml | 31 --------------------------- .github/workflows/release-drafter.yml | 22 ------------------- .github/workflows/release-please.yml | 30 ++++++++++++++++++++++++++ 3 files changed, 30 insertions(+), 53 deletions(-) delete mode 100644 .github/workflows/publish.yml delete mode 100644 .github/workflows/release-drafter.yml diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml deleted file mode 100644 index 9f1f1d6..0000000 --- a/.github/workflows/publish.yml +++ /dev/null @@ -1,31 +0,0 @@ -name: Relase -on: - push: - tags: - - '*' -jobs: - build: - strategy: - matrix: - java-version: [ '17' ] - os: [ 'ubuntu-latest'] - runs-on: ${{ matrix.os }} - steps: - - name: Checkout Source Code - uses: actions/checkout@v7 - - name: Setup Java ${{ matrix.java-version }} - uses: actions/setup-java@v5 - with: - java-version: ${{ matrix.java-version }} - architecture: x64 - distribution: "temurin" - - name: Publish with gradle - run: | - ./gradlew applyPatches - ./gradlew build - ./gradlew publishAllPublicationsToHangar - ./gradlew modrinth - env: - TAG_VERSION: ${{ github.ref_name }} - MODRINTH_TOKEN: ${{ secrets.MODRINTH_KEY }} - HANGAR_KEY: ${{secrets.HANGAR_KEY}} diff --git a/.github/workflows/release-drafter.yml b/.github/workflows/release-drafter.yml deleted file mode 100644 index 10e768a..0000000 --- a/.github/workflows/release-drafter.yml +++ /dev/null @@ -1,22 +0,0 @@ -name: draft release -on: - push: - branches: - - master - pull_request: - types: [opened, reopened, synchronize] - pull_request_target: - types: [opened, reopened, synchronize] -permissions: - contents: read -jobs: - update_release_draft: - permissions: - contents: write - pull-requests: write - if: ${{ github.event_name != 'pull_request' || github.repository != github.event.pull_request.head.repo.full_name }} - runs-on: ubuntu-latest - steps: - - uses: release-drafter/release-drafter@v7 - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} \ No newline at end of file diff --git a/.github/workflows/release-please.yml b/.github/workflows/release-please.yml index 6e0e1ca..7c4971d 100644 --- a/.github/workflows/release-please.yml +++ b/.github/workflows/release-please.yml @@ -18,6 +18,36 @@ jobs: uses: OneLiteFeatherNET/workflows/.github/workflows/release-please.yml@v2.8.1 secrets: inherit + publish: + name: Publish to Hangar and Modrinth + needs: release-please + if: needs.release-please.outputs.release_created == 'true' + runs-on: ubuntu-latest + steps: + - name: Checkout the released tag + uses: actions/checkout@v6 + with: + ref: ${{ needs.release-please.outputs.tag_name }} + + - name: Set up JDK + uses: actions/setup-java@v5 + with: + java-version: "17" + architecture: x64 + distribution: "temurin" + + # Same sequence the tag-triggered publish workflow ran, with the version + # coming from release-please instead of from the pushed tag name. + - name: Publish with gradle + run: | + ./gradlew applyPatches + ./gradlew build + ./gradlew publishAllPublicationsToHangar + ./gradlew modrinth + env: + TAG_VERSION: ${{ needs.release-please.outputs.tag_name }} + MODRINTH_TOKEN: ${{ secrets.MODRINTH_KEY }} + HANGAR_KEY: ${{ secrets.HANGAR_KEY }} sbom: name: Attach SBOM to release needs: release-please From 9594879ad8086c3a717b754e2a48d4d68b5ff90b Mon Sep 17 00:00:00 2001 From: TheMeinerLP Date: Fri, 21 Aug 2026 21:12:11 +0200 Subject: [PATCH 4/4] fix(ci): restore Renovate platform presets and anchor the version in build.gradle.kts - marker on baseVersion (the derived version keeps its own logic); extra-files now points at build.gradle.kts - bootstrap-sha set from tag 1.0.1 --- build.gradle.kts | 2 +- release-please-config.json | 11 +++++++++-- 2 files changed, 10 insertions(+), 3 deletions(-) diff --git a/build.gradle.kts b/build.gradle.kts index a71d827..e8bde27 100644 --- a/build.gradle.kts +++ b/build.gradle.kts @@ -2,7 +2,7 @@ plugins { id("dev.onelitefeather.glue") version "0.0.13" } -val baseVersion = "1.0.0" +val baseVersion = "1.0.1" // x-release-please-version version = System.getenv("TAG_VERSION") ?: "$baseVersion-dev" group = "dev.onelitefeather.plugin" glue { diff --git a/release-please-config.json b/release-please-config.json index 93826b4..715aa39 100644 --- a/release-please-config.json +++ b/release-please-config.json @@ -6,7 +6,14 @@ "packages": { ".": { "package-name": "CoinCoffer", - "changelog-path": "CHANGELOG.md" + "changelog-path": "CHANGELOG.md", + "extra-files": [ + { + "type": "generic", + "path": "build.gradle.kts" + } + ] } - } + }, + "bootstrap-sha": "bb09ff8e44acf0764e20410310def4598e235432" }