Skip to content

chore: open every standard release in every repository - #54

Merged
WillieCubed merged 1 commit into
mainfrom
chore/standard-propagation
Sep 28, 2026
Merged

WillieCubed merged 1 commit into
mainfrom
chore/standard-propagation

Conversation

@WillieCubed

Copy link
Copy Markdown
Contributor

TL;DR

Every release of the standard now opens a pull request in every LVBT repository, and that pull
request merges itself once Validate passes. A daily check fails when any repository falls behind,
so drift gets noticed within days, not weeks.

Overview of Changes

Why

On 2026-09-27 the six non-template repositories sat on five different releases, from v0.2.8 to
v0.4.5. None of them had edited its vendored copy. They had simply never been updated.

  • A release reached only the three template repositories, through Publish template.
  • The release guide said Renovate would open the other updates, but Renovate is not installed on the
    organization. It also cannot bump vendored file: dependencies.
  • Nothing noticed a stale repository. standards:check proves only that the vendored copy is
    intact.
  • A repository therefore updated only when an agent session working in it needed something from a
    new release. With eight releases on 2026-09-23 alone, three repositories were already out of date
    when their update merged.

How it works now

Publish standard replaces Publish template.

  • When it runs: when a release tag is pushed, by hand for any stable tag, and daily for the
    latest release.
  • What it does: for each repository in standards/repositories.json, the new
    standards/propagate.ts applies the release and opens one pull request on
    automation/repository-standard-<tag>, then turns on auto-merge.
    • Each entry now has a kind: template repositories are regenerated from their example.
    • consumer repositories run the release's own updater. A repository several releases behind
      therefore gets every migration in one pass, including the ones that used to need a second run
      below v0.3.5.
  • Safe to rerun:
    • A template keeps its published lockfile, so pnpm resolves only what the release changed.
    • A repository that already matches gets nothing.
    • An update branch that fell behind main is rebuilt.
    • A branch someone pushed a fix to is left alone.
    • A newer release closes the older pull requests, and an older tag never downgrades a repository.

Standard status runs daily and after every publication. The new standards/status.ts (also
pnpm standards:status) writes one table of every repository to the job summary. It fails when a
repository:

  • has been behind the latest release for more than three days, counted from the first release it
    missed;
  • vendors an unreleased commit on main;
  • has a failing update pull request;
  • pins the contribution plugin to a different release than it vendors;
  • has merge settings other than rebase-only with auto-merge and branch deletion.

A dated exception in repositories.json can silence one rule for one repository, with a reason.

Decisions

  • GitHub App instead of a personal access token. Both workflows authenticate as an App. The old
    token went missing for 18 consecutive releases and would expire anyway. App tokens also make
    Validate run on the pull requests they open.
    docs/how-to/set-up-the-standard-bot.md gives every value for creating and installing it.
  • Auto-merge on green. The maintainer chose this; approving the release is the only review.
  • Release notes are required. The notes for 0.2.9 and 0.4.5 are backfilled, and pnpm check now
    fails when a stable release has no docs/reference/release-<version>.md.
  • This is not a release. Nothing vendored changes behavior; the new scripts only run from this
    repository.

Testing

  • pnpm check passes: 240 node tests plus the web-platform suite.
  • New tests cover:
    • version ordering;
    • superseding older update pull requests;
    • the pull request body against the template;
    • a real forward update of a fixture repository, with its rerun and a refused downgrade;
    • the lockfile-preserving template republish;
    • every drift rule and exception expiry.
  • Dry runs of v0.4.5 against fresh clones of all nine targets behaved as expected:
    • analytics, week-without-driving, website, transit-mapper and .github each got one commit.
    • Analytics also gained the three ignore lines its hand update had skipped.
    • labs and the templates were already current.
  • pnpm standards:status against the live organization reported the drift the audit found.

Follow-ups

  • Create the LVBT standard bot App and add its two credentials. The workflows fail until they exist.
  • Have the updater take over the standard files it still skips (the setup action, hooks, and plugin
    ref), and remove ci as a commit type and scope, in the next release.

🤖 Generated with Claude Code

Until now a release reached only the three template repositories. The
other six repositories updated only when an agent session happened to
need something from a new release, so they drifted to five different
releases. The documented Renovate path could not work: Renovate is not
installed, and it cannot bump vendored file: dependencies.

Publish standard replaces Publish template. On each release tag, by
hand, and daily for the latest release, it opens one self-merging pull
request in every repository listed in standards/repositories.json.
Consumers run the release's own updater, so a repository several
releases behind needs one pass. Older update pull requests are closed,
a branch someone fixed is kept, and a rerun with nothing new proposes
nothing.

Standard status runs daily and after each publication and fails when a
repository has drifted: behind the latest release for more than three
days, an unreleased vendored commit on main, a failing update, a stale
plugin ref, or merge settings that differ from the standard.

Both workflows authenticate as a GitHub App instead of an expiring
personal access token; the setup guide gives every value. Missing
release notes for 0.2.9 and 0.4.5 are backfilled, and a test now
requires them.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@WillieCubed
WillieCubed merged commit e8f7980 into main Sep 28, 2026
1 check passed
@WillieCubed
WillieCubed deleted the chore/standard-propagation branch September 28, 2026 03:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant