fix(ci): enforce release checks#4380
Merged
Merged
Conversation
Collaborator
Author
|
Review completed in 3 passes with 0 remaining findings.
Final-head CI is fully green with no skipped checks: Build and checks, Coverage, all three test shards, review, and CodeQL/Analyze. The API PR workflow completed in 4m37s; all three test shards started at 19:56:36 UTC, confirming parallel execution. |
TaprootFreak
marked this pull request as ready for review
July 24, 2026 20:13
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What & why
Release PRs from
developtomaincurrently skip the API PR workflow. In addition, the automatic release PR is created withGITHUB_TOKEN; GitHub does not trigger downstreampull_requestworkflows for that creation event.This change closes both gaps:
RELEASE_PR_TOKENsecret so their PR workflows start normallydevelopexclusion so release PRs run the same parallel CI as normal PRsCoverageandRun coverageGITHUB_TOKENpull-request permission to read-only after moving PR creation to the dedicated tokenRelease PRs therefore run:
Build and checksCoverageThe coverage command remains the existing Bank Frick-specific
test:frick:covgate and its strict thresholds are unchanged.Validation
git diff --checkactionlintfor both changed workflows (with the three pre-existingSC2086notices in unchanged lines ignored)