Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

semver release tags #307

Closed
thepwagner opened this issue Nov 17, 2020 · 3 comments
Closed

semver release tags #307

thepwagner opened this issue Nov 17, 2020 · 3 comments

Comments

@thepwagner
Copy link

Would it be possible to start tagging semver-compatible releases?

We follow GitHub's best practice of pinning our Actions to full length commit SHAs.
We use Dependabot version updates to keep our other Actions up to date. This doesn't work with github/codeql-action since there are no released tags.

I think everything would work if there were semver compatible tags (e.g. v1.0.0, v1.1.0 along the v1 branch).

@Mogost
Copy link

Mogost commented Mar 20, 2021

Faced with the same thing.
I don't understand why this hasn't been done yet.

@adityasharad
Copy link
Contributor

Thanks for the feedback. We started creating v1.* tags from May 2021 onwards and have incorporated them into our regular release process. Workflows may continue to use v1 to follow the release branch of this Action, or use a specific v1.* tag (ideally together with Dependabot version updates as @thepwagner suggests).
I'll close this issue, but please feel free to reopen if the release tags aren't working for you, especially with Dependabot.

@aliscco
Copy link

aliscco commented Sep 8, 2021 via email

evverx added a commit to evverx/systemd that referenced this issue Nov 12, 2021
to let Dependabot keep track of them using SHAs

codeql-actions doesn't point to SHAs because it isn't clear
whether Dependabot supports their release cycle mentioned
at github/codeql-action#307
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants