From e2b72f5c4ca981b696f8eb334fc8347604229315 Mon Sep 17 00:00:00 2001 From: jgjesdal Date: Thu, 1 Oct 2026 12:09:43 +0200 Subject: [PATCH] ci: require releases to be tagged on a release/v* branch CI now also runs on pushes to release/v*. release.yml refuses to publish a vX.Y.Z tag unless its commit is on release/vX.Y or release/vX.Y.Z. Co-Authored-By: Claude Opus 5.5 (1M context) Signed-off-by: jgjesdal --- .github/workflows/ci.yml | 2 +- .github/workflows/release.yml | 11 +++++++++++ AGENTS.md | 5 +++++ 3 files changed, 17 insertions(+), 1 deletion(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 05d3a5e..01f6d5e 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -2,7 +2,7 @@ name: CI on: push: - branches: [main] + branches: [main, 'release/v*'] pull_request: workflow_dispatch: diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 58d10eb..5ef6f3f 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -22,6 +22,8 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@v6 + with: + fetch-depth: 0 - run: | set -euo pipefail crate=$(grep -m1 '^version' Cargo.toml | cut -d'"' -f2) @@ -44,6 +46,15 @@ jobs: echo "::error::tag $GITHUB_REF_NAME does not match manifest version $crate" exit 1 fi + # Releases are cut from release/vX.Y (or release/vX.Y.Z), never from main. + minor=$(printf '%s' "$GITHUB_REF_NAME" | cut -d. -f1,2) + git fetch --quiet origin '+refs/heads/release/v*:refs/remotes/origin/release/v*' + branches=$(git branch -r --contains "$GITHUB_SHA" --list 'origin/release/v*' | sed 's/^ *//') + echo "release branches containing $GITHUB_SHA: ${branches:-none}" + if ! printf '%s\n' "$branches" | grep -Fxq -e "origin/release/$minor" -e "origin/release/$GITHUB_REF_NAME"; then + echo "::error::tag $GITHUB_REF_NAME is not on release/$minor or release/$GITHUB_REF_NAME" + exit 1 + fi fi crate: diff --git a/AGENTS.md b/AGENTS.md index 20d8576..7b432db 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -19,6 +19,11 @@ A release is a docs event too. When you tag `vX.Y.Z`, open an issue on datahub-s start names the latest release, and a new minor version gets a frozen snapshot of the docs. The rules are in that repository's `AGENTS.md`, under "Versions". +Releases are cut from a release branch, not from `main`. Tag `vX.Y.Z` on a commit of +`release/vX.Y` (one branch per minor line; `release/vX.Y.Z` is also accepted). `release.yml` +refuses to publish a tag that no matching release branch contains, so push the branch before the +tag. CI runs on pushes to `main` and `release/v*`. + ## Build / Test ```