Skip to content

ci: refine release-plz workflow and enable semver checks - #14

Merged
nh13 merged 1 commit into
mainfrom
nh_release-plz-refinements
Jun 21, 2026
Merged

nh13 merged 1 commit into
mainfrom
nh_release-plz-refinements

Conversation

@nh13

@nh13 nh13 commented Jun 20, 2026 •

Copy link
Copy Markdown
Contributor

What

mako already runs release-plz — it lives in the release-pr job of publish.yml ("Manage Release PRs and Publish"), not in a standalone release-plz.yml. This PR pulls in the "best bits" from the rest of the fg-labs/fulcrumgenomics fleet (fgumi, tricord, redskull) without changing that architecture, which is already the most complete instance of the pattern (it's the only one with the cross-platform binaries matrix, backfill-binaries.yml, and a publish-dry-run gate).

Changes

  1. Bump pinned action SHAs in publish.yml to match tricord/redskull:
    • release-plz/action v0.5.128 → v0.5.129
    • actions/create-github-app-token v3.0.0 → v3.1.1
    • actions/checkout v6.0.2 → v6.0.3
  2. Fork guard (from redskull): if: ${{ github.repository_owner == 'fg-labs' }} on the release-pr and publish jobs so release machinery never fires on a fork. The binaries job is covered transitively via needs: publish.
  3. Enable semver_check in release-plz.toml — it was disabled "until after the first release", and the crate is now past v0.1.2.

Notes

A redskull-style standalone release-plz.yml was intentionally not added — it would duplicate the existing release-pr job and cause double release PRs.

The check.yml and backfill-binaries.yml workflows still pin actions/checkout@v6.0.2; left out of scope here to keep the PR focused on release machinery. Happy to align them in a follow-up.

Summary by CodeRabbit

  • Chores
    • Improved release pipeline safety by preventing automated releases from repositories outside the primary owner
    • Enabled semantic versioning checks to help detect accidental breaking changes before release
    • Updated GitHub Actions versions used in the release workflow for improved stability and security

@coderabbitai

coderabbitai Bot commented Jun 20, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@nh13, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 36 minutes and 22 seconds. Learn how PR review limits work.

Your organization has used up its prepaid credits, and credit purchases are no longer available. Enable the review add-on in the billing tab to keep reviews running — you're only billed for reviews past your plan's rate limits ($0.25/file).

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based credits.

🚦 How do rate limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan refill rate.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, the refill rate gradually slows as usage increases. The highest same-day bursts are limited more strictly.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 3772cbe6-54c1-4f3c-97be-8f541459f5dc

📥 Commits

Reviewing files that changed from the base of the PR and between cfc99a1 and 8dd1c84.

📒 Files selected for processing (2)
  • .github/workflows/publish.yml
  • release-plz.toml
📝 Walkthrough

Walkthrough

The publish workflow gains an if: github.repository_owner == 'fg-labs' guard on the release-pr and publish jobs to block execution on forks. Action versions for create-github-app-token, checkout, and release-plz/action are bumped across all jobs. In release-plz.toml, semver_check is switched from false to true.

Changes

Release CI and Config Updates

Layer / File(s) Summary
Fork guard and action version bumps in publish workflow
.github/workflows/publish.yml
Adds if: github.repository_owner == 'fg-labs' to release-pr and publish jobs; bumps actions/create-github-app-token to v3.1.1, actions/checkout to v6.0.3, and release-plz/action to v0.5.129 across the release-pr, publish, and binaries jobs.
Enable semver_check in release-plz.toml
release-plz.toml
Sets semver_check = true and updates the adjacent comment to indicate cargo-semver-checks will now run on each release to detect accidental breaking changes.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~3 minutes

Poem

🐇 A fork shall not sneak through the gate,
For fg-labs must own the estate.
Semver now checks every bump,
No accidental breaking clump!
Versions pinned, the CI hops straight. 🌿

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the main changes: refining the release-plz workflow and enabling semver checks, which are the two key modifications in the PR.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@nh13

nh13 commented Jun 20, 2026

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jun 20, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/publish.yml:
- Around line 24-27: Add permission constraints to the create-github-app-token
action calls to scope tokens to least privilege. For the release-pr job's
app-token step (lines 24-27), add permissions for pull-requests write and
contents write. For the publish job's app-token step (lines 55-58), add
permission for contents write only. For the binaries job's app-token step (lines
133-136), add permission for contents read (or write if preferred for
consistency). Each token should inherit only the permissions required for its
respective job by adding the appropriate permission-pull-requests and
permission-contents fields with their required values (read or write) to the
with block of each create-github-app-token action.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 98914e6d-a4e6-4507-a829-9e298a00914a

📥 Commits

Reviewing files that changed from the base of the PR and between 033f959 and c6327d9.

📒 Files selected for processing (2)
  • .github/workflows/publish.yml
  • release-plz.toml

Comment thread .github/workflows/publish.yml
@nh13
nh13 force-pushed the nh_release-plz-refinements branch from c6327d9 to cfc99a1 Compare June 20, 2026 23:55
@nh13

nh13 commented Jun 21, 2026

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jun 21, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Bump pinned action SHAs in publish.yml to match the rest of the
fg-labs fleet (release-plz/action v0.5.128 -> v0.5.129,
create-github-app-token v3.0.0 -> v3.1.1, actions/checkout
v6.0.2 -> v6.0.3), guard the release-pr and publish jobs with
`github.repository_owner == 'fg-labs'` so release machinery never
fires on forks, and enable `semver_check` in release-plz.toml now
that the crate has published releases.
@nh13
nh13 force-pushed the nh_release-plz-refinements branch from cfc99a1 to 8dd1c84 Compare June 21, 2026 01:13
@nh13
nh13 merged commit ab7edca into main Jun 21, 2026
8 checks passed
@nh13
nh13 deleted the nh_release-plz-refinements branch June 21, 2026 01:15
@fg-labs-bot fg-labs-bot Bot mentioned this pull request Jul 19, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant