chore: harden repo automation for public release

This commit is contained in:
xixu-me committed 2026-04-11 14:49:02 +08:00
1 parent f55c48d639
commit 8b7c333a5f
8 files changed
+155 -21

No files matched your search

+45
View File
@@ -0,0 +1,45 @@
version: 2
updates:
- package-ecosystem: "bun"
directory: "/"
schedule:
interval: "weekly"
day: "monday"
time: "09:00"
timezone: "Asia/Shanghai"
open-pull-requests-limit: 5
labels:
- "dependencies"
commit-message:
prefix: "chore"
include: "scope"
groups:
bun-minor-patch:
update-types:
- "minor"
- "patch"
patterns:
- "*"
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "weekly"
day: "monday"
time: "09:30"
timezone: "Asia/Shanghai"
open-pull-requests-limit: 3
labels:
- "dependencies"
- "github-actions"
commit-message:
prefix: "ci"
include: "scope"
groups:
github-actions-minor-patch:
update-types:
- "minor"
- "patch"
patterns:
- "*"
+58
View File
@@ -0,0 +1,58 @@
name: Auto Merge
on:
pull_request_target:
types:
- opened
- synchronize
- reopened
- ready_for_review
- labeled
- unlabeled
permissions:
contents: write
pull-requests: write
concurrency:
group: auto-merge-${{ github.event.pull_request.number }}
cancel-in-progress: true
jobs:
enable-auto-merge:
if: >
github.event.pull_request.draft == false &&
github.event.pull_request.base.ref == 'main' &&
contains(github.event.pull_request.labels.*.name, 'dependencies') &&
(
github.event.pull_request.head.repo.full_name == github.repository ||
github.event.pull_request.user.login == 'dependabot[bot]'
)
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- name: Enable GitHub auto-merge
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
PR_URL: ${{ github.event.pull_request.html_url }}
run: gh pr merge --auto --squash "$PR_URL"
disable-auto-merge:
if: >
github.event.action == 'unlabeled' &&
github.event.label.name == 'dependencies' &&
github.event.pull_request.base.ref == 'main' &&
(
github.event.pull_request.head.repo.full_name == github.repository ||
github.event.pull_request.user.login == 'dependabot[bot]'
)
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- name: Disable GitHub auto-merge
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
PR_URL: ${{ github.event.pull_request.html_url }}
run: gh pr merge --disable-auto "$PR_URL"
+4
View File
@@ -12,6 +12,7 @@ permissions:
jobs: jobs:
validate: validate:
runs-on: ubuntu-latest runs-on: ubuntu-latest
timeout-minutes: 15
steps: steps:
- name: Check out repository - name: Check out repository
@@ -25,6 +26,9 @@ jobs:
- name: Install dependencies - name: Install dependencies
run: bun install --frozen-lockfile run: bun install --frozen-lockfile
- name: Generate Worker types
run: bun run cf-typegen
- name: Type check - name: Type check
run: bun run typecheck run: bun run typecheck
+5 -3
View File
@@ -15,7 +15,9 @@ concurrency:
jobs: jobs:
deploy: deploy:
if: ${{ secrets.CLOUDFLARE_API_TOKEN != '' && secrets.CLOUDFLARE_ACCOUNT_ID != '' }}
runs-on: ubuntu-latest runs-on: ubuntu-latest
timeout-minutes: 20
env: env:
CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }} CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
@@ -33,11 +35,11 @@ jobs:
- name: Install dependencies - name: Install dependencies
run: bun install --frozen-lockfile run: bun install --frozen-lockfile
- name: Generate Worker types
run: bun run cf-typegen
- name: Validate before deploy - name: Validate before deploy
run: bun run check run: bun run check
- name: Verify Wrangler dry-run build
run: bunx wrangler deploy --dry-run
- name: Deploy Worker - name: Deploy Worker
run: bun run deploy run: bun run deploy
+1
View File
@@ -2,6 +2,7 @@ node_modules/
.wrangler/ .wrangler/
coverage/ coverage/
dist/ dist/
worker-configuration.d.ts
.dev.vars .dev.vars
.env .env
.DS_Store .DS_Store
+4 -4
View File
@@ -8,11 +8,11 @@
"@getpaseo/relay": "^0.1.52", "@getpaseo/relay": "^0.1.52",
}, },
"devDependencies": { "devDependencies": {
"@cloudflare/vitest-pool-workers": "^0.8.40", "@cloudflare/vitest-pool-workers": "^0.8.71",
"@types/node": "^24.3.0", "@types/node": "^24.12.2",
"typescript": "^5.9.2", "typescript": "^5.9.3",
"vitest": "^3.2.4", "vitest": "^3.2.4",
"wrangler": "^4.39.0", "wrangler": "^4.81.1",
}, },
}, },
}, },
+15 -7
View File
@@ -1,13 +1,21 @@
{ {
"name": "paseo-relay", "name": "paseo-relay",
"version": "0.1.0",
"private": true, "private": true,
"license": "MIT",
"type": "module", "type": "module",
"repository": {
"type": "git",
"url": "https://github.com/xixu-me/paseo-relay.git"
},
"bugs": {
"url": "https://github.com/xixu-me/paseo-relay/issues"
},
"homepage": "https://github.com/xixu-me/paseo-relay",
"scripts": { "scripts": {
"dev": "bunx wrangler dev", "dev": "bunx wrangler dev",
"deploy": "bunx wrangler deploy", "deploy": "bunx wrangler deploy",
"check": "bun run typecheck && bun run test && bun run cf-typegen:check", "check": "bun run typecheck && bun run test && bun run cf-typegen:check && bunx wrangler deploy --dry-run",
"typecheck": "tsc --noEmit", "typecheck": "bun run cf-typegen && tsc --noEmit",
"test": "vitest run", "test": "vitest run",
"test:watch": "vitest", "test:watch": "vitest",
"cf-typegen": "bunx wrangler types", "cf-typegen": "bunx wrangler types",
@@ -17,11 +25,11 @@
"@getpaseo/relay": "^0.1.52" "@getpaseo/relay": "^0.1.52"
}, },
"devDependencies": { "devDependencies": {
"@cloudflare/vitest-pool-workers": "^0.8.40", "@cloudflare/vitest-pool-workers": "^0.8.71",
"@types/node": "^24.3.0", "@types/node": "^24.12.2",
"typescript": "^5.9.2", "typescript": "^5.9.3",
"vitest": "^3.2.4", "vitest": "^3.2.4",
"wrangler": "^4.39.0" "wrangler": "^4.81.1"
}, },
"packageManager": "bun@1.3.12" "packageManager": "bun@1.3.12"
} }
+23 -7
View File
@@ -3,21 +3,37 @@
"name": "paseo-relay", "name": "paseo-relay",
"main": "src/index.ts", "main": "src/index.ts",
"compatibility_date": "2026-04-11", "compatibility_date": "2026-04-11",
"workers_dev": false,
"alias": { "alias": {
"@getpaseo/relay/cloudflare": "./node_modules/@getpaseo/relay/dist/cloudflare-adapter.js" "@getpaseo/relay/cloudflare": "./node_modules/@getpaseo/relay/dist/cloudflare-adapter.js",
}, },
"durable_objects": { "durable_objects": {
"bindings": [ "bindings": [
{ {
"name": "RELAY", "name": "RELAY",
"class_name": "RelayDurableObject" "class_name": "RelayDurableObject",
} },
] ],
}, },
"migrations": [ "migrations": [
{ {
"tag": "v1", "tag": "v1",
"new_sqlite_classes": ["RelayDurableObject"] "new_sqlite_classes": ["RelayDurableObject"],
} },
] ],
"observability": {
"enabled": true,
"head_sampling_rate": 1,
"logs": {
"enabled": true,
"head_sampling_rate": 1,
"persist": true,
"invocation_logs": true,
},
"traces": {
"enabled": true,
"persist": true,
"head_sampling_rate": 1,
},
},
} }