fix(release): verify main promotions by content, not merge-commit message - #2551
Conversation
|
Note Gemini is unable to generate a review for this pull request due to the file types involved not being currently supported. |
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7505a83795
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| startsWith(github.event.workflow_run.head_commit.message, 'Merge pull request') && | ||
| contains(github.event.workflow_run.head_commit.message, '/dev')) | ||
| || | ||
| (github.event.workflow_run.head_branch == 'main') || |
There was a problem hiding this comment.
Scope the auto-version skip away from rebase promotions
This new main promotion path is still nested under the job-level !contains(..., '[auto-version]') guard above. The dev bump step creates the dev tip as chore(version): ... [auto-version], so when the dev→main PR is rebase-merged and that rebased bump commit becomes the push head, workflow_run.head_commit.message contains [auto-version] and the entire job is skipped before Verify dev promotion can do the content check. In that merge mode, the stable dispatch still never fires; scope the auto-version skip to the dev bump path or otherwise let main promotions reach the promotion gate.
Useful? React with 👍 / 👎.
7505a83 to
4915087
Compare
Goal-loop structural fix: version.yml gated the stable/homolog release on the head commit message starting with 'Merge pull request … /dev'. A rebase- or squash-merged dev→main PR produces no such commit, so the stable release silently never fired — observed on #2537 (2026-07-09) and #2542 (2026-07-10): main advanced, .well-known/latest.json stayed stale, and pre-guard clients downgraded (reproduced live on the reference machine).
Fix: job-level message conditions replaced by a 'Verify dev promotion' step on the no-bump path — promoted when the head commit IS a dev merge commit (legacy fast path) OR when the pushed content equals dev's tip excluding .well-known (what rebase/squash promotions produce; manifests land on main only, which is exactly where a rebased tree always differs). Non-promotions skip the dispatch with a ::notice. If dev advanced past the PR head, the content check misses and the next promotion catches up — same posture as the existing atomic tag-push race.
Effect: the pending #2545 promotion publishes stable regardless of which merge button gets clicked.