Skip to content

ci: automate checks merges and releases - #1

Merged
mastertyko merged 1 commit into
mainfrom
chore/github-release-automation
Sep 3, 2026
Merged

mastertyko merged 1 commit into
mainfrom
chore/github-release-automation

Conversation

@mastertyko

Copy link
Copy Markdown
Owner

Summary

  • Add read-only Bun CI for pull requests and pushes to main.
  • Enable owner-only, same-repository PR auto-merge without checking out or executing PR code.
  • Add automated patch releases, npm trusted publishing with provenance, and generated GitHub release notes.
  • Document repository settings and trusted publisher requirements.

Security

  • All external actions are pinned to immutable full commit SHAs.
  • The privileged pull_request_target workflow only calls the GitHub API and never checks out PR code.
  • npm publishing uses GitHub OIDC (id-token: write) with no npm token secret.
  • Release execution is gated by NPM_TRUSTED_PUBLISHING_ENABLED=true.
  • main requires pull requests and the Bun check; force pushes and deletion are blocked.

Verification

  • actionlint
  • bun run check — 21 files, 233 tests
  • npm pack --dry-run
  • Gitleaks — no leaks
  • Semantic workflow assertions for permissions, owner/repository guards, OIDC, token absence, and trigger isolation

Bootstrap

This first PR must have auto-merge enabled manually because
pull_request_target loads workflow code from the default branch. After merge,
the npm trusted publisher and release gate variable will be configured, then a
second owner PR will prove the complete automatic merge and release chain.

@mastertyko
mastertyko enabled auto-merge September 3, 2026 16:54
@mastertyko
mastertyko merged commit ebe5ef8 into main Sep 3, 2026
1 check passed
@mastertyko
mastertyko deleted the chore/github-release-automation branch September 3, 2026 16:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant