fix(autorelease): email publish runs, set Latest, and resume finalize - #164
Conversation
Publish runs are dispatched with GITHUB_TOKEN, so GitHub never started the workflow_run digest for them. The publish workflow now calls the email workflow from a final always() job with the conclusion its jobs reached, and publish is no longer a workflow_run trigger, so each run attempt is emailed once. Publication sets make_latest explicitly: true only when no published release sorts above the version, comparing major, minor, patch and revision numerically, so a rebuild of an older branch no longer takes the Latest badge. A finalize rerun now recognizes a record already on main for exactly this release, withdraws a PR or branch an earlier attempt left on its run-scoped branch, and reports recorded from main whenever the attempt did not merge. Every single-record merge asserts Protected controls. Also: the sealed-patch PR body gets real newlines, both force-with-lease pushes fetch their tracking ref with a forced refspec, the unused repair and auth_failure action-key families are removed, the stale mise-php snapshot digest in the admin evidence is corrected, and the failing-install packaging test asserts the refused copy.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Team Run ID: 📒 Files selected for processing (3)
Limit details: You’ve used all 5 included reviews currently available. Your 55 included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour. 📝 WalkthroughWalkthroughThe changes update release ordering and event-record validation. Publish finalization handles existing records and stale run-specific pull requests. Publish attempts invoke the email workflow directly, while watcher completions continue to trigger it through workflow events. ChangesAuto-release lifecycle
Packaging failure test
Priority: ➖ Normal Estimated code review effort: 4 (Complex) | ~50 minutes Change: Bug fix Sequence Diagram(s)sequenceDiagram
participant PublishWorkflow
participant WatcherCompletion
participant EmailWorkflow
PublishWorkflow->>EmailWorkflow: Call with run metadata and conclusion
WatcherCompletion->>EmailWorkflow: Completion event with run metadata
Merge Risk: ⚪ Minimal · up to No actionable merge-blocking risk is established by the reviewed changes; the inspected fallback and email-routing behavior match their stated contracts. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 14.71% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 34 functions across 6 files. (2 skipped: 2 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Usage-based review receipt
Note This review was completed with usage-based billing: files reviewed beyond your plan's included limits are billed at $0.25/file. View usage-based billing. Comment |
* origin/main: fix(autorelease): email publish runs, set Latest, and resume finalize (#164)
Publish runs never sent their digest email, because the watcher dispatches them with
GITHUB_TOKENand GitHub starts noworkflow_runfor those, so the publish workflow now calls the email workflow from its own last job and the watcher keepsworkflow_run. Publication now setsmake_latestexplicitly (true only for the highest published version, revisions included), afinalizererun reuses a record already on main or withdraws what an earlier attempt left and reportsrecordedfrom main, and every record merge asserts Protected controls.It also fixes the literal
\nin the sealed-patch PR body, forces the tracking-ref fetch before both--force-with-leasepushes, drops the unusedrepair:andauth_failure:action-key families, including from the verifier's cross-repo filename check, which pairs with Bigpixelrocket/mise-php#35 (the pipeline is safe in either merge order, butverify-autorelease-systemfrom php-bin main fails against mise-php#35 until this PR is in), corrects the stale mise-php snapshot digest in the admin evidence, and makes the failing-install test check the refused copy. No recipe input changes, so nothing is rebuilt.Summary by CodeRabbit