From 2584aca6f710f1a922be89f65dbbb0289ce0b83f Mon Sep 17 00:00:00 2001 From: Savyasachi Date: Fri, 28 Aug 2026 19:50:10 -0700 Subject: [PATCH] ci: gate the release on the full test matrix The release gate was strictly weaker than the test gate. test.yml ran a JDK matrix plus a lint job, while release.yml pinned a single JDK and ran one test step, so a red main could still publish to Clojars. This is not hypothetical. jose-clj 0.7.0 published broken: both JDK 11 cells and the lint job were failing on main, and the tag's own weaker check passed. The matrix and lint jobs move to a reusable test-matrix.yml that both workflows call, so the two gates cannot drift apart. release.yml becomes guards -> verify -> release: the cheap metadata guards fail fast before the matrix runs, verification covers everything test.yml covers for the tagged commit itself, and only then does anything reach Clojars. Verifying the tagged commit directly rather than querying the test workflow's conclusion avoids a race, since a tag can be pushed before the branch run finishes and a commit that never landed on a branch has no run at all. Publishing stays conditioned on github.ref_type == 'tag', and contents: write is now scoped to the release job instead of the whole workflow. --- .github/workflows/release.yml | 63 +++++++++++++++++++++---------- .github/workflows/test-matrix.yml | 53 ++++++++++++++++++++++++++ .github/workflows/test.yml | 44 +-------------------- 3 files changed, 97 insertions(+), 63 deletions(-) create mode 100644 .github/workflows/test-matrix.yml diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 921c22c..44db3f8 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -8,31 +8,16 @@ on: workflow_dispatch: {} # manual run for testing; publishing remains tag-only permissions: - contents: write # create the GitHub Release + contents: read jobs: - release: + guards: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 with: fetch-depth: 0 - - uses: actions/setup-java@v4 - with: - distribution: temurin - java-version: '21' - - - uses: DeLaGuardo/setup-clojure@13.6.1 - with: - lein: 2.12.0 - - - uses: actions/cache@v4 - with: - path: ~/.m2/repository - key: ${{ runner.os }}-m2-${{ hashFiles('project.clj') }} - restore-keys: ${{ runner.os }}-m2- - - name: Verify tag matches project.clj version if: github.ref_type == 'tag' run: | @@ -79,9 +64,6 @@ jobs: exit 1 fi - - name: Test - run: lein test - - name: Extract release notes from CHANGELOG if: github.ref_type == 'tag' run: | @@ -98,6 +80,47 @@ jobs: fi cat release-notes.md + - name: Upload release notes + if: github.ref_type == 'tag' + uses: actions/upload-artifact@v4 + with: + name: release-notes + path: release-notes.md + + verify: + needs: guards + uses: ./.github/workflows/test-matrix.yml + + release: + needs: [guards, verify] + runs-on: ubuntu-latest + permissions: + contents: write + steps: + - uses: actions/checkout@v4 + with: + fetch-depth: 0 + + - uses: actions/setup-java@v4 + with: + distribution: temurin + java-version: '21' + + - uses: DeLaGuardo/setup-clojure@13.6.1 + with: + lein: 2.12.0 + + - uses: actions/cache@v4 + with: + path: ~/.m2/repository + key: ${{ runner.os }}-m2-${{ hashFiles('project.clj') }} + restore-keys: ${{ runner.os }}-m2- + + - uses: actions/download-artifact@v4 + if: github.ref_type == 'tag' + with: + name: release-notes + - name: Deploy to Clojars if: github.ref_type == 'tag' env: diff --git a/.github/workflows/test-matrix.yml b/.github/workflows/test-matrix.yml new file mode 100644 index 0000000..d40c11f --- /dev/null +++ b/.github/workflows/test-matrix.yml @@ -0,0 +1,53 @@ +name: test matrix + +on: + workflow_call: + +permissions: + contents: read + +jobs: + lint: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + + - name: Set up clj-kondo + uses: DeLaGuardo/setup-clojure@13.6.1 + with: + clj-kondo: '2026.05.25' + + - name: Run clj-kondo + run: clj-kondo --lint src test + + test: + name: JDK ${{ matrix.jdk }} / Leiningen ${{ matrix.lein }} + runs-on: ubuntu-latest + strategy: + fail-fast: false + matrix: + jdk: ['8', '17', '21'] + lein: ['2.9.10', '2.11.2', '2.12.0'] + steps: + - uses: actions/checkout@v4 + + - name: Set up JDK ${{ matrix.jdk }} + uses: actions/setup-java@v4 + with: + distribution: temurin + java-version: ${{ matrix.jdk }} + + - name: Set up Leiningen ${{ matrix.lein }} + uses: DeLaGuardo/setup-clojure@13.6.1 + with: + lein: ${{ matrix.lein }} + + - name: Cache Maven dependencies + uses: actions/cache@v4 + with: + path: ~/.m2 + key: ${{ runner.os }}-m2-lein${{ matrix.lein }}-${{ hashFiles('project.clj') }} + restore-keys: ${{ runner.os }}-m2-lein${{ matrix.lein }}- + + - name: Run tests + run: lein test diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 541f40a..58efc15 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -6,47 +6,5 @@ on: pull_request: jobs: - lint: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@v4 - - - name: Set up clj-kondo - uses: DeLaGuardo/setup-clojure@13.6.1 - with: - clj-kondo: '2026.05.25' - - - name: Run clj-kondo - run: clj-kondo --lint src test - test: - name: JDK ${{ matrix.jdk }} / Leiningen ${{ matrix.lein }} - runs-on: ubuntu-latest - strategy: - fail-fast: false - matrix: - jdk: ['8', '17', '21'] - lein: ['2.9.10', '2.11.2', '2.12.0'] - steps: - - uses: actions/checkout@v4 - - - name: Set up JDK ${{ matrix.jdk }} - uses: actions/setup-java@v4 - with: - distribution: temurin - java-version: ${{ matrix.jdk }} - - - name: Set up Leiningen ${{ matrix.lein }} - uses: DeLaGuardo/setup-clojure@13.6.1 - with: - lein: ${{ matrix.lein }} - - - name: Cache Maven dependencies - uses: actions/cache@v4 - with: - path: ~/.m2 - key: ${{ runner.os }}-m2-lein${{ matrix.lein }}-${{ hashFiles('project.clj') }} - restore-keys: ${{ runner.os }}-m2-lein${{ matrix.lein }}- - - - name: Run tests - run: lein test + uses: ./.github/workflows/test-matrix.yml