This repository releases in lockstep: one tag covers every action in it.
vX.Y.Z— an immutable, signed, annotated tag per release. Semantic versioning applies to the repository as a whole: a breaking change to any action's inputs or behaviour is a major bump.v1— a moving major tag, retargeted to the latestv1.x.xon every release. Consumers pinning@v1pick up fixes automatically.
Consumers choose their trade-off:
- uses: owncloud/actions/<name>@v1 # convenient
- uses: owncloud/actions/<name>@0000000000000000000000000000000000000000 # immutableAccepted trade-off: because releases are lockstep, a fix to one action bumps the
version for all of them. That is deliberate for a curated organisation toolkit — it
keeps one release cadence, one changelog and one governance surface. If an action ever
genuinely needs independent semver, promote it into its own owncloud/action-<name>
repository.
-
Make sure the default branch is green and every action has a passing self-test.
-
For any JavaScript action, rebuild and commit its
dist/before tagging — GitHub runs the committed bundle, not the sources. (Composite actions have no build step; prefer them.) -
Create the signed, annotated version tag on the release commit:
git tag -s v1.2.0 -m "v1.2.0" git push origin v1.2.0 -
Retarget the moving major tag:
git tag -f -s v1 -m "v1 -> v1.2.0" git push --force origin v1 -
Publish a GitHub Release for
v1.2.0with notes describing, per action, what changed and whether consumers must act.
- Tags must be signed — the organisation's branch policy requires signatures, and a release tag is part of the history consumers trust.
- The moving
v1tag is the only force-push this repository performs. It is expected and only ever moves forward within the same major version. - Publishing to the GitHub Marketplace is not possible from this repository: a
Marketplace listing needs a single
action.ymlat the repository root, and there is none by design. A flagship action that should be publicly discoverable gets a thinowncloud/action-<name>repository whose rootaction.ymldelegates here, so the logic stays single-sourced.