Skip to content

refactor(ci): harden release follow-up jobs (force-with-lease, GH_REPO) - #51

Merged
trsdn merged 1 commit into
mainfrom
trsdn-release-job-refinements
Aug 24, 2026
Merged

trsdn merged 1 commit into
mainfrom
trsdn-release-job-refinements

Conversation

@trsdn

@trsdn trsdn commented Aug 24, 2026

Copy link
Copy Markdown
Owner

Follow-up to #50 (merged as a998c5a), applying two review refinements from the
comparison with the parallel PR #49.

1. --force → --force-with-lease

update-docs overwrites docs/changelog-v<version> on a re-run of the same tag.
--force-with-lease keeps that idempotency but refuses to discard a foreign
commit that landed on the branch in the meantime. The lease basis is sound here:
the job checks out with fetch-depth: 0, so remote-tracking refs for all
branches exist before the push.

2. -R on the call → GH_REPO in the step env

post-release-validation has no actions/checkout, so gh cannot infer the
repository from a git remote — that was the root cause of the false
"❌ GitHub release missing". Setting it via the step env instead of a single
-R flag covers every gh call in the step and puts the explanatory comment
where the cause actually is:

env:
  GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
  # This job has no checkout, so `gh` cannot infer the repository from a
  # git remote and reported "GitHub release missing" for a release that
  # actually existed.
  GH_REPO: ${{ github.repository }}

Deliberately not included: tag guards

PR #49 additionally adds if: startsWith(github.ref, 'refs/tags/') to publish,
create-github-release and post-release-validation. That is not adopted here,
on purpose.

This workflow has a required tag input on workflow_dispatch, and every job
checks out ref: ${{ inputs.tag || github.ref }} — a dispatch is the intended way
to re-run the pipeline for an existing tag. During a workflow_dispatch run,
github.ref is refs/heads/main, so the condition would always evaluate to
false and those three jobs would be silently skipped. That is precisely the
re-run path that v2.0.0 depended on (three attempts, because of the mypy/3.12
gate).

Validation

  • actionlint .github/workflows/release.yml — no findings in the changed jobs
    (remaining SC2086/SC2046 infos are pre-existing, in untouched jobs)
  • YAML parses cleanly
  • grep startsWith(github.ref confirms no tag guards were introduced
  • CHANGELOG [Unreleased] / ### Fixed wording updated to match the GH_REPO approach

Only update-docs and post-release-validation are touched. No release run, no
tag created, release workflow not triggered.

Follow-up to #50 with two review refinements:

- update-docs pushes the changelog branch with --force-with-lease instead of
  --force, so a foreign commit that landed on docs/changelog-v<version> is not
  silently discarded on a re-run.
- post-release-validation sets GH_REPO in the step env instead of passing -R on
  a single call. The job has no checkout, so gh cannot infer the repository from
  a git remote; setting it via env covers every gh call in the step and puts the
  explanatory comment where the root cause is.

Deliberately does not add `if: startsWith(github.ref, 'refs/tags/')` guards to
publish, create-github-release or post-release-validation. The workflow has a
required `tag` input on workflow_dispatch and every job checks out
`${{ inputs.tag || github.ref }}`, so a dispatch is the supported way to re-run
the pipeline for an existing tag. During a dispatch github.ref is
refs/heads/main, so such a guard would always be false and would silently skip
those jobs - exactly the re-run path that v2.0.0 needed.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@github-actions

Copy link
Copy Markdown
Contributor

🔍 PR Quality Summary

CI Status

✅ Docs: success
✅ Security: success
✅ Quality: success

Metrics

Metric Value Trend
📊 Coverage N/A -
🧪 Tests Test results pending -
⏱️ Performance No performance data -

Quality Checks

  • Format & Lint: Ruff formatting and linting
  • Type Safety: MyPy strict type checking
  • Security: Bandit, Safety, GitLeaks scanning
  • MCP Protocol: Tool schema validation
  • Documentation: Docstring coverage (80%+)

MCP Tools

  • convert_file - Convert individual files to Markdown
  • convert_directory - Batch convert directories
  • list_supported_formats - Query supported file types

🤖 Auto-generated by CI • Last updated: 2026-08-24 22:30 UTC

@trsdn
trsdn merged commit ccb88a1 into main Aug 24, 2026
22 checks passed
@trsdn
trsdn deleted the trsdn-release-job-refinements branch August 24, 2026 22:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant