Using ssh to push the new tags.
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 25/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Stale
- Tech stack
- git, javascript, node.js
Research direction
Start with @semantic-release/gitlab/lib/verify.js and the verifyConditions entry point in index.js, then compare their token checks with the authentication guidance in the README. Reproduce the SSH remote scenario and establish whether the requested behavior is supported; done means the behavior or limitation is verified and covered by an appropriate documented or automated check.
Written by the indexing model from the issue text.
Description
I'm a free user of gitlab.com therefore I don't have access to project/namespace tokens and since I intend on protecting my master branch from being pushed directly I have to resort into deployment tokens.
Steps:
- I created a ssh key
- encoded with base64
- create a file variable with the new encoded base64 string
- adjusted my pipeline to first decode the base64 string from the file and write the private key to ~/.ssh/id_rsa
- from the key above generated the pub key
- changed the remote origin from https:// to [email protected]
- ran git ls-remote to ensure that the key worked.
- in my local environment I used the same key above to push to my protected branch and it works like a charm. As well as to create tags
I have a token set for different pipelines and it still throws the error bellow. My assumption is that the code is checking the origin url and looking for that token? In this case, since I'm using ssh it shouldn't require a token should it for the release creation it would make sense to require that but not for creating the tag itself
If my approach is completely wrong how do I approach this problem without having to keep my master branch open
$ npx semantic-release
[1:29:35 PM] [semantic-release] › ℹ Running semantic-release version 23.1.1
[1:29:36 PM] [semantic-release] › ✔ Loaded plugin "verifyConditions" from "@semantic-release/changelog"
[1:29:36 PM] [semantic-release] › ✔ Loaded plugin "verifyConditions" from "@semantic-release/gitlab"
[1:29:36 PM] [semantic-release] › ✔ Loaded plugin "analyzeCommits" from "@semantic-release/commit-analyzer"
[1:29:36 PM] [semantic-release] › ✔ Loaded plugin "generateNotes" from "@semantic-release/release-notes-generator"
[1:29:36 PM] [semantic-release] › ✔ Loaded plugin "prepare" from "@semantic-release/changelog"
[1:29:36 PM] [semantic-release] › ✔ Loaded plugin "publish" from "@semantic-release/gitlab"
[1:29:36 PM] [semantic-release] › ✔ Loaded plugin "success" from "@semantic-release/gitlab"
[1:29:36 PM] [semantic-release] › ✔ Loaded plugin "success" from "./custom-discord-notifier.js"
[1:29:36 PM] [semantic-release] › ✔ Loaded plugin "fail" from "@semantic-release/gitlab"
[1:29:46 PM] [semantic-release] › ✔ Run automated release from branch next on repository [email protected]:redactedDev/redacted-client-26.git
[1:29:47 PM] [semantic-release] › ✔ Allowed to push to the Git repository
[1:29:47 PM] [semantic-release] › ℹ Start step "verifyConditions" of plugin "@semantic-release/changelog"
[1:29:47 PM] [semantic-release] › ✔ Completed step "verifyConditions" of plugin "@semantic-release/changelog"
[1:29:47 PM] [semantic-release] › ℹ Start step "verifyConditions" of plugin "@semantic-release/gitlab"
[1:29:47 PM] [semantic-release] › ✘ Failed step "verifyConditions" of plugin "@semantic-release/gitlab"
[1:29:47 PM] [semantic-release] › ℹ Start step "fail" of plugin "@semantic-release/gitlab"
[1:29:47 PM] [semantic-release] › ✘ Failed step "fail" of plugin "@semantic-release/gitlab"
[1:29:47 PM] [semantic-release] › ✘ ENOGLTOKEN No GitLab token specified.
A GitLab personal access token (https://github.com/semantic-release/gitlab/blob/master/README.md#gitlab-authentication) must be created and set in the GL_TOKEN or GITLAB_TOKEN environment variable on your CI environment.
Please make sure to create a GitLab personal access token (https://docs.gitlab.com/ce/user/profile/personal_access_tokens.html) and to set it in the GL_TOKEN or GITLAB_TOKEN environment variable on your CI environment. The token must allow to push to the repository [email protected] (mailto:[email protected]):redacted/redacted.git.
[1:29:47 PM] [semantic-release] › ✘ ENOGLTOKEN No GitLab token specified.
A GitLab personal access token (https://github.com/semantic-release/gitlab/blob/master/README.md#gitlab-authentication) must be created and set in the GL_TOKEN or GITLAB_TOKEN environment variable on your CI environment.
Please make sure to create a GitLab personal access token (https://docs.gitlab.com/ce/user/profile/personal_access_tokens.html) and to set it in the GL_TOKEN or GITLAB_TOKEN environment variable on your CI environment. The token must allow to push to the repository [email protected] (mailto:[email protected]):redactedDev/redacted-client-26.git.
AggregateError:
SemanticReleaseError: No GitLab token specified.
at default (file:///builds/redactedDev/redacted-client-26/node_modules/@semantic-release/gitlab/lib/get-error.js:6:10)
at default (file:///builds/redactedDev/redacted-client-26/node_modules/@semantic-release/gitlab/lib/verify.js:54:17)
at verifyConditions (file:///builds/redactedDev/redacted-client-26/node_modules/@semantic-release/gitlab/index.js:11:9)
at validator (file:///builds/redactedDev/redacted-client-26/node_modules/semantic-release/lib/plugins/normalize.js:36:30)
at file:///builds/redactedDev/redacted-client-26/node_modules/semantic-release/lib/plugins/pipeline.js:38:42
at next (file:///builds/redactedDev/redacted-client-26/node_modules/semantic-release/node_modules/p-reduce/index.js:16:10)
at file:///builds/redactedDev/redacted-client-26/node_modules/semantic-release/lib/plugins/pipeline.js:55:13
at async pluginsConfigAccumulator.<computed> [as verifyConditions] (file:///builds/redactedDev/redacted-client-26/node_modules/semantic-release/lib/plugins/index.js:87:11)
at async run (file:///builds/redactedDev/redacted-client-26/node_modules/semantic-release/index.js:106:3)
at async Module.default (file:///builds/redactedDev/redacted-client-26/node_modules/semantic-release/index.js:278:22)
at async default (file:///builds/redactedDev/redacted-client-26/node_modules/semantic-release/cli.js:55:5) {
errors: [
SemanticReleaseError: No GitLab token specified.
at default (file:///builds/redactedDev/redacted-client-26/node_modules/@semantic-release/gitlab/lib/get-error.js:6:10)
at default (file:///builds/redactedDev/redacted-client-26/node_modules/@semantic-release/gitlab/lib/verify.js:54:17)
at verifyConditions (file:///builds/redactedDev/redacted-client-26/node_modules/@semantic-release/gitlab/index.js:11:9)
at validator (file:///builds/redactedDev/redacted-client-26/node_modules/semantic-release/lib/plugins/normalize.js:36:30)
at file:///builds/redactedDev/redacted-client-26/node_modules/semantic-release/lib/plugins/pipeline.js:38:42
at next (file:///builds/redactedDev/redacted-client-26/node_modules/semantic-release/node_modules/p-reduce/index.js:16:10) {
code: 'ENOGLTOKEN',
details: 'A [GitLab personal access token](https://github.com/semantic-release/gitlab/blob/master/README.md#gitlab-authentication) must be created and set in the `GL_TOKEN` or `GITLAB_TOKEN` environment variable on your CI environment.\n' +
'\n' +
'Please make sure to create a [GitLab personal access token](https://docs.gitlab.com/ce/user/profile/personal_access_tokens.html) and to set it in the `GL_TOKEN` or `GITLAB_TOKEN` environment variable on your CI environment. The token must allow to push to the repository [email protected]:redactedDev/redacted-client-26.git.',
semanticRelease: true,
pluginName: '@semantic-release/gitlab'
}
]
}
Cleaning up project directory and file based variables 00:00
ERROR: Job failed: exit code 1
variables:
project_name: "${CI_PROJECT_TITLE}"
SEMANTIC_RELEASE_PACKAGE: "${project_name}"
GIT_SUBMODULE_STRATEGY: normal
GIT_DEPTH: 0 # Disable shallow cloning for full history
GIT_SUBMODULE_DEPTH: 0
stages:
- semantic_release
semantic_release:
stage: semantic_release
image: node:lts
variables:
# Define GIT_SSH_COMMAND to use the specified SSH key and settings
GIT_SSH_COMMAND: "ssh -v -i ~/.ssh/id_rsa -o StrictHostKeyChecking=accept-new"
before_script:
# 1. Create the .ssh directory
- mkdir -p ~/.ssh
# 2. Decode the Base64-encoded SSH key and save it to ~/.ssh/id_rsa
- cat "$DEPLOY_SSH_KEY64" | base64 -d > ~/.ssh/id_rsa
# 3. Generate .pub from our new private key
- ssh-keygen -y -f ~/.ssh/id_rsa > ~/.ssh/id_rsa.pub
# 4. Set the correct permissions for the SSH key
- chmod 600 ~/.ssh/id_rsa
# 5. Add GitLab to known_hosts to prevent host verification prompts
- ssh-keyscan gitlab.com >> ~/.ssh/known_hosts
# 6. Update the Git remote URL to use SSH instead of HTTPS
- git remote set-url origin "[email protected]:${CI_PROJECT_NAMESPACE}/${CI_PROJECT_NAME}.git"
# 7. (Optional) Verify that the remote URL has been updated
- git remote -v
script:
- export GIT_SSH_COMMAND="ssh -v -i ~/.ssh/id_rsa -o StrictHostKeyChecking=accept-new"
- npm install semantic-release @semantic-release/changelog @semantic-release/commit-analyzer @semantic-release/gitlab @semantic-release/npm @semantic-release/release-notes-generator conventional-changelog-conventionalcommits axios
- npx semantic-release
#dependencies:
# - build
# - hash_job
# - collect_and_symstore_job
- Dominant language
- JavaScript
- Stars
- 343
- Forks
- 91
- Avg merge
- 1d 54m
- Merged PRs (30d)
- 2
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from semantic-release/gitlab
-
`useJobToken` verifyConditions omits proxy, so `got` bypasses `HTTPS_PROXY`Possibly taken @ar7bd claimed this 7 days ago. Open
Difficulty 1/5 Under an hour Newbie friendliness 90/100
semantic-release/gitlab#1032 ·
-
bug feature
Difficulty 4/5 3-5 days Newbie friendliness 48/100
semantic-release/gitlab#891 · 28 comments · 15 reactions ·
-
feature
Difficulty 4/5 3-5 days Newbie friendliness 35/100
semantic-release/gitlab#857 · 1 reaction ·
-
Autodetect components projectMay be free again A pull request for this issue was closed without being merged. Openfeature
Difficulty 4/5 3-5 days Newbie friendliness 35/100
semantic-release/gitlab#851 ·
-
feature help wanted
Difficulty 4/5 3-5 days Newbie friendliness 45/100
semantic-release/gitlab#830 · 5 comments ·
All issues in semantic-release/gitlab
Similar issues
-
needs triage
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
solana-foundation/solana-com#2245 ·
Maintainers usually reply within 1 day
-
tech debt
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
TAMULib/fw-registry#543 ·
Maintainers usually reply within 1 day
-
security
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 63/100
FortAwesome/Font-Awesome#21688 ·