From 90b1eaa55a28429bc2315c0fe1d926b4de9ae59f Mon Sep 17 00:00:00 2001 From: Yuri Rocha Date: Sat, 20 Jun 2026 21:55:04 +0900 Subject: [PATCH] Fix release workflow and CodeQL setup --- .github/workflows/build.yml | 91 +++++++++++++++++++++++++-- .github/workflows/codeql-analysis.yml | 71 --------------------- README.md | 4 +- 3 files changed, 87 insertions(+), 79 deletions(-) delete mode 100644 .github/workflows/codeql-analysis.yml diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index bbafa9f..d8dfbed 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -11,6 +11,8 @@ jobs: deploy: runs-on: ubuntu-latest + permissions: + contents: write steps: - uses: actions/checkout@v7 @@ -55,12 +57,24 @@ jobs: raise SystemExit("Could not find __version__") PY )" - latest_pypi_version="$(uv run python - <<'PY' + pypi_version_exists="$(CURRENT_VERSION="$current_version" uv run python - <<'PY' import json + import os import urllib.request + import urllib.error - with urllib.request.urlopen("https://pypi.org/pypi/leet2git/json", timeout=20) as response: - print(json.load(response)["info"]["version"]) + current_version = os.environ["CURRENT_VERSION"] + url = f"https://pypi.org/pypi/leet2git/{current_version}/json" + try: + with urllib.request.urlopen(url, timeout=20) as response: + json.load(response) + except urllib.error.HTTPError as e: + if e.code == 404: + print("false") + else: + raise + else: + print("true") PY )" @@ -69,7 +83,7 @@ jobs: if [ "$NEW_TAG_VERSION" != "$TAG_VERSION" ]; then release_version="$NEW_TAG_VERSION" release_reason="tag" - elif [ "$current_version" != "$latest_pypi_version" ]; then + elif [ "$pypi_version_exists" != "true" ]; then release_reason="package-version" fi @@ -79,13 +93,13 @@ jobs: fi echo "current_version=$current_version" >> "$GITHUB_OUTPUT" - echo "latest_pypi_version=$latest_pypi_version" >> "$GITHUB_OUTPUT" + echo "pypi_version_exists=$pypi_version_exists" >> "$GITHUB_OUTPUT" echo "version=$release_version" >> "$GITHUB_OUTPUT" echo "reason=$release_reason" >> "$GITHUB_OUTPUT" echo "should_release=$should_release" >> "$GITHUB_OUTPUT" echo "Current version: $current_version" - echo "Latest PyPI version: $latest_pypi_version" + echo "Current version exists on PyPI: $pypi_version_exists" echo "Release version: $release_version" echo "Release reason: $release_reason" - name: Update app version @@ -122,3 +136,68 @@ jobs: with: user: __token__ password: ${{ secrets.PYPI_API_TOKEN }} + skip-existing: true + - name: Verify PyPI release + if: ${{ steps.release_version.outputs.should_release == 'true' }} + env: + RELEASE_VERSION: ${{ steps.release_version.outputs.version }} + run: | + uv run python - <<'PY' + import json + import os + import time + import urllib.request + + release_version = os.environ["RELEASE_VERSION"] + url = f"https://pypi.org/pypi/leet2git/{release_version}/json" + + for _ in range(12): + try: + with urllib.request.urlopen(url, timeout=20) as response: + payload = json.load(response) + except Exception: + time.sleep(5) + continue + if payload["info"]["version"] == release_version: + print(f"Verified leet2git {release_version} on PyPI") + break + time.sleep(5) + else: + raise SystemExit(f"Could not verify leet2git {release_version} on PyPI") + PY + - name: Create GitHub release + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + RELEASE_VERSION: ${{ steps.release_version.outputs.version }} + run: | + tag="v$RELEASE_VERSION" + if ! uv run python - <<'PY' + import json + import os + import urllib.error + import urllib.request + + release_version = os.environ["RELEASE_VERSION"] + url = f"https://pypi.org/pypi/leet2git/{release_version}/json" + try: + with urllib.request.urlopen(url, timeout=20) as response: + json.load(response) + except urllib.error.HTTPError as e: + if e.code == 404: + raise SystemExit(1) + raise + PY + then + echo "leet2git $RELEASE_VERSION is not on PyPI yet; skipping GitHub release" + exit 0 + fi + + if gh release view "$tag" >/dev/null 2>&1; then + echo "Release $tag already exists" + else + if ! git ls-remote --exit-code --tags origin "refs/tags/$tag" >/dev/null 2>&1; then + git tag "$tag" + git push origin "$tag" + fi + gh release create "$tag" --title "$tag" --generate-notes + fi diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml deleted file mode 100644 index 7c157ce..0000000 --- a/.github/workflows/codeql-analysis.yml +++ /dev/null @@ -1,71 +0,0 @@ -# For most projects, this workflow file will not need changing; you simply need -# to commit it to your repository. -# -# You may wish to alter this file to override the set of languages analyzed, -# or to provide custom queries or build logic. -# -# ******** NOTE ******** -# We have attempted to detect the languages in your repository. Please check -# the `language` matrix defined below to confirm you have the correct set of -# supported CodeQL languages. -# -name: "CodeQL" - -on: - push: - branches: [ main ] - pull_request: - # The branches below must be a subset of the branches above - branches: [ main ] - schedule: - - cron: '00 0 * * 5' - -jobs: - analyze: - name: Analyze - runs-on: ubuntu-latest - permissions: - actions: read - contents: read - security-events: write - - strategy: - fail-fast: false - matrix: - language: [ 'python' ] - # CodeQL supports [ 'cpp', 'csharp', 'go', 'java', 'javascript', 'python' ] - # Learn more: - # https://docs.github.com/en/free-pro-team@latest/github/finding-security-vulnerabilities-and-errors-in-your-code/configuring-code-scanning#changing-the-languages-that-are-analyzed - - steps: - - name: Checkout repository - uses: actions/checkout@v7 - - # Initializes the CodeQL tools for scanning. - - name: Initialize CodeQL - uses: github/codeql-action/init@v4.36.2 - with: - languages: ${{ matrix.language }} - # If you wish to specify custom queries, you can do so here or in a config file. - # By default, queries listed here will override any specified in a config file. - # Prefix the list here with "+" to use these queries and those in the config file. - # queries: ./path/to/local/query, your-org/your-repo/queries@main - - # Autobuild attempts to build any compiled languages (C/C++, C#, or Java). - # If this step fails, then you should remove it and run the build manually (see below) - - name: Autobuild - uses: github/codeql-action/autobuild@v4.36.2 - - # â„šī¸ Command-line programs to run using the OS shell. - # 📚 https://git.io/JvXDl - - # âœī¸ If the Autobuild fails above, remove it and uncomment the following three lines - # and modify them (or add more) to build your code if your project - # uses a compiled language - - #- run: | - # make bootstrap - # make release - - - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@v4.36.2 diff --git a/README.md b/README.md index 0df3dd8..23a0d4e 100644 --- a/README.md +++ b/README.md @@ -3,8 +3,8 @@ [![Python 3.11+](https://img.shields.io/badge/python-3.11%2B-blue.svg)](https://www.python.org/downloads/) [![Code style: Ruff](https://img.shields.io/badge/code%20style-ruff-46a2f1.svg)](https://docs.astral.sh/ruff/) [![Linting: Ruff & ty](https://img.shields.io/badge/linting-ruff%20%26%20ty-green)](https://docs.astral.sh/) -[![Stable Version](https://img.shields.io/github/v/tag/yurirocha15/leetcode2github)](https://img.shields.io/github/v/tag/yurirocha15/leetcode2github) -[![Latest Release](https://img.shields.io/github/v/release/yurirocha15/leetcode2github?color=%233D9970)](https://img.shields.io/github/v/release/yurirocha15/leetcode2github?color=%233D9970) +[![Stable Version](https://img.shields.io/github/v/tag/yurirocha15/leetcode2github)](https://github.com/yurirocha15/leetcode2github/tags) +[![Latest Release](https://img.shields.io/github/v/release/yurirocha15/leetcode2github?color=%233D9970)](https://github.com/yurirocha15/leetcode2github/releases/latest) [![Pypi Version](https://img.shields.io/pypi/v/leet2git)](https://pypi.org/project/leet2git/) [![All Contributors](https://img.shields.io/badge/all_contributors-2-orange.svg)](#contributors-)