Skip to content

ci(release): automate releases with release-please - #1490

Merged
LucasSantana-Dev merged 3 commits into
mainfrom
ci/release-please-1478
Jun 19, 2026
Merged

LucasSantana-Dev merged 3 commits into
mainfrom
ci/release-please-1478

Conversation

@LucasSantana-Dev

@LucasSantana-Dev LucasSantana-Dev commented Jun 17, 2026 •

Copy link
Copy Markdown
Owner

What

Implements the accepted ADR decisions/2026-06-16-release-cadence-automate-releases.md (#1478) — never actually built until now (no config/manifest/workflow existed on disk).

release-please maintains one open release PR on every push to main, pre-computing the next semver bump + CHANGELOG from conventional commits. Merging that PR tags v* and publishes a GitHub Release, whose release: published event triggers the unchanged deploy.yml gate (30-min bake → homelab webhook → migrations → auto-rollback).

Why now

git rev-list --count v2.17.0..main = 145 commits stranded undeployed since v2.17.0 (2026-06-08) — incl. prod-breaking /download+/help fixes, security fixes (#1457 vite/form-data HIGH, #1283 CSP), and incident fixes (#1469, #1472). Releases were still fully manual and stalled — the exact failure the ADR was written to stop.

Changes

  • release-please-config.json — node release-type, root package lucky-bot, include-component-in-tag: false so the tag stays v2.18.0 (what deploy.yml expects).
  • .release-please-manifest.json — seeded at 2.17.0 → first managed release is 2.18.0, not a reset.
  • .github/workflows/release-please.yml — push: main, action pinned to a commit SHA (repo convention), no auto-merge (the one-click merge is the deliberate ship-to-prod checkpoint, per ADR + chore(deploy): rapid successive merges cause false-failure in 'Validate deployed version' #1397).
  • Retire release.yml — it created a Release on v* tag push; release-please does that on release-PR merge, so leaving it would double-create. Confirmed no other workflow triggers on v*. Its build+test gate is already covered by Quality Gates on main.

Deploy chain verified

  • deploy.yml triggers on release: published (+ workflow_dispatch) — intact.
  • docker-publish.yml builds :<sha> images on every main push — images exist for the release-PR-merge SHA.
  • Hotfix workflow_dispatch-by-SHA fast-path unchanged.

⚠️ One operator setting to confirm

release-please uses secrets.RELEASE_PLEASE_TOKEN (a PAT), NOT the default GITHUB_TOKEN — because Releases published by GITHUB_TOKEN don't propagate events, so deploy.yml (on: release: [published]) would never fire. Before merging, create the secret:

  • A fine-grained PAT scoped to this repo with Contents: Read+Write and Pull requests: Read+Write (or a classic PAT with repo), saved as repo secret RELEASE_PLEASE_TOKEN.
  • No-expiry alternative: a GitHub App token via actions/create-github-app-token.
  • The PAT also creates the release PR without the "Allow Actions to create PRs" repo setting.

Pilot / next step (the ADR's dry-run gate)

On merge, release-please opens the v2.18.0 release PR batching all 145 commits. That PR is the review checkpoint — inspect the computed bump + CHANGELOG before merging it; merging is the explicit ship-to-prod action (left to you, not automated here).

Refs #1478


Summary by cubic

Automates releases with release-please, keeping one open release PR on main. Merging it tags v*, publishes the Release, and triggers deploy.yml; uses RELEASE_PLEASE_TOKEN (PAT) so events propagate (ADR #1478).

  • New Features

    • Add .github/workflows/release-please.yml (on main, no auto-merge; merging tags v* and publishes the Release to trigger deploy.yml).
    • Seed .release-please-manifest.json at 2.17.0; add release-please-config.json (node type for lucky-bot, plain v* tags).
    • Remove release.yml to prevent duplicate Releases; deploy chain unchanged.
  • Migration

    • Add secret RELEASE_PLEASE_TOKEN (PAT: contents+pull-requests RW) so release: published triggers deploy.yml and the “Allow GitHub Actions to create and approve pull requests” setting isn’t needed.

Written for commit 2130099. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Chores
    • Added an automated release workflow that runs on updates to the main branch.
    • Introduced release-please configuration to standardize release behavior and changelog sourcing.
    • Removed the previous tag-based release workflow in favor of the new branch-based automation.
    • Updated the release manifest to include version mapping for the root workspace.

@vercel

vercel Bot commented Jun 17, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
lucky Ready Ready Preview, Comment Jun 19, 2026 12:54am

@github-actions github-actions Bot added the ci label Jun 17, 2026

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your free trial has ended. If you'd like to continue receiving code reviews, you can add a payment method here.

@coderabbitai

coderabbitai Bot commented Jun 17, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

Adds release-please-config.json (node release type, lucky-bot package name, CHANGELOG.md path, single PR mode) and .release-please-manifest.json (root package version 2.17.0) to establish release-please automation configuration.

Changes

Release-please configuration

Layer / File(s) Summary
release-please config and manifest
release-please-config.json, .release-please-manifest.json
Adds release-please-config.json with node release type, lucky-bot package name, single PR mode, no component tags, and CHANGELOG.md path. Adds .release-please-manifest.json mapping the root package to version 2.17.0.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~3 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title 'ci(release): automate releases with release-please' directly and clearly summarizes the main change: automating releases using the release-please tool via CI/CD configuration.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch ci/release-please-1478

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions

Copy link
Copy Markdown

Failed to generate code suggestions for PR

Comment thread .github/workflows/release-please.yml Outdated
coderabbitai[bot]
coderabbitai Bot previously approved these changes Jun 17, 2026
cubic-dev-ai[bot]
cubic-dev-ai Bot previously approved these changes Jun 17, 2026

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 4 files

Auto-approved: Adds release-please configuration and workflow for automated releases, removes old release workflow. CI/CD changes only, no logic or production code changes.

Re-trigger cubic

@LucasSantana-Dev

Copy link
Copy Markdown
Owner Author

Good catch — fixed in 706b351. Releases published by the default GITHUB_TOKEN don't propagate events (GitHub's recursion guard), so deploy.yml would never fire. Switched token: to secrets.RELEASE_PLEASE_TOKEN (a PAT) so the published Release triggers the deploy chain. The PAT also removes the dependency on the 'Allow Actions to create PRs' repo setting.

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your free trial has ended. If you'd like to continue receiving code reviews, you can add a payment method here.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

0 issues found across 1 file (changes from recent commits).

Requires human review: Adds release automation and removes old workflow; CI/CD and deployment pipeline changes are high-impact and require human review.

Re-trigger cubic

Implements the accepted ADR (decisions/2026-06-16-release-cadence-automate-releases.md):
release-please maintains a single open release PR on every main push,
pre-computing the next semver bump + CHANGELOG from conventional commits.
Merging that PR tags v* and publishes a GitHub Release, whose
release:published event triggers the unchanged deploy.yml gate.

- Add release-please-config.json (node release-type, root package, tag
  without component prefix so it stays v2.18.0).
- Seed .release-please-manifest.json at 2.17.0 → first managed release
  is 2.18.0, not a reset.
- Add .github/workflows/release-please.yml (push:main, no auto-merge —
  the one-click merge is the deliberate ship-to-prod checkpoint).
- Retire release.yml: it created a GitHub Release on v* tag push, which
  release-please now does on release-PR merge; leaving it would
  double-create. Its build+test gate is already covered by Quality Gates.

Refs #1478
Releases created with the default GITHUB_TOKEN do not raise events that
trigger other workflows (GitHub's recursion guard), so the
release: published event would fire but deploy.yml would never run —
silently breaking the prod deploy chain. Switch release-please to a PAT
(RELEASE_PLEASE_TOKEN, contents RW + pull-requests RW) so the published
release propagates to deploy.yml. The PAT also creates the release PR
without needing the 'Allow Actions to create PRs' repo setting.
@LucasSantana-Dev
LucasSantana-Dev force-pushed the ci/release-please-1478 branch from 706b351 to 3630da1 Compare June 17, 2026 19:39

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your free trial has ended. If you'd like to continue receiving code reviews, you can add a payment method here.

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your free trial has ended. If you'd like to continue receiving code reviews, you can add a payment method here.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
.github/workflows/release-please.yml (1)

16-18: ⚡ Quick win

Reduce default GITHUB_TOKEN to least privilege.

Line 16–18 grants write on the default token, but this job authenticates release operations with secrets.RELEASE_PLEASE_TOKEN (Line 38). Tightening these to read-only reduces blast radius if a step/action is compromised.

Suggested hardening diff
 permissions:
-    contents: write
-    pull-requests: write
+    contents: read
+    pull-requests: read
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/release-please.yml around lines 16 - 18, The permissions
block at lines 16-18 grants write access to contents and pull-requests for the
default GITHUB_TOKEN, but since this workflow authenticates release operations
using secrets.RELEASE_PLEASE_TOKEN instead, the default token should be
restricted to follow the least privilege principle. Change the permissions for
both contents and pull-requests from write to read to minimize the blast radius
if a step or action becomes compromised.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Nitpick comments:
In @.github/workflows/release-please.yml:
- Around line 16-18: The permissions block at lines 16-18 grants write access to
contents and pull-requests for the default GITHUB_TOKEN, but since this workflow
authenticates release operations using secrets.RELEASE_PLEASE_TOKEN instead, the
default token should be restricted to follow the least privilege principle.
Change the permissions for both contents and pull-requests from write to read to
minimize the blast radius if a step or action becomes compromised.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: dfd89410-02bf-44fd-9e61-22277cb25dea

📥 Commits

Reviewing files that changed from the base of the PR and between 596a55a and 2130099.

📒 Files selected for processing (4)
  • .github/workflows/release-please.yml
  • .github/workflows/release.yml
  • .release-please-manifest.json
  • release-please-config.json
💤 Files with no reviewable changes (1)
  • .github/workflows/release.yml
✅ Files skipped from review due to trivial changes (2)
  • .release-please-manifest.json
  • release-please-config.json
📜 Review details
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (13)
  • GitHub Check: Test — frontend
  • GitHub Check: Test — backend
  • GitHub Check: Test — shared
  • GitHub Check: Test — bot
  • GitHub Check: Checks
  • GitHub Check: Vercel Agent Review
  • GitHub Check: danger / danger
  • GitHub Check: quality / Dead code (knip)
  • GitHub Check: quality / Lint (lint)
  • GitHub Check: quality / SAST (CodeQL) (javascript-typescript)
  • GitHub Check: Build — frontend
  • GitHub Check: Build — backend
  • GitHub Check: Security

@sonarqubecloud

Copy link
Copy Markdown

@LucasSantana-Dev
LucasSantana-Dev merged commit 4b9fa33 into main Jun 19, 2026
44 checks passed
@LucasSantana-Dev
LucasSantana-Dev deleted the ci/release-please-1478 branch June 19, 2026 00:56

This branch was successfully deployed

1 active deployment
Preview — 21300999 Deployed Jun 19, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant