Skip to content

Use github-release-actions for CI/CD - #557

Merged
danielemery merged 5 commits into
mainfrom
use-github-release-actions
Jun 16, 2026
Merged

danielemery merged 5 commits into
mainfrom
use-github-release-actions

Conversation

@danielemery

@danielemery danielemery commented Jun 15, 2026 •

Copy link
Copy Markdown
Owner
  • Added plan to adopt semver release actions
  • Added PR semver label gate and split CI workflows

Summary by CodeRabbit

Release Notes

  • New Features

    • Added an automated release-candidate pipeline with staging deployment and prerelease asset publishing.
    • Added a manual stable-promotion workflow to promote an existing prerelease to stable (including Docker, Helm, and monitoring updates).
  • Chores

    • Introduced CI for linting and tests, plus PR checks for required semver labeling.
    • Updated dependency automation settings and replaced/removed older publish/validation automation.
  • Documentation

    • Updated README and CONTRIBUTING to describe the semver label workflow and promotion/pinning rules.

@danielemery danielemery added the semver:patch A PR with this label will trigger a patch semver bump label Jun 15, 2026
@coderabbitai

coderabbitai Bot commented Jun 15, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@danielemery, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 34 minutes and 47 seconds. Learn how PR review limits work.

Your organization has used up its prepaid credits, and credit purchases are no longer available. Enable the review add-on in the billing tab to keep reviews running — you're only billed for reviews past your plan's rate limits ($0.25/file).

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 112a7935-4927-4950-a29d-dec2d17e0204

📥 Commits

Reviewing files that changed from the base of the PR and between 5d673d9 and 7840dbc.

📒 Files selected for processing (5)
  • .github/workflows/publish.yml
  • .github/workflows/release-candidate.yml
  • .github/workflows/release-stable.yml
  • CONTRIBUTING.md
  • README.md
📝 Walkthrough

Walkthrough

The PR replaces the old validate-pr.yaml workflow with separate ci.yml and docker-build.yml PR checks, adds a validate-pr.yml that enforces exactly one semver label per PR, reworks release-candidate.yml to trigger on merged PRs and orchestrate versioned artifact publishing, introduces a new release-stable.yml for manual RC-to-stable promotion, and updates Dependabot/Renovate to auto-apply semver:patch labels with documentation in README.md and CONTRIBUTING.md.

Changes

Release pipeline overhaul

Layer / File(s) Summary
Semver label enforcement and dependency tool config
.github/workflows/validate-pr.yml, .github/dependabot.yml, renovate.json
validate-pr.yml enforces exactly one semver label on PRs via validate-semver-label@v0.5.1. dependabot.yml disables version-update PRs and tags security PRs with semver:patch. renovate.json auto-labels dependency PRs with semver:patch and adds :prConcurrentLimitNone.
PR CI and Docker build checks
.github/workflows/ci.yml, .github/workflows/docker-build.yml
Adds ci.yml (lint, test, Codecov upload) and docker-build.yml (build + Docker image build without push) as focused PR checks targeting main.
Release-candidate pipeline rework
.github/workflows/release-candidate.yml
Reworks trigger from tag-push to merged-PR-to-main. Introduces a version job for prerelease metadata; wires build, docker-publish, helm-publish, and sentry jobs through those outputs. Adds create-prerelease job that packages and uploads sourcemaps.tar.gz as a release asset to support stable promotion.
Stable promotion workflow
.github/workflows/release-stable.yml
New workflow_dispatch workflow that promotes a named RC to stable: pre_release captures metadata, retag-image retags the GHCR image to stable/latest, helm-stable publishes the Helm chart at the exact RC commit, sentry-stable creates a prod Sentry deployment from RC sourcemaps, and post_release finalises the GitHub release and cleans up RC intermediates.
Release process documentation
CONTRIBUTING.md, README.md
CONTRIBUTING.md documents the semver label flow, RC creation on merge, stable promotion steps, and operator pinning rules. README.md adds a release summary section referencing CONTRIBUTING.md.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Poem

🐇 Hop, hop, a label must be placed,
Before your code can be embraced!
RC tags bounce off to staging they go,
Then stable promotion puts on a show.
With sourcemaps zipped and Helm charts set,
The tidiest pipeline yet! 🎉

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title 'Use github-release-actions for CI/CD' is partially related to the changeset. While the PR does implement github-release-actions for release workflows, the primary changes also include major CI/CD restructuring (splitting workflows, adding semver-based labeling, and reconfiguring Dependabot), making the title incomplete and somewhat narrow.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch use-github-release-actions

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Comment thread .github/workflows/validate-pr.yml Dismissed
@codecov-commenter

codecov-commenter commented Jun 15, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 36.30%. Comparing base (89e3143) to head (7840dbc).

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #557   +/-   ##
=======================================
  Coverage   36.30%   36.30%           
=======================================
  Files          28       28           
  Lines         942      942           
  Branches      188      188           
=======================================
  Hits          342      342           
  Misses        548      548           
  Partials       52       52           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

danielemery and others added 2 commits June 16, 2026 17:19
Documented the migration from the manual tag-push release model to the
semver, label-driven flow from danielemery/github-release-actions
(pinned to v0.5.1), adapted for this repo's three artifacts (docker
image, helm chart, sentry release).

Covers the five-workflow shape, the build-inline-then-retag promotion
pattern, resolved design decisions (sentry deploy model, helm
re-package, checkout map, monotonic promotion, first-rc), bot
self-labelling for Renovate and Dependabot, and a commit/rollout
sequence.

Co-Authored-By: Claude <noreply@anthropic.com>
First step of the github-release-actions semver migration (PR 1 of the
plan in TASKS.md). Splits the old validate-pr.yaml into focused PR
checks and prepares the bots for the upcoming required label gate.

- validate-pr.yml: gates each PR on exactly one semver:* label via
  github-release-actions/validate-semver-label
- ci.yml: lint + unit tests + Codecov on pull requests
- docker-build.yml: builds the image with push:false so Dockerfile or
  build breakage surfaces at PR time
- renovate.json: labels every Renovate PR semver:patch
- dependabot.yml: keeps Dependabot for security updates only
  (open-pull-requests-limit: 0) and labels them semver:patch

main.yml is kept as-is for the Codecov badge / base coverage. The
label gate is not made a required check here; that is an admin step
(F2) taken after the semver:* labels exist.

Checked off Phase A (A1-A7) in TASKS.md.

Co-Authored-By: Claude <noreply@anthropic.com>
@danielemery
danielemery force-pushed the use-github-release-actions branch from 21a2a82 to 23ab9d3 Compare June 16, 2026 15:19
@danielemery
danielemery marked this pull request as ready for review June 16, 2026 15:20
@danielemery danielemery self-assigned this Jun 16, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 5

🧹 Nitpick comments (1)
.github/workflows/release-stable.yml (1)

11-14: ⚡ Quick win

Enforce “latest RC only” promotion in workflow logic (not docs-only).

Right now an operator can promote an older RC and move :latest backwards. Add a pre-check in pre_release that rejects promotion unless the provided RC is the highest -rc.N for that base version.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/release-stable.yml around lines 11 - 14, Add validation
logic in the `pre_release` step of the workflow to enforce that the provided
prerelease_version parameter is the highest RC for its base version. Extract the
base version and RC number from the provided prerelease_version input, query
existing RC tags or releases to determine the highest RC for that base version,
and fail the workflow if the provided RC is not the latest. This check should
occur before any promotion logic executes, preventing operators from promoting
older RCs that would move the latest tag backwards.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/ci.yml:
- Line 19: Replace all mutable GitHub Actions version tags with their
corresponding full commit SHAs to eliminate the risk of tag retargeting by
maintainers. In .github/workflows/ci.yml, update the uses entries at lines 19,
22, and 36 for actions/checkout@v6.0.2, actions/setup-node@v6.4.0, and
codecov/codecov-action@v6.0.1 respectively to use their full commit SHAs. In
.github/workflows/docker-build.yml, update the uses entries at lines 20, 23, and
34 for actions/checkout@v6.0.2, actions/setup-node@v6.4.0, and
docker/build-push-action@v7.2.0 respectively to use their full commit SHAs. In
.github/workflows/validate-pr.yml, update the uses entry at line 14 for
danielemery/github-release-actions/validate-semver-label@v0.5.1 to use its full
commit SHA. This ensures deterministic and tamper-resistant workflow runs.

In @.github/workflows/release-candidate.yml:
- Around line 15-17: Change the top-level permissions in the release-candidate
workflow to be read-only by removing `contents: write` and `packages: write`
from the permissions block at lines 15-17, leaving only read permissions. Then
add job-level permissions that grant `contents: write` and `packages: write`
only to the specific jobs that require write access, such as docker-publish and
release creation jobs. Apply the same permission-scoping fix to
`.github/workflows/release-stable.yml` where the identical overly-broad
top-level write permissions exist.
- Line 38: Replace all version tag references in the `uses:` directives with
immutable full commit SHAs to prevent supply-chain drift. In
`.github/workflows/release-candidate.yml`, update the `uses:` action on line 38
(danielemery/github-release-actions/calculate-prerelease-version) and the
corresponding entries on lines 173 and 181 by replacing the mutable version tags
(such as `@v0.5.1`) with their full commit SHA equivalents. Apply the same fix
to all corresponding `uses:` entries in `.github/workflows/release-stable.yml`
that currently use version tags instead of commit SHAs.

In @.github/workflows/release-stable.yml:
- Around line 59-66: Replace all usages of the raw workflow_dispatch input
`inputs.prerelease_version` with the canonicalized output from the `pre_release`
job to eliminate injection risks and ensure consistent formatting. In
.github/workflows/release-stable.yml at line 59, change the RC_TAG environment
variable assignment from using `inputs.prerelease_version` to
`needs.pre_release.outputs.release-tag`. Apply the same fix at lines 75-75 and
103-104 where `inputs.prerelease_version` is referenced directly in shell
commands or other contexts, using the appropriate pre_release job output (either
release-tag or release-version as applicable to each location).
- Around line 1-4: The top-of-file comments in the release-stable workflow
incorrectly state that stable promotion performs "no sourcemap re-upload," but
the sentry-stable step actually downloads and re-uploads sourcemaps under the
stable release name. Update the header comments to accurately reflect this
current behavior by removing or correcting the statement about sourcemap
handling to match what the sentry-stable step actually does.

---

Nitpick comments:
In @.github/workflows/release-stable.yml:
- Around line 11-14: Add validation logic in the `pre_release` step of the
workflow to enforce that the provided prerelease_version parameter is the
highest RC for its base version. Extract the base version and RC number from the
provided prerelease_version input, query existing RC tags or releases to
determine the highest RC for that base version, and fail the workflow if the
provided RC is not the latest. This check should occur before any promotion
logic executes, preventing operators from promoting older RCs that would move
the latest tag backwards.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 60e9bc64-2156-4883-a369-239314054001

📥 Commits

Reviewing files that changed from the base of the PR and between 89e3143 and 23ab9d3.

📒 Files selected for processing (10)
  • .github/dependabot.yml
  • .github/workflows/ci.yml
  • .github/workflows/docker-build.yml
  • .github/workflows/release-candidate.yml
  • .github/workflows/release-stable.yml
  • .github/workflows/validate-pr.yaml
  • .github/workflows/validate-pr.yml
  • CONTRIBUTING.md
  • README.md
  • renovate.json
💤 Files with no reviewable changes (1)
  • .github/workflows/validate-pr.yaml

Comment thread .github/workflows/ci.yml
Comment thread .github/workflows/release-candidate.yml Outdated
Comment thread .github/workflows/release-candidate.yml
Comment thread .github/workflows/release-stable.yml Outdated
Comment thread .github/workflows/release-stable.yml
@danielemery
danielemery force-pushed the use-github-release-actions branch from 23ab9d3 to 5d673d9 Compare June 16, 2026 19:22

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/release-candidate.yml:
- Around line 59-69: The `.dockerignore` file is a hidden file (starts with `.`)
and will be excluded from the artifacts by default when using
`actions/upload-artifact@v7.0.1` since it excludes hidden files by default.
Either remove `.dockerignore` from the path list in the Upload build artifacts
action if it is not needed in the downloaded artifacts, or add
`include-hidden-files: true` to the `with:` section of the upload-artifact step
if `.dockerignore` is necessary for the build process and should be included.
- Around line 17-19: The release-candidate.yml and release-stable.yml workflows
use different concurrency groups (main and prod-deployment respectively),
allowing RC version calculations and stable promotion cleanup to interleave, and
without queue: max, GitHub Actions skips older pending runs during merge bursts.
In .github/workflows/release-candidate.yml lines 17-19, change the concurrency
group from main to a shared release-specific group name and add queue: max. In
.github/workflows/release-stable.yml lines 23-24, make the identical change to
use the same shared group name and add queue: max. This ensures all release
mutations (version calculation, tag creation, and RC cleanup) serialize through
a single queued lane.

In @.github/workflows/release-stable.yml:
- Around line 66-75: The "Retag prerelease image as stable" step applies both
the stable version tag and the mutable `latest` tag before the `helm-stable` and
`sentry-stable` jobs complete, creating a risk that `latest` points to an
incompletely released version if those jobs fail. Remove the `--tag
"${REGISTRY}/${IMAGE_NAME}:latest"` line from the docker buildx imagetools
create command in this step so it only tags the stable version. Then create a
new `retag-latest` job that depends on `retag-image`, `helm-stable`, and
`sentry-stable`, and have it apply the `latest` tag to the stable image.
Finally, update `post_release` to depend on this new `retag-latest` job to
ensure the latest tag is only applied after all release steps succeed.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: ec3756da-ad6f-4690-a04c-04d3b54bd435

📥 Commits

Reviewing files that changed from the base of the PR and between 23ab9d3 and 5d673d9.

📒 Files selected for processing (5)
  • .github/workflows/publish.yml
  • .github/workflows/release-candidate.yml
  • .github/workflows/release-stable.yml
  • CONTRIBUTING.md
  • README.md
💤 Files with no reviewable changes (1)
  • .github/workflows/publish.yml
✅ Files skipped from review due to trivial changes (1)
  • README.md
🚧 Files skipped from review as they are similar to previous changes (1)
  • CONTRIBUTING.md

Comment thread .github/workflows/release-candidate.yml
Comment thread .github/workflows/release-candidate.yml
Comment thread .github/workflows/release-stable.yml
danielemery and others added 3 commits June 16, 2026 21:47
Cut the merge-triggered prerelease pipeline: a labelled PR merge to
main now builds and pushes the vX.Y.Z-rc.N docker, helm and sentry-stg
artifacts, then tags last via create-prerelease. Deleted the old
tag-push publish.yml and its check-version-format usage; no push:tags
triggers remain.

Co-Authored-By: Claude <noreply@anthropic.com>
Manual workflow_dispatch that promotes a chosen rc to stable without
rebuilding: perform-pre-release promotes, the prerelease docker image
is retagged to :<stable>+:latest via imagetools, helm is re-packaged
from the rc commit, and the rc's persisted sourcemaps are re-uploaded
under the stable Sentry release with a prod deploy. perform-post-release
publishes the release and cleans up the -rc.N intermediates.

Co-Authored-By: Claude <noreply@anthropic.com>
Rewrote the README Deployment section to describe label -> merge ->
staging rc -> manual promote-to-stable, replacing the old manual
tag-push instructions. Added CONTRIBUTING.md with a Releasing section
covering PR labelling, cutting a candidate, promoting via the Release
Stable dispatch, and the operator rules (promote the latest rc; pinned
infra deploys an exact version, never :latest).

Removed the branch's TASKS.md migration plan now that the work is
complete.

Co-Authored-By: Claude <noreply@anthropic.com>
@danielemery
danielemery force-pushed the use-github-release-actions branch from 5d673d9 to 7840dbc Compare June 16, 2026 19:48
@danielemery
danielemery merged commit 53cd9b2 into main Jun 16, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

semver:patch A PR with this label will trigger a patch semver bump

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants