项目文件夹

文件
Asim Aslam 8e3ba68d58
goreleaser / goreleaser (push) Has been cancelled
loop-release: fix 403 on tag push (checkout token clobbered the PAT) (#3638)
* docs: complete Ollama provider surface (capability matrix, README, example fixes)

Follow-up cleanup after merging the Ollama provider (#3636):

- Add the `ollama` row to the AI provider capability matrix in the provider
  guide, and blank-import `ai/ollama` in provider_capabilities_test.go so the
  matrix stays enforced against the registry (the provider registers a stream
  but wasn't imported in that test, so its row went unchecked).
- README: bump "7 LLM providers" → 8 and list Ollama (local + cloud); add its
  default model (`llama3.2`) to the model table.
- Fix a fictional model name shipped in the example and package doc:
  `gemma4:31b-cloud` → `gpt-oss:120b`. gemma4 doesn't exist, and the `-cloud`
  suffix is for cloud models proxied through a local Ollama, not the direct
  ollama.com/v1 endpoint the example uses.
- Record the provider and the new agent.BaseURL/micro.AgentBaseURL option in
  the CHANGELOG [Unreleased] section.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CmdEY7pYmV5zzwCjNJ4ykL

* loop-release: don't let checkout's persisted GITHUB_TOKEN clobber the PAT push

The daily release job computed the next tag correctly but the tag push 403'd:
"Permission to micro/go-micro.git denied to github-actions[bot]" (run
28554612450). Cause: actions/checkout persists the default GITHUB_TOKEN as an
http.extraheader Authorization credential for github.com, which git sends on
ALL requests to that host — including our manual
`git push https://x-access-token:${PAT}@github.com/...`. The persisted header
overrides the URL-embedded PAT, so the push authenticates as
github-actions[bot], which can't push tags (the job only grants
contents: read).

Set persist-credentials: false so no extraheader is written and the PAT in the
push URL is the only credential used.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CmdEY7pYmV5zzwCjNJ4ykL

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-07-02 07:51:31 +01:00

85 行
3.5 KiB
YAML

name: "Loop: Release (daily patch)"
# Keeps the installable framework tracking the loop's daily improvements. Once a
# day, if master has new commits since the latest v6 tag, this cuts the next
# PATCH release (v6.MINOR.PATCH+1) and pushes the tag — which triggers the
# existing goreleaser workflow (release.yml, tag-triggered) to build the release,
# binaries, and images.
#
# The tag is pushed with a PAT (CODEX_TRIGGER_TOKEN), NOT the default GITHUB_TOKEN:
# a tag pushed by GITHUB_TOKEN would not trigger release.yml (Actions blocks that
# recursion). Minor/major bumps stay with the human (notable / breaking releases).
on:
workflow_dispatch: {}
schedule:
- cron: "0 23 * * *" # daily 23:00 UTC — captures the day's merges (tunable)
permissions:
contents: read
concurrency:
group: loop-release
cancel-in-progress: false
jobs:
release:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0 # need full history + all tags
# Do NOT persist the default GITHUB_TOKEN as a git credential.
# actions/checkout otherwise sets an http.extraheader Authorization
# for github.com that is sent on ALL pushes — including our manual
# PAT push below — and overrides the PAT, so the tag push
# authenticates as github-actions[bot] and 403s (the job only has
# contents: read). With this off, the PAT embedded in the push URL
# is the only credential. (Fixes run 28554612450.)
persist-credentials: false
- name: Cut the next patch release if there are new commits
env:
RELEASE_TOKEN: ${{ secrets.CODEX_TRIGGER_TOKEN }}
REPO: ${{ github.repository }}
run: |
if [ -z "$RELEASE_TOKEN" ]; then
echo "CODEX_TRIGGER_TOKEN is not set — skipping."
echo "A tag pushed by the default GITHUB_TOKEN would not trigger the"
echo "goreleaser workflow, so a user PAT is required to cut releases."
exit 0
fi
git fetch --tags --force
LATEST=$(git tag --list 'v6.*.*' --sort=-v:refname | head -1)
if [ -z "$LATEST" ]; then
echo "no v6.x.x tag found — aborting so nothing weird gets tagged."
exit 1
fi
echo "latest release tag: $LATEST"
COUNT=$(git rev-list --count "$LATEST"..HEAD)
echo "commits on HEAD since $LATEST: $COUNT"
if [ "$COUNT" -eq 0 ]; then
echo "no new commits since $LATEST — no release today."
exit 0
fi
# Bump the patch: v6.MINOR.PATCH -> v6.MINOR.(PATCH+1)
ver="${LATEST#v}" # 6.3.10
major="${ver%%.*}" # 6
rest="${ver#*.}" # 3.10
minor="${rest%%.*}" # 3
patch="${rest#*.}" # 10
case "$major.$minor.$patch" in
[0-9]*.[0-9]*.[0-9]*) ;;
*) echo "unexpected tag shape: $LATEST" ; exit 1 ;;
esac
NEXT="v${major}.${minor}.$((patch + 1))"
echo "cutting: $NEXT ($COUNT commits since $LATEST)"
git config user.name "go-micro release bot"
git config user.email "noreply@go-micro.dev"
git tag -a "$NEXT" -m "Release $NEXT — automated daily patch ($COUNT commits since $LATEST)"
git push "https://x-access-token:${RELEASE_TOKEN}@github.com/${REPO}.git" "$NEXT"
echo "Pushed $NEXT. goreleaser (release.yml) will build and publish it."