Skip to content

Commit 2fb1fc4

Browse files
2403905mklos-kwmzner
authored
[full-ci] Release 8.1.0 (#12498)
* chore: release 8.1.0-rc.2 * fix: skip docker jobs * chore: update changelog * chore: bump version to 12.4.2 * fix: changelog titles too long * feat: ci, changelog lint * fix: fixed the empty mount ID for storage-users (#12492) * fix: fixed the empty mount ID for storage-users * bump deps * Release 8.1.0 * feat: translations * chore: backport trivy scan --------- Co-authored-by: Michal Klos <michal.klos@kiteworks.com> Co-authored-by: Matteo <matteo.sonnenholzner@kiteworks.com>
1 parent 2094b03 commit 2fb1fc4

158 files changed

Lines changed: 1707 additions & 155 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.github/workflows/acceptance-tests.yml‎

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -41,6 +41,7 @@ jobs:
4141
make govulncheck > /tmp/govulncheck.log 2>&1 & PIDS+=($!)
4242
make ci-node-generate > /tmp/node-gen.log 2>&1 & PIDS+=($!)
4343
make ci-go-generate > /tmp/go-gen.log 2>&1 & PIDS+=($!)
44+
make changelog-lint > /tmp/changelog-lint.log 2>&1 & PIDS+=($!)
4445
4546
FAILED=0
4647
for PID in "${PIDS[@]}"; do wait "$PID" || FAILED=1; done
@@ -63,9 +64,19 @@ jobs:
6364
echo "=== govulncheck ===" && cat /tmp/govulncheck.log
6465
echo "=== ci-node-generate ===" && cat /tmp/node-gen.log
6566
echo "=== ci-go-generate ===" && cat /tmp/go-gen.log
67+
echo "=== changelog-lint ===" && cat /tmp/changelog-lint.log
6668
6769
exit $FAILED
6870
71+
- name: Trivy scan
72+
uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 # v0.35.0
73+
with:
74+
scan-type: fs
75+
format: table
76+
exit-code: 1
77+
severity: CRITICAL,HIGH
78+
trivy-config: .trivy.yaml
79+
6980
- name: Build, lint and test
7081
run: |
7182
# Phase 2 — all three are CPU-bound Go compilation on 2 vCPU.

‎.github/workflows/release.yml‎

Lines changed: 16 additions & 34 deletions
Original file line numberDiff line numberDiff line change
@@ -4,14 +4,12 @@ on:
44
push:
55
tags:
66
- 'v*'
7-
branches:
8-
- 'feat/release-pipeline**'
97
workflow_dispatch:
108
inputs:
119
version_override:
12-
description: 'Version override (leave empty to auto-detect from latest tag)'
10+
description: 'Version (required, e.g. 8.1.0-rc.3)'
1311
type: string
14-
default: ''
12+
required: true
1513

1614
env:
1715
PRODUCTION_RELEASE_TAGS: '5.0,7,8'
@@ -29,33 +27,10 @@ jobs:
2927
is_prerelease: ${{ steps.info.outputs.is_prerelease }}
3028
docker_repos: ${{ steps.info.outputs.docker_repos }}
3129
steps:
32-
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
33-
if: ${{ github.ref_type == 'branch' || (github.event_name == 'workflow_dispatch' && inputs.version_override == '') }}
34-
with:
35-
fetch-depth: 0
36-
fetch-tags: true
37-
3830
- id: info
3931
run: |
40-
next_dev() {
41-
# If latest tag is already a pre-release (e.g. v8.0.2-dev.1), reuse its base
42-
# version (8.0.2-dev.1) so repeated branch runs don't bump the patch counter.
43-
# If latest tag is a production release (e.g. v8.0.1), increment patch (8.0.2-dev.1).
44-
local tag=$(git tag --sort=-version:refname | grep -m1 '^v' || echo "v0.0.0")
45-
local ver="${tag#v}"
46-
if [[ "$ver" == *"-"* ]]; then
47-
echo "${ver%%-*}-dev.1"
48-
else
49-
IFS='.' read -r M m p <<< "$ver"
50-
echo "${M}.${m}.$((p + 1))-dev.1"
51-
fi
52-
}
53-
5432
if [[ "${{ github.event_name }}" == "workflow_dispatch" ]]; then
5533
VERSION="${{ inputs.version_override }}"
56-
[[ -z "$VERSION" ]] && VERSION=$(next_dev)
57-
elif [[ "${{ github.ref_type }}" == "branch" ]]; then
58-
VERSION=$(next_dev)
5934
else
6035
VERSION="${GITHUB_REF#refs/tags/v}"
6136
fi
@@ -112,6 +87,7 @@ jobs:
11287
retention-days: 1
11388

11489
docker-build:
90+
if: false
11591
name: docker-build (${{ matrix.arch }}, ${{ matrix.repo }})
11692
runs-on: ${{ matrix.arch == 'amd64' && 'ubuntu-24.04' || 'ubuntu-24.04-arm' }}
11793
needs: [determine-release-type, generate-code, security-scan-trivy]
@@ -217,6 +193,7 @@ jobs:
217193
exit 1
218194
219195
docker-manifest:
196+
if: false
220197
name: docker-manifest (${{ matrix.repo }})
221198
runs-on: ubuntu-latest
222199
needs: [determine-release-type, docker-build, docker-scan]
@@ -242,6 +219,7 @@ jobs:
242219
"${{ matrix.repo }}:${{ needs.determine-release-type.outputs.version }}-linux-arm64"
243220
244221
docker-readme:
222+
if: false
245223
name: docker-readme (${{ matrix.repo }})
246224
runs-on: ubuntu-latest
247225
needs: [determine-release-type, docker-manifest]
@@ -333,7 +311,15 @@ jobs:
333311
with:
334312
go-version-file: go.mod
335313
- run: |
336-
make changelog CHANGELOG_VERSION=$(echo "${{ needs.determine-release-type.outputs.version }}" | cut -d'-' -f1)
314+
VERSION="${{ needs.determine-release-type.outputs.version }}"
315+
# For prereleases (e.g. 8.1.0-rc.2), pass the full version so calens finds
316+
# changelog/8.1.0-rc.2_*/ rather than falling through to the missing 8.1.0_*/ dir.
317+
if [[ "$VERSION" == *-* ]]; then
318+
CHANGELOG_VERSION="$VERSION"
319+
else
320+
CHANGELOG_VERSION=$(echo "$VERSION" | cut -d'-' -f1)
321+
fi
322+
make changelog CHANGELOG_VERSION="$CHANGELOG_VERSION"
337323
# calens produces empty output when no versioned changelog directory exists (e.g. dev builds).
338324
# Fall back to a pointer to the unreleased entries.
339325
if [[ $(wc -l < ocis/dist/CHANGELOG.md) -lt 5 ]]; then
@@ -347,7 +333,7 @@ jobs:
347333

348334
create-github-release:
349335
runs-on: ubuntu-latest
350-
needs: [determine-release-type, build-binaries, license-check, generate-changelog, security-scan-trivy, docker-readme]
336+
needs: [determine-release-type, build-binaries, license-check, generate-changelog, security-scan-trivy]
351337
steps:
352338
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
353339
with:
@@ -378,10 +364,6 @@ jobs:
378364
needs:
379365
- determine-release-type
380366
- generate-code
381-
- docker-build
382-
- docker-scan
383-
- docker-manifest
384-
- docker-readme
385367
- build-binaries
386368
- security-scan-trivy
387369
- license-check
@@ -405,7 +387,7 @@ jobs:
405387
python3 scripts/audit-release.py \
406388
--version "${{ needs.determine-release-type.outputs.version }}" \
407389
--dir release-assets/ \
408-
--github-release --docker
390+
--github-release
409391
env:
410392
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
411393

‎Makefile‎

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -328,6 +328,17 @@ endif
328328
mkdir -p ocis/dist
329329
$(CALENS) --version $(CHANGELOG_VERSION) -o ocis/dist/CHANGELOG.md
330330

331+
.PHONY: changelog-lint
332+
changelog-lint:
333+
@FAILED=0; \
334+
while IFS= read -r -d '' f; do \
335+
title=$$(head -1 "$$f"); \
336+
if [ $${#title} -gt 80 ]; then \
337+
echo "$$f: title too long ($${#title}/80)"; FAILED=1; \
338+
fi; \
339+
done < <(find changelog -mindepth 2 -name "*.md" -print0); \
340+
exit $$FAILED
341+
331342
.PHONY: changelog-csv
332343
changelog-csv: $(CALENS)
333344
mkdir -p ocis/dist
Lines changed: 1 addition & 1 deletion

‎changelog/2.0.0_2022-11-30/spaces-capabilities.md‎

Lines changed: 1 addition & 1 deletion

changelog/8.1.0-rc.1_2026-05-22/add-space-editor-without-versions-without-trashbin-role.md renamed to changelog/8.1.0_2026-07-03/add-space-editor-without-versions-without-trashbin-role.md

changelog/8.1.0-rc.1_2026-05-22/add-vault-mode-permission.md renamed to changelog/8.1.0_2026-07-03/add-vault-mode-permission.md

changelog/8.1.0-rc.1_2026-05-22/bugfix-dont-index-failed-uploads.md renamed to changelog/8.1.0_2026-07-03/bugfix-dont-index-failed-uploads.md

0 commit comments

Comments
 (0)