From bdc266fb746da56f0db27006d140930cfbf17d45 Mon Sep 17 00:00:00 2001 From: David Bourgault Date: Tue, 6 Oct 2026 10:24:43 -0400 Subject: [PATCH] Release without Grafana's catalog validator; run CI on main The v2.0.0 release failed in grafana/plugin-actions/build-plugin. That action runs Grafana's catalog-submission validator (@grafana/plugin-validator@latest) as a hard gate, and it reported three errors: - "organization not found": the catalog requires the plugin ID's prefix (transitapp) to be a registered Grafana Cloud account. - Relative links in the README, which the catalog cannot resolve. - High-severity advisories in package-lock.json for basic-ftp and braces. This plugin is installed directly, not published to the catalog, so the release workflow now builds, tests and packages it itself and publishes a GitHub release with the zip, its sha1, and the latest CHANGELOG section as notes. It checks that the tag matches package.json's version. Two other reasons to drop the action: braces has no fixed release (every version through 3.0.3, the latest, is affected), so the scanner would block every release regardless; and the action pulls its packaging step from @main and the validator from @latest, so the rules a release must pass change without notice. Grafana's plugin.json check still runs in CI. If the plugin ever goes to the catalog, switch back to build-plugin. Also fixed: - basic-ftp: overridden to ^6.2.2. Nothing upstream offers a fixed version; even the latest get-uri, via @grafana/sign-plugin's proxy support, wants 5.x. 6.0's only breaking change disables separate FTP transfer hosts, which get-uri does not use. braces is dev-only (jest, eslint-webpack-plugin) and not in the bundle. - README links are absolute, and the screenshot and licence URLs point at main; they pointed at master, which does not exist here, and returned 404. - CI and CodeQL only ran on master, so they never ran on this repo, including on the PR that merged the modernisation. They now run on main, and CodeQL moves to its current major, v4. - The release uses the Node version in .nvmrc (22); the action defaulted to 20. The README gains an Installation section with the Helm values, and CONTRIBUTING describes the new release steps. Co-Authored-By: Claude Opus 5.5 --- .github/workflows/ci.yml | 4 +- .github/workflows/codeql-analysis.yml | 10 ++-- .github/workflows/release.yml | 82 ++++++++++++++++++++++----- CONTRIBUTING.md | 14 +++-- README.md | 35 +++++++++--- package-lock.json | 6 +- package.json | 3 +- src/plugin.json | 2 +- 8 files changed, 118 insertions(+), 38 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 2e5d33c..38f8f2b 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -3,10 +3,10 @@ name: CI on: push: branches: - - master + - main pull_request: branches: - - master + - main permissions: contents: read diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml index c1f05a8..3ce1dd1 100644 --- a/.github/workflows/codeql-analysis.yml +++ b/.github/workflows/codeql-analysis.yml @@ -13,10 +13,10 @@ name: "CodeQL" on: push: - branches: [ master ] + branches: [ main ] pull_request: # The branches below must be a subset of the branches above - branches: [ master ] + branches: [ main ] schedule: - cron: '18 0 * * 2' @@ -42,7 +42,7 @@ jobs: # Initializes the CodeQL tools for scanning. - name: Initialize CodeQL - uses: github/codeql-action/init@v3 + uses: github/codeql-action/init@v4 with: languages: ${{ matrix.language }} # If you wish to specify custom queries, you can do so here or in a config file. @@ -53,7 +53,7 @@ jobs: # Autobuild attempts to build any compiled languages (C/C++, C#, or Java). # If this step fails, then you should remove it and run the build manually (see below) - name: Autobuild - uses: github/codeql-action/autobuild@v3 + uses: github/codeql-action/autobuild@v4 # â„šī¸ Command-line programs to run using the OS shell. # 📚 https://git.io/JvXDl @@ -67,4 +67,4 @@ jobs: # make release - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@v3 + uses: github/codeql-action/analyze@v4 diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 93073d1..d3fa7ab 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -1,28 +1,84 @@ -# This GitHub Action automates the process of building Grafana plugins. -# (For more information, see https://github.com/grafana/plugin-actions/blob/main/build-plugin/README.md) +# Builds the plugin on a version tag and publishes it as a GitHub release, with +# the zip that Grafana installs (see the Helm example in the README). +# +# This deliberately does not use grafana/plugin-actions/build-plugin. That +# action runs Grafana's catalog-submission validator as a hard gate: it requires +# the plugin ID's prefix to be a registered Grafana Cloud account, and it fails on +# any high-severity advisory in package-lock.json, including development-only +# tools that never reach the plugin bundle. This plugin is installed directly +# rather than published to the catalog, so those rules do not apply. Grafana's +# plugin.json check still runs in CI. If the plugin is ever submitted to the +# catalog, switch back to build-plugin. name: Release on: push: tags: - - 'v*' # Run workflow on version tags, e.g. v1.0.0. + - 'v*' # e.g. v2.0.0 -permissions: read-all +permissions: + contents: read jobs: release: - permissions: - contents: write runs-on: ubuntu-latest + permissions: + contents: write # to create the release steps: - uses: actions/checkout@v6 with: persist-credentials: false - - uses: grafana/plugin-actions/build-plugin@build-plugin/v1.2.0 - # Uncomment to enable plugin signing - # (For more info on how to generate the access policy token see - # https://grafana.com/developers/plugin-tools/publish-a-plugin/sign-a-plugin#generate-an-access-policy-token) - # with: - # # Make sure to save the token in your repository secrets - # policy_token: ${{ secrets.GRAFANA_ACCESS_POLICY_TOKEN }} + - name: Setup Node.js environment + uses: actions/setup-node@v6 + with: + node-version-file: .nvmrc + cache: 'npm' + + - name: Install dependencies + run: npm ci + + - name: Check types + run: npm run typecheck + - name: Lint + run: npm run lint + - name: Unit tests + run: npm run test:ci + - name: Build frontend + run: npm run build + + - name: Check the tag matches the plugin version + id: metadata + run: | + PLUGIN_ID=$(jq -r .id dist/plugin.json) + PLUGIN_VERSION=$(jq -r .info.version dist/plugin.json) + if [ "v${PLUGIN_VERSION}" != "${GITHUB_REF_NAME}" ]; then + echo "::error::Tag ${GITHUB_REF_NAME} does not match the version in package.json (${PLUGIN_VERSION})" + exit 1 + fi + echo "plugin-id=${PLUGIN_ID}" >> "$GITHUB_OUTPUT" + echo "archive=${PLUGIN_ID}-${PLUGIN_VERSION}.zip" >> "$GITHUB_OUTPUT" + + - name: Package plugin + run: | + # Grafana expects the zip to hold a single folder named after the plugin ID + mv dist "${PLUGIN_ID}" + zip -qr "${ARCHIVE}" "${PLUGIN_ID}" + sha1sum "${ARCHIVE}" > "${ARCHIVE}.sha1" + env: + PLUGIN_ID: ${{ steps.metadata.outputs.plugin-id }} + ARCHIVE: ${{ steps.metadata.outputs.archive }} + + - name: Release notes from the changelog + # The first "## " section of CHANGELOG.md, i.e. the latest version's entry + run: awk '/^## /{n++} n==1' CHANGELOG.md > release-notes.md + + - name: Create release + run: | + gh release create "${GITHUB_REF_NAME}" "${ARCHIVE}" "${ARCHIVE}.sha1" \ + --verify-tag \ + --title "${GITHUB_REF_NAME}" \ + --notes-file release-notes.md + env: + GH_TOKEN: ${{ github.token }} + ARCHIVE: ${{ steps.metadata.outputs.archive }} diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 09de288..5d5e81b 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -106,14 +106,16 @@ for the supported ways to customise it. ## Releasing a new version -1. Update the CHANGELOG.md document to include changes of the new release -1. Bump `version` in `package.json` to match -1. Tag the master with the new version: +1. Add a `## vX.Y.Z` section at the top of CHANGELOG.md for the new release +1. Bump `version` in `package.json` to match (`npm version --no-git-tag-version X.Y.Z`) +1. Merge to `main`, then tag that commit: ```sh - git tag v2.0.0 - git push origin v2.0.0 + git tag vX.Y.Z + git push origin vX.Y.Z ``` -1. Complete the release information in github. +1. The Release workflow builds, tests and packages the plugin, then publishes a + GitHub release with the zip attached and the changelog section as its notes. + It fails if the tag doesn't match the version in `package.json`. ## Notes diff --git a/README.md b/README.md index fc9c8e7..697239b 100644 --- a/README.md +++ b/README.md @@ -5,7 +5,7 @@ > to its authors. That project is no longer maintained. TransitApp has modified > this fork since October 2026: it runs on current Grafana (12.3 and later) and > adds layer reordering, per-layer query handling and other fixes; see the -> [changelog](CHANGELOG.md). It remains licensed under the [AGPL-3.0](LICENSE). +> [changelog](https://github.com/TransitApp/map-panel/blob/main/CHANGELOG.md). It remains licensed under the [AGPL-3.0](https://github.com/TransitApp/map-panel/blob/main/LICENSE). > > **Maintenance:** TransitApp maintains this fork for its own use. Issues and pull > requests are welcome and handled on a best-effort basis. @@ -20,9 +20,9 @@ panel with several functionalities: * A new map layer leveraging [Inverse distance weighting](https://en.wikipedia.org/wiki/Inverse_distance_weighting) (IDW) interpolation for scattered data points using Shepard's method. -![Marker layer](https://github.com/TransitApp/map-panel/raw/master/example.png) +![Marker layer](https://github.com/TransitApp/map-panel/raw/main/example.png) -![IDW layer](https://github.com/TransitApp/map-panel/raw/master/example4.png) +![IDW layer](https://github.com/TransitApp/map-panel/raw/main/example4.png) New customization options available for the markers layer: @@ -31,7 +31,7 @@ New customization options available for the markers layer: * A fully customizable pin with the possibility to change colors, shapes and sizes * The possibility to select which properties to be displayed on the popup -![Marker layer options](https://github.com/TransitApp/map-panel/raw/master/example2.png) +![Marker layer options](https://github.com/TransitApp/map-panel/raw/main/example2.png) Cluster options: @@ -52,7 +52,7 @@ Popup Options: * Display the Timestamp * Selectable properties -![Marker layer options](https://github.com/TransitApp/map-panel/raw/master/example3.png) +![Marker layer options](https://github.com/TransitApp/map-panel/raw/main/example3.png) Options available for the IDW layer: @@ -70,10 +70,31 @@ Pupup Options: * Selectable properties -![Marker layer options](https://github.com/TransitApp/map-panel/raw/master/example5.png) +![Marker layer options](https://github.com/TransitApp/map-panel/raw/main/example5.png) It requires Grafana 12.3 or later. +## Installation + +The plugin is not in Grafana's plugin catalog and is not signed. Grafana +installs it from the zip attached to each +[GitHub release](https://github.com/TransitApp/map-panel/releases), and has to be +told to allow it. With the +[Grafana Helm chart](https://github.com/grafana-community/helm-charts/tree/main/charts/grafana): + +```yaml +plugins: + - transitapp-map-panel@2.0.0@https://github.com/TransitApp/map-panel/releases/download/v2.0.0/transitapp-map-panel-2.0.0.zip +grafana.ini: + plugins: + allow_loading_unsigned_plugins: transitapp-map-panel +``` + +The version in the entry decides which release is installed; change it to +upgrade. Without Helm, set `GF_PLUGINS_PREINSTALL_SYNC` to the same +`id@version@url` value and `GF_PLUGINS_ALLOW_LOADING_UNSIGNED_PLUGINS` to the +plugin ID. + ## Migrating from the Orchestra Cities Map Panel The plugin ID changed from `orchestracities-map-panel` to `transitapp-map-panel`. @@ -114,4 +135,4 @@ For more information about panels, refer to the documentation on [Panels](https: ## Set up dev environment -See [Contributing](CONTRIBUTING.md). +See [Contributing](https://github.com/TransitApp/map-panel/blob/main/CONTRIBUTING.md). diff --git a/package-lock.json b/package-lock.json index 7c74e11..a253104 100644 --- a/package-lock.json +++ b/package-lock.json @@ -6008,9 +6008,9 @@ } }, "node_modules/basic-ftp": { - "version": "5.3.1", - "resolved": "https://registry.npmjs.org/basic-ftp/-/basic-ftp-5.3.1.tgz", - "integrity": "sha512-bopVNp6ugyA150DDuZfPFdt1KZ5a94ZDiwX4hMgZDzF+GttD80lEy8kj98kbyhLXnPvhtIo93mdnLIjpCAeeOw==", + "version": "6.2.2", + "resolved": "https://registry.npmjs.org/basic-ftp/-/basic-ftp-6.2.2.tgz", + "integrity": "sha512-LIkJcf/F6bTTfvE3k2YcTxrJsLKKVXiEpHZYkQP6JoqTb7khng7c13ckRTDQbqRh5IkehVH3F00sSlAa2F6DwA==", "dev": true, "license": "MIT", "engines": { diff --git a/package.json b/package.json index 0329e93..dd74191 100644 --- a/package.json +++ b/package.json @@ -95,6 +95,7 @@ }, "packageManager": "npm@11.19.1", "overrides": { - "ol": "$ol" + "ol": "$ol", + "basic-ftp": "^6.2.2" } } diff --git a/src/plugin.json b/src/plugin.json index 0515006..e066d58 100644 --- a/src/plugin.json +++ b/src/plugin.json @@ -27,7 +27,7 @@ }, { "name": "License", - "url": "https://github.com/TransitApp/map-panel/blob/master/LICENSE" + "url": "https://github.com/TransitApp/map-panel/blob/main/LICENSE" }, { "name": "Original project (Orchestra Cities)",