← posts/b.log()

blog92@web:~$ cat posts/github-09-pages-releases-and-security.md

GIT2 min read

GitHub 완전 정복 9편 — Pages·Releases·보안 기능·gh CLI와 오픈소스 기여

GitHub Pages 배포 워크플로, 태그와 Semantic Versioning·릴리스 자동화, Dependabot·CodeQL·Secret scanning·Push protection, gh CLI 주요 명령, fork에서 PR까지의 오픈소스 기여 흐름과 저장소 문서·라이선스 선택을 다룹니다.

이전 편: 8편 — GitHub Actions와 브랜치 보호 규칙

이 글의 예제에 나오는 액션 버전(@v4 등)은 작성 시점 기준입니다. 실제로 적용할 때는 각 액션 저장소의 최신 릴리스를 확인하세요.

절 번호는 원본 문서의 것을 그대로 유지합니다. 8편이 6.2 브랜치 보호 규칙에서 끝났으니 이 편은 같은 6장의 6.3부터 이어집니다.

6.3 GitHub Pages

yaml
name: Deploy Pages
on:
  push:
    branches: [main]
 
permissions:
  contents: read
  pages: write
  id-token: write
 
jobs:
  deploy:
    environment:
      name: github-pages
      url: ${{ steps.deployment.outputs.page_url }}
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: actions/setup-node@v4
        with: { node-version-file: .nvmrc, cache: 'npm' }
      - run: npm ci && npm run build
      - uses: actions/configure-pages@v5
      - uses: actions/upload-pages-artifact@v3
        with:
          path: ./out
      - id: deployment
        uses: actions/deploy-pages@v5

username.github.io 저장소를 만들면 개인 사이트가 됩니다. 커스텀 도메인은 Settings → Pages에서 연결하고 DNS에 CNAME을 등록합니다.

6.4 Releases와 태그

bash
git tag v1.0.0                              # 경량 태그
git tag -a v1.0.0 -m "첫 정식 릴리스"        # 주석 태그 (권장) ★
git tag -s v1.0.0 -m "서명된 릴리스"         # 서명 태그
git tag                                     # 목록
git show v1.0.0                             # 상세
git push origin v1.0.0                      # 태그 전송 (push에 자동 포함 안 됨!) ★
git push origin --tags                      # 전부
git tag -d v1.0.0                           # 로컬 삭제
git push origin --delete v1.0.0             # 원격 삭제 ⚠

Semantic Versioning

text
MAJOR.MINOR.PATCH   예: 2.4.1
  │     │     └── 버그 수정 (하위 호환)
  │     └──────── 기능 추가 (하위 호환)
  └────────────── 호환성 깨짐
 
프리릴리스: 1.0.0-alpha.1, 1.0.0-rc.2

릴리스 자동화

yaml
name: Release
on:
  push:
    tags: ['v*']
 
permissions:
  contents: write
 
jobs:
  release:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
        with: { fetch-depth: 0 }
      - run: npm ci && npm run build
      - uses: softprops/action-gh-release@v2
        with:
          generate_release_notes: true
          files: dist/*

Conventional Commits를 지켰다면 semantic-release가 커밋만 읽고 버전 결정 → CHANGELOG 생성 → 태그 → 배포까지 전부 자동으로 합니다. 2편의 커밋 컨벤션이 여기서 보상을 줍니다.

6.5 보안 기능

기능설명
Dependabot alerts취약한 의존성 자동 탐지
Dependabot updates업데이트 PR 자동 생성
CodeQL코드 정적 분석으로 취약점 탐지
Secret scanning커밋된 API 키/토큰 탐지
Push protection키가 포함된 push 자체를 차단 ★
Security policySECURITY.md — 취약점 신고 창구
yaml
# .github/dependabot.yml
version: 2
updates:
  - package-ecosystem: "npm"
    directory: "/"
    schedule:
      interval: "weekly"
    open-pull-requests-limit: 5
    groups:
      dev-dependencies:
        dependency-type: "development"

6.6 GitHub CLI (gh)

bash
gh auth login
 
# 저장소
gh repo create my-project --public --clone
gh repo clone user/repo
gh repo view --web
 
# PR
gh pr create --title "feat: 로그인" --body "Closes #42"
gh pr list
gh pr view 42
gh pr checkout 42            # 남의 PR을 로컬에서 테스트 ★
gh pr diff 42
gh pr review 42 --approve
gh pr merge 42 --squash --delete-branch
 
# 이슈
gh issue create --title "버그" --label bug
gh issue list --assignee @me
 
# Actions
gh run list
gh run view --log
gh run watch                 # 실시간 모니터링 ★
 
# 릴리스
gh release create v1.0.0 --generate-notes

gh pr checkout은 특히 유용합니다. 리뷰할 PR을 브라우저로만 보지 말고 로컬에서 직접 돌려볼 수 있습니다.

6.7 오픈소스 기여 워크플로

bash
# 1. GitHub에서 Fork 버튼 클릭
 
# 2. 내 포크 클론
git clone git@github.com:myname/project.git
cd project
 
# 3. 원본을 upstream으로 등록 ★
git remote add upstream https://github.com/original/project.git
git remote -v
 
# 4. 최신 동기화
git fetch upstream
git switch main
git merge upstream/main
git push origin main
 
# 5. 브랜치 생성 후 작업
git switch -c fix/typo-in-readme
# ... README.md를 고친다 ...
git add README.md
git commit -m "docs: README 오타 수정"
git push -u origin fix/typo-in-readme
 
# 6. PR 생성 (base: original/main ← head: myname/fix/typo-in-readme)
gh pr create --repo original/project

기여 전 체크리스트: CONTRIBUTING.md 읽기 / 이슈로 먼저 논의 / 기존 코드 스타일 따르기 / 테스트 추가 / 커밋 스쿼시해서 깔끔하게.

6.8 저장소 문서화

text
repo/
├── README.md              # 프로젝트 소개 (필수)
├── LICENSE                # 라이선스 (오픈소스면 필수)
├── CONTRIBUTING.md        # 기여 가이드
├── CODE_OF_CONDUCT.md     # 행동 강령
├── SECURITY.md            # 보안 신고 절차
├── CHANGELOG.md           # 변경 이력
└── .github/
    ├── CODEOWNERS
    ├── PULL_REQUEST_TEMPLATE.md
    ├── ISSUE_TEMPLATE/
    ├── dependabot.yml
    └── workflows/

README 구성

markdown
# 프로젝트명
한 줄 설명
 
![badge](https://img.shields.io/...)
 
## 설치
## 사용법
## 기능
## 기술 스택
## 기여
## 라이선스

라이선스 선택

라이선스특징
MIT가장 자유로움, 저작권 표시만
Apache 2.0MIT + 특허 조항
GPL v3파생물도 반드시 공개 (copyleft)
BSD-3MIT와 유사

라이선스가 없으면 법적으로 "모든 권리 유보" 라 남이 쓸 수 없습니다. 공개할 거면 반드시 넣으세요.

더 깊이

COMMENTS (…)

댓글을 불러오는 중이에요.

NEW COMMENT0 / 1000
⌘↵ 전송

blog92@web:~$ cd ..