Skip to content

V10.8.0/post ci fix - #173

Merged
gimlichael merged 7 commits into
mainfrom
v10.8.0/post-ci-fix
Oct 3, 2026
Merged

gimlichael merged 7 commits into
mainfrom
v10.8.0/post-ci-fix

Conversation

@gimlichael

Copy link
Copy Markdown
Member

This pull request makes release finalization recoverable and verifies that post-release assurance is recorded against the released commit on the canonical main branch. It adds separate recovery paths for OCI asset attachment and assurance replay, while keeping GitHub Release publication under maintainer control.

Release recovery:

  • Resume OCI asset attachment from the verified source artifact without rebuilding or republishing products.
  • Replay release tests and analysis against the exact released SHA without changing published products or deployment state.

Assurance identity:

  • Report SonarCloud and Codecov results on main and CodeQL results on refs/heads/main, all tied to the released SHA.
  • Verify the services’ recorded branch, commit, and version before accepting assurance.

Repository guidance:

  • Document the recovery procedures and the manual release publication decision.
  • Clarify which bot-folder and DocFX working files belong in source control.

Allow maintainers to resume OCI asset attachment from the original verified artifact after NuGet publication. Keep recovery from rebuilding or republishing immutable products, and leave GitHub Release publication as a human decision.
Explain how maintainers review draft releases and recover OCI asset attachment from the original Actions artifact. This keeps the human publication decision and separate deployment approval clear.
Make clear that the README is intentionally tracked while other bot working material stays local. This prevents the directory guidance from contradicting the repository contents.
Limit the temporary artifact restrictions to files created by DocFX maintenance. This preserves the documentation workflow safeguards without presenting them as repository-wide file rules.
Let maintainers replay post-release tests and repository-health analyses against the exact released SHA after correcting workflow telemetry. Verify that SonarCloud, Codecov and CodeQL record the canonical main identity before treating the replay as successful.
Document the reporting branch and commit identities required for release assurance, plus the recovery dispatch maintainers can use to replay checks against the released SHA.
@gimlichael gimlichael self-assigned this Oct 3, 2026
@greptile-apps

greptile-apps Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[High risk] Adds manual workflow dispatch to the release pipeline.

The PR appears safe to merge based on the reviewed changes.

Summary

The PR adds separate OCI-asset and assurance recovery paths, verifies quality-service records against the released commit, and leaves GitHub Release publication to a maintainer. The latest changes allow recovery to create a missing draft and search paginated SonarCloud analyses; both previously reported threads are resolved.

Diagram

%%{init: {'theme': 'neutral'}}%%
flowchart LR
  Tag[Release tag push] --> Products[Publish NuGet and build OCI artifact]
  Products --> Draft[Resolve draft and attach verified assets]
  Products --> Assurance[Run tests and quality analysis]
  AssetsRecovery[Asset recovery from main] --> Draft
  AssuranceRecovery[Assurance recovery from main] --> Assurance
  Draft --> Human[Maintainer publishes release]
Loading

Reviews (2) · Last reviewed commit: "🐛 handle release recovery edge cases"

Comment thread .github/workflows/release.yml Outdated
Comment thread .github/workflows/release.yml Outdated
Allow asset recovery to restore a missing draft release and search paginated SonarCloud analyses for the released revision. This keeps recovery reliable after release edits or newer main analyses.
@codecov

codecov Bot commented Oct 3, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 94.18%. Comparing base (33e6e75) to head (c7f0c12).

Additional details and impacted files
@@            Coverage Diff             @@
##             main     #173      +/-   ##
==========================================
+ Coverage   90.06%   94.18%   +4.11%     
==========================================
  Files         606      605       -1     
  Lines       12884    19089    +6205     
  Branches     1819     1831      +12     
==========================================
+ Hits        11604    17979    +6375     
- Misses        781     1083     +302     
+ Partials      499       27     -472     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@gimlichael
gimlichael merged commit 3561362 into main Oct 3, 2026
323 checks passed
@gimlichael
gimlichael deleted the v10.8.0/post-ci-fix branch October 3, 2026 23:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants