feat(release): fully automated release pipeline on main push - #172
Merged
Conversation
push to main -> auto-release.yml computes next semver from conventional commits (scripts/auto-release.sh, detection-only), bumps both version files, pushes the bump via RELEASE_AUTOMATION_TOKEN (owner bypass; PAT push so follow-up workflows fire) -> auto-tag.yml tags + releases, then dispatches groundwork's sync-dev-loop-pin.yml immediately (hourly schedule stays as backstop). Loop safety: 'skip: awaiting tag' detection + chore(release) head-commit guard. Review fixes: strict X.Y.Z segment-count validation (4-segment versions previously slipped the guard); non-fast-forward push on back-to-back merges is a logged supersede, not a failed run. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01B4zKA2wmVG1621R5ynC8uc
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Closes the remaining manual steps of the release chain. After this, any push to main auto-releases end to end:
Loop & race safety
auto-release.shprintsskip: awaiting tagwhenever plugin.json is ahead of the tags (the exact post-bump state), plus a job-level guard onchore(release)head commits.X.Y.Zvalidation (4-segment/empty-segment versions rejected — caught in independent review).Requires (one-time)
RELEASE_AUTOMATION_TOKENrepo secret — fine-grained PAT (repos: dev-loop + groundwork; Contents R/W + Actions R/W). Without it the bump step fails loudly with setup instructions; nothing releases silently wrong. Set the secret before merging to avoid one red run.Tests
tests/auto-release.bats: 15 cases (patch/minor/major, scope+bang, BREAKING body, highest-wins, both skip states, collision exit 1, malformed/4-segment/empty-segment versions, usage). Full suite green locally.
🤖 Generated with Claude Code
https://claude.ai/code/session_01B4zKA2wmVG1621R5ynC8uc