Skip to content

ci(release): gate release publish on tests (#1480) - #1484

Merged
LucasSantana-Dev merged 2 commits into
mainfrom
security/release-tests-gate-1480
Jun 17, 2026
Merged

LucasSantana-Dev merged 2 commits into
mainfrom
security/release-tests-gate-1480

Conversation

@LucasSantana-Dev

@LucasSantana-Dev LucasSantana-Dev commented Jun 17, 2026 •

Copy link
Copy Markdown
Owner

Part of #1480 (deploy posture). Addresses F4 (safe half).

Change

Remove continue-on-error: true from the Run tests step in release.yml. The Create GitHub Release step runs if: success() by default, so a failing test:ci now blocks the release publish (and the downstream deploy.yml release: published trigger) instead of being advisory.

Why

Before: merge to main (0 required reviews) → tag → release with tests that can't block → prod. Tests were decorative at the release gate.

Velocity preserved

The emergency hotfix fast-path uses workflow_dispatch on deploy.yml, not release.yml (docs/runbooks/hotfix.md), so a flaky release-test run cannot block an incident hotfix.

Scope note

The release-please ADR (#1478) is merged but not yet implemented — release.yml is still the live release mechanism, so this hardens the current path. Harmless if release.yml is later replaced by release-please.

Not included (operator/governance — see #1480 comment)

  • F4 other half (require ≥1 review on main) — would break the solo-operator auto-merge ship-lane; deliberately not applied.

@cubic-dev-ai


Summary by cubic

Gate release publishing on passing tests by removing continue-on-error from the Run tests step in release.yml. A failing npm run test:ci now blocks Create GitHub Release and the downstream deploy trigger, aligning with #1480 (deploy posture F4).

Written for commit 3b98b14. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Chores
    • Updated release workflow to enforce test passage before creating releases, improving overall release reliability and preventing failed deployments.

@vercel

vercel Bot commented Jun 17, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
lucky Ready Ready Preview, Comment Jun 17, 2026 12:49pm

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your free trial has ended. If you'd like to continue receiving code reviews, you can add a payment method here.

@LucasSantana-Dev

Copy link
Copy Markdown
Owner Author

@cubic-dev-ai please review.

@cubic-dev-ai

cubic-dev-ai Bot commented Jun 17, 2026

Copy link
Copy Markdown

@cubic-dev-ai please review.

@LucasSantana-Dev I have started the AI code review. It will take a few minutes to complete.

@github-actions

github-actions Bot commented Jun 17, 2026 •

Copy link
Copy Markdown
Warnings
⚠️

Branch security/release-tests-gate-1480 doesn't follow the standard prefix convention (feature/, fix/, refactor/, chore/, docs/, ci/, test/, release/).

Generated by 🚫 dangerJS against 3b98b14

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 1 file

Requires human review: Removing continue-on-error: true from the tests step will block releases if tests fail.

Re-trigger cubic

@coderabbitai

coderabbitai Bot commented Jun 17, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

The continue-on-error: true setting is removed from the "Run tests" step in .github/workflows/release.yml, making test failures block the release job instead of allowing it to proceed to version extraction and GitHub Release creation.

Changes

Release Workflow Test Gate

Layer / File(s) Summary
Remove continue-on-error from Run tests step
.github/workflows/release.yml
Deletes continue-on-error: true from the "Run tests" step so that test failures now stop the release job.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Suggested labels

size/m

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title directly reflects the main change: gating the release publish process on test passage by removing continue-on-error from the test step.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch security/release-tests-gate-1480

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot added the size/m label Jun 17, 2026

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your free trial has ended. If you'd like to continue receiving code reviews, you can add a payment method here.

@sonarqubecloud

Copy link
Copy Markdown

@LucasSantana-Dev
LucasSantana-Dev merged commit 98e0387 into main Jun 17, 2026
42 checks passed
@LucasSantana-Dev
LucasSantana-Dev deleted the security/release-tests-gate-1480 branch June 17, 2026 12:51

This branch was successfully deployed

1 active deployment
Preview — 3b98b140 Deployed Jun 17, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant