dependabot[bot] and GitHub
7cab05d58f
Bump goreleaser/goreleaser-action from 7.1.0 to 7.2.2
...
Bumps [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action ) from 7.1.0 to 7.2.2.
- [Release notes](https://github.com/goreleaser/goreleaser-action/releases )
- [Commits](https://github.com/goreleaser/goreleaser-action/compare/e24998b8b67b290c2fa8b7c14fcfa7de2c5c9b8c...5daf1e915a5f0af01ddbcd89a43b8061ff4f1a89 )
---
updated-dependencies:
- dependency-name: goreleaser/goreleaser-action
dependency-version: 7.2.2
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-05-26 08:04:40 +00:00
dependabot[bot] and GitHub
972dd19d0e
Bump actions/github-script from 8 to 9
...
Bumps [actions/github-script](https://github.com/actions/github-script ) from 8 to 9.
- [Release notes](https://github.com/actions/github-script/releases )
- [Commits](https://github.com/actions/github-script/compare/v8...v9 )
---
updated-dependencies:
- dependency-name: actions/github-script
dependency-version: '9'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-26 17:58:44 +00:00
dependabot[bot] and GitHub
1e66ec08bd
Bump goreleaser/goreleaser-action from 7.0.0 to 7.1.0
...
Bumps [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action ) from 7.0.0 to 7.1.0.
- [Release notes](https://github.com/goreleaser/goreleaser-action/releases )
- [Commits](https://github.com/goreleaser/goreleaser-action/compare/ec59f474b9834571250b370d4735c50f8e2d1e29...e24998b8b67b290c2fa8b7c14fcfa7de2c5c9b8c )
---
updated-dependencies:
- dependency-name: goreleaser/goreleaser-action
dependency-version: 7.1.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-26 17:55:35 +00:00
dependabot[bot] and GitHub
6500e75921
Bump peter-evans/create-pull-request from 8.1.0 to 8.1.1
...
Bumps [peter-evans/create-pull-request](https://github.com/peter-evans/create-pull-request ) from 8.1.0 to 8.1.1.
- [Release notes](https://github.com/peter-evans/create-pull-request/releases )
- [Commits](https://github.com/peter-evans/create-pull-request/compare/c0f553fe549906ede9cf27b5156039d195d2ece0...5f6978faf089d4d20b00c7766989d076bb2fc7f1 )
---
updated-dependencies:
- dependency-name: peter-evans/create-pull-request
dependency-version: 8.1.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-26 17:51:58 +00:00
Ubuntu
4caee0886b
fix: yaml.github-actions.security.run-shell-injection.run-shell-injection security vulnerability
...
Automated security fix generated by Orbis Security AI
2026-04-08 04:49:26 +00:00
dependabot[bot] and GitHub
ba386fd19c
Bump actions/upload-artifact from 6 to 7
...
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact ) from 6 to 7.
- [Release notes](https://github.com/actions/upload-artifact/releases )
- [Commits](https://github.com/actions/upload-artifact/compare/v6...v7 )
---
updated-dependencies:
- dependency-name: actions/upload-artifact
dependency-version: '7'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-31 11:22:48 +00:00
dependabot[bot] and GitHub
3804dc7ca1
Bump actions/download-artifact from 7 to 8
...
Bumps [actions/download-artifact](https://github.com/actions/download-artifact ) from 7 to 8.
- [Release notes](https://github.com/actions/download-artifact/releases )
- [Commits](https://github.com/actions/download-artifact/compare/v7...v8 )
---
updated-dependencies:
- dependency-name: actions/download-artifact
dependency-version: '8'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-31 11:19:16 +00:00
dependabot[bot] and GitHub
1f41e7d47a
Bump actions/cache from 4 to 5
...
Bumps [actions/cache](https://github.com/actions/cache ) from 4 to 5.
- [Release notes](https://github.com/actions/cache/releases )
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md )
- [Commits](https://github.com/actions/cache/compare/v4...v5 )
---
updated-dependencies:
- dependency-name: actions/cache
dependency-version: '5'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-31 11:16:15 +00:00
Stefan Haller
82ff9495ed
Update all actions to their newest versions
2026-03-31 11:40:49 +02:00
dagecko and Stefan Haller
35db80f150
fix: pin 7 unpinned action(s) to commit SHAs
2026-03-31 10:27:07 +02:00
dagecko and Stefan Haller
821a2809a8
fix: extract inline secret from run block in ci.yml
2026-03-31 10:27:07 +02:00
Stefan Haller
bdc780a890
Disable the automatic, scheduled release
...
There's too much manual work involved in releasing now (updating translations,
copying docs-master) to make automatic releases infeasible. I'm not worried that
I forget to release on the first Saturday of every month.
Keeping the code commented out in case we want to re-enable it at some point.
2026-02-06 19:36:58 +01:00
Padraic Slattery and Stefan Haller
3d78263e0c
chore: Update outdated GitHub Actions versions
2026-01-24 16:26:11 +01:00
Stefan Haller
6ab40df429
Add a check to the release workflow to abort if docs or schema are not up to date
...
Of course it would be cooler if the workflow could create the PR and merge it if
necessary, but this will have to do for now.
2025-11-12 08:44:56 +01:00
kyu08
76948f82c1
Add synchronize event to the hooks of "Check Required Labels"
2025-10-19 22:12:23 +09:00
kyu08 and Stefan Haller
93b8d70209
Update go to 1.25
2025-10-05 10:17:03 +02:00
kyu08 and Stefan Haller
47b1ededf3
Bump golangci-lint to v.2.4.0 from v2.2.1
2025-10-05 10:17:03 +02:00
kyu08 and Stefan Haller
e932ea24f2
Run label check workflow only on label events and open pr event
2025-08-18 07:40:38 +02:00
Stefan Haller
04c2be826b
Stop bumping our homebrew formula
...
It is being auto-bumped by homebrew, like most formulae these days, so no reason
for us to do that explicitly; and it actually fails with an error message, so
stop trying.
2025-08-06 14:02:23 +02:00
Stefan Haller and kyu08
38fc107f94
Use a better way of pinning the version of golangci-lint
...
Instead of requiring the user to install the right version of the tool in their
.bin folder, create a shim that automatically runs the right version of the
tool. This has several benefits:
- it works out of the box with no setup required (the tool will be automatically
downloaded and compiled the first time it is used)
- no work needed for developers when we bump the golangci-lint version
- it works in working copies that are used in different environments (e.g.
locally on a Mac, or inside a dev container)
Co-authored-by: kyu08 <49891479+kyu08@users.noreply.github.com >
2025-07-18 15:33:23 +02:00
Stefan Haller
e27422f894
Bump minimum required git version to 2.32
...
The version choice is a little arbitrary, but see discussion at
https://github.com/jesseduffield/lazygit/pull/4559#issuecomment-2876201680 .
The main reason why I'm updating the version now is that versions before 2.27
had a bug with branch sorting, where sorting by -committerdate (which will be
our default soon) would sort branches that point at the same commit in reverse
alphabetical order rather than alphabetical order. While this is only slightly
annoying but not a huge deal for users, it makes maintaining our integration
tests across versions very hard. So I wanted to update to at least 2.27 to get
around this problem, and went with 2.32 after the discussion linked to above.
The choice of which versions to run integration tests on is pretty arbitrary
too, I just picked some at random which are about 5 to 6 minor versions apart.
2025-07-09 12:18:57 +02:00
Stefan Haller
05d1a7a804
Make it run at 8am instead of in the middle of the night
...
This gives me a chance to react if necessary, e.g. by tweaking the release
notes, or by deleting it again if something went wrong.
2025-07-06 12:08:25 +02:00
Stefan Haller
db3a23a11c
Create annotated tags
...
They are preferable over lightweight tags because they carry information about
who created them, and when.
2025-07-06 12:08:25 +02:00
Stefan Haller
f735c6af17
Make the release workflow run only from stefanhaller's fork
...
As far as I can tell, this is the only way to make sure that releases show up as
created by me. Also, we totally don't want it to run in other people's forks
(although it would likely just have failed there, but still).
The restriction only applies to scheduled runs; manually triggering the action
is still possible from everywhere. There needs to be a personal access token
named LAZYGIT_RELEASE_PAT configured on the repo for this to work, though.
2025-07-06 12:08:25 +02:00
Stefan Haller
7ef8385f2e
Set a default shell for all jobs
...
Setting the shell to 'bash' turns on -e and -o pipefail, both of which are very
desirable to have.
https://github.com/actions/runner-images/issues/4459#issuecomment-965290856
2025-07-06 11:59:02 +02:00
Stefan Haller
2659a8cd90
Update goreleaser to v2
2025-07-06 11:59:02 +02:00
Jesse Duffield
cea7d1b4d0
Remove redundant curlies
2025-07-06 19:54:31 +10:00
Jesse Duffield
878f762b6f
Properly use sponsors PR token
2025-07-06 19:43:00 +10:00
Jesse Duffield
955d4dd80c
Use fine-grained sponsors PR token
...
This uses a fine-grained token
2025-07-06 19:38:29 +10:00
Jesse Duffield
7753659c2a
Try using PAT on sponsors CI
2025-07-06 19:28:15 +10:00
Stefan Haller
f80860f8db
Update the peter-evans/create-pull-request action to v7
...
This is needed for the draft: always-true setting.
2025-07-06 11:00:55 +02:00
Stefan Haller
48c3f347ce
Move if to job level so that the entire thing doesn't run in forks
2025-07-06 10:51:46 +02:00
Jesse Duffield
80da133a1a
Raise sponsors PRs as a draft
...
See
https://github.com/peter-evans/create-pull-request/blob/main/docs/concepts-guidelines.md#workarounds-to-trigger-further-workflow-runs
2025-07-06 18:42:20 +10:00
Stefan Haller
c4de94cff0
Update .golangci.yml to use version 2
...
The config file was migrated using `golangci-lint migrate`, and then edited by
hand to disable a few checks that we don't want.
2025-06-30 18:30:11 +02:00
Jesse Duffield
b353d2a55a
Allow closing issues via github actions
...
This provides some basic admin permissions without needing to go all the
way up to a collaborator.
2025-04-26 14:42:21 +10:00
Jesse Duffield
f7eb9113f3
Skip date check when release worfklow is manually invoked
2025-04-14 18:24:45 +10:00
Stefan Haller
ad813503fb
Bump minimum required git version to 2.22
...
Versions older than 2.22 have issues with "git cherry-pick --continue" and
"git cherry-pick --skip" that are difficult to work around.
2025-04-09 10:40:52 +02:00
Kevin Radloff
be7583dd40
Update to go 1.24
2025-03-08 14:53:54 -05:00
Stefan Haller
f7fd5217cb
Fix release schedule again
...
There's no way to tell cron to run a job on the first Saturday of a month, so we
tell it to run every Saturday, and manually check whether it's the first week of
the month. This is not ideal because we'll get notifications about failed
releases three times a month, but it's better than nothing for now.
2025-03-06 10:04:15 +01:00
Jesse Duffield
471f72e607
Fix release script once again
2025-02-25 22:18:59 +11:00
Jesse Duffield
f5cd02b54f
Fix release script
2025-02-25 22:07:11 +11:00
Jesse Duffield
fcf48c4f08
Improve release workflow
...
1) the cron schedule was wrong: it was doing every saturday, rather than
the first saturday of each month.
2) It wasn't triggering a deploy despite pushing a tag because clearly
github doesn't want that to happen.
Now it triggers a deploy, and it also allows triggering from the UI,
letting you specify minor/patch bump and whether to ignore blocking
PRs/issues. As such I'm removing support for the old method of pushing
the tag. The new way is the only way.
2025-02-24 07:18:45 +11:00
Jesse Duffield
a81f9ea97c
Fix auto-release schedule
...
It was previously on each saturday
2025-02-22 23:03:42 +11:00
Jesse Duffield
57220ba478
Use personal access token to push tag
...
Github actions refuses to trigger a workflow from another workflow, but
if you use your own personal access token (in this case,
GITHUB_API_TOKEN), it should work.
2025-02-15 15:54:47 +11:00
Jesse Duffield
269d89ea51
Fix issue where latest tag wasn't obtained early enough in auto-release script
2025-02-15 15:36:54 +11:00
Jesse Duffield
977a01172f
Automatically cut release each month
2025-01-11 15:44:00 +11:00
Eng Zer Jun
181b00b758
ci: update upload-artifact and download-artifact actions to v4
...
v3 of `actions/upload-artifact` and `actions/download-artifact` will be
fully deprecated by 5 December 2024. Jobs that are scheduled to run
during the brownout periods will also fail. See [1][2].
[1]: https://github.blog/changelog/2024-04-16-deprecation-notice-v3-of-the-artifact-actions/
[2]: https://github.blog/changelog/2024-11-05-notice-of-breaking-changes-for-github-actions/
Signed-off-by: Eng Zer Jun <engzerjun@gmail.com >
2024-11-16 00:42:08 +08:00
Jesse Duffield
0d633896ae
Add performance improvements section to release notes
2024-09-18 21:06:02 +10:00
Yaroslav Halchenko and Stefan Haller
56be1a4950
Add github action to codespell master on push and PRs
...
Signed-off-by: Yaroslav Halchenko <debian@onerussian.com >
2024-08-27 18:03:00 +02:00
Stefan Haller
457c4c248d
Upgrade golangci-lint-action to latest version
2024-08-27 10:33:06 +02:00