From e22fdec607d353983234e971ae001a4fb293e40d Mon Sep 17 00:00:00 2001 From: D3strukt0r Date: Wed, 25 Mar 2026 12:25:30 +0100 Subject: [PATCH 01/11] docs: document lib setting in README Add the `lib` configuration to the documentation table to explain its role in supporting modern array functions such as `toSorted`. --- README.md | 13 +++++++------ 1 file changed, 7 insertions(+), 6 deletions(-) diff --git a/README.md b/README.md index 96472b1..b787168 100644 --- a/README.md +++ b/README.md @@ -79,12 +79,13 @@ This configuration extends three base configurations for comprehensive TypeScrip The following settings are relaxed from the strictest defaults for practical development: -| Setting | Value | Reason | -| ------------------------------------ | ------- | ---------------------------------------------------- | -| `erasableSyntaxOnly` | `false` | Allows enums, namespaces, and classes | -| `noPropertyAccessFromIndexSignature` | `false` | Allows dot notation for index signatures | -| `noImplicitAny` | `false` | Permits implicit `any` types where inference fails | -| `exactOptionalPropertyTypes` | `false` | Allows `undefined` assignment to optional properties | +| Setting | Value | Reason | +| ------------------------------------ | ------------------------------- | ---------------------------------------------------- | +| `lib` | `ES2023`, `DOM`, `DOM.Iterable` | Supports modern array functions (e.g. `toSorted`) | +| `erasableSyntaxOnly` | `false` | Allows enums, namespaces, and classes | +| `noPropertyAccessFromIndexSignature` | `false` | Allows dot notation for index signatures | +| `noImplicitAny` | `false` | Permits implicit `any` types where inference fails | +| `exactOptionalPropertyTypes` | `false` | Allows `undefined` assignment to optional properties | ## Contributing From 9b2d60a71682a4bd3048185e29ca711cd3928aaa Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 10 Apr 2026 07:35:16 +0000 Subject: [PATCH 02/11] chore(deps): bump dependabot/fetch-metadata from 2 to 3 Bumps [dependabot/fetch-metadata](https://github.com/dependabot/fetch-metadata) from 2 to 3. - [Release notes](https://github.com/dependabot/fetch-metadata/releases) - [Commits](https://github.com/dependabot/fetch-metadata/compare/v2...v3) --- updated-dependencies: - dependency-name: dependabot/fetch-metadata dependency-version: '3' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] --- .github/workflows/dependabot-automerge.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/dependabot-automerge.yml b/.github/workflows/dependabot-automerge.yml index 0869bc4..402a8f1 100644 --- a/.github/workflows/dependabot-automerge.yml +++ b/.github/workflows/dependabot-automerge.yml @@ -20,7 +20,7 @@ jobs: uses: actions/checkout@v6 - name: Fetch Dependabot metadata 🔍 - uses: dependabot/fetch-metadata@v2 + uses: dependabot/fetch-metadata@v3 id: metadata with: github-token: ${{ github.token }} From e5c1f34d4318b42393916348042da351e8965fd6 Mon Sep 17 00:00:00 2001 From: D3strukt0r Date: Tue, 14 Apr 2026 15:09:05 +0200 Subject: [PATCH 03/11] ci: run workflow on all pull requests Remove the branch filter for pull request triggers to ensure CI runs for all pull requests regardless of the target branch. --- .github/workflows/ci.yml | 1 - 1 file changed, 1 deletion(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 28b7e9d..e28191e 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -4,7 +4,6 @@ on: push: branches: [main, develop] pull_request: - branches: [main, develop] permissions: contents: read From 35f790b8af922edd2f95690b47563ed7dcf0da5b Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 17 Apr 2026 07:35:21 +0000 Subject: [PATCH 04/11] chore(deps): bump pnpm/action-setup from 5 to 6 Bumps [pnpm/action-setup](https://github.com/pnpm/action-setup) from 5 to 6. - [Release notes](https://github.com/pnpm/action-setup/releases) - [Commits](https://github.com/pnpm/action-setup/compare/v5...v6) --- updated-dependencies: - dependency-name: pnpm/action-setup dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] --- .github/workflows/ci.yml | 2 +- .github/workflows/release.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index e28191e..3e9b492 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -21,7 +21,7 @@ jobs: node-version: 24.x - name: Install pnpm - uses: pnpm/action-setup@v5 + uses: pnpm/action-setup@v6 - name: Get pnpm cache directory path id: pnpm-cache-dir-path diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index fc00ab4..61fd7aa 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -38,7 +38,7 @@ jobs: registry-url: https://registry.npmjs.org - name: Install pnpm - uses: pnpm/action-setup@v5 + uses: pnpm/action-setup@v6 #- name: Get pnpm cache directory path # id: pnpm-cache-dir-path From aa8fd1cd45cd8b7b01368d4d705434c4e9dd331f Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 24 Apr 2026 07:35:36 +0000 Subject: [PATCH 05/11] chore(deps): bump googleapis/release-please-action from 4 to 5 Bumps [googleapis/release-please-action](https://github.com/googleapis/release-please-action) from 4 to 5. - [Release notes](https://github.com/googleapis/release-please-action/releases) - [Changelog](https://github.com/googleapis/release-please-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/googleapis/release-please-action/compare/v4...v5) --- updated-dependencies: - dependency-name: googleapis/release-please-action dependency-version: '5' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] --- .github/workflows/release.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 61fd7aa..d94be1f 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -16,7 +16,7 @@ jobs: release_created: ${{ steps.release.outputs.release_created }} steps: - name: Create Release PR - uses: googleapis/release-please-action@v4 + uses: googleapis/release-please-action@v5 id: release publish: From 7b7f491d2c5e3b32efc830bbb0f3c096d8f6cc8b Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 1 May 2026 08:35:25 +0000 Subject: [PATCH 06/11] chore(deps): bump ghcr.io/devcontainers/features/node Bumps ghcr.io/devcontainers/features/node from 1.7.1 to 2.0.0. --- updated-dependencies: - dependency-name: ghcr.io/devcontainers/features/node dependency-version: 2.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] --- .devcontainer/devcontainer.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.devcontainer/devcontainer.json b/.devcontainer/devcontainer.json index b508983..06d6eb2 100644 --- a/.devcontainer/devcontainer.json +++ b/.devcontainer/devcontainer.json @@ -18,7 +18,7 @@ "ghcr.io/devcontainers/features/common-utils:2": { "configureZshAsDefaultShell": true }, - "ghcr.io/devcontainers/features/node:1": { + "ghcr.io/devcontainers/features/node:2": { "version": "24", "pnpmVersion": "latest" }, From 49c2f4907f849b06f0da93307f8a3c48329f9fd5 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 15 May 2026 07:36:27 +0000 Subject: [PATCH 07/11] chore(deps): bump @tsconfig/vite-react from 7.0.2 to 8.0.6 Bumps [@tsconfig/vite-react](https://github.com/tsconfig/bases/tree/HEAD/bases) from 7.0.2 to 8.0.6. - [Commits](https://github.com/tsconfig/bases/commits/HEAD/bases) --- updated-dependencies: - dependency-name: "@tsconfig/vite-react" dependency-version: 8.0.6 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] --- package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package.json b/package.json index 43d0a69..cefc825 100644 --- a/package.json +++ b/package.json @@ -32,7 +32,7 @@ "dependencies": { "@tsconfig/recommended": "^1.0.0", "@tsconfig/strictest": "^2.0.0", - "@tsconfig/vite-react": "^7.0.0" + "@tsconfig/vite-react": "^8.0.6" }, "devDependencies": { "typescript": "^6.0.2" From 1cde102d2a09d43327281dd58a8fead8e6d675ba Mon Sep 17 00:00:00 2001 From: D3strukt0r Date: Mon, 8 Jun 2026 17:33:03 +0200 Subject: [PATCH 08/11] chore(deps): @tsconfig/vite-react added ""types": ["vite/client"]", so add vite as dependency --- package.json | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/package.json b/package.json index cefc825..f1c3f51 100644 --- a/package.json +++ b/package.json @@ -35,7 +35,8 @@ "@tsconfig/vite-react": "^8.0.6" }, "devDependencies": { - "typescript": "^6.0.2" + "typescript": "^6.0.2", + "vite": "^8.0.16" }, "packageManager": "pnpm@10.26.0+sha512.3b3f6c725ebe712506c0ab1ad4133cf86b1f4b687effce62a9b38b4d72e3954242e643190fc51fa1642949c735f403debd44f5cb0edd657abe63a8b6a7e1e402" } From bb93e3c6c75b29188d6289fd2adb807736ce3285 Mon Sep 17 00:00:00 2001 From: D3strukt0r Date: Mon, 8 Jun 2026 17:38:02 +0200 Subject: [PATCH 09/11] chore(deps): Update to pnpm 11 and handle default minimumReleaseAge --- .github/dependabot.yml | 2 ++ .gitignore | 1 + .vscode/settings.json | 6 ------ CLAUDE.md => AGENTS.md | 5 +++-- package.json | 4 ++-- 5 files changed, 8 insertions(+), 10 deletions(-) delete mode 100644 .vscode/settings.json rename CLAUDE.md => AGENTS.md (85%) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 6237594..05a918e 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -36,3 +36,5 @@ updates: interval: weekly time: '09:30' timezone: Europe/Zurich + cooldown: + default-days: 1 # Match pnpm 11 default minimumReleaseAge (1440 min = 1 day) diff --git a/.gitignore b/.gitignore index 9dc1996..667fb88 100644 --- a/.gitignore +++ b/.gitignore @@ -3,3 +3,4 @@ node_modules pnpm-lock.yaml *.tgz +CLAUDE.md diff --git a/.vscode/settings.json b/.vscode/settings.json deleted file mode 100644 index b4bd5be..0000000 --- a/.vscode/settings.json +++ /dev/null @@ -1,6 +0,0 @@ -{ - "editor.formatOnSave": true, - "markdown.extension.list.indentationSize": "adaptive", - "markdown.extension.italic.indicator": "_", - "markdown.extension.orderedList.marker": "one" -} diff --git a/CLAUDE.md b/AGENTS.md similarity index 85% rename from CLAUDE.md rename to AGENTS.md index 7b10d2f..3b3232a 100644 --- a/CLAUDE.md +++ b/AGENTS.md @@ -1,6 +1,6 @@ -# CLAUDE.md +# AGENTS.md -This file provides guidance to Claude Code (claude.ai/code) when working with code in this repository. +This file provides guidance to AI coding agents when working with code in this repository. ## Project Overview @@ -10,6 +10,7 @@ This is `@iwf-web/tsconfig`, a TypeScript configuration package for IWF projects ```bash pnpm install # Install dependencies +pnpm ts:check # Type-check the configs against test/index.ts (tsc --noEmit) ``` No build step required - the package exports JSON configuration files directly. diff --git a/package.json b/package.json index f1c3f51..dabf982 100644 --- a/package.json +++ b/package.json @@ -32,11 +32,11 @@ "dependencies": { "@tsconfig/recommended": "^1.0.0", "@tsconfig/strictest": "^2.0.0", - "@tsconfig/vite-react": "^8.0.6" + "@tsconfig/vite-react": "^8.0.0" }, "devDependencies": { "typescript": "^6.0.2", "vite": "^8.0.16" }, - "packageManager": "pnpm@10.26.0+sha512.3b3f6c725ebe712506c0ab1ad4133cf86b1f4b687effce62a9b38b4d72e3954242e643190fc51fa1642949c735f403debd44f5cb0edd657abe63a8b6a7e1e402" + "packageManager": "pnpm@11.5.2+sha512.71c631e382066efc25625d5cf029075de07b61b37f6e27350fbd84b1bda5864c8c1967adc280776b45c30a715c0359a3be08fef42d5bb09e2b99029979692916" } From 241a9291befd50d66f5a30354b4070e0c9922d9e Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 19 Jun 2026 07:32:58 +0000 Subject: [PATCH 10/11] chore(deps): bump actions/checkout from 6 to 7 Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/checkout/compare/v6...v7) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] --- .github/workflows/ci.yml | 2 +- .github/workflows/dependabot-automerge.yml | 2 +- .github/workflows/release.yml | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 3e9b492..9f23b85 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -13,7 +13,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@v6 + uses: actions/checkout@v7 - name: Setup Node.js uses: actions/setup-node@v6 diff --git a/.github/workflows/dependabot-automerge.yml b/.github/workflows/dependabot-automerge.yml index 402a8f1..a137adb 100644 --- a/.github/workflows/dependabot-automerge.yml +++ b/.github/workflows/dependabot-automerge.yml @@ -17,7 +17,7 @@ jobs: steps: - name: Checkout - uses: actions/checkout@v6 + uses: actions/checkout@v7 - name: Fetch Dependabot metadata 🔍 uses: dependabot/fetch-metadata@v3 diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index d94be1f..f38dfea 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -28,7 +28,7 @@ jobs: id-token: write # for provenance steps: - name: Checkout - uses: actions/checkout@v6 + uses: actions/checkout@v7 # Setup .npmrc file to publish to npm - name: Setup Node.js From a11cfcb545dec5e2736c7f0930847857c6863543 Mon Sep 17 00:00:00 2001 From: D3strukt0r Date: Thu, 25 Jun 2026 10:19:18 +0200 Subject: [PATCH 11/11] fix(ci): group dependabot updates and harden release workflow Group Dependabot version updates by ecosystem so related bumps land in one PR: github-actions and devcontainers each group all patterns, while npm groups non-breaking (minor and patch) updates and keeps the existing pnpm release cooldown. Pin the weekly schedule explicitly to monday across all three ecosystems. Move the release-please config and manifest into .github (dropping the leading dot from the manifest) and point the action at them via config-file and manifest-file. Add a reattribute job that rewrites the release-PR commit author to github-actions[bot] since the action commits as the PAT owner, and mark it continue-on-error because the PR branch may already be deleted when it runs. Switch the release-please and dependabot auto-merge approval tokens to the GH_PAT so the bot can trigger workflows and its approval counts, and skip the greetings job for dependabot[bot]. Relocate CODEOWNERS into .github and add the Dependabot-managed paths (package manifest, workflows, devcontainer) co-owned by @iwf-web/CI so the bot's auto-approval satisfies the code-owner requirement. Align the AGENTS.md intro wording and import note. Bump the pinned pnpm to 11.9.0, extend the LICENSE copyright to 2025-2026, and add the Keep a Changelog header. --- .devcontainer/devcontainer-lock.json | 29 +++++++++++ .github/CODEOWNERS | 14 +++++ .github/dependabot.yml | 18 ++++++- .../release-please-config.json | 0 .../release-please-manifest.json | 0 .github/workflows/dependabot-automerge.yml | 2 +- .github/workflows/greetings.yml | 1 + .github/workflows/release.yml | 52 ++++++++++++++++++- AGENTS.md | 2 +- CHANGELOG.md | 5 ++ CODEOWNERS | 4 -- LICENSE.txt | 2 +- package.json | 2 +- 13 files changed, 121 insertions(+), 10 deletions(-) create mode 100644 .devcontainer/devcontainer-lock.json create mode 100644 .github/CODEOWNERS rename release-please-config.json => .github/release-please-config.json (100%) rename .release-please-manifest.json => .github/release-please-manifest.json (100%) delete mode 100644 CODEOWNERS diff --git a/.devcontainer/devcontainer-lock.json b/.devcontainer/devcontainer-lock.json new file mode 100644 index 0000000..f449ba6 --- /dev/null +++ b/.devcontainer/devcontainer-lock.json @@ -0,0 +1,29 @@ +{ + "features": { + "ghcr.io/devcontainers-extra/features/act:1": { + "version": "1.0.15", + "resolved": "ghcr.io/devcontainers-extra/features/act@sha256:db4a2194930d1f7ec62822d4f600dd2fa4aff3c33b98cdb0b578b64ffb10924c", + "integrity": "sha256:db4a2194930d1f7ec62822d4f600dd2fa4aff3c33b98cdb0b578b64ffb10924c" + }, + "ghcr.io/devcontainers/features/common-utils:2": { + "version": "2.5.9", + "resolved": "ghcr.io/devcontainers/features/common-utils@sha256:cb0c4d3c276f157eed17935747e364178d75fee17f55c4e129966f64633deb3a", + "integrity": "sha256:cb0c4d3c276f157eed17935747e364178d75fee17f55c4e129966f64633deb3a" + }, + "ghcr.io/devcontainers/features/docker-outside-of-docker:1": { + "version": "1.10.0", + "resolved": "ghcr.io/devcontainers/features/docker-outside-of-docker@sha256:c2c2cf829505ead8e4892c88c31b6594ae94a2bbb209e16e1fac456c1a3a624e", + "integrity": "sha256:c2c2cf829505ead8e4892c88c31b6594ae94a2bbb209e16e1fac456c1a3a624e" + }, + "ghcr.io/devcontainers/features/github-cli:1": { + "version": "1.1.0", + "resolved": "ghcr.io/devcontainers/features/github-cli@sha256:d22f50b70ed75339b4eed1ba9ecde3a1791f90e88d37936517e3bace0bbad671", + "integrity": "sha256:d22f50b70ed75339b4eed1ba9ecde3a1791f90e88d37936517e3bace0bbad671" + }, + "ghcr.io/devcontainers/features/node:2": { + "version": "2.1.0", + "resolved": "ghcr.io/devcontainers/features/node@sha256:586c9a6f7dd40bd3ba2cd41e7f2f88dcc31fbe5d1442afcbf07ffbc66b686857", + "integrity": "sha256:586c9a6f7dd40bd3ba2cd41e7f2f88dcc31fbe5d1442afcbf07ffbc66b686857" + } + } +} diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS new file mode 100644 index 0000000..df9ad07 --- /dev/null +++ b/.github/CODEOWNERS @@ -0,0 +1,14 @@ +# https://docs.github.com/en/github/creating-cloning-and-archiving-repositories/about-code-owners +# Last matching pattern wins. Only ONE listed owner needs to approve, not all. + +# Default owner for everything. +* @D3strukt0r + +# Files Dependabot manages — @iwf-web/CI (incl. the bot user) can also review, +# so the bot's auto-approval satisfies the code-owner requirement on these paths. +# npm +/package.json @D3strukt0r @iwf-web/CI +# github-actions +/.github/workflows/ @D3strukt0r @iwf-web/CI +# devcontainers +/.devcontainer/ @D3strukt0r @iwf-web/CI diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 05a918e..7b10756 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -13,9 +13,14 @@ updates: labels: - "dependabot :robot:" schedule: - interval: weekly # on monday + interval: weekly + day: monday time: '09:30' timezone: Europe/Zurich + groups: + github-actions: + patterns: + - "*" - package-ecosystem: devcontainers directory: / @@ -24,8 +29,13 @@ updates: - "dependabot :robot:" schedule: interval: weekly + day: monday time: '09:30' timezone: Europe/Zurich + groups: + devcontainers: + patterns: + - "*" - package-ecosystem: npm # pnpm directory: / @@ -34,7 +44,13 @@ updates: - "dependabot :robot:" schedule: interval: weekly + day: monday time: '09:30' timezone: Europe/Zurich cooldown: default-days: 1 # Match pnpm 11 default minimumReleaseAge (1440 min = 1 day) + groups: + npm-non-breaking: + update-types: + - minor + - patch diff --git a/release-please-config.json b/.github/release-please-config.json similarity index 100% rename from release-please-config.json rename to .github/release-please-config.json diff --git a/.release-please-manifest.json b/.github/release-please-manifest.json similarity index 100% rename from .release-please-manifest.json rename to .github/release-please-manifest.json diff --git a/.github/workflows/dependabot-automerge.yml b/.github/workflows/dependabot-automerge.yml index a137adb..33b660b 100644 --- a/.github/workflows/dependabot-automerge.yml +++ b/.github/workflows/dependabot-automerge.yml @@ -29,7 +29,7 @@ jobs: if: steps.metadata.outputs.update-type == 'version-update:semver-minor' || steps.metadata.outputs.update-type == 'version-update:semver-patch' env: PR_URL: ${{ github.event.pull_request.html_url }} - GITHUB_TOKEN: ${{ github.token }} + GITHUB_TOKEN: ${{ secrets.GH_PAT }} run: | gh pr checkout "$PR_URL" # sets the upstream metadata for `gh pr status` if [ "$(gh pr status --json reviewDecision -q .currentBranch.reviewDecision)" != "APPROVED" ]; then diff --git a/.github/workflows/greetings.yml b/.github/workflows/greetings.yml index 1ffdfa8..666b188 100644 --- a/.github/workflows/greetings.yml +++ b/.github/workflows/greetings.yml @@ -16,6 +16,7 @@ jobs: greeting: name: Greet First-Time Contributors runs-on: ubuntu-latest + if: github.actor != 'dependabot[bot]' steps: - name: Greet First-Time Contributors diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index f38dfea..2115199 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -14,10 +14,60 @@ jobs: pull-requests: write outputs: release_created: ${{ steps.release.outputs.release_created }} + # Non-empty JSON when release-please created or updated a release PR + # this run. Used by `reattribute` below to decide whether to amend. + pr: ${{ steps.release.outputs.pr }} steps: - name: Create Release PR - uses: googleapis/release-please-action@v5 id: release + uses: googleapis/release-please-action@v5 + with: + config-file: .github/release-please-config.json + manifest-file: .github/release-please-manifest.json + # Bot PAT with access to Workflows + # The built-in GITHUB_TOKEN has cannot trigger other workflows + token: ${{ secrets.GH_PAT }} + + # release-please-action commits the release PR's contents as the PAT + # owner (the action has no input to override the commit author). Re-attribute + # to github-actions[bot] so the PR shows the bot as author instead of the + # person the PAT belongs to. + reattribute: + needs: release-please + if: ${{ needs.release-please.outputs.pr != '' }} + runs-on: ubuntu-latest + permissions: + contents: write + # Cosmetic best-effort: rewrites the release-PR commit author to the bot. If + # the release PR is merged before this runs, its branch is deleted and the + # checkout below can't fetch it — don't fail the release workflow over that. + continue-on-error: true + env: + # release-please's branch name varies by config (`release-please--branches--` + # for single-package, with extra `--components--` segments for component mode). + # The action emits the PR object as JSON — pull `headBranchName` from it instead of + # guessing the pattern. + PR_BRANCH: ${{ fromJSON(needs.release-please.outputs.pr).headBranchName }} + steps: + - name: Checkout release-please branch + uses: actions/checkout@v7 + with: + token: ${{ secrets.GH_PAT }} + ref: ${{ env.PR_BRANCH }} + fetch-depth: 2 + + - name: Configure git + run: | + git config user.name "github-actions[bot]" + git config user.email "41898282+github-actions[bot]@users.noreply.github.com" + + - name: Amend release commit as github-actions[bot] + run: | + set -euo pipefail + # --reset-author rewrites both author and committer to the configured + # identity; --no-edit keeps the existing commit message verbatim. + git commit --amend --reset-author --no-edit + git push origin "$PR_BRANCH" --force-with-lease publish: needs: release-please diff --git a/AGENTS.md b/AGENTS.md index 3b3232a..0532ad5 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -1,6 +1,6 @@ # AGENTS.md -This file provides guidance to AI coding agents when working with code in this repository. +This file provides guidance to coding agents (Claude Code, etc.) when working with code in this repository. `CLAUDE.md` simply imports this file via `@AGENTS.md`. ## Project Overview diff --git a/CHANGELOG.md b/CHANGELOG.md index 61d8838..e119f8e 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,10 @@ # Changelog +All notable changes to this project will be documented in this file. + +The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/), +and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). + ## [1.1.0](https://github.com/iwf-web/tsconfig/compare/1.0.2...1.1.0) (2026-03-25) diff --git a/CODEOWNERS b/CODEOWNERS deleted file mode 100644 index 240fb51..0000000 --- a/CODEOWNERS +++ /dev/null @@ -1,4 +0,0 @@ -# https://docs.github.com/en/github/creating-cloning-and-archiving-repositories/about-code-owners - -# These owners will be the default owners for everything in the repo. -* @D3strukt0r diff --git a/LICENSE.txt b/LICENSE.txt index 8eb2532..3901047 100644 --- a/LICENSE.txt +++ b/LICENSE.txt @@ -1,6 +1,6 @@ MIT License -Copyright (c) 2025 IWF Web Solutions +Copyright (c) 2025-2026 IWF Web Solutions Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal diff --git a/package.json b/package.json index dabf982..d5717b1 100644 --- a/package.json +++ b/package.json @@ -38,5 +38,5 @@ "typescript": "^6.0.2", "vite": "^8.0.16" }, - "packageManager": "pnpm@11.5.2+sha512.71c631e382066efc25625d5cf029075de07b61b37f6e27350fbd84b1bda5864c8c1967adc280776b45c30a715c0359a3be08fef42d5bb09e2b99029979692916" + "packageManager": "pnpm@11.9.0+sha512.bd682d5d03fe525ef7c9fd6780c6884d1e756ac4c9c9fe00c538782824310dcf90e3ddc4f53835f06dfaebd5085e41855e0bcbb3b60de2ac5bbab89e5036f03b" }