From eebc88a30a2e54109fce7d6768f91ab3e8b6fba8 Mon Sep 17 00:00:00 2001 From: Simon Schrottner Date: Fri, 11 Sep 2026 14:01:10 +0200 Subject: [PATCH 1/2] chore: cut specification releases with release-please The specification's vX.Y.Z tags are created by hand today. That is a step easy to postpone -- v0.9.0 went out in July and the four commits since it are unreleased -- and a step where the changelog is assembled by whoever remembers to. release-please proposes the version and the notes as a pull request instead, and tags when it is merged. Nothing about the tag shape changes. include-component-in-tag is false, so releases stay vX.Y.Z rather than becoming spec/vX.Y.Z, and the manifest starts at 0.9.0 so numbering continues from the current release instead of restarting. bump-minor-pre-major keeps the pre-1.0 convention the specification already follows, where a breaking change bumps the minor. release-type is simple because the root package.json is private and carries no version of its own; simple tracks the version in version.txt. One consequence worth naming in review: release notes become generated from conventional commits, where v0.9.0's were written by hand. Anything that needs saying beyond the commit subjects -- the breaking-change callout at the top of v0.9.0, say -- now has to be added to the release pull request before it is merged. This is deliberately the whole of it: a single package, no tag separator and no component tagging, because there is nothing else in the repository to release yet. Signed-off-by: Simon Schrottner --- .github/workflows/release-please.yaml | 30 +++++++++++++++++++++++++++ .release-please-manifest.json | 3 +++ release-please-config.json | 12 +++++++++++ version.txt | 1 + 4 files changed, 46 insertions(+) create mode 100644 .github/workflows/release-please.yaml create mode 100644 .release-please-manifest.json create mode 100644 release-please-config.json create mode 100644 version.txt diff --git a/.github/workflows/release-please.yaml b/.github/workflows/release-please.yaml new file mode 100644 index 00000000..95512b09 --- /dev/null +++ b/.github/workflows/release-please.yaml @@ -0,0 +1,30 @@ +name: Run Release Please + +# Cuts the specification's releases. Until now its vX.Y.Z tags were created by hand, which +# is easy to postpone and easy to get wrong; release-please proposes the next version and +# the changelog as a pull request, and tags once that pull request is merged. +# +# The tag shape is unchanged: include-component-in-tag is false in release-please-config.json, +# so a release is tagged vX.Y.Z, continuing from v0.9.0 rather than restarting. Versioning +# stays below 1.0.0 for now, so a breaking change bumps the minor. + +on: + push: + branches: + - main + +permissions: + contents: write + pull-requests: write + +jobs: + release-please: + runs-on: ubuntu-latest + steps: + - uses: googleapis/release-please-action@v5 + with: + command: manifest + token: ${{ secrets.GITHUB_TOKEN }} + default-branch: main + # This repository enforces DCO, so the bot's own commits need a sign-off too. + signoff: "OpenFeature Bot <109696520+openfeaturebot@users.noreply.github.com>" diff --git a/.release-please-manifest.json b/.release-please-manifest.json new file mode 100644 index 00000000..76d5538a --- /dev/null +++ b/.release-please-manifest.json @@ -0,0 +1,3 @@ +{ + ".": "0.9.0" +} diff --git a/release-please-config.json b/release-please-config.json new file mode 100644 index 00000000..a0ed0886 --- /dev/null +++ b/release-please-config.json @@ -0,0 +1,12 @@ +{ + "$schema": "https://raw.githubusercontent.com/googleapis/release-please/main/schemas/config.json", + "packages": { + ".": { + "release-type": "simple", + "package-name": "spec", + "include-component-in-tag": false, + "changelog-path": "CHANGELOG.md", + "bump-minor-pre-major": true + } + } +} diff --git a/version.txt b/version.txt new file mode 100644 index 00000000..ac39a106 --- /dev/null +++ b/version.txt @@ -0,0 +1 @@ +0.9.0 From 3fc3458104ddeee99caf99636444d84256db3636 Mon Sep 17 00:00:00 2001 From: Simon Schrottner Date: Fri, 11 Sep 2026 14:13:12 +0200 Subject: [PATCH 2/2] fix: configure release-please the way v5 actually reads it Three inputs in the workflow were written against the v3 action and are silently ignored by v5, which is worse than an error because the workflow still runs and appears to work: - command: manifest is not an input. v5 is manifest-mode whenever a config file is present, which it is. - default-branch was renamed target-branch. - signoff moved to the configuration file, as $.signoff. The last one matters here. This repository enforces DCO, so an ignored signoff means release-please's own commits arrive without a Signed-off-by line and its release pull request fails the DCO check -- the failure the option was added to prevent. It is now a key in release-please-config.json, where v5 reads it. Also adds issues: write, which the action's own recommended permissions block carries; release-please labels its pull requests, and labelling goes through the issues API. Signed-off-by: Simon Schrottner --- .github/workflows/release-please.yaml | 10 ++++++---- release-please-config.json | 1 + 2 files changed, 7 insertions(+), 4 deletions(-) diff --git a/.github/workflows/release-please.yaml b/.github/workflows/release-please.yaml index 95512b09..ffcb30a9 100644 --- a/.github/workflows/release-please.yaml +++ b/.github/workflows/release-please.yaml @@ -7,6 +7,10 @@ name: Run Release Please # The tag shape is unchanged: include-component-in-tag is false in release-please-config.json, # so a release is tagged vX.Y.Z, continuing from v0.9.0 rather than restarting. Versioning # stays below 1.0.0 for now, so a breaking change bumps the minor. +# +# This repository enforces DCO, so the bot's own commits need a sign-off too. That is the +# signoff key in release-please-config.json: as of v5 it is a configuration-file option, and +# an action input of the same name is ignored. on: push: @@ -15,6 +19,7 @@ on: permissions: contents: write + issues: write pull-requests: write jobs: @@ -23,8 +28,5 @@ jobs: steps: - uses: googleapis/release-please-action@v5 with: - command: manifest token: ${{ secrets.GITHUB_TOKEN }} - default-branch: main - # This repository enforces DCO, so the bot's own commits need a sign-off too. - signoff: "OpenFeature Bot <109696520+openfeaturebot@users.noreply.github.com>" + target-branch: main diff --git a/release-please-config.json b/release-please-config.json index a0ed0886..875b6ba4 100644 --- a/release-please-config.json +++ b/release-please-config.json @@ -1,5 +1,6 @@ { "$schema": "https://raw.githubusercontent.com/googleapis/release-please/main/schemas/config.json", + "signoff": "OpenFeature Bot <109696520+openfeaturebot@users.noreply.github.com>", "packages": { ".": { "release-type": "simple",