diff --git a/.github/workflows/auto-merge-dependabot.yml b/.github/workflows/auto-merge-dependabot.yml deleted file mode 100644 index 80e0d71e4f..0000000000 --- a/.github/workflows/auto-merge-dependabot.yml +++ /dev/null @@ -1,17 +0,0 @@ -name: Merge Dependabot PR - -on: - pull_request: - branches: - - main - - '*.x' - - 'docs-build' - -run-name: Merge Dependabot PR ${{ github.ref_name }} - -jobs: - merge-dependabot-pr: - permissions: write-all - uses: spring-io/spring-github-workflows/.github/workflows/spring-merge-dependabot-pr.yml@0d3f15bb384839966a1ff5c4383731a2b747f24b # v7 - with: - mergeArguments: --auto --rebase \ No newline at end of file diff --git a/.github/workflows/check-snapshots.yml b/.github/workflows/check-snapshots.yml deleted file mode 100644 index 2414893011..0000000000 --- a/.github/workflows/check-snapshots.yml +++ /dev/null @@ -1,36 +0,0 @@ -name: CI - -on: - schedule: - - cron: '0 10 * * *' # Once per day at 10am UTC - workflow_dispatch: # Manual trigger - -env: - DEVELOCITY_ACCESS_KEY: ${{ secrets.DEVELOCITY_ACCESS_KEY }} - -permissions: - contents: read - -jobs: - snapshot-test: - name: Test Against Snapshots - uses: spring-io/spring-security-release-tools/.github/workflows/test.yml@b92832ecbc7cbe969201e6beafbde0ee400cf095 # v1.0.15 - strategy: - matrix: - include: - - java-version: 25 - toolchain: 25 - with: - java-version: ${{ matrix.java-version }} - test-args: --refresh-dependencies -PforceMavenRepositories=snapshot,https://oss.sonatype.org/content/repositories/snapshots -PisOverrideVersionCatalog -PtestToolchain=${{ matrix.toolchain }} -PspringFrameworkVersion=7.0.+ -PreactorVersion=2025.+ -PspringDataVersion=2025.+ -PmicrometerVersion=1.+ --stacktrace - secrets: inherit - send-notification: - name: Send Notification - needs: [ snapshot-test ] - if: ${{ !success() }} - runs-on: ubuntu-latest - steps: - - name: Send Notification - uses: spring-io/spring-security-release-tools/.github/actions/send-notification@b92832ecbc7cbe969201e6beafbde0ee400cf095 # v1.0.15 - with: - webhook-url: ${{ secrets.SPRING_SECURITY_CI_GCHAT_WEBHOOK_URL }} diff --git a/.github/workflows/clean_build_artifacts.yml b/.github/workflows/clean_build_artifacts.yml deleted file mode 100644 index c116fac71d..0000000000 --- a/.github/workflows/clean_build_artifacts.yml +++ /dev/null @@ -1,23 +0,0 @@ -name: Clean build artifacts -on: - schedule: - - cron: '0 10 * * *' # Once per day at 10am UTC - -permissions: - contents: read - -jobs: - main: - runs-on: ubuntu-latest - if: ${{ github.repository == 'spring-projects/spring-security' }} - permissions: - contents: none - steps: - - name: Delete artifacts in cron job - env: - GH_ACTIONS_REPO_TOKEN: ${{ secrets.GH_ACTIONS_REPO_TOKEN }} - run: | - echo "Running clean build artifacts logic" - output=$(curl -X GET -H "Authorization: token $GH_ACTIONS_REPO_TOKEN" https://api.github.com/repos/spring-projects/spring-security/actions/artifacts | grep '"id"' | cut -d : -f2 | sed 's/,*$//g') - echo Output is $output - for id in $output; do curl -X DELETE -H "Authorization: token $GH_ACTIONS_REPO_TOKEN" https://api.github.com/repos/spring-projects/spring-security/actions/artifacts/$id; done; diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml deleted file mode 100644 index 28a3c138b2..0000000000 --- a/.github/workflows/codeql.yml +++ /dev/null @@ -1,17 +0,0 @@ -name: "CodeQL Advanced" - -on: - push: - pull_request: - workflow_dispatch: - schedule: - # https://docs.github.com/en/actions/writing-workflows/choosing-when-your-workflow-runs/events-that-trigger-workflows#schedule - - cron: '0 5 * * *' -permissions: read-all -jobs: - codeql-analysis-call: - permissions: - actions: read - contents: read - security-events: write - uses: spring-io/github-actions/.github/workflows/codeql-analysis.yml@e415dadd0910c901e7a7fabd67bbb355b2324500 # 1 diff --git a/.github/workflows/continuous-integration-workflow.yml b/.github/workflows/continuous-integration-workflow.yml deleted file mode 100644 index 706333eeca..0000000000 --- a/.github/workflows/continuous-integration-workflow.yml +++ /dev/null @@ -1,56 +0,0 @@ -name: CI - -on: - push: - branches-ignore: - - "dependabot/**" - schedule: - - cron: '0 10 * * *' # Once per day at 10am UTC - workflow_dispatch: # Manual trigger - -env: - DEVELOCITY_ACCESS_KEY: ${{ secrets.DEVELOCITY_ACCESS_KEY }} - -permissions: - contents: read - -jobs: - build: - name: Build - uses: spring-io/spring-security-release-tools/.github/workflows/build.yml@b92832ecbc7cbe969201e6beafbde0ee400cf095 # v1.0.15 - strategy: - matrix: - os: [ ubuntu-latest, windows-latest ] - jdk: [ 25 ] - with: - runs-on: ${{ matrix.os }} - java-version: ${{ matrix.jdk }} - distribution: temurin - secrets: inherit - deploy-artifacts: - name: Deploy Artifacts - needs: [ build ] - uses: spring-io/spring-security-release-tools/.github/workflows/deploy-artifacts.yml@b92832ecbc7cbe969201e6beafbde0ee400cf095 # v1.0.15 - with: - should-deploy-artifacts: ${{ needs.build.outputs.should-deploy-artifacts }} - default-publish-milestones-central: true - java-version: 25 - secrets: inherit - deploy-schema: - name: Deploy Schema - needs: [ build ] - uses: spring-io/spring-security-release-tools/.github/workflows/deploy-schema.yml@b92832ecbc7cbe969201e6beafbde0ee400cf095 # v1.0.15 - with: - should-deploy-schema: ${{ needs.build.outputs.should-deploy-artifacts }} - java-version: 25 - secrets: inherit - send-notification: - name: Send Notification - needs: [ deploy-artifacts, deploy-schema ] - if: ${{ !success() }} - runs-on: ubuntu-latest - steps: - - name: Send Notification - uses: spring-io/spring-security-release-tools/.github/actions/send-notification@b92832ecbc7cbe969201e6beafbde0ee400cf095 # v1.0.15 - with: - webhook-url: ${{ secrets.SPRING_SECURITY_CI_GCHAT_WEBHOOK_URL }} diff --git a/.github/workflows/defer-issues.yml b/.github/workflows/defer-issues.yml deleted file mode 100644 index d26efafc5f..0000000000 --- a/.github/workflows/defer-issues.yml +++ /dev/null @@ -1,76 +0,0 @@ -name: Defer Issues - -on: - workflow_dispatch: - -permissions: - contents: read - -jobs: - defer-issues: - name: Defer Issues - runs-on: ubuntu-latest - if: github.repository_owner == 'spring-projects' - permissions: - issues: write - steps: - - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - name: Compute Version - id: compute-version - uses: spring-io/spring-release-actions/compute-version@a1f321783a0769dd2aea4fad6c2ae2f95a52b885 # 0.0.5 - - name: Get Today's Release Version - id: todays-release - uses: spring-io/spring-release-actions/get-todays-release-version@a1f321783a0769dd2aea4fad6c2ae2f95a52b885 # 0.0.5 - with: - snapshot-version: ${{ steps.compute-version.outputs.version }} - milestone-repository: ${{ github.repository }} - milestone-token: ${{ secrets.GITHUB_TOKEN }} - - name: Compute Next Version - id: next-version - uses: spring-io/spring-release-actions/compute-next-version@a1f321783a0769dd2aea4fad6c2ae2f95a52b885 # 0.0.5 - with: - version: ${{ steps.todays-release.outputs.release-version }} - - name: Schedule Next Milestone - uses: spring-io/spring-release-actions/schedule-milestone@a1f321783a0769dd2aea4fad6c2ae2f95a52b885 # 0.0.5 - with: - version: ${{ steps.next-version.outputs.version }} - version-date: ${{ steps.next-version.outputs.version-date }} - repository: ${{ github.repository }} - token: ${{ secrets.GITHUB_TOKEN }} - - name: Move Open Issues to Next Milestone - env: - GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} - CURRENT_MILESTONE: ${{ steps.todays-release.outputs.release-version }} - NEXT_MILESTONE: ${{ steps.next-version.outputs.version }} - run: | - current_milestone_number=$(gh api repos/${{ github.repository }}/milestones \ - --jq ".[] | select(.title == \"$CURRENT_MILESTONE\") | .number") - if [ -z "$current_milestone_number" ]; then - echo "No milestone found for $CURRENT_MILESTONE" - exit 0 - fi - next_milestone_number=$(gh api repos/${{ github.repository }}/milestones \ - --jq ".[] | select(.title == \"$NEXT_MILESTONE\") | .number") - if [ -z "$next_milestone_number" ]; then - echo "No milestone found for $NEXT_MILESTONE" - exit 1 - fi - echo "Moving open issues from milestone '$CURRENT_MILESTONE' (#$current_milestone_number) to '$NEXT_MILESTONE' (#$next_milestone_number)" - page=1 - while true; do - issues=$(gh api "repos/${{ github.repository }}/issues?milestone=$current_milestone_number&state=open&per_page=100&page=$page" \ - --jq '.[].number') - if [ -z "$issues" ]; then - break - fi - for issue in $issues; do - echo "Moving issue/PR #$issue to milestone $NEXT_MILESTONE" - gh api repos/${{ github.repository }}/issues/$issue \ - --method PATCH \ - --field milestone=$next_milestone_number \ - --silent - done - page=$((page + 1)) - done - echo "Done." diff --git a/.github/workflows/deploy-docs.yml b/.github/workflows/deploy-docs.yml deleted file mode 100644 index 54e88173c7..0000000000 --- a/.github/workflows/deploy-docs.yml +++ /dev/null @@ -1,33 +0,0 @@ -name: Deploy Docs -on: - push: - branches-ignore: - - "gh-pages" - - "dependabot/**" - tags: '**' - repository_dispatch: - types: request-build-reference # legacy - #schedule: - #- cron: '0 10 * * *' # Once per day at 10am UTC - workflow_dispatch: -permissions: read-all -jobs: - build: - runs-on: ubuntu-latest - if: github.repository_owner == 'spring-projects' - steps: - - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - ref: docs-build - fetch-depth: 1 - - name: Dispatch (partial build) - if: github.ref_type == 'branch' - env: - GH_TOKEN: ${{ secrets.GH_ACTIONS_REPO_TOKEN }} - run: gh workflow run deploy-docs.yml -r $(git rev-parse --abbrev-ref HEAD) -f build-refname=${{ github.ref_name }} - - name: Dispatch (full build) - if: github.ref_type == 'tag' - env: - GH_TOKEN: ${{ secrets.GH_ACTIONS_REPO_TOKEN }} - run: gh workflow run deploy-docs.yml -r $(git rev-parse --abbrev-ref HEAD) diff --git a/.github/workflows/gradle-wrapper-upgrade-execution.yml b/.github/workflows/gradle-wrapper-upgrade-execution.yml deleted file mode 100644 index f9776716b1..0000000000 --- a/.github/workflows/gradle-wrapper-upgrade-execution.yml +++ /dev/null @@ -1,34 +0,0 @@ -name: Execute Gradle Wrapper Upgrade - -on: - schedule: - - cron: '0 2 * * *' # 2am UTC - workflow_dispatch: -permissions: - pull-requests: write -jobs: - upgrade_wrapper: - name: Execution - if: ${{ github.repository == 'spring-projects/spring-security' }} - runs-on: ubuntu-latest - steps: - - name: Set up Git configuration - env: - TOKEN: ${{ secrets.GITHUB_TOKEN }} - run: | - git config --global url."https://unused-username:${TOKEN}@github.com/".insteadOf "https://github.com/" - git config --global user.name 'github-actions[bot]' - git config --global user.email 'github-actions[bot]@users.noreply.github.com' - - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - name: Set up JDK 25 - uses: actions/setup-java@b6effb05e454b25005698d916606bdc6ffcbf961 # v5.7.0 - with: - java-version: '25' - distribution: 'temurin' - - name: Set up Gradle - uses: gradle/setup-gradle@f29f5a9d7b09a7c6b29859002d29d24e1674c884 # v5.0.1 - - name: Upgrade Wrappers - run: ./gradlew clean upgradeGradleWrapperAll --continue -Porg.gradle.java.installations.auto-download=false - env: - WRAPPER_UPGRADE_GIT_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/pr-build-workflow.yml b/.github/workflows/pr-build-workflow.yml deleted file mode 100644 index d17c45373a..0000000000 --- a/.github/workflows/pr-build-workflow.yml +++ /dev/null @@ -1,51 +0,0 @@ -name: PR Build - -on: pull_request - -permissions: - contents: read - -jobs: - build: - name: Build - runs-on: ubuntu-latest - if: ${{ github.repository == 'spring-projects/spring-security' }} - steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - name: Set up gradle - uses: spring-io/spring-gradle-build-action@c8668747d7c264864c8c7f7026d0d277d14a78dc # v2.0.6 - with: - java-version: '25' - distribution: 'temurin' - - name: Build with Gradle - run: ./gradlew clean build -PskipCheckExpectedBranchVersion --continue --scan - generate-docs: - name: Generate Docs - runs-on: ubuntu-latest - if: ${{ github.repository == 'spring-projects/spring-security' }} - steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - name: Set up gradle - uses: spring-io/spring-gradle-build-action@c8668747d7c264864c8c7f7026d0d277d14a78dc # v2.0.6 - with: - java-version: '25' - distribution: 'temurin' - - name: Run Antora - run: ./gradlew -PbuildSrc.skipTests=true :spring-security-docs:antora - - name: Upload Docs - id: upload - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 - with: - name: docs - path: docs/build/site - overwrite: true - send-notification: - name: Send Notification - needs: [ build, generate-docs ] - if: ${{ failure() && github.event.pull_request.user.login == 'dependabot[bot]' && github.repository == 'spring-projects/spring-security' }} - runs-on: ubuntu-latest - steps: - - name: Send Notification - uses: spring-io/spring-security-release-tools/.github/actions/send-notification@b92832ecbc7cbe969201e6beafbde0ee400cf095 # v1.0.15 - with: - webhook-url: ${{ secrets.SPRING_SECURITY_CI_GCHAT_WEBHOOK_URL }} diff --git a/.github/workflows/update-antora-ui-spring.yml b/.github/workflows/update-antora-ui-spring.yml deleted file mode 100644 index d6006b8e81..0000000000 --- a/.github/workflows/update-antora-ui-spring.yml +++ /dev/null @@ -1,37 +0,0 @@ -name: Update Antora UI Spring - -on: - schedule: - - cron: '0 10 * * *' # Once per day at 10am UTC - workflow_dispatch: - -permissions: - pull-requests: write - issues: write - contents: write - -jobs: - update-antora-ui-spring: - name: Update on Supported Branches - if: ${{ github.repository == 'spring-projects/spring-security' }} - runs-on: ubuntu-latest - strategy: - matrix: - branch: [ '6.5.x', '7.0.x', 'main' ] - steps: - - uses: spring-io/spring-doc-actions/update-antora-spring-ui@415e2b11a766ba64799fffb5c97a4f7e17f677cf # v0.0.22 - name: Update - with: - docs-branch: ${{ matrix.branch }} - token: ${{ secrets.GITHUB_TOKEN }} - antora-file-path: 'docs/antora-playbook.yml' - update-antora-ui-spring-docs-build: - name: Update on docs-build - if: ${{ github.repository == 'spring-projects/spring-security' }} - runs-on: ubuntu-latest - steps: - - uses: spring-io/spring-doc-actions/update-antora-spring-ui@415e2b11a766ba64799fffb5c97a4f7e17f677cf # v0.0.22 - name: Update - with: - docs-branch: 'docs-build' - token: ${{ secrets.GITHUB_TOKEN }}