Skip to content

ci: harden release publication from shared source - #192

Merged
jaysin586 merged 4 commits into
mainfrom
ci/shared-release-safety
Oct 2, 2026
Merged

jaysin586 merged 4 commits into
mainfrom
ci/shared-release-safety

Conversation

@jaysin586

@jaysin586 jaysin586 commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Harden humanspeak/memory-cache releases using the shared source in docs-kit PR #23, pinned to 1ba2cdb. The vendored bundle and workflows have recorded SHA-256 hashes and can be checked or refreshed with the source sync tool.

Changes

  • Serialize repository releases without cancelling the running release. GitHub’s default pending-run replacement still does not guarantee every event or original trigger order.
  • Resolve one baseline before source checks, build, and units; every later code-consuming job checks out that SHA. Keep PR lookup, labels, skip rules, and notes tied to the original event.
  • Recheck remote main immediately before mutation. Allow advancement only across individually verified release metadata; unrelated source, configuration, dependency, mode, or ancestry changes skip the stale run.
  • Push main by ordinary fast-forward and push only the intended annotated tag; a failed main push prevents later publication.
  • Record run identity, exact tag object, release commit, and numeric release ID; prove ownership before cleanup, retain ambiguous or replaced artifacts, and protect confirmed or unknown canonical publication outcomes.
  • Make the actual source/type check blocking before build and units, and correct relevant workflow path filters.
  • Download the README updater at docs-kit revision 882b87e6a73c408c6b31fe8a185e8d0ea397fa37, execute with only PATH before Git write authentication, and skip safely on failed or partial downloads.

Compatibility

Retain pnpm@12.6.0, OIDC, signed commits and annotated tags, npmjs publication and existing versioning/permissions/environments.

Validation

  • 58 applicable offline release tests passed on each of Node 22.23.3 and 24.18.0. Reference-only or inapplicable cases are explicitly skipped; consumer integration cases check the actual workflow/policy.
  • pnpm run check, pnpm run build, and 276 unit tests passed.
  • Shared-source --check, SHA-256 consistency, workflow linting, and whitespace checks passed.
  • Trunk formatting and checks passed for changed workflows/helpers/configuration.

No live release, publication, workflow dispatch, deployment, or merge was performed. The PR carries skip-publish. Review the shared-source PR and consumer CI before authorizing rollout.

Commits

  • 52585f9 ci: follow docs-kit shared release source
  • d2c38c2 ci: retain version tags for workflow actions
  • 14c6291 ci: pin final shared release source revision
  • 7eacded ci: harden release publication from shared source

@jaysin586 jaysin586 added enhancement Apply to new features or improvements to existing features skip-publish This is something important, but we dont want to publish it security Apply to security fixes or improvements labels Oct 2, 2026
@jaysin586 jaysin586 self-assigned this Oct 2, 2026
@jaysin586
jaysin586 merged commit 84adade into main Oct 2, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement Apply to new features or improvements to existing features security Apply to security fixes or improvements skip-publish This is something important, but we dont want to publish it

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant