Skip to content

ci(release): stop pushing version bumps to protected main - #30

Merged
asachs01 merged 1 commit into
mainfrom
ci/fix-semantic-release-protected-branch-push
Sep 8, 2026
Merged

asachs01 merged 1 commit into
mainfrom
ci/fix-semantic-release-protected-branch-push

Conversation

@asachs01

@asachs01 asachs01 commented Sep 8, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Release job has failed with GH006 ("Changes must be made through a pull request") since the WYRE-AI org migration (v1.0.6) tightened branch protection on main.
  • @semantic-release/git's prepare step tries to commit package.json/package-lock.json/CHANGELOG.md back to main directly — blocked, and has blocked every release attempt since, including PR fix: correct org-scoping header name and checkin/computer-group response contracts #29's org-scoping-header fix from this session.
  • Removes @semantic-release/git and @semantic-release/changelog from the plugin pipeline. @semantic-release/npm still bumps and publishes the package version correctly on its own; only the commit-back to the repo is gone. Same fix conduit's own release pipeline already adopted for this exact class of failure — release notes move to GitHub Releases, CHANGELOG.md becomes hand-maintained going forward (noted at the top of the file).
  • Also fixed this repo's origin remote, which still pointed at the pre-migration wyre-technology URL (worked via GitHub's redirect, but worth cleaning up).

Test plan

  • .releaserc.json validated as parseable JSON
  • Post-merge: confirm the Release workflow actually succeeds and publishes v1.0.7 (this PR can't self-verify that — the next push to main will)

https://claude.ai/code/session_01DYZ5f9GLKpF8Cke9Xoh3a8


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

…ected main

The Release job has failed with GH006 ("Changes must be made through a
pull request") since the WYRE-AI org migration (1.0.6) tightened branch
protection on main. @semantic-release/git's prepare step tries to commit
package.json/package-lock.json/CHANGELOG.md back to main directly, which
that protection now correctly rejects — blocking every release since,
including this session's threatlocker org-scoping-header fix (#29).

Removes @semantic-release/git and @semantic-release/changelog from the
plugin pipeline (changelog's local file write is pointless without git
to persist it). @semantic-release/npm still bumps and publishes the
package version correctly on its own; only the commit-back is gone.
Same fix conduit's own release pipeline already adopted for this exact
GH006 class — release notes move to GitHub Releases, this file becomes
hand-maintained going forward.

Claude-Session: https://claude.ai/code/session_01DYZ5f9GLKpF8Cke9Xoh3a8
@coderabbitai

coderabbitai Bot commented Sep 8, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: d8a56562-0214-4b3d-8b0c-c1863e59414d


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@asachs01
asachs01 merged commit 7352a24 into main Sep 8, 2026
2 checks passed
@asachs01
asachs01 deleted the ci/fix-semantic-release-protected-branch-push branch September 8, 2026 20:51
@github-actions

github-actions Bot commented Sep 8, 2026

Copy link
Copy Markdown

🎉 This PR is included in version 1.0.7 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant