14 Commits

Author SHA1 Message Date
b9f9f87068 feat: add release job
All checks were successful
Cog release / Create release (push) Successful in 9s
2026-01-04 02:23:22 +02:00
cd9815dfb3 fix(cocogitto/cocogitto-action): checkout head sha 2026-01-04 02:17:45 +02:00
50ff19fae2 chore(deps): cocogitto/cocogitto-action - checkout head sha
All checks were successful
Cog release / Create release (push) Successful in 8s
2026-01-04 01:41:25 +02:00
63da84fe0a chore(deps): update cocogitto/cocogitto-action action to v4
All checks were successful
Cog check / Create release (pull_request) Successful in 6s
Cog release / Create release (push) Successful in 9s
2026-01-03 17:59:18 +02:00
4b3b1ab69f chore(deps): update cocogitto/cocogitto-action action to v4
Some checks failed
Cog check / Create release (pull_request) Failing after 6s
2026-01-03 17:51:42 +02:00
f6750482a7 chore(deps): update docker/build-push-action action to v6
All checks were successful
Cog release / Create release (push) Successful in 7s
2026-01-03 17:51:15 +02:00
4d667c9fe0 chore(deps): update stefanzweifel/git-auto-commit-action action to v7
Some checks failed
Cog release / Create release (push) Has been cancelled
2026-01-03 17:51:09 +02:00
d9ffd2726f chore(deps): update oxsecurity/megalinter action to v9
Some checks failed
Cog release / Create release (push) Has been cancelled
2026-01-03 17:51:03 +02:00
d7dde0e936 chore(deps): update tj-actions/verify-changed-files action to v20
Some checks failed
Cog check / Create release (pull_request) Successful in 6s
Cog release / Create release (push) Has been cancelled
2026-01-03 15:42:12 +00:00
173c01c9ca chore: update cocogitto config
All checks were successful
Cog release / Create release (push) Successful in 7s
2026-01-03 17:40:45 +02:00
39fd0b7054 chore(deps): update peter-evans/create-pull-request action to v8
All checks were successful
Cog release / Create release (push) Successful in 7s
2026-01-03 17:38:49 +02:00
9104c113dc chore(deps): update actions/cache action to v5
Some checks failed
Cog release / Create release (push) Has been cancelled
2026-01-03 17:38:41 +02:00
2ce0f74e27 chore(deps): update github artifact actions
Some checks failed
Cog release / Create release (push) Has been cancelled
2026-01-03 17:38:32 +02:00
728bae9120 chore(deps): update actions/checkout action to v6
All checks were successful
Cog check / Create release (pull_request) Successful in 11s
Cog release / Create release (push) Successful in 8s
2025-11-21 00:01:07 +00:00
13 changed files with 67 additions and 51 deletions

View File

@@ -21,7 +21,7 @@ jobs:
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@v4 uses: actions/checkout@v6
- name: Set up QEMU - name: Set up QEMU
uses: docker/setup-qemu-action@v3 uses: docker/setup-qemu-action@v3
- name: Set up Docker Buildx - name: Set up Docker Buildx
@@ -46,7 +46,7 @@ jobs:
username: ${{ secrets.registry-user }} username: ${{ secrets.registry-user }}
password: ${{ secrets.registry-password }} password: ${{ secrets.registry-password }}
- name: Build and push - name: Build and push
uses: docker/build-push-action@v5 uses: docker/build-push-action@v6
with: with:
context: . context: .
platforms: linux/amd64,linux/arm64 platforms: linux/amd64,linux/arm64

View File

@@ -15,14 +15,14 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- uses: actions/checkout@v4 - uses: actions/checkout@v6
with: with:
fetch-depth: 0 fetch-depth: 0
- name: Semver release - name: Semver release
uses: cocogitto/cocogitto-action@v3 uses: cocogitto/cocogitto-action@v4
with: with:
# check-latest-tag-only: ${{ inputs.check-latest-tag-only }} command: check
check-latest-tag-only: true args: --from-latest-tag
git-user: "gitea-bot" git-user: "gitea-bot"
git-user-email: "bot@git.palkoi.net" git-user-email: "bot@git.palkoi.net"

View File

@@ -1,15 +1,12 @@
--- ---
name: Cog release name: Cog release
on: on:
push:
branches:
- main
workflow_call: workflow_call:
# inputs: inputs:
# check-latest-tag-only: ref:
# type: boolean type: string
# required: false required: false
# default: true default: ""
jobs: jobs:
release: release:
@@ -17,9 +14,10 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- uses: actions/checkout@v4 - uses: actions/checkout@v6
with: with:
fetch-depth: 0 fetch-depth: 0
ref: ${{ inputs.ref == '' && github.sha || inputs.ref }}
- run: | - run: |
git config user.name gitea-bot git config user.name gitea-bot
@@ -28,20 +26,23 @@ jobs:
git config --global user.name gitea-bot git config --global user.name gitea-bot
- name: Semver release - name: Semver release
uses: cocogitto/cocogitto-action@v3 uses: cocogitto/cocogitto-action@v4
id: release id: release
with: with:
release: true command: bump
args: --auto
git-user: "gitea-bot" git-user: "gitea-bot"
git-user-email: "bot@git.palkoi.net" git-user-email: "bot@git.palkoi.net"
check-latest-tag-only: true
# check-latest-tag-only: ${{ inputs.check-latest-tag-only }}
- name: Generate Changelog - name: Generate Changelog
run: cog changelog --at ${{ steps.release.outputs.version }} -t full_hash > GITHUB_CHANGELOG.md id: changelog
uses: cocogitto/cocogitto-action@v4
with:
command: changelog
args: --at ${{ steps.release.outputs.version }} -t full_hash
- name: Upload github release - name: Upload github release
uses: softprops/action-gh-release@v2 uses: softprops/action-gh-release@v2
with: with:
body_path: GITHUB_CHANGELOG.md body: ${{ steps.changelog.outputs.stdout }}
tag_name: ${{ steps.release.outputs.version }} tag_name: ${{ steps.release.outputs.version }}

View File

@@ -27,10 +27,10 @@ jobs:
steps: steps:
- name: Clone repo - name: Clone repo
uses: actions/checkout@v4 uses: actions/checkout@v6
- name: Retrieve artifacts - name: Retrieve artifacts
id: download id: download
uses: actions/download-artifact@v3 uses: actions/download-artifact@v7
with: with:
name: artifacts name: artifacts
- name: Check if job errored - name: Check if job errored
@@ -42,7 +42,7 @@ jobs:
exit "$(cat exitcode)"; exit "$(cat exitcode)";
fi fi
- name: Clone blackbox repo - name: Clone blackbox repo
uses: actions/checkout@v4 uses: actions/checkout@v6
if: ${{ steps.check.outputs.code == 2 }} if: ${{ steps.check.outputs.code == 2 }}
with: with:
repository: xaked/blackbox repository: xaked/blackbox
@@ -76,7 +76,7 @@ jobs:
known-hosts: ${{ secrets.ssh-known-hosts }} known-hosts: ${{ secrets.ssh-known-hosts }}
- name: Restore tofu cache - name: Restore tofu cache
if: ${{ steps.check.outputs.code == 2 }} if: ${{ steps.check.outputs.code == 2 }}
uses: actions/cache@v4 uses: actions/cache@v5
id: cache-tofu-restore id: cache-tofu-restore
with: with:
path: .terraform path: .terraform
@@ -96,7 +96,7 @@ jobs:
run: tofu apply -input=false -auto-approve tfplan.binary; run: tofu apply -input=false -auto-approve tfplan.binary;
- name: Save tofu cache - name: Save tofu cache
if: ${{ steps.check.outputs.code == 2 }} if: ${{ steps.check.outputs.code == 2 }}
uses: actions/cache/save@v4 uses: actions/cache/save@v5
id: cache-tofu-save id: cache-tofu-save
with: with:
path: .terraform path: .terraform

View File

@@ -31,9 +31,9 @@ jobs:
tofu_version: ${{ inputs.tofu-version }} tofu_version: ${{ inputs.tofu-version }}
cli_config_credentials_token: ${{ secrets.tf-api-token }} cli_config_credentials_token: ${{ secrets.tf-api-token }}
- name: Clone repo - name: Clone repo
uses: actions/checkout@v4 uses: actions/checkout@v6
- name: Clone blackbox repo - name: Clone blackbox repo
uses: actions/checkout@v4 uses: actions/checkout@v6
with: with:
repository: xaked/blackbox repository: xaked/blackbox
path: blackbox path: blackbox
@@ -57,7 +57,7 @@ jobs:
private-key-name: id_ed25519 private-key-name: id_ed25519
known-hosts: ${{ secrets.ssh-known-hosts }} known-hosts: ${{ secrets.ssh-known-hosts }}
- name: Restore tofu cache - name: Restore tofu cache
uses: actions/cache@v4 uses: actions/cache@v5
id: cache-tofu-restore id: cache-tofu-restore
with: with:
path: .terraform path: .terraform
@@ -77,7 +77,7 @@ jobs:
shell: bash shell: bash
run: printf "${{ steps.tfplan.outputs.exitcode }}" > exitcode; run: printf "${{ steps.tfplan.outputs.exitcode }}" > exitcode;
- name: Upload artifacts - name: Upload artifacts
uses: actions/upload-artifact@v3 uses: actions/upload-artifact@v6
with: with:
name: artifacts name: artifacts
path: | path: |
@@ -90,7 +90,7 @@ jobs:
exit 1; exit 1;
fi fi
- name: Save tofu cache - name: Save tofu cache
uses: actions/cache/save@v4 uses: actions/cache/save@v5
id: cache-tofu-save id: cache-tofu-save
with: with:
path: .terraform path: .terraform

View File

@@ -0,0 +1,12 @@
---
name: Cog release
on:
push:
branches:
- main
jobs:
release:
name: Create release
runs-on: ubuntu-latest
uses: ./.gitea/workflows/cog-release.yml

View File

@@ -13,7 +13,7 @@ jobs:
steps: steps:
- name: Clone blackbox repo - name: Clone blackbox repo
uses: actions/checkout@v4 uses: actions/checkout@v6
with: with:
repository: xaked/blackbox repository: xaked/blackbox
path: blackbox path: blackbox

View File

@@ -9,7 +9,7 @@ jobs:
steps: steps:
- name: Clone repo - name: Clone repo
uses: actions/checkout@v4 uses: actions/checkout@v6
- name: Run Trivy vulnerability scanner in IaC mode (LOW/MED) - name: Run Trivy vulnerability scanner in IaC mode (LOW/MED)
uses: aquasecurity/trivy-action@master uses: aquasecurity/trivy-action@master
with: with:

View File

@@ -43,7 +43,7 @@ jobs:
steps: steps:
# Git Checkout # Git Checkout
- name: Checkout Code - name: Checkout Code
uses: actions/checkout@v4 uses: actions/checkout@v6
with: with:
token: ${{ secrets.gitea-token }} token: ${{ secrets.gitea-token }}
fetch-depth: 0 # If you use VALIDATE_ALL_CODEBASE = true, you can remove this line to improve performances fetch-depth: 0 # If you use VALIDATE_ALL_CODEBASE = true, you can remove this line to improve performances
@@ -53,7 +53,7 @@ jobs:
id: ml id: ml
# You can override MegaLinter flavor used to have faster performances # You can override MegaLinter flavor used to have faster performances
# More info at https://megalinter.io/flavors/ # More info at https://megalinter.io/flavors/
uses: oxsecurity/megalinter@v7 uses: oxsecurity/megalinter@v9
env: env:
# All available variables are described in documentation # All available variables are described in documentation
# https://megalinter.io/configuration/ # https://megalinter.io/configuration/
@@ -65,7 +65,7 @@ jobs:
# Upload MegaLinter artifacts # Upload MegaLinter artifacts
- name: Archive production artifacts - name: Archive production artifacts
if: success() || failure() if: success() || failure()
uses: actions/upload-artifact@v3 uses: actions/upload-artifact@v6
with: with:
name: MegaLinter reports name: MegaLinter reports
path: | path: |
@@ -81,7 +81,7 @@ jobs:
- name: Create Pull Request with applied fixes - name: Create Pull Request with applied fixes
id: cpr id: cpr
if: steps.ml.outputs.has_updated_sources == 1 && (env.APPLY_FIXES_EVENT == 'all' || env.APPLY_FIXES_EVENT == github.event_name) && env.APPLY_FIXES_MODE == 'pull_request' && (github.event_name == 'push' || github.event.pull_request.head.repo.full_name == github.repository) && !contains(github.event.head_commit.message, 'skip fix') if: steps.ml.outputs.has_updated_sources == 1 && (env.APPLY_FIXES_EVENT == 'all' || env.APPLY_FIXES_EVENT == github.event_name) && env.APPLY_FIXES_MODE == 'pull_request' && (github.event_name == 'push' || github.event.pull_request.head.repo.full_name == github.repository) && !contains(github.event.head_commit.message, 'skip fix')
uses: peter-evans/create-pull-request@v6 uses: peter-evans/create-pull-request@v8
with: with:
token: ${{ secrets.gitea-token }} token: ${{ secrets.gitea-token }}
commit-message: "[MegaLinter] Apply linters automatic fixes" commit-message: "[MegaLinter] Apply linters automatic fixes"
@@ -99,7 +99,7 @@ jobs:
run: sudo chown -Rc $UID .git/ run: sudo chown -Rc $UID .git/
- name: Commit and push applied linter fixes - name: Commit and push applied linter fixes
if: steps.ml.outputs.has_updated_sources == 1 && (env.APPLY_FIXES_EVENT == 'all' || env.APPLY_FIXES_EVENT == github.event_name) && env.APPLY_FIXES_MODE == 'commit' && github.ref != 'refs/heads/main' && (github.event_name == 'push' || github.event.pull_request.head.repo.full_name == github.repository) && !contains(github.event.head_commit.message, 'skip fix') if: steps.ml.outputs.has_updated_sources == 1 && (env.APPLY_FIXES_EVENT == 'all' || env.APPLY_FIXES_EVENT == github.event_name) && env.APPLY_FIXES_MODE == 'commit' && github.ref != 'refs/heads/main' && (github.event_name == 'push' || github.event.pull_request.head.repo.full_name == github.repository) && !contains(github.event.head_commit.message, 'skip fix')
uses: stefanzweifel/git-auto-commit-action@v4 uses: stefanzweifel/git-auto-commit-action@v7
with: with:
branch: ${{ github.event.pull_request.head.ref || github.head_ref || github.ref }} branch: ${{ github.event.pull_request.head.ref || github.head_ref || github.ref }}
commit_message: "feat(linter): apply linters fixes" commit_message: "feat(linter): apply linters fixes"

View File

@@ -22,10 +22,10 @@ jobs:
steps: steps:
- name: Clone repo - name: Clone repo
uses: actions/checkout@v4 uses: actions/checkout@v6
- name: Retrieve artifacts - name: Retrieve artifacts
id: download id: download
uses: actions/download-artifact@v3 uses: actions/download-artifact@v7
with: with:
name: artifacts name: artifacts
- name: Check if job errored - name: Check if job errored
@@ -37,7 +37,7 @@ jobs:
exit "$(cat exitcode)"; exit "$(cat exitcode)";
fi fi
- name: Clone blackbox repo - name: Clone blackbox repo
uses: actions/checkout@v4 uses: actions/checkout@v6
if: ${{ steps.check.outputs.code == 2 }} if: ${{ steps.check.outputs.code == 2 }}
with: with:
repository: xaked/blackbox repository: xaked/blackbox
@@ -71,7 +71,7 @@ jobs:
known-hosts: ${{ secrets.ssh-known-hosts }} known-hosts: ${{ secrets.ssh-known-hosts }}
- name: Restore terraform cache - name: Restore terraform cache
if: ${{ steps.check.outputs.code == 2 }} if: ${{ steps.check.outputs.code == 2 }}
uses: actions/cache@v4 uses: actions/cache@v5
id: cache-terraform-restore id: cache-terraform-restore
with: with:
path: .terraform path: .terraform
@@ -91,7 +91,7 @@ jobs:
run: terraform apply -input=false -auto-approve tfplan.binary; run: terraform apply -input=false -auto-approve tfplan.binary;
- name: Save terraform cache - name: Save terraform cache
if: ${{ steps.check.outputs.code == 2 }} if: ${{ steps.check.outputs.code == 2 }}
uses: actions/cache/save@v4 uses: actions/cache/save@v5
id: cache-terraform-save id: cache-terraform-save
with: with:
path: .terraform path: .terraform

View File

@@ -8,7 +8,7 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- uses: actions/checkout@v4 - uses: actions/checkout@v6
with: with:
ref: ${{ github.event.pull_request.head.ref }} ref: ${{ github.event.pull_request.head.ref }}
- name: Install terraform docs - name: Install terraform docs
@@ -25,14 +25,14 @@ jobs:
terraform-docs --version terraform-docs --version
terraform-docs markdown table --output-file README.md --output-mode inject . terraform-docs markdown table --output-file README.md --output-mode inject .
- name: Verify Changed files - name: Verify Changed files
uses: tj-actions/verify-changed-files@v19 uses: tj-actions/verify-changed-files@v20
id: verify-changed-files id: verify-changed-files
with: with:
files: | files: |
README.md README.md
- name: Commit and push new terraform docs version - name: Commit and push new terraform docs version
if: steps.verify-changed-files.outputs.files_changed == 'true' if: steps.verify-changed-files.outputs.files_changed == 'true'
uses: stefanzweifel/git-auto-commit-action@v4 uses: stefanzweifel/git-auto-commit-action@v7
with: with:
branch: ${{ github.event.pull_request.head.ref || github.head_ref || github.ref }} branch: ${{ github.event.pull_request.head.ref || github.head_ref || github.ref }}
commit_message: "docs(tf-docs): update docs" commit_message: "docs(tf-docs): update docs"

View File

@@ -26,9 +26,9 @@ jobs:
terraform_version: 1.7.5 terraform_version: 1.7.5
cli_config_credentials_token: ${{ secrets.tf-api-token }} cli_config_credentials_token: ${{ secrets.tf-api-token }}
- name: Clone repo - name: Clone repo
uses: actions/checkout@v4 uses: actions/checkout@v6
- name: Clone blackbox repo - name: Clone blackbox repo
uses: actions/checkout@v4 uses: actions/checkout@v6
with: with:
repository: xaked/blackbox repository: xaked/blackbox
path: blackbox path: blackbox
@@ -52,7 +52,7 @@ jobs:
private-key-name: id_ed25519 private-key-name: id_ed25519
known-hosts: ${{ secrets.ssh-known-hosts }} known-hosts: ${{ secrets.ssh-known-hosts }}
- name: Restore terraform cache - name: Restore terraform cache
uses: actions/cache@v4 uses: actions/cache@v5
id: cache-terraform-restore id: cache-terraform-restore
with: with:
path: .terraform path: .terraform
@@ -72,7 +72,7 @@ jobs:
shell: bash shell: bash
run: printf "${{ steps.tfplan.outputs.exitcode }}" > exitcode; run: printf "${{ steps.tfplan.outputs.exitcode }}" > exitcode;
- name: Upload artifacts - name: Upload artifacts
uses: actions/upload-artifact@v3 uses: actions/upload-artifact@v6
with: with:
name: artifacts name: artifacts
path: | path: |
@@ -85,7 +85,7 @@ jobs:
exit 1; exit 1;
fi fi
- name: Save terraform cache - name: Save terraform cache
uses: actions/cache/save@v4 uses: actions/cache/save@v5
id: cache-terraform-save id: cache-terraform-save
with: with:
path: .terraform path: .terraform

View File

@@ -10,3 +10,6 @@
# tf-apply = { path = ".gitea/workflows/tf-apply.yml" } # tf-apply = { path = ".gitea/workflows/tf-apply.yml" }
# tf-docs = { path = ".gitea/workflows/tf-docs.yml" } # tf-docs = { path = ".gitea/workflows/tf-docs.yml" }
# tf-plan = { path = ".gitea/workflows/tf-plan.yml" } # tf-plan = { path = ".gitea/workflows/tf-plan.yml" }
[commit_types]
version = { bump_patch = true, changelog_title = "Version" }
chore = { bump_patch = true, changelog_title = "Chore" }