Skip to content

promote.yml carries the stable feed to main through a PR, and fails loudly when it cannot (nxf 6j6v.exga) - #3

Merged
cabcookie merged 1 commit into
mainfrom
feat/exga-promote-feed-pr
Sep 24, 2026
Merged

cabcookie merged 1 commit into
mainfrom
feat/exga-promote-feed-pr

Conversation

@cabcookie

Copy link
Copy Markdown
Member

Why

Since 2026-09-24, main carries ruleset 23939298: every change through a pull request, no bypass, GitHub Actions included. promote.yml still pushed the regenerated release-notes.json straight to the line, and a rejected push only produced ::warning::. The first stable promotion from the public repo would have stayed green while main's feed and the public changelog silently lacked the stable entry.

What

  • The feed commit goes to release-notes/promote-v<version>, and the job opens a PR against the line (main or release/x.Y), labelled skip-changelog. A re-run force-updates its own branch and reuses an open PR.
  • Owner step, decided with the owner: a PR opened with GITHUB_TOKEN starts no workflows, so its required checks would never report. The owner closes and re-opens it, waits for the checks and merges. The job summary prints the three gh commands. The alternative, a GitHub App token, was declined: a stable promotion is already a deliberate human gesture, and the app would add a secret to maintain.
  • Fails loudly: no more continue-on-error. If the branch push or the PR fails, the job goes red; the promotion itself has landed by then.
  • No explicit publish-content dispatch (and no actions: write). It would now run before the merge. The owner's merge is a human push touching release-notes.json, which fires publish-content.yml by itself.
  • Updated prose: spec §5.5 step 5 and the release runbook, backport runbook step 6, and the release-cut-runbook memory (NEXUS_MEMORY.md).

Evidence

actionlint is clean. The step itself only runs on a real stable promotion, the first being 0.200.0 → stable. promote-ci.yml covers promote-release.sh, which this diff does not touch.

skip-changelog: promote.yml is a carved-out delivery file, but nothing a user installs changes.

🤖 Generated with Claude Code

https://claude.ai/code/session_01NhwrYjEtdnS3jCneb57X3k

…oudly when it cannot (nxf 6j6v.exga)

main's ruleset allows no direct push, not even for GitHub Actions (owner
rule: every change through a pull request). promote.yml still pushed the
regenerated release-notes.json straight to the line, and a rejected push
only warned: the promotion stayed green while main's feed and the public
changelog silently lacked the stable entry.

The feed commit now goes to release-notes/promote-v<v>, and the job opens
a PR against the line (skip-changelog label). A workflow-opened PR starts
no workflows, so the owner closes and re-opens it to run the required
checks, then merges. The owner chose this over a GitHub App token. The
job summary prints the commands. The merge is a human push touching
release-notes.json, which fires publish-content.yml by itself, so the
explicit dispatch (and actions: write) is gone. Failing to open the PR
fails the job.

Spec §5.5 and the release runbook, the backport runbook step 6 and the
release-cut-runbook memory describe the new step.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NhwrYjEtdnS3jCneb57X3k
@cabcookie cabcookie added the skip-changelog Opt out of changelog-check (PRs with no user impact) label Sep 24, 2026
@cabcookie
cabcookie merged commit e137726 into main Sep 24, 2026
13 of 14 checks passed
@cabcookie
cabcookie deleted the feat/exga-promote-feed-pr branch September 24, 2026 23:13
cabcookie added a commit that referenced this pull request Sep 27, 2026
The promotion itself ran (promote.yml run 36309436401: S3 copy, stable manifest,
sidecars verified), but the release event runs the workflow as of the tag, and
v0.200.0 predates PR #3: its best-effort step pushed the feed straight to main and
the ruleset declined it. This is that same entry, regenerated locally with
`cargo xtask changelog promote 0.200.0` (same 17+/1- diff as the rejected commit).

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
@cabcookie cabcookie mentioned this pull request Oct 2, 2026
cabcookie added a commit that referenced this pull request Oct 2, 2026
A re-ship with no user impact: since v0.200.0 only CI and the changelog feed
changed (#2-#6). It is the first release through staged npm publishing
(6j6v.c7dd) and the first tag whose promote.yml opens the stable feed PR (#3).


Claude-Session: https://claude.ai/code/session_018Sipejn8YQhKgngxeHpMhT

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

skip-changelog Opt out of changelog-check (PRs with no user impact)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant