Skip to content

ci: support Pro in release-tag-creation action [ED-25747] - #60

Open
davseve wants to merge 6 commits into
mainfrom
ci/ED-25747-release-tag-creation-pro
Open

davseve wants to merge 6 commits into
mainfrom
ci/ED-25747-release-tag-creation-pro

Conversation

@davseve

@davseve davseve commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

Summary

Lets the release-tag-creation action release Elementor Pro as well as Core, selected by one new input.

  • New input plugin: core | pro (default core). It replaces plugin_file, version_constant, update_readme and update_elementor_tested_up_to. The mapping is in plugin-config.ts:

    plugin Plugin file Version constant readme.txt "Elementor tested up to"
    core elementor.php ELEMENTOR_VERSION updated not touched
    pro elementor-pro.php ELEMENTOR_PRO_VERSION not touched set from Core release/<channel>
  • Pro "Elementor tested up to". The action fetches elementor.php from Core's matching release/<channel> branch, reads its Version: and writes it as X.Y.Z, with any beta suffix removed (elementor-tested-up-to.ts).

  • Shared utils (version-files.ts). patchPhpVersion takes the constant to update, typed as VersionConstant (ELEMENTOR_VERSION or ELEMENTOR_PRO_VERSION). A new patchPhpHeaderField updates any * Field: value header line. Both now throw if the expected line is missing, instead of silently committing an unchanged file.

  • The commit step and the job summary now read plugin_file and update_readme from the version-update step's outputs, not from inputs.

Compatibility

  • Core: no change needed. Core's workflow doesn't pass the old inputs, and plugin defaults to core, which matches the old defaults (elementor.php, ELEMENTOR_VERSION, readme updated).
  • Pro: must pass plugin: pro. If it's forgotten, the run fails reading elementor.php, which doesn't exist in the Pro repo, before anything is committed or tagged.

Testing

  • vitest in actions/release-tag-creation and packages/editor-github-actions-utils passes.
  • tsc and eslint are clean.
  • Not yet run end to end in a workflow.

✨ PR Description

1. Problem & Context

Support for releasing Elementor Pro via the release-tag-creation action ED-25747. The action now differentiates between 'core' and 'pro' plugins to apply specific version constants and handle the "Elementor tested up to" header for Pro.

2. What Changed (Where)

File Change
elementor-tested-up-to.ts Added version fetching and semver normalization from Core release branches.
plugin-config.ts Defined configurations for 'core' vs 'pro' (files, constants, toggle flags).
update-version-files.ts Refactored run() to use dynamic plugin config and conditional header patching.
action.yml Added plugin input and updated outputs/commit logic to be plugin-aware.
version-files.ts Added patchPhpHeaderField and parameterized patchPhpVersion for custom constants.
*.test.ts Added unit tests for new patching logic, config resolution, and version fetching.

3. How It Works

Action reads INPUT_PLUGIN $\rightarrow$ resolves config (file path/constant) $\rightarrow$ patches version in PHP $\rightarrow$ if Pro, fetches latest Core version via HTTP to update "Elementor tested up to" header $\rightarrow$ conditionally updates readme.txt for Core.

Generated by LinearB AI and added by gitStream.
AI-generated content may contain inaccuracies. Please verify before using.
💡 Tip: You can customize your AI Description using Guidelines Learn how

Replace plugin_file, version_constant, update_readme and update_elementor_tested_up_to with a single required plugin input (core | pro). Pro bumps elementor-pro.php / ELEMENTOR_PRO_VERSION and sets the "Elementor tested up to" header from Core release/<channel>; Core keeps bumping elementor.php and readme.txt.

Co-authored-by: Cursor <cursoragent@cursor.com>
@wiz-9a149474ff

wiz-9a149474ff Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Wiz Scan Summary

Scanner Findings
Vulnerability Finding Vulnerabilities -
Data Finding Sensitive Data -
Secret Finding Secrets -
IaC Misconfiguration IaC Misconfigurations -
SAST Finding SAST Findings 4 Medium
Software Management Finding Software Management Findings -
Total 4 Medium

View scan details in Wiz

To detect these findings earlier in the dev lifecycle, try the Wiz Code extension for VS Code, JetBrains, or Visual Studio.

davseve and others added 3 commits October 6, 2026 14:51
…25747]

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
max-zu
max-zu previously approved these changes Oct 6, 2026
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>

@Ntnelbaba Ntnelbaba left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review

Re-checked at df341e32 (not from zero).

Still open:

  1. Medium — fetchCoreReleaseVersion raw.githubusercontent fetch has no cache-bust (inline).
  2. Low — plugin_file / update_readme outputs are set before the PHP write succeeds (inline).
  3. Low — no unit/integration test for run() in update-version-files.ts.

plugin default core, plugin-config mapping, and throw-on-missing header/define behavior look good.

Comment-only; not approving.

channel: ReleaseChannel,
): Promise<string> {
const url = coreReleasePluginFileUrl(channel);
const response = await fetch(url);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Medium: fetch(url) against raw.githubusercontent.com has no cache-bust (Cache-Control, ?t=, or authenticated GitHub Contents API).

CDN/cache can return a stale elementor.php / Version: for Pro’s “Elementor tested up to”, so a release tag can bake an outdated Core version.

Suggestion: Add a cache-buster query param (e.g. run id / timestamp), send Cache-Control: no-cache, or read via the GitHub API / git checkout of release/<channel> instead of raw.

console.log('Update readme', shouldUpdateReadme);
console.log('Update Elementor tested up to', shouldUpdateTestedUpTo);

setOutput('plugin_file', pluginFile);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✨ Low: plugin_file / update_readme are written to $GITHUB_OUTPUT before readFileSync / patchPhpVersion / writeFileSync.

If the patch fails afterward the step exits non-zero (so commit won’t run), but outputs are already emitted. Prefer setting those outputs only after a successful write.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants