ci: automate release publication - #70
Merged
Merged
Conversation
Niicolaa
pushed a commit
to Niicolaa/bumblebee
that referenced
this pull request
Aug 20, 2026
moritzdagee
added a commit
to moritzdagee/bumblebee
that referenced
this pull request
Sep 23, 2026
….2.0) (#12) * feat(threat_intel): add GlassWorm exposure catalog (perplexityai#51) Co-authored-by: Perplexity Computer <computer@perplexity.ai> * feat(threat_intel): add Mastra npm supply-chain exposure catalog (perplexityai#57) * feat(threat_intel): add Mastra npm supply-chain exposure catalog * refactor(threat_intel): drop non-schema _indicators from Mastra catalog --------- Co-authored-by: adel-pplx <254727879+adel-pplx@users.noreply.github.com> * feat(threat_intel): add Mini Shai-Hulud / Miasma LeoPlatform exposure catalog (perplexityai#60) Co-authored-by: adel-pplx <254727879+adel-pplx@users.noreply.github.com> * feat(exposure): add any-version ("*") catalog entries in schema v0.2.0 A catalog entry may declare versions ["*"] to match every version of its package. tools/osvcatalog emits ["*"] for OSV affected entries whose ranges declare all versions affected (a single introduced:"0" SEMVER/ECOSYSTEM event) instead of dropping them, raising npm malicious-package coverage from ~8% to ~96% of the OSV corpus. v0.1.0 catalogs are still accepted; they cannot use "*". Fixes perplexityai#64 * chore(threat_intel): bump shipped catalogs to schema_version 0.2.0 All threat_intel catalogs and the embedded selftest catalog now declare 0.2.0, so they can be merged in one --exposure-catalog directory with generated v0.2.0 catalogs (the loader requires a uniform schema_version per directory). Entry content is unchanged; two trapdoor comments referencing "the v0.1 schema enum" are made version-neutral. * perf(walk): one stat per directory, basename-indexed exclude matching (perplexityai#69) The symlink-check Lstat result now feeds the dev+inode loop guard, so each directory costs one stat syscall instead of two. Excludes are indexed by last path component: single-component entries match by basename lookup, multi-component entries pay a suffix comparison only when the directory name already matches. Output unchanged; prior walker contracts pinned by new tests. * ci: automate release publication (perplexityai#70) * docs(changelog): Upstream-Zusammenfuehrung bis d76e369 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: adel <adel.karimishiraz@perplexity.ai> Co-authored-by: Perplexity Computer <computer@perplexity.ai> Co-authored-by: adel-pplx <254727879+adel-pplx@users.noreply.github.com> Co-authored-by: ronheichman <ron.heichman@perplexity.ai> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Add an Actions-driven release path that validates a SemVer tag, creates it from
main, and verifies the release source before GoReleaser runs. Remove draft-only publishing so the workflow completes the release without a manual publication step.Tests
The release job now runs module tidiness, vet, race tests, and the Bumblebee self-test before publishing.
Checks