From 21216c2bfd36e13e7b0022627fdb01c844e66051 Mon Sep 17 00:00:00 2001 From: Albert Hui Date: Tue, 15 Sep 2026 09:09:02 +0800 Subject: [PATCH] ci(release-plz): refresh lens/Cargo.lock on the release PR Stop the freshness gate from breaking on every timeglyph release. release-plz regenerates only the root workspace lock; `lens/` is a separate workspace (excluded because it is Windows-only) with its own committed Cargo.lock, so after each version bump it still pins the previous `timeglyph` path-dep version and the freshness job's `cargo update --locked --manifest-path lens/Cargo.toml` fails (as it did on 0.9.8, #30). Add a release-plz-pr post-step that refreshes lens/Cargo.lock on the same release PR branch whenever a release PR exists. lens is not published, so this touches no cargo-vet attestations. The step is guarded (exits cleanly if there is no release PR branch) and only commits when the lock actually changes. wasm/bindings-python/fuzz keep no committed lock, so freshness does not gate them and they need no handling. Co-Authored-By: Claude Opus 5 --- .github/workflows/release-plz.yml | 32 +++++++++++++++++++++++++++++++ 1 file changed, 32 insertions(+) diff --git a/.github/workflows/release-plz.yml b/.github/workflows/release-plz.yml index 246a9a1..deab31f 100644 --- a/.github/workflows/release-plz.yml +++ b/.github/workflows/release-plz.yml @@ -54,9 +54,41 @@ jobs: fetch-depth: 0 - uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable - name: release-plz release-pr + id: release-pr uses: release-plz/action@e8792575c7f2366cf6ff3ccc33ead9ace5b691c7 # v0.5.130 with: command: release-pr env: GITHUB_TOKEN: ${{ secrets.RELEASE_PLZ_TOKEN || secrets.GITHUB_TOKEN }} CARGO_REGISTRY_TOKEN: ${{ secrets.CARGO_REGISTRY_TOKEN }} + + # release-plz regenerates only the ROOT workspace lock. `lens/` is a + # separate workspace (excluded because it is Windows-only) with its own + # committed Cargo.lock, so after a version bump it still pins the old + # `timeglyph` version (a path dep) and the freshness gate's + # `cargo update --locked --manifest-path lens/Cargo.toml` fails on the very + # next release. Refresh it on the same release PR branch. lens is not + # published, so this touches no cargo-vet attestations. Runs only when a + # release PR exists (created or updated). + - name: Refresh lens/Cargo.lock on the release PR + if: steps.release-pr.outputs.prs != '' && steps.release-pr.outputs.prs != '[]' + env: + GH_TOKEN: ${{ secrets.RELEASE_PLZ_TOKEN || secrets.GITHUB_TOKEN }} + run: | + branch="$(printf '%s' '${{ steps.release-pr.outputs.prs }}' | jq -r '.[0].head_branch')" + if [ -z "$branch" ] || [ "$branch" = "null" ]; then + echo "no release PR branch — nothing to refresh" + exit 0 + fi + git fetch origin "$branch" + git checkout "$branch" + cargo update --manifest-path lens/Cargo.toml + if git diff --quiet -- lens/Cargo.lock; then + echo "lens/Cargo.lock already current" + else + git config user.name "github-actions[bot]" + git config user.email "41898282+github-actions[bot]@users.noreply.github.com" + git add lens/Cargo.lock + git commit -m "chore: refresh lens/Cargo.lock behind the version bump" + git push origin "HEAD:$branch" + fi