Skip to content

Commit eab31fd

Browse files
docs: add CodeQL review steps and restructure after-release checklist (#4200)
After the last release, @rejas left some notes in the collaboration chat. This PR tries to address them. Additionally I went through the whole file and fixed some typos and formatting.
1 parent df6170c commit eab31fd

1 file changed

Lines changed: 41 additions & 25 deletions

File tree

Collaboration.md

Lines changed: 41 additions & 25 deletions
Original file line numberDiff line numberDiff line change
@@ -4,67 +4,78 @@ This document describes how collaborators of this repository should work togethe
44

55
## Pull Requests
66

7-
- never merge your own PR's
8-
- never merge without someone having approved (approving and merging from same person is allowed)
7+
- never merge your own PRs
8+
- never merge without someone having approved (approving and merging by the same person is allowed)
99
- wait for all approvals requested (or the author decides something different in the comments)
1010
- merge to `master` only for releases or other urgent issues (update notification is only triggered by tags)
11-
- merges to master should be tagged with the "mastermerge" label so that the test runs through
11+
- merges to `master` should be tagged with the `mastermerge` label so that the test runs through
1212

1313
## Issues
1414

15-
- "real" Issues are closed if the problem is solved and the fix is released
16-
- unrelated Issues (e.g. related to a foreign module) are closed immediately with a comment to open an issue in the module repository or to discuss this further in the forum or discord
15+
- "real" issues are closed if the problem is solved and the fix is released
16+
- unrelated issues (e.g. related to a third-party module) are closed immediately with a comment to open an issue in the module repository or to discuss this further in the forum or Discord
1717

1818
## Releases
1919

20-
Are done by
20+
Releases are done by:
2121

22-
- [ ] @rejas
23-
- [ ] @sdetweil
24-
- [ ] @khassel
25-
- [ ] @KristjanESPERANTO
22+
- @rejas
23+
- @sdetweil
24+
- @khassel or
25+
- @KristjanESPERANTO
2626

27-
### Pre-Deployment steps
27+
### Pre-Deployment Steps
2828

2929
- [ ] update dependencies (a few days before)
3030

31-
### Deployment steps
31+
### Deployment Steps
3232

33-
- [ ] pull latest `develop` branch
33+
- [ ] pull the latest `develop` branch
3434
- [ ] create `prep-release` branch from `develop`
3535
- [ ] update `package.json` and `package-lock.json` to reflect correct version number `2.xx.0`
3636
- [ ] test `prep-release` branch
3737
- [ ] commit and push all changes
3838
- [ ] create pull request from `prep-release` to `develop` branch with title `Prepare Release 2.xx.0`
39-
- [ ] after successful test run via github actions: merge pull request to `develop`
39+
- [ ] after successful test run via GitHub Actions: merge pull request to `develop`
4040
- [ ] review the content of the automatically generated draft release named `unreleased`
4141
- [ ] check contributor names
42-
- [ ] check auto generated min. node version and adjust it for better readability if necessary
42+
- [ ] check auto-generated minimum Node.js version and adjust it for better readability if necessary
4343
- [ ] check if all elements are assigned to the correct category
4444
- [ ] change release name to `v2.xx.0`
45-
- [ ] after successful test run via github actions: create pull request from `develop` to `master` branch
45+
- [ ] after successful test run via GitHub Actions: create pull request from `develop` to `master` branch
4646
- [ ] add label `mastermerge`
4747
- [ ] title of the PR is `Release 2.xx.0`
4848
- [ ] description of the PR is the body of the draft release with name `v2.xx.0`
49-
- [ ] check if new PR has merge conflicts, if so, merge `master` into the new PR and solve the conflicts
50-
- [ ] after PR tests run without issues, merge PR
49+
- [ ] review all `github-code-quality` / CodeQL review comments in the release PR (these comments are triggered automatically)
50+
- [ ] triage findings: if non-critical, continue the release; if critical and unclear, check with other maintainers and postpone the release if needed
51+
- [ ] if a finding is a false positive, dismiss it in the CodeQL alert with a short explanation
52+
- [ ] check if the new PR has merge conflicts; if so, merge `master` into the new PR and solve the conflicts
53+
- [ ] after PR tests run without issues, merge the PR
5154
- [ ] edit draft release with name `v2.xx.0`
5255
- [ ] set corresponding version tag `v2.xx.0` (with `Select tag` and then `Create new tag`)
53-
- [ ] update release link in `Compare to previous Release` by replacing `develop` with new tag `v2.xx.0`
56+
- [ ] update release link in `Compare to previous Release` by replacing `develop` with the new tag `v2.xx.0`
5457
- [ ] publish the release (button at the bottom)
5558

5659
### Draft new development release
5760

58-
- [ ] checkout `develop` branch
61+
- [ ] check out `develop` branch
5962
- [ ] update `package.json` and `package-lock.json` to reflect correct version number `2.xx.0-develop`
6063
- [ ] commit and push `develop` branch
61-
- [ ] if new release will be in January, update the year in LICENSE.md
64+
- [ ] if the new release will be in January, update the year in `LICENSE.md`
6265

6366
### After release
6467

65-
- [ ] publish release notes with link to github release on forum in new locked topic (use edit release on github to copy the content with markdown syntax)
66-
- [ ] close all issues with label `ready (coming with next release)`
67-
- [ ] release new documentation by merging `develop` on `master` in documentation repository
68+
#### Documentation repository
69+
70+
- [ ] create a pull request from `develop` to `master` with title `Release v2.xx.0`
71+
- [ ] after successful test run via GitHub Actions: merge the pull request to `master`
72+
- [ ] verify the updated documentation site is live
73+
- [ ] create/publish a release in the documentation repository for the same version (`v2.xx.0`)
74+
- [ ] update `package.json` and `package-lock.json` in the `develop` branch to reflect the next version number `2.xx.0-develop`
75+
- [ ] commit and push `develop` branch
76+
77+
#### npm
78+
6879
- [ ] publish new version on [npm](https://www.npmjs.com/package/magicmirror)
6980
- [ ] use a clean environment (e.g. container)
7081
- [ ] clone this repository with the new `master` branch and `cd` into the local repository directory
@@ -74,7 +85,7 @@ Are done by
7485
- [ ] execute `npm publish`
7586
- [ ] **Method 2 (fallback for headless environments): With token (bypasses 2FA)**
7687
- [ ] ⚠️ Note: This method bypasses 2FA and should only be used when a browser is not available
77-
- [ ] goto `https://www.npmjs.com/settings/<username>/tokens/` and click `generate new token`
88+
- [ ] go to `https://www.npmjs.com/settings/<username>/tokens/` and click `generate new token`
7889
- [ ] enable `Bypass two-factor authentication (2FA)` and under `Packages and scopes` give `Read and write` permission to the `magicmirror` package, press `Generate token`
7990
- [ ] execute:
8091

@@ -83,3 +94,8 @@ Are done by
8394
npm set "//registry.npmjs.org/:_authToken=$NPM_TOKEN"
8495
npm publish
8596
```
97+
98+
#### Housekeeping
99+
100+
- [ ] publish release notes with a link to the GitHub release on the forum in a new locked topic (use edit release on GitHub to copy the content with Markdown syntax)
101+
- [ ] close all issues with label `ready (coming with next release)` in both repositories

0 commit comments

Comments
 (0)