Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
28 changes: 28 additions & 0 deletions .github/workflows/release-check.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,10 @@ name: release-check
on:
push:
branches: [master]
# Tag pushes fire the tag-integrity job (below): the tag push itself
# is the green proof after a release, so no empty-commit re-trigger
# on master is needed.
tags: ['v*']

jobs:
tag-current:
Expand All @@ -25,3 +29,27 @@ jobs:
echo "::error:: git push origin --tags"
exit 1
fi

tag-integrity:
# Tag push is the green proof after a release. tag-current above only
# proves the tag EXISTs on origin; this proves the tag's CONTENT: the
# VERSION in the tagged tree must equal the tag name minus the leading
# v. Runs on tag pushes only.
if: startsWith(github.ref, "refs/tags/v")
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
# The tag ref itself (github.ref_name is the tag name on a tag
# push). We only read the checked-out tree, so no fetch-depth: 0.
ref: ${{ github.ref_name }}

- name: Tagged tree VERSION must equal the tag name
run: |
TAG=${GITHUB_REF_NAME#v}
VERSION=$(cat VERSION)
if [ "$VERSION" != "$TAG" ]; then
echo "::error::tag ${GITHUB_REF_NAME} points at a tree with VERSION=${VERSION}, tag name says ${TAG}"
echo "::error::re-tag on the right commit or fix VERSION before pushing"
exit 1
fi
14 changes: 8 additions & 6 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,11 +17,12 @@ Three files move together, as one unit, in the PR that ships a release:

**Why the tag is not optional:** `.github/workflows/release-check.yml`
runs `tag-current` on every push to master and fails the build with
`VERSION=X but tag vX is not on origin` if the tag is missing. The
workflow only triggers on push — pushing the tag alone does NOT
re-run it. If you add the tag after merging, push an empty commit to
master (`git commit --allow-empty`) to re-trigger `release-check` and
turn the red X green.
`VERSION=X but tag vX is not on origin` if the tag is missing. Pushing
the tag ALSO fires the workflow: the `tag-integrity` job runs on tag
pushes, checks out the tagged tree, and fails if that tree's `VERSION`
does not equal the tag name (leading `v` stripped). So the tag push
itself is the green proof after a release — no empty commit, no direct
push to master.

`skills/box-audit/SKILL.md` carries a `version:` in its frontmatter,
kept in sync **by hand** with `VERSION` (see the comment in that file)
Expand Down Expand Up @@ -84,7 +85,8 @@ follow:
file/line citations. Reviewers never merge.
3. **Maintainer release-tail card** (created only after an approving
verdict) merges, tags `v$VERSION` on the merge commit, and pushes
the empty commit to re-trigger `release-check`.
the tag — the tag push fires release-check (tag-integrity) which
is the green proof. No empty commit.

No agent merges without an approving review verdict on the PR — not
the coder that opened it, not a steered mid-run instruction, not
Expand Down
Loading