diff --git a/.github/workflows/tag-release.yml b/.github/workflows/tag-release.yml new file mode 100644 index 0000000..f702918 --- /dev/null +++ b/.github/workflows/tag-release.yml @@ -0,0 +1,57 @@ +name: Tag Release + +on: + push: + branches: [main] + paths: + - licenses.json + workflow_dispatch: # Allow manual trigger + +permissions: {} + +concurrency: + group: tag-release + cancel-in-progress: false + +jobs: + tag: + runs-on: ubuntu-latest + permissions: + contents: write + + steps: + - name: Checkout + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + fetch-depth: 0 + persist-credentials: false + + - name: Compute next version + id: version + run: | + latest=$(git tag --list 'v*' --sort=-v:refname | head -n 1) + if [ -z "$latest" ]; then + echo "No existing v* tags found" + exit 1 + fi + + if [ "$(git rev-parse "$latest^{commit}")" = "$GITHUB_SHA" ]; then + echo "HEAD is already tagged as $latest" + echo "skip=true" >> "$GITHUB_OUTPUT" + exit 0 + fi + + IFS=. read -r major minor patch <<< "${latest#v}" + next="v${major}.${minor}.$((patch + 1))" + echo "next=$next" >> "$GITHUB_OUTPUT" + echo "Tagging $next (previous: $latest)" + + - name: Create tag + if: steps.version.outputs.skip != 'true' + env: + GH_TOKEN: ${{ github.token }} + NEXT: ${{ steps.version.outputs.next }} + run: | + gh api "repos/$GITHUB_REPOSITORY/git/refs" \ + -f ref="refs/tags/$NEXT" \ + -f sha="$GITHUB_SHA"