Skip to content

ci: own shared package release workflows - #23

Merged
jaysin586 merged 4 commits into
mainfrom
ci/shared-release-safety
Oct 2, 2026
Merged

jaysin586 merged 4 commits into
mainfrom
ci/shared-release-safety

Conversation

@jaysin586

@jaysin586 jaysin586 commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Make docs-kit the shared publishing source for Humanspeak’s maintained packages, as requested by the maintainer. The source adapts the svelte-diff PR #216 reference; svelte-diff is a consumer and retains its package-specific shim policy. Docs-kit also retains its signed CalVer GitHub release policy.

Changes

  • Add policy-aware templates, a fail-closed sync tool, immutable source manifests, consumer inventory, and documented compatibility decisions.
  • Own the generalized release helpers and their tests, with policy-driven canonical manifests, real aliases, npm lockfile root versions, and managed or unchanged READMEs. Svelte-diff’s two tombstone manifests remain explicit only in that consumer’s policy.
  • Preserve one tested SHA, original-event provenance, repository release serialization, fast-forward main/single-tag pushes, exact artifact ownership, and canonical publication cleanup barriers.
  • Retain signed tag-only CalVer releases and generated notes; add no npm publication. Preserve consumer registries, managers, signing, authentication, version labels, and manual-release policies.
  • Pin the isolated, best-effort README updater to reviewed docs-kit revision 882b87e. GitHub actions retain version tags with the established zizmor annotations, as requested.

Validation

  • 62 applicable offline release/updater/CalVer tests passed on both Node 22.23.3 and 24.18.0; mocked Git, GitHub, download, and registry transports cover stale/overlapping runs, rejected pushes, collisions, replacements, malformed/foreign state, ambiguous outcomes, publication followed by failure, and repeated cleanup.
  • Five Python sync regression scenarios passed, including manager variants, manual choices, version-tagged generated actions, idempotence, drift, failure before partial writes, and source/reference ownership separation.
  • Source check, build, 29 unit tests, Trunk formatting/checking, and whitespace validation passed.
  • All 14 consumer worktrees passed their applicable offline suites on Node 22/24 and root check/build/unit validation. Consumer PRs record repository-specific warnings and lint installer limitations.

GitHub-hosted signing, trusted publishing, and live release execution have not been exercised. This PR is labeled skip-publish; merging, publishing, deployment, and workflow dispatch require separate authorization.

Commits

  • 1ba2cdb ci: own shared package release workflows in docs-kit
  • 5a425da ci: retain version tags for workflow actions
  • 7f0b6ac ci: pin final shared release source revision
  • 18840fb ci: guard signed CalVer release ownership

@jaysin586 jaysin586 added enhancement Apply to new features or improvements to existing features skip-publish This is something important, but we dont want to publish it security Apply to security fixes or improvements labels Oct 2, 2026
@jaysin586 jaysin586 self-assigned this Oct 2, 2026
@jaysin586 jaysin586 changed the title ci: guard signed CalVer release ownership ci: own shared package release workflows Oct 2, 2026
@jaysin586
jaysin586 merged commit a59fede into main Oct 2, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement Apply to new features or improvements to existing features security Apply to security fixes or improvements skip-publish This is something important, but we dont want to publish it

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant