Skip to content

fix(tooling): let self-updates commit, push, and run Validate - #57

Merged
WillieCubed merged 2 commits into
mainfrom
fix/self-update-hooks-and-approval
Sep 28, 2026
Merged

WillieCubed merged 2 commits into
mainfrom
fix/self-update-hooks-and-approval

Conversation

@WillieCubed

Copy link
Copy Markdown
Contributor

TL;DR

The daily Standard update workflow now finishes on its own: it can commit and push in every
repository, and its update pull requests get their Validate check without anyone clicking
approve.

Overview of Changes

What the first self-updates showed

v0.5.1 was the first release to reach repositories through their own workflow. labs,
week-without-driving, and .github opened their pull requests, but analytics and the three templates
failed:

  • The workflow's setup step installs dependencies, which switches on the repository's own git hooks.
    In analytics, the bot's git push therefore ran the full pre-push check, end-to-end tests
    included, which can't pass in that job, so the push was rejected.
  • In the templates, regenerating the tree deleted node_modules while git still pointed at hooks
    inside it. prepare-commit-msg runs even with --no-verify, so the commit failed.

The pull requests that did open showed a second gap. GitHub now holds the workflow runs of a pull
request that a workflow's own token opened until someone with write access approves them. The
ci.yml run the update dispatched did pass. But its check never counted for the pull request, which
stayed blocked until I approved the held runs by hand; labs#41 then merged itself.

The fix

The bot's commit and push run with core.hooksPath=/dev/null; the hooks are for people. After
opening its pull request, the update now finds the runs GitHub is holding for that branch and
approves them through the API, instead of dispatching ci.yml. If the token isn't allowed to
approve them, the workflow says so and fails after the pull request is open, which leaves a
one-click job for a maintainer. ci.yml no longer needs a workflow_dispatch trigger, so that
requirement is gone from the drift check and the adoption guide.

Rollout

A repository runs its vendored copy of this code to propose the next release, so analytics and the
templates can't apply 0.5.2 on their own. I'll apply it once to those four with the maintainer
script; everything after that is automatic. labs, week-without-driving, and .github pick it up
from their daily run, and that run is the first test of whether a workflow token may approve its
own held runs.

Testing

pnpm check passes. The proposal tests now cover:

  • that the push runs without hooks;
  • that each held run is approved exactly once, with late-arriving runs caught;
  • that a refused approval is reported without throwing.

Follow-ups

  • If the token turns out not to be allowed to approve held runs, record that in the release process
    and have Standard status point maintainers at waiting pull requests.

🤖 Generated with Claude Code

WillieCubed and others added 2 commits September 28, 2026 10:50
The first self-updates exposed three problems. Installing dependencies
switches on a repository's own git hooks, so the bot's push ran the
pre-push check, end-to-end tests included, and a template's regenerated
tree left prepare-commit-msg pointing at deleted files. And GitHub holds
the workflow runs of a pull request a workflow token opened until
someone approves them, so the dispatched ci.yml run never counted for
the pull request.

The bot now commits and pushes with hooks switched off, and approves
the held runs its own update started instead of dispatching ci.yml. A
run the token may not approve is reported and fails the workflow after
the pull request is open. ci.yml no longer needs a workflow_dispatch
trigger for updates.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Publish self-update fixes for hooks and held workflow runs
as a patch release of the shared web standard.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@WillieCubed
WillieCubed merged commit 878cea0 into main Sep 28, 2026
1 check passed
@WillieCubed
WillieCubed deleted the fix/self-update-hooks-and-approval branch September 28, 2026 17:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant