Releases: github/branch-deploy
v10.2.0
What's Changed
- Update deployment-payload.md by @GrantBirki in #359
- Update .node-version by @GrantBirki in #360
- feat: allow non-default target branch deployments via a new input option by @GrantBirki in #361
Full Changelog: v10.1.0...v10.2.0
v10.1.0
What's Changed
This release adds new attributes to the payload
which gets sent to GitHub's deployment API. These attributes can be used by subsequent systems that might read, parse, or interact with the deployments that this Action creates.
For nearly all users (including users that interact with the payload
attribute), this new version should be a seamless upgrade. Enjoy!
- Node Updates by @GrantBirki in #357
- Deployment Payload Updates by @GrantBirki in #358
Full Changelog: v10.0.2...v10.1.0
v10.0.2
What's Changed
No major changes with this release, just dependency updates 📦
- Workflow Updates by @GrantBirki in #354
- update all node packages with
npm update
by @GrantBirki in #355 - bump it a patch version by @GrantBirki in #356
Full Changelog: v10.0.1...v10.0.2
v10.0.1
What's Changed
- Bump actions/upload-artifact from 4.4.3 to 4.5.0 in the github-actions group by @dependabot in #349
- Bump @types/node from 22.10.1 to 22.10.3 in the npm-dependencies group by @dependabot in #350
- Remove maintain permissions by @VOVELEE in #351 (only
read
,write
, andadmin
were ever actually valid) - bump release version to v10.0.1 by @GrantBirki in #353
New Contributors
Full Changelog: v10...v10.0.1
v10.0.0
v10.0.0
v10 of the github/branch-deploy Action is focused around safety, security, and usability improvements 🚀
BREAKING
Please note that even though there are breaking changes listed, the vast majority of users should be able to simply upgrade to
github/branch-deploy@v10
without any issues
- The
checks
input option can now be used with a comma separated list of CI checks if you only want certain checks to be considered "blocking" in terms of deployments. Read more here. - Pull requests in the
CHANGES_REQUESTED
state are now treated the same as PRs in theREVIEW_REQUIRED
state. - The structure and content of the pre/post deployment messages (that get written to PRs) has changed to contain more rich information. This isn't really a breaking change, but it could be if you are parsing these comments in some way.
- The deployment payload that gets set to the GitHub API will now contain two new attributes:
params
andparsed_params
- By default, you can no longer
.deploy
or.noop
a pull request fork unless it has approvals - reference. These changes have been made as an extra safety check against potentially untrusted commits - You will no longer be able to deploy a pull request if the target branch is not the default branch - reference1 reference2
Key Changes
- You should use
${{ steps.branch-deploy.outputs.sha }}
everywhere instead of${{ steps.branch-deploy.outputs.ref }}
- documentation - The structure of the deployment payload that gets sent to the GitHub API has a few new attributes - documentation
- You can now have fine grained control to include or ignore CI checks that can (or can't) block your deployments - documentation
- The message rendering system for pre/post deployment messages has been greatly improved. It now has many more variables for custom deployment messages and the default structures have been updated a bit - PR reference
- A new input option has been added
commit_verification: true
that enforces commits to be signed/verified before they can be deployed by this Action - PR reference - A lot of new outputs have been added so subsequent workflow steps have access to even more rich data related to deployments
- Preventing the ability to deploy a pull request that is not targeting the default branch
- Branch ruleset warning checks - If you have a potential security misconfiguration in your branch rulesets, this Action will loudly warn you about it in the deployment logs
- The
sha
output is now available on "Merge commit strategy" deployments as well
What's Changed
Here is a full list of changes:
- Docs updates about
.noop
by @caridinL6 in #324 - Store params and parsed params into deployment payload by @fabn in #325
- Bump the npm-dependencies group with 2 updates by @dependabot in #326
- update all node packages with
npm update
by @GrantBirki in #327 - Commit Improvements by @GrantBirki in #328
- General Fixes + Dependency Updates by @GrantBirki in #329
- Change docs around
ref
to point tosha
by @GrantBirki in #330 - Fork Deployment Safety 🔒 by @GrantBirki in #331
- Improved Messaging by @GrantBirki in #332
- Commit Verification 🔒 by @GrantBirki in #333
- API Version Headers by @GrantBirki in #334
total_seconds
- Output Variable by @GrantBirki in #335- node package updates by @GrantBirki in #336
- feat:
ignored_checks
by @GrantBirki in #337 - General Fixes + More Logging by @GrantBirki in #338
- feat: respect
CHANGES_REQUESTED
approval state by @GrantBirki in #339 - feat: prevent deployment when the target branch is not the default branch by @GrantBirki in #341
- Branch Ruleset Checks by @GrantBirki in #342
- General Cleanup + SHA outputs for merge deploy mode by @GrantBirki in #343
- Unlock on Merge branch check improvements by @GrantBirki in #344
- bug: Branch Ruleset API call fails when a user/org doesn't have the ruleset feature by @GrantBirki in #345
- Improve commit verification failure text by @GrantBirki in #346
New Contributors
- @caridinL6 made their first contribution in #324
Full Changelog: v9.10.0...v10.0.0
v10.0.0-rc.1
v10.0.0-rc.1 (⚠️ this is a release candidate)
Do not use this release unless you want to live on the edge
BREAKING
Please note that even though there are breaking changes listed, the vast majority of users should be able to simply upgrade to
github/branch-deploy@v10
without any issues
- The
checks
input option can now be used with a comma separated list of CI checks if you only want certain checks to be considered "blocking" in terms of deployments. Read more here. - Pull requests in the
CHANGES_REQUESTED
state are now treated the same as PRs in theREVIEW_REQUIRED
state. - The structure and content of the pre/post deployment messages (that get written to PRs) has changed to contain more rich information. This isn't really a breaking change, but it could be if you are parsing these comments in some way.
- The deployment payload that gets set to the GitHub API will now contain two new attributes:
params
andparsed_params
- By default, you can no longer
.deploy
or.noop
a pull request fork unless it has approvals - reference. These changes have been made as an extra safety check against potentially untrusted commits - You will no longer be able to deploy a pull request if the target branch is not the default branch - reference1 reference2
Key Changes
- You should use
${{ steps.branch-deploy.outputs.sha }}
everywhere instead of${{ steps.branch-deploy.outputs.ref }}
- documentation - The structure of the deployment payload that gets sent to the GitHub API has a few new attributes - documentation
- You can now have fine grained control to include or ignore CI checks that can (or can't) block your deployments - documentation
- The message rendering system for pre/post deployment messages has been greatly improved. It now has many more variables for custom deployment messages and the default structures have been updated a bit - PR reference
- A new input option has been added
commit_verification: true
that enforces commits to be signed/verified before they can be deployed by this Action - PR reference - A lot of new outputs have been added so subsequent workflow steps have access to even more rich data related to deployments
- Preventing the ability to deploy a pull request that is not targeting the default branch
- Branch ruleset warning checks - If you have a potential security misconfiguration in your branch rulesets, this Action will loudly warn you about it in the deployment logs
- The
sha
output is now available on "Merge commit strategy" deployments as well
What's Changed
Here is a full list of changes:
- Docs updates about
.noop
by @caridinL6 in #324 - Store params and parsed params into deployment payload by @fabn in #325
- Bump the npm-dependencies group with 2 updates by @dependabot in #326
- update all node packages with
npm update
by @GrantBirki in #327 - Commit Improvements by @GrantBirki in #328
- General Fixes + Dependency Updates by @GrantBirki in #329
- Change docs around
ref
to point tosha
by @GrantBirki in #330 - Fork Deployment Safety 🔒 by @GrantBirki in #331
- Improved Messaging by @GrantBirki in #332
- Commit Verification 🔒 by @GrantBirki in #333
- API Version Headers by @GrantBirki in #334
total_seconds
- Output Variable by @GrantBirki in #335- node package updates by @GrantBirki in #336
- feat:
ignored_checks
by @GrantBirki in #337 - General Fixes + More Logging by @GrantBirki in #338
- feat: respect
CHANGES_REQUESTED
approval state by @GrantBirki in #339 - feat: prevent deployment when the target branch is not the default branch by @GrantBirki in #341
- Branch Ruleset Checks by @GrantBirki in #342
- General Cleanup + SHA outputs for merge deploy mode by @GrantBirki in #343
- Unlock on Merge branch check improvements by @GrantBirki in #344
New Contributors
- @caridinL6 made their first contribution in #324
Full Changelog: v9.10.0...v10.0.0-rc.1
v9.10.0
What's Changed
This release contains standard dependency updates and a great new feature to add parsed JSON params as a GitHub Actions output. Thanks to @fabn for this great new feature!
- Add parsed_params output by @fabn in #322
- Bump actions/upload-artifact from 4.4.0 to 4.4.3 in the github-actions group by @dependabot in #317
- Bump the npm-dependencies group across 1 directory with 4 updates by @dependabot in #323
New Contributors
Full Changelog: v9...v9.10.0
v9.9.1
v9.9.0
What's Changed
- #312 Include deployment started comment id in output by @walkerk1980 in #313
- Bump @types/node from 22.6.1 to 22.7.4 in the npm-dependencies group by @dependabot in #309
- Node Package Updates by @GrantBirki in #314
New Contributors
- @walkerk1980 made their first contribution in #313
Full Changelog: v9.8.1...v9.9.0
v9.8.1
What's Changed
A follow-up to the v9.8.0
release to implement GraphQL pagination to make "latest deployment checks" more robust when using enforced deployment order.
- Latest Deployments Pagination by @GrantBirki in #307
- node package updates by @GrantBirki in #308
Full Changelog: v9.8.0...v9.8.1