Skip to content

Rebuild - #67

Merged
qianmoQ merged 6 commits into
devfrom
rebuild
Oct 5, 2026
Merged

qianmoQ merged 6 commits into
devfrom
rebuild

Conversation

@qianmoQ

@qianmoQ qianmoQ commented Oct 5, 2026

Copy link
Copy Markdown
Member

Changelog category (leave one)

  • New Feature
  • Bug Fix
  • Documentation (changelog entry is not required)
  • Other

Changelog entry (Details of this change)

If there is an issue connection, write it to the end of the question
e.g: issue-7
Please delete this information when submitting

  • e.g: Support XXXXX

Affected version

  • e.g: latest version

Dependency review rejected robust-predicates (Unlicense and public domain) and uri-js
(BSD-2-Clause with BSD-2-Clause-Views), both pulled in by the documentation site and both
compatible with distributing GrantForge under MIT.
A pushed tag v<version> now builds the distribution, a CycloneDX SBOM of what it ships and
their checksums with script/ci/release.sh, takes the notes from the version's changelog page,
pushes a multi-arch image to GHCR and creates the GitHub release; -rc.N versions are
pre-releases. check_versions.py keeps the version equal in every pom, package, the Helm chart,
the console and the README, and changes them all with --set. The chart defaults to the
published image.
Packaging builds the console with pnpm, which the nightly image smoke tests and the release
job did not install, so every smoke test failed before it started.
gitleaks flagged the Base32 TOTP key in TotpCodesTest, which is the public test vector of
RFC 6238 and no secret. A .gitleaksignore keeps that one fingerprint, with its reason, so the
full-history scan passes without loosening any rule.
distribution: temurin
java-version: '21'
cache: maven
- uses: pnpm/action-setup@v4
distribution: temurin
java-version: '21'
cache: maven
- uses: pnpm/action-setup@v4
version="${GITHUB_REF_NAME#v}"
echo "version=${version}" >> "${GITHUB_OUTPUT}"
if [[ "${version}" == *-rc.* ]]; then echo "prerelease=true" >> "${GITHUB_OUTPUT}"; else echo "prerelease=false" >> "${GITHUB_OUTPUT}"; fi
- uses: docker/setup-qemu-action@v3
echo "version=${version}" >> "${GITHUB_OUTPUT}"
if [[ "${version}" == *-rc.* ]]; then echo "prerelease=true" >> "${GITHUB_OUTPUT}"; else echo "prerelease=false" >> "${GITHUB_OUTPUT}"; fi
- uses: docker/setup-qemu-action@v3
- uses: docker/setup-buildx-action@v3
if [[ "${version}" == *-rc.* ]]; then echo "prerelease=true" >> "${GITHUB_OUTPUT}"; else echo "prerelease=false" >> "${GITHUB_OUTPUT}"; fi
- uses: docker/setup-qemu-action@v3
- uses: docker/setup-buildx-action@v3
- uses: docker/login-action@v3
The image smoke test asked Maven for the mysql.version property, which the imported Spring
Boot BOM does not expose, so it fetched mysql-connector-j:null and the MySQL run failed.
@qianmoQ
qianmoQ merged commit e3ed773 into dev Oct 5, 2026
17 of 21 checks passed
@qianmoQ
qianmoQ deleted the rebuild branch October 5, 2026 05:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants