From 4574d990a3b6bae409ec0a13fbb03da920dce897 Mon Sep 17 00:00:00 2001 From: Claire Peng Date: Mon, 24 Aug 2026 01:06:34 +0100 Subject: [PATCH 1/4] fix: update deploy.yaml trigger to be upon release publish, instead of merges to the release branch --- .github/workflows/deploy.yml | 9 +++------ 1 file changed, 3 insertions(+), 6 deletions(-) diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml index 08e8f4ffe5..51450c355b 100644 --- a/.github/workflows/deploy.yml +++ b/.github/workflows/deploy.yml @@ -1,11 +1,8 @@ name: Deploy to production on: - workflow_run: - workflows: ["Test"] - branches: - - release + release: types: - - completed + - published env: PROJECT_ID: ${{ secrets.GKE_PROJECT }} GKE_CLUSTER: p5-gke-cluster @@ -21,7 +18,7 @@ jobs: - name: Check out the repo uses: actions/checkout@v3 with: - ref: release + ref: ${{ github.event.release.tag_name }} - name: Set up Docker Buildx uses: docker/setup-buildx-action@v2 with: From 167d4441c93faba5e977683c959745fac02b9908 Mon Sep 17 00:00:00 2001 From: Claire Peng Date: Sat, 3 Oct 2026 15:04:14 +0100 Subject: [PATCH 2/4] address feedback: run unit tests again on deploy as safetyguard, and only run deploy if the branch is called release --- .github/workflows/deploy.yml | 19 +++++++++++++++++++ .github/workflows/test.yml | 2 +- contributor_docs/release.md | 7 ++++--- 3 files changed, 24 insertions(+), 4 deletions(-) diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml index 51450c355b..332ba679cc 100644 --- a/.github/workflows/deploy.yml +++ b/.github/workflows/deploy.yml @@ -10,7 +10,25 @@ env: DEPLOYMENT_NAME: web-editor-node IMAGE: ${{ secrets.DOCKER_USERNAME }}/p5.js-web-editor jobs: + # Only deploy tags whose commit is on the `release` branch + verify_release_branch: + name: Verify release tag is on the release branch + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v3 + with: + ref: ${{ github.event.release.tag_name }} + fetch-depth: 0 + - run: |- + if ! git merge-base --is-ancestor "$GITHUB_SHA" origin/release; then + echo "::error::Tag ${{ github.event.release.tag_name }} ($GITHUB_SHA) is not on the release branch" + exit 1 + fi + test: + needs: verify_release_branch + uses: ./.github/workflows/test.yml push_to_registry: + needs: test environment: production name: Push Docker image to Docker Hub runs-on: ubuntu-latest @@ -37,6 +55,7 @@ jobs: push: true tags: | ${{ env.IMAGE }}:${{ github.sha }} + ${{ env.IMAGE }}:${{ github.event.release.tag_name }} ${{ env.IMAGE }}:latest target: production # Setup gcloud CLI diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 4a39783065..b9ade4a130 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -1,6 +1,6 @@ name: Test -on: [push, pull_request] +on: [push, pull_request, workflow_call] jobs: test: diff --git a/contributor_docs/release.md b/contributor_docs/release.md index d2e17f5501..d3d4470cb0 100644 --- a/contributor_docs/release.md +++ b/contributor_docs/release.md @@ -24,8 +24,8 @@ This project's release guide is based on: 9. `$ git checkout develop` 10. `$ git merge --no-ff release-` 11. `$ git push origin develop` (Note: tests need to complete before pushing, which you can check the status of in Github Actions) -12. [Draft a new release on Github](https://github.com/processing/p5.js-web-editor/releases/new). Choose the tag that is the release version you just created, and then click "Generate release notes" (the title will be autogenerated as well) and publish the release. -13. Check that Github actions are running. +12. [Draft a new release on Github](https://github.com/processing/p5.js-web-editor/releases/new). Choose the tag that is the release version you just created, and then click "Generate release notes" (the title will be autogenerated as well) and publish the release. **Publishing the release is what triggers the deploy to production.** The "Deploy to production" workflow first checks that the tag is on the `release` branch, then runs the tests, and only deploys if both pass. +13. Check that the "Deploy to production" Github action is running and that all of its jobs pass. 14. `$ kubectl get pods --namespace production` to check the pods are running (this might take a few minutes and you can rerun the command to check again). 15. Validate that [production](https://stagingeditor.p5js.org/) is working and you are finished! @@ -44,7 +44,8 @@ Sometimes you might need to push a release for an isolated and small bug fix wit 9. `$ git checkout develop` 10. `$ git merge --no-ff release-` 11. `$ git push origin develop` -12. [Draft a new release on Github](https://github.com/processing/p5.js-web-editor/releases/new). Choose the tag that is the release version you just created, and then title it `v`. Then click "Generate release notes". Publish the release and you are finished! +12. [Draft a new release on Github](https://github.com/processing/p5.js-web-editor/releases/new). Choose the tag that is the release version you just created, and then title it `v`. Then click "Generate release notes". Publishing the release triggers the deploy to production (which verifies the tag is on `release` and runs the tests before deploying). +13. Check that the "Deploy to production" Github action passes, then validate that production is working and you are finished! ### What if the PR Bug Fix is branched from `develop`? From e8d684aa07c8484cb7bf907b76bb1aa641b9a43a Mon Sep 17 00:00:00 2001 From: Claire Peng Date: Sat, 3 Oct 2026 15:11:53 +0100 Subject: [PATCH 3/4] address feedback: prevent shell command injection --- .github/workflows/deploy.yml | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml index 332ba679cc..9d07458a00 100644 --- a/.github/workflows/deploy.yml +++ b/.github/workflows/deploy.yml @@ -21,9 +21,11 @@ jobs: fetch-depth: 0 - run: |- if ! git merge-base --is-ancestor "$GITHUB_SHA" origin/release; then - echo "::error::Tag ${{ github.event.release.tag_name }} ($GITHUB_SHA) is not on the release branch" + printf '::error::Tag %s (%s) is not on the release branch\n' "$RELEASE_TAG" "$GITHUB_SHA" exit 1 fi + env: + RELEASE_TAG: ${{ github.event.release.tag_name }} test: needs: verify_release_branch uses: ./.github/workflows/test.yml From 7877ed27f5a1e01e4449f06997c00815957e452c Mon Sep 17 00:00:00 2001 From: Claire Peng <128436909+clairep94@users.noreply.github.com> Date: Sat, 3 Oct 2026 15:23:12 +0100 Subject: [PATCH 4/4] Potential fix for pull request finding 'Avoid passing Git release tags with '+' as Docker tags' Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> --- .github/workflows/deploy.yml | 1 - 1 file changed, 1 deletion(-) diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml index 9d07458a00..2d3629c418 100644 --- a/.github/workflows/deploy.yml +++ b/.github/workflows/deploy.yml @@ -57,7 +57,6 @@ jobs: push: true tags: | ${{ env.IMAGE }}:${{ github.sha }} - ${{ env.IMAGE }}:${{ github.event.release.tag_name }} ${{ env.IMAGE }}:latest target: production # Setup gcloud CLI