Compare commits

..
4 Commits
Author SHA1 Message Date
gitea-actions a9c5e56a24 chore: bump version [skip ci] 2026-08-21 19:03:47 +00:00
deac 4e765e5c64 add-promotion-gate-action: Add git/promotion-gate composite action
publish.yaml / publish (push) Successful in 4s
Enforces which source branches may merge into which target branches, configured via a rules input (one target:allowed,allowed per line, glob-capable). Empty rules (default) skips enforcement entirely, so repos can adopt it without immediately gating on rules they have not configured. Extracted for reuse across repos moving to a gitflow-style branch promotion model, starting with stat-tackler-api.
2026-08-21 14:57:03 -04:00
gitea-actions 50dc06f634 chore: bump version [skip ci] 2026-08-18 13:38:29 +00:00
deac 992d3630e9 ci: maintain a floating v1 major-version tag on release
publish.yaml / publish (push) Successful in 8s
Lets consumers pin actions to @v1 instead of an exact vX.Y.Z, so they
pick up fixes automatically without per-repo version bumps.
2026-08-18 09:38:15 -04:00
6 changed files with 103 additions and 2 deletions
+4 -1
View File
@@ -24,6 +24,9 @@ jobs:
git add VERSION git add VERSION
git diff --cached --quiet || git commit -m "chore: bump version [skip ci]" git diff --cached --quiet || git commit -m "chore: bump version [skip ci]"
version=$(cat VERSION) version=$(cat VERSION)
major="${version%%.*}"
git tag "v${version}" git tag "v${version}"
git tag -f "v${major}"
git push git push
git push --tags git push origin "refs/tags/v${version}"
git push --force origin "refs/tags/v${major}"
+1
View File
@@ -2,6 +2,7 @@ ACTIONS := \
docker \ docker \
node \ node \
git/create_tag \ git/create_tag \
git/promotion-gate \
helm/diff \ helm/diff \
helm/template \ helm/template \
helm/upgrade \ helm/upgrade \
+1
View File
@@ -15,6 +15,7 @@ Reusable composite actions for Gitea CI/CD pipelines.
| Action | Description | | Action | Description |
|---|---| |---|---|
| [git/create_tag](git/create_tag/README.md) | Create and push a git tag in the current repository | | [git/create_tag](git/create_tag/README.md) | Create and push a git tag in the current repository |
| [git/promotion-gate](git/promotion-gate/README.md) | Enforce which source branches may merge into which target branches |
### Helm ### Helm
+1 -1
View File
@@ -1 +1 @@
1.17.0 1.19.0
+21
View File
@@ -0,0 +1,21 @@
# Promotion Gate
<!-- action-docs-description source="action.yml" -->
## Description
Enforce which source branches may merge into which target branches
<!-- action-docs-description source="action.yml" -->
<!-- action-docs-inputs source="action.yml" -->
## Inputs
| name | description | required | default |
| --- | --- | --- | --- |
| `rules` | <p>One rule per line: "target:allowed1,allowed2,…". Targets not listed are unrestricted. Allowed entries may use a trailing glob, e.g. <code>hotfix-*</code>. Leave empty (default) to skip entirely.</p> | `false` | `""` |
<!-- action-docs-inputs source="action.yml" -->
<!-- action-docs-runs source="action.yml" -->
## Runs
This action is a `composite` action.
<!-- action-docs-runs source="action.yml" -->
+75
View File
@@ -0,0 +1,75 @@
name: Promotion Gate
description: Enforce which source branches may merge into which target branches
inputs:
rules:
description: |
One rule per line: "target:allowed1,allowed2,...". Targets not
listed are unrestricted. Allowed entries may use a trailing glob,
e.g. `hotfix-*`. Leave empty (default) to skip entirely.
default: ""
runs:
using: composite
steps:
- name: Check merge source is allowed for target branch
shell: sh
env:
BASE: ${{ gitea.event.pull_request.base.ref }}
HEAD: ${{ gitea.event.pull_request.head.ref }}
RULES: ${{ inputs.rules }}
run: |
if [ -z "$RULES" ]; then
echo "No promotion rules configured — skipping."
exit 0
fi
rc=0
found=0
oldIFS=$IFS
IFS='
'
set -f
set -- $RULES
set +f
IFS=$oldIFS
for line in "$@"; do
if [ -z "$line" ]; then
continue
fi
target=${line%%:*}
allowed=${line#*:}
if [ "$target" = "$line" ]; then
continue
fi
if [ "$BASE" = "$target" ]; then
found=1
matched=0
innerIFS=$IFS
IFS=','
for pat in $allowed; do
IFS=$innerIFS
case "$HEAD" in
$pat)
matched=1
;;
esac
IFS=','
done
IFS=$innerIFS
if [ "$matched" -eq 1 ]; then
echo "Allowed: '$HEAD' -> '$BASE' (matches: $allowed)"
else
echo "::error::$BASE only accepts merges from: $allowed — got '$HEAD'"
rc=1
fi
fi
done
if [ "$found" -eq 0 ]; then
echo "No promotion-source restriction configured for base '$BASE'"
fi
exit $rc