.. _migration_guide: Migration guide =============== This guide provides information on new features, breaking changes, how to migrate from one version of the actions to another, and other upstream dependencies that have been updated. Version ``v11`` --------------- **Breaking Changes:** - **Deprecation of release-pypi-public and release-pypi-test actions:** The ``release-pypi-public`` and ``release-pypi-test`` actions no longer support publishing packages to PyPI using tokens. As a result, they are deprecated starting with ``v11``. Projects must migrate to trusted publishing. Contact the PyAnsys Core Team at pyansys.core@ansys.com for enabling trusted publishing for your project and refer to :ref:`release_pypi_trusted_publisher` for setup details. Note that ``release-pypi-private`` is not affected and still supports token-based publishing due to the limitations of the private index. - **Removal of deprecated inputs from multiple actions:** Several inputs that were previously deprecated have been completely removed: - ``generate_release_notes`` removed from ``release-github``. Use ``generate-release-notes`` instead. - ``toml-version`` removed from ``doc-changelog``, ``doc-deploy-changelog``, ``doc-style``, and ``release-github``. - ``python-version`` and ``use-uv`` removed from ``hk-package-clean-except`` and ``hk-package-clean-untagged``. These actions now use an internally managed Python setup. Note that the removal of ``use-uv`` from the ``hk-package-clean-*`` actions is unrelated to the new ``use-uv`` semantics described in the *Automatic install from uv.lock* new feature below. - **Conflict between uv.lock and legacy requirement files now errors:** Starting with ``v11``, the ``doc-build``, ``tests-pytest``, and ``check-vulnerabilities`` (when ``skip-install: true``) actions fail with an error when both a ``uv.lock`` file and a ``requirements/requirements_.txt`` file are present in the working directory. Previously, one of the two was silently ignored. Delete whichever file is no longer authoritative for your project (usually the legacy requirements file) to unblock the actions. **New actions:** - **Deploy documentation to a custom path:** A new ``doc-deploy-custom-path`` action has been added. It deploys HTML documentation to a user-specified subdirectory of the deployment branch (``gh-pages`` by default). The rendered documentation is available at ``https:////``. The action validates the ``custom-path`` input to prevent conflicts with reserved paths used by the other ``doc-deploy-*`` actions (such as ``version`` and ``pull``). See :doc:`../doc-actions/index` for usage details. **New Features:** - **Pinned action dependencies:** All actions that install Python tooling at runtime now install their dependencies from pinned requirements. Every direct and transitive dependency is version-locked, which makes action runs reproducible, mitigates supply chain risks, and prevents breakage of actions behaviour when a transitive dependency releases a new version. As a consequence, several ``*-version`` inputs that used to control tool versions no longer have any effect and are now scheduled for removal in ``v12`` (see the *Review usage of still-deprecated inputs* migration step). - **Automatic install from uv.lock:** The semantics of the ``use-uv`` input now goes beyond simply controlling whether the ``uv`` package manager should be used to install project dependencies. When ``use-uv`` is ``true`` (the default) and a ``uv.lock`` file is present in the working directory, the actions now install project dependencies from the lock file. Practical implications: - The dependency versions installed at runtime come from ``uv.lock``, not from a fresh resolution of ``pyproject.toml``. Keep the lockfile up to date so that the actions install what you intend. - The ``dev`` dependency group is intentionally excluded (``--no-dev``). If your tests, docs, or style checks rely on dev-only dependencies, move them to a dedicated group or extras target (depending on the action) and reference it via the relevant action input. - Projects that do not commit a ``uv.lock`` are unaffected; behavior falls back to using ``uv`` to install project dependencies. - **Poetry-native install in check-licenses:** For Poetry-based projects, the ``check-licenses`` action now installs the project and its dependency targets through Poetry, aligning with the installation behavior of the other actions. This improves reliability of license checks for Poetry projects. No user-facing input change is required. - **Minimum permissions documented in examples:** All action examples now also document the minimum GitHub permissions required to run them, making it easier to set up workflows with the correct permissions. - **SEO refinements in the documentation deployment actions:** The ``ansys/actions/doc-deploy-dev``, ``ansys/actions/doc-deploy-stable`` and ``ansys/actions/_pr-doc-deployment`` actions now enforce a consistent set of SEO signals across every deployed page. No changes to ``conf.py`` or workflow files are required. Notable behavior changes: - Every non-stable version page and every pull-request preview under ``pull//`` is stamped with ````. This complements the existing ``robots.txt`` ``Disallow`` rules so that pages discovered through direct backlinks also drop out of search-engine indexes. - The generated ``robots.txt`` file switched from enumerating every deployed version to a wildcard rule (``Disallow: /version/`` combined with ``Allow: /version/stable/``). Projects that do not maintain a ``version/stable/`` alias no longer have any version crawled; add the ``stable`` alias to restore indexing of the release documentation. - The generated ``sitemap.xml`` now excludes pages that declare ```` in their ```` and skips a default list of boilerplate/utility filenames (``announcement.html``, ``search.html``, ``genindex.html``, ``py-modindex.html``, ``404.html``, ``webpack-macros.html``). ```` is emitted only for the site root, since ``actions/download-artifact`` does not preserve per-file mtimes. - The generated ``robots.txt`` conditionally advertises the sitemap: the deployment actions omit the ``Sitemap:`` line automatically when no ``version/stable/`` exists, so ``robots.txt`` no longer points at a URL that would return 404. - The root landing page is now stripped of any inherited ``robots`` meta tag and pinned to a self-referential ```` after being copied from a non-stable version. This prevents the site's root from being deindexed when only prerelease or development documentation is available. **Migration Steps:** - **Changed default behavior of doc-build dependency inputs:** The default behavior of the ``optional-dependencies-name`` and ``group-dependencies-name`` inputs of the ``doc-build`` action has changed. Previously, ``optional-dependencies-name`` always defaulted to ``doc`` even when ``group-dependencies-name`` is not empty, which can cause failures if ``doc`` optional extra is absent from the ``pyproject.toml`` file. The new behavior is: - Both inputs now default to empty (``''``). - If **neither** input is provided, the action defaults to ``optional-dependencies-name=doc`` (for backwards compatibility). - If **only one** is provided, only that one is used. - If **both** are provided, both are used (a warning is logged). Although backwards compatibility is maintained, you are advised to set one of the inputs explicitly to avoid future breaking changes. - **Changed default behavior of tests-pytest dependency inputs:** The ``tests-pytest`` action now mirrors the ``doc-build`` behavior described above for the ``optional-dependencies-name`` and ``group-dependencies-name`` inputs. The important differences are: - The action defaults to ``optional-dependencies-name=tests`` (for backwards compatibility). - The requirements-file lookup remains driven by ``optional-dependencies-name``: the action still installs from ``requirements/requirements_.txt`` when that file exists. - **Remove references to removed inputs from your workflows:** Search your workflows for references to the inputs listed in the preceding breaking changes section (``generate_release_notes`` on the ``release-github`` action, ``toml-version`` on the ``doc-*`` and ``release-github`` actions, and ``python-version`` / ``use-uv`` on the ``hk-package-clean-*`` actions) and drop them. For example, for ``hk-package-clean-untagged``: .. tab-set:: .. tab-item:: Before .. code:: yaml - name: "Clean untagged packages" uses: ansys/actions/hk-package-clean-untagged@v10 with: package-name: my-package python-version: '3.12' use-uv: true .. tab-item:: After .. code:: yaml - name: "Clean untagged packages" uses: ansys/actions/hk-package-clean-untagged@v11 with: package-name: my-package - **Adoption of uv.lock installs:** If your project commits a ``uv.lock`` file, verify that the lockfile is up to date and includes every extra and group your workflows pass to the actions through relevant inputs. If you also maintain a legacy ``requirements/requirements_.txt`` for ``doc-build``, ``tests-pytest``, or ``check-vulnerabilities`` actions, remove one of the two to avoid the new error described in the breaking changes section. - **Review usage of still-deprecated inputs:** The following inputs still exist but now emit an ``ERROR``-level deprecation notice (previously ``WARNING``) and are scheduled for removal in ``v12``. In ``v11`` the inputs are no longer used because the corresponding tools are now installed from the action's pinned requirements (see *Pinned action dependencies* in the new feature section). Migrate away from them now to avoid disruption in the next major release: - ``use-conventional-commits`` on the ``doc-changelog`` action: use ``use-pull-request-title`` instead. - ``tomli-version`` on the ``doc-changelog``, ``doc-deploy-changelog``, ``doc-style``, and ``release-github`` actions. - ``towncrier-version`` and ``tomlkit-version`` on the ``doc-changelog``, ``doc-deploy-changelog``, and ``release-github`` actions. ``tomlkit-version`` is also affected in the ``doc-style`` action. - ``pypandoc-binary-version`` on the ``release-github`` action. Version ``v10.3`` ----------------- **New actions:** - **Migrate fork pull requests:** The ``hk-migrate-fork-pr`` action migrates pull requests from forks to branches within the main repository, enabling workflows that require repository secrets to run. It handles team membership verification and automated PR creation during migration. Subsequent triggers sync the migration branch. See :ref:`hk-migrate-fork-pr-setup` for setup details. - **Tag repository version:** The ``hk-tag-repository-version`` action creates and updates ``vX`` and ``vX.Y`` tags pointing to the latest released version. It also pushes a ``release/vX.Y.Z`` branch for hot fixes and optionally creates a ``latest`` branch. This action is intended to be used in a workflow triggered by a release event. The action is mostly useful for projects that only want to release code and do not need to follow the usual release process of the PyAnsys ecosystem. See :doc:`../housekeeping-actions/index` for usage details. **New features:** - **Prek for code style:** The ``code-style`` action now uses `prek `_ as a drop-in replacement for ``pre-commit`` to make execution faster. To revert to ``pre-commit``, set the new ``use-prek`` input to ``false`` (default: ``true``). - **Minimum permissions documented:** All action descriptions now document the minimum GitHub permissions required to run each action. Check the documentation for each action for details. - **Changelog improvements:** The changelog (``doc-changelog`` and ``doc-deploy-changelog``) actions include two new changes: - A new ``breaking`` fragment type has been added for tracking breaking changes in the changelog. - Changelog tabs are now ordered by importance in the deployed changelog, with the following order: Breaking > Added > Fixed > Documentation > Dependencies > Maintenance > Miscellaneous > Test. - **Filtering GitHub releases:** The ``release-github`` action now includes a ``dist-filter`` input (default: ``''``) that accepts a comma-separated list of glob patterns for filtering the ``dist/`` directory. Files that do not match any of the provided patterns are removed before the GitHub release is created. This is useful for projects with large build matrices where only a subset of artifacts should appear on the release page. - **Safety policy file:** The ``check-vulnerabilities`` action now supports custom safety policy files, which can be used for specifying vulnerabilities to ignore among other things. - **UV build in build-library:** When ``use-uv`` is set to ``true`` (the default), the ``build-library`` action now uses ``uv build`` instead of ``python -m build``, avoiding the need to install the ``build`` package as a separate dependency and speeding up builds. - **Optional token for check-pr-title:** The ``check-pr-title`` action no longer requires a ``token`` input. It is now optional and defaults to the ``GITHUB_TOKEN``. - **Unified artifact names:** The artifacts generated by the build actions (``build-library`` and ``build-wheelhouse``) now have consistent names that make use of underscores instead of hyphens for the library name. - **Version validation in release actions:** The ``release-github`` and ``release-pypi-*`` actions now ensure that the tag that triggered a release matches the version specified in the ``pyproject.toml`` file. Version ``v10.2`` ----------------- **New Features:** - **Build-Library Changes:** The ``build-library`` action now includes two new inputs: - ``checkout-fetch-depth`` (default: ``1``): Allows configuring the fetch depth when checking out the repository. Setting this to ``0`` fetches the entire history, which may be necessary for certain build processes that rely on full commit history. - ``checkout-fetch-tags`` (default: ``false``): When set to ``true``, this input enables fetching all tags from the repository. This is useful for build processes that depend on tag information. - **Changelog Action Changes:** The ``doc-changelog`` action input ``use-conventional-commits`` has been renamed to ``use-pull-request-title`` for clarity. If you use the old input, a deprecation warning appears. - **Check-Vulnerabilities Changes:** The ``check-vulnerabilities`` action now includes a ``safety-configfile`` input (default: ``""``) that allows users to specify a custom configuration file to use with ``safety``. This is useful for users who want to customize the behavior of ``safety`` or provide additional configuration options. - **PR Documentation Deployment:** The ``doc-deploy-pr`` action is now easier to use. Starting with version ``v10.2``, you no longer need to include the ``closed`` pull request event in your workflows because deployed documentation is cleaned up asynchronously. For more details, see :ref:`docs-deploy-pr-setup`. - **Release-Github Changes:** The ``release-github`` action now includes a ``upload-documentation`` (default: ``true``) input. This input allows users to control whether documentation artifacts are included in the GitHub release. Setting this to ``false`` skips the upload of documentation artifacts, which can be useful for releases without documentation artifacts. Version ``v10.1`` ----------------- **New Features:** - ``ansys/actions/doc-deploy-stable`` action now supports pre-releases. The identifiers must be one of ``a|b|rc`` for alpha, beta, and release candidates respectively. Furthermore, only patch pre-release are supported, meaning the `PEP 440 ` compliant version identifiers are limited to those that comply with the following scheme: .. code-block:: yaml N.N.N[{a|b|rc}N] .. note:: In the same pre-release cycle, documentation is retained for a maximum of three pre-release versions and removed following a normal release. - Added a ``checkout`` option (default: ``true``) to ``build-library``, ``check-actions-security``, and ``code-style`` actions. Setting ``checkout`` to ``false`` allows reuse of the workspace from a prior step without modification. - Introduced an ``upload-artifact-name-prefix`` option (default: ``documentation``) in the ``doc-build`` action, enabling customization of uploaded documentation artifact names. This also allows distinct documentation artifacts to be uploaded for separate documentation build jobs within the same workflow. **Migration Steps:** - For Poetry-based projects, ensure that you provide the correct values for ``optional-dependencies-name`` (default: ``doc``) and ``group-dependencies-name``. - ``optional-dependencies-name``: Refers to the extras defined in the ``pyproject.toml`` file. - ``group-dependencies-name``: Refers to the dependency groups defined in the same file. If your documentation dependencies are defined as extras, changes to your workflow are likely not needed since the default value for ``optional-dependencies-name`` will target the ``doc`` extra. However, using dependency groups (as is the case with most PyAnsys libraries) requires the following update to your workflow: .. tab-set:: .. tab-item:: Before .. code:: yaml doc-build: name: Documentation Build runs-on: ubuntu-latest steps: - name: "Run Ansys documentation building action" uses: ansys/actions/doc-build@33399106dc8b62d83c8aad1fb2c333c8055df180 # v10.0.20 with: check-links: false dependencies: "pandoc" sphinxopts: "-n -W --keep-going" .. tab-item:: After .. code:: yaml doc-build: name: Documentation Build runs-on: ubuntu-latest steps: - name: "Run Ansys documentation building action" uses: ansys/actions/doc-build@ed773aba3478d311decff2d4313e0cd19a945dd8 # v10.1.0 with: check-links: false dependencies: "pandoc" sphinxopts: "-n -W --keep-going" optional-dependencies-name: "" group-dependencies-name: "doc" Version ``v10`` ----------------- **New Features:** - **Workflow Security Audits:** Introduced ``ansys/action/check-actions-security`` to audit workflow files for security and vulnerability issues. Provides summary and detailed reports using the `zizmor `_ static analysis tool. See `zizmor audit rules `_ for information about detected issues and their remediation. - **PR Documentation Deployment:** Added ``ansys/action/doc-deploy-pr`` to deploy HTML documentation for pull requests at ``https:///pull//``. Documentation is automatically removed when the pull request is closed. Refer to :ref:`docs-deploy-pr-setup` for setup details. - **Faster Package Installation:** Added a ``use-uv`` option (default: true) to ``build-library``, ``build-wheelhouse``, ``check-licenses``, ``check-vulnerabilities``, ``code-style``, ``doc-build``, ``doc-changelog``, ``doc-deply-changelog``, ``hk-package-clean-except``, ``hk-package-clean-untagged``, ``release-github``, and ``tests-pytest`` actions. This leverages `uv `_ for faster package installation, improving workflow speed for projects with multiple dependencies. .. admonition:: About pre-releases and extra indices The installation of pre-releases by ``uv`` is only supported if these are listed in the ``pyproject.toml`` file. If you wish to install pre-releases at all levels, you must set the ``UV_PRERELEASE=allow`` environment variable. Regarding extra indices, ``uv`` supports the ``UV_EXTRA_INDEX_URL`` for specifying extra indices. This is the equivalent to the ``PIP_EXTRA_INDEX_URL`` environment variable. - **Dependency Groups Support:** ``doc-build`` and ``tests-pytest`` actions now support `PEP 735 `_ dependency groups via the ``group-dependencies-name`` input. Extras remain supported through the ``optional-dependencies-name`` input. - **SBOM Generation:** ``build-wheelhouse`` action now generates a Software Bill of Materials (SBOM) in SPDX format and uploads it as an artifact. This SBOM is generated using `Syft `_. Note that the SBOM artifacts are now included in the Github release. **Breaking Changes:** - **Python Version Support:** Dropped support for Python versions below ``3.9``. - **JSON Builder Removal:** ``ansys/actions/doc-build`` no longer supports the ``JSON`` builder for documentation rendering. - **Dependency Groups Parsing:** Replaced the ``toml`` library with ``tomli`` in ``doc-style``, ``doc-changelog``, and ``release-github`` actions due to improved support for ``pyproject.toml`` files with nested dependency groups. The ``tomli-version`` input replaces the former ``toml-version`` input. - **Build-Wheelhouse Changes:** the ``build-wheelhouse`` action now installs packages in a virtual environment instead of at the system level. If you have subsequent workflow steps (e.g., running smoke tests) that depend on these packages, activate the virtual environment using the action's ``activate-venv`` output. For example: .. code-block:: yaml build-wheelhouse-and-smoke-test: name: Build wheelhouse and perform smoke test runs-on: ${{ matrix.os }} strategy: matrix: os: [ubuntu-latest, windows-latest] python-version: ['3.10', '3.11', '3.12', '3.13', '3.14'] steps: - name: Build wheelhouse id: build-wheelhouse uses: ansys/actions/build-wheelhouse@v10 with: library-name: ${{ env.PACKAGE_NAME }} operating-system: ${{ matrix.os }} python-version: ${{ matrix.python-version }} check-licenses: true - name: Perform additional smoke tests shell: bash run: | ${{ steps.build-wheelhouse.outputs.activate-venv }} Version ``v9.0`` ---------------- **Breaking changes:** - Use ``ansys/actions/check-licenses`` actions with Python version 3.10 or higher. - To use ``check-licenses: true`` with the ``ansys/actions/build-wheelhouse`` action, use Python version 3.10 or higher. - Update your workflow to not use ``use-trusted-publisher: true`` with our pypi release actions. .. warning:: Using the trusted publisher approach in ``ansys/release-pypi-public`` and ``ansys/release-pypi-private`` actions is not possible anymore. The reason for that is related to the action `pypa/gh-action-pypi-publish `_ which allows to use the trusted publisher. Indeed, it is no longer possible to use the action in a composite action for versions after ``v1.12.0``, see `pypa/gh-action-pypi-publish@v1.12.0 `_. However, the latest versions of this action is required to upload `PEP 639 licensing metadata `_ to PyPI. This allows to avoid adding upper bounds on build system like ``setuptools<=67.0.0``, ``wheel<0.46.0`` or ``flit_core>=3.2,<3.11``. **Migration Steps:** - Update input ``python-version`` to ``3.10`` or higher in the ``ansys/actions/check-licenses`` action or in the ``ansys/actions/build-wheelhouse`` action if you are using the ``check-licenses`` input. For example: .. code-block:: yaml build-wheelhouse: name: Build wheelhouse runs-on: ${{ matrix.os }} strategy: matrix: os: [ubuntu-latest, windows-latest] python-version: ['3.10', '3.11', '3.12', '3.13', '3.14'] steps: - name: Build wheelhouse and perform smoke test uses: ansys/actions/build-wheelhouse@v9 with: library-name: ${{ env.PACKAGE_NAME }} operating-system: ${{ matrix.os }} python-version: ${{ matrix.python-version }} - When using trusted publisher to publish to PyPI, define you own release job instead of using the ``ansys/actions/release-pypi-*`` actions. See :ref:`release_pypi_trusted_publisher` for more details. Version ``v8.2`` ---------------- **New Features:** - Added a new action named ``ansys/actions/hk-automerge-prs``. This action allows maintainers to auto-approve and merge ``dependabot`` PRs and ``pre-commit.ci`` PRs. It is recommended to add the action at the end of the workflow, once all the stages have finished successfully. That way, in case a repository has failing stages, it is not run. This action will run in case the PR has been created by ``dependabot`` or ``pre-commit.ci``. You can see an example of its implementation `here `_ and the `associated PR/commit `_. - Added a new input parameter ``use-ansys-default-template`` to the ``ansys/actions/doc-changelog`` action. This input allows users to utilize the default template provided by the ``ansys/actions`` repository. For migration instructions, see the migration steps below. .. note:: The default template is only available for the ``ansys/actions/doc-changelog`` action and is in the reStructuredText (rst) format. - Added a new input parameter ``fail-level`` to the ``ansys/actions/doc-style`` action. This input allows users to select the report level used to control check results. Default value is ``"error"`` but it can be changed to ``"any"``, ``"info"``, ``"warning"``, or ``"error"``. - The ``release-github/action.yml`` action has been improved with the ability to extend a Github release note with instructions on how to verify the release's artifacts attestations with `Github's command-line tool `_. - Added a new input ``attest-provenance`` to the ``ansys/actions/build-library`` and ``ansys/actions/build-wheelhouse`` actions. Note that adding provenance attestations requires write permissions for `id-token` and `attestation`. For example: .. code-block:: yaml build-library: name: Build library runs-on: ubuntu-latest permissions: attestations: write contents: read id-token: write steps: - name: "Build library source and wheel artifacts" uses: ansys/actions/build-library@v8 with: library-name: ${{ env.PACKAGE_NAME }} python-version: ${{ env.MAIN_PYTHON_VERSION }} attest-provenance: true - Added two inputs to the ``release-github/action.yml`` action. The first input parameter ``add-artifact-attestation-notes`` allows users to add artifact attestation notes to the Github release notes. The second input parameter ``generate_release_notes`` allows users to deactivate the notes automatically generated by default. - Added a new input parameter ``randomize`` to the ``ansys/actions/tests-pytest`` action to randomize the order of the tests. **Migration Steps:** - The default documentation includes tabs and tab items, providing a clean changelog reStructuredText (rst) file. To use this feature, add ``sphinx-design`` as a dependency in your ``pyproject.toml`` file and include ``sphinx_design`` as an extension in your ``conf.py`` file. .. code-block:: toml [project.optional-dependencies] doc = [ "sphinx-design", ] In your ``conf.py`` file, add the following line: .. code-block:: python extensions = [ "sphinx_design", ] After updating the actions to v9, a comment is made in the PR with the changelog file, suggesting to add ``sphinx-design`` as a dependency. You can ignore that comment if you have already added the dependency. After merging the PR, the changelog file updates with the new template, and the new release changelog is created using the new template. Version ``v8`` -------------- **Breaking changes:** - Use secrets for commit and push credentials within ``ansys/actions/doc-changelog``, ``ansys/actions/doc-deploy-changelog``, ``ansys/actions/doc-deploy-dev``, and ``ansys/actions/doc-deploy-stable``. - The token input is required in the ``ansys/actions/release-github`` action. **Deprecated features:** - The ``ansys/actions/doc-deploy-index`` action has been deprecated and will be removed in the next release. With the deprecation of ``pymeilisearch`` and the adoption of a static search index via the ``ansys-sphinx-theme``, the ``ansys/actions/doc-deploy-index`` action is no longer necessary. - The ``ansys/actions/commit-style`` action has been renamed to ``ansys/actions/check-pr-title``. - The ``ansys/actions/branch-name-style`` actions has been removed in favor of `GitHub rulesets `_. **Migration steps:** - Add the following required inputs to ``ansys/actions/doc-changelog``, ``ansys/actions/doc-deploy-changelog``, ``ansys/actions/doc-deploy-dev``, and ``ansys/actions/doc-deploy-stable``: .. code:: yaml bot-user: ${{ secrets.PYANSYS_CI_BOT_USERNAME }} bot-email: ${{ secrets.PYANSYS_CI_BOT_EMAIL }} - Add the permissions and token to the ``ansys/actions/release-github`` action as follows: .. code:: yaml release-github: name: "Release to GitHub" runs-on: ubuntu-latest needs: [build-library] if: github.event_name == 'push' && contains(github.ref, 'refs/tags') permissions: contents: write steps: - name: "Release to GitHub" uses: ansys/actions/release-github@{{ version }} with: library-name: "ansys--" token: ${{ secrets.GITHUB_TOKEN }} Version ``v7`` -------------- **New features:** - Added an optional input to the ``ansys/actions/build-library`` action to disable library build validation on demand using the ``validate-build: false`` argument. This is useful when you want to skip the library build validation step in the action. - Incorporated the usage of `Trusted Publisher `_ in the ``ansys/actions/release-pypi-*`` actions. This is useful when you want to sign the package before uploading it to PyPI. **Migration steps:** - To set up your repository to use the ``ansys/actions/release-pypi-*`` action with the `Trusted Publisher`_ approach, see the :ref:`release_pypi_trusted_publisher`. Version ``v6`` -------------- **New features:** - Added the ``ansys/actions/check-vulnerabilities`` action to check for third-party and first-party vulnerabilities. This is useful when you want to hide the vulnerabilities from the logs, but still want to fail the action if vulnerabilities are found. - Avoid creating issues by default if vulnerabilities are found in the ``ansys/actions/check-vulnerabilities`` action. - Create a changelog fragment file for each pull request using ``towncrier`` in the ``ansys/actions/doc-changelog`` action. - Generate a new section in ``CHANGELOG.md`` if fragment files exist using ``towncrier`` in the ``ansys/actions/doc-deploy-changelog`` action. By default, it updates the CHANGELOG in the release branch and creates a pull request into the main branch with the updated CHANGELOG and deleted fragment files. - SEO improvements. These are implemented inside the `doc-deploy-dev `_ and the `doc-deploy-stable `_. Users are not required to apply any changes to their ``conf.py`` or ``.github/workflows/*.yml`` files. Noticable changes include: - No more redirect from landing page to `version/stable/index.html` - Generation of ``robots.txt`` file for avoiding indexing old documentation versions - Generation of `sitemap.xml` file for quicker indexing of `version/stable/` pages - Inclusion of `canonical` link tags in all HTML files for SEO purposes - Extend ``ansys/actions/doc-build`` to be able to run in Windows runners. To build the documentation in a Windows runner, we install ``Chocolatey`` and ``MiKTeX``. - Allow ``ansys/actions/commit-style`` to work with upper case in the type field of a commit. Expected types are upper cases of `conventional commit types `_. **Breaking changes:** - Upgrade default ``vale`` version from ``2.29.6`` to ``3.4.1`` in ``ansys/actions/doc-style`` action. - Vale configuration file ``.vale.ini`` and ``Vocab/ANSYS`` has to be changed. **Migration steps:** - To set up your repository to use the ``ansys/actions/doc-changelog`` action, see the :ref:`docs_changelog_action_setup`. - To set up your repository to use the ``ansys/actions/doc-deploy-changelog`` action, see the :ref:`docs_deploy_changelog_action_setup`. - To set up your repository to use the ``ansys/actions/doc-style`` action, see the :ref:`docs_style_vale_update`. Version ``v5`` -------------- **New features:** - Added ``ansys/action/check-vulnerabilities`` to verify third party and first party vulnerabilities. This action uses ``bandit`` and ``safety`` to detect vulnerabilities in the code and dependencies, respectively. - Added ``ansys/actions/docker-style`` to detect Dockerfile style issues using ``hadolint``. - Allow ``vale`` version input in ``ansys/actions/doc-style`` action. By default, ``2.29.6`` is used. - Allow using the twine ``--skip-existing`` flag in the ``ansys/actions/release-pypi-*`` actions. - Allow using the ``ansys/actions/doc-build`` action to build documentation using a dedicated requirements file (and consequently, no need to have a Python project to use it). - Allow for independent documentation releases in case of patch release when using ``ansys/actions/doc-deploy-stable`` action. This will create independent documentation versions for patch releases. **Breaking changes:** - Upgrade ``actions/upload-artifact`` and ``actions/download-artifact`` to version ``v4``. - Upgrade ``actions/setup-python`` to version ``v5``. **Migration steps:** - Since artifacts are uploaded/downloaded using the new ``actions/*-artifact``, artifact names cannot be duplicated inside the workflow. Also, versions ``v3`` and ``v4`` are incompatible with each other. If you are using version ``v3`` independently inside your workflow, you need to upgrade to version ``v4``. - The upgrade to ``actions/setup-python`` version ``v5`` is not mandatory, but it is recommended to use the latest version. However, it has been seen that in Windows self-hosted runners, if a certain Python version is not already stored in the cache, the action fails. This is a known issue and the workaround is to use the previous version of the action. **Dependency changes:** - Upgrade ``actions/checkout`` to version ``v4``. - Upgrade ``pypa/cibuildwheel`` to version ``v2.16.2``. - Upgrade ``peter-evans/create-or-update-comment`` to version ``v4``. - Upgrade ``vimtor/action-zip`` to version ``v1.2``. Version ``v4`` -------------- **Breaking changes:** - Multi-version documentation deployment using ``ansys/actions/doc-deploy-stable`` and ``ansys/actions/doc-deploy-dev``. **Migration steps:** - Visit `Enable multi-version documentation `_ for a detailed migration guide. .. toctree:: :hidden: :maxdepth: 3 docs-changelog-setup docs-deploy-changelog-setup docs-style-vale-version-update docs-deploy-pr-setup release-pypi-trusted-publisher docs-migrate-fork-pr-setup