Skip to content

feat(desktop): publish the production app on merge, and say what changed - #120

Merged
tusharbhardwaj-bk merged 1 commit into
expbkmainfrom
t3code/desktop-auto-publish
Aug 19, 2026
Merged

tusharbhardwaj-bk merged 1 commit into
expbkmainfrom
t3code/desktop-auto-publish

Conversation

@tusharbhardwaj-bk

@tusharbhardwaj-bk tusharbhardwaj-bk commented Aug 19, 2026 •

Copy link
Copy Markdown
Collaborator

Lands on expbkmain so it joins the open promotion PR #119 into bkmain.

Auto-publish

A merge to bkmain built the production desktop app and then waited on a manual approval before publishing, so the team's download lagged the server deploy.

The gate was required_reviewers: tusharbhardwaj-bk on the bk-desktop-production environment — a repository setting, not workflow YAML. I removed it via the API; the environment now matches bk-desktop-staging exactly (no protection rules, no branch policy), which is the config that has always auto-published staging.

Nothing in this diff can express that removal, which is exactly why the workflow comment now records where the gate lived and how to restore it. Please sanity-check the environment settings alongside this diff — the diff alone cannot show you the change that matters most.

One correction worth flagging: my first API call also set deployment_branch_policy.protected_branches: true. bkmain is not a protected branch, so that would have blocked production publishing outright — worse than the gate it replaced. Caught and corrected before any release ran; both environments now read {"rules": [], "branchPolicy": null}.

Signing is unaffected: the key lives in the build job, which has no environment.

Compact change list in the release

Release notes previously carried only build metadata. They now open with what changed since the previous build of the same channel:

  • subject lines only, bodies dropped
  • merge commits dropped — on this fork every change arrives through a merge, so keeping them lists each change twice
  • duplicates collapsed (rebases, cherry-picks)
  • capped at 15 with …and N more commits.

Resolved through the compare API rather than git log, because the publish job checks out at depth 1 and has no history to walk. Every failure path returns an empty list rather than throwing: a release without its change list is cosmetic; a release that does not ship is an outage of the update channel.

Verification

8 tests passed in scripts/publish-bk-desktop-dmg.test.ts, covering subject extraction, merge-commit removal, dedupe, the overflow tail, and the empty case. tsgo --noEmit clean for scripts (0 errors), lint and check-fork-markers.ts pass.

Not verifiable locally: the publish itself runs on GitHub-hosted macOS with the signing key. The first real proof is the next release's body.

🤖 Generated with Claude Code


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

A merge to bkmain built the production app and then waited for a human to
approve the publish, so the team's download lagged the deploy by however long
that took. The required-reviewer rule is removed and both channels now publish
the moment their build is green.

That rule lived in the `bk-desktop-production` environment's settings, not in
this workflow — protection rules are repository settings and no workflow file
can express their absence. The comment says so, so the next reader looking for
a gate that is not in the YAML knows where it went and how to put it back.

Release notes now open with the commits since the previous build of the same
channel: subject lines only, merge commits dropped so each change is listed
once rather than twice, duplicates collapsed, and a tail summary past fifteen.
Resolved through the compare API because the publish job checks out at depth 1
and has no history to walk, and never fatal — a release without its change list
is cosmetic, a release that does not ship is an outage of the update channel.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions github-actions Bot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:L labels Aug 19, 2026
@github-actions

Copy link
Copy Markdown

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ℹ️ No successful main baseline artifact is available yet. This run establishes the initial measurement.

Provider Metric Main baseline This PR Impact PR ceiling
Codex Total thread wire — 11.4 KiB — 15.1 KiB ✅
Codex Thread snapshot wire — 5.7 KiB — 7.3 KiB ✅
Codex Live turn WebSocket wire — 5.7 KiB — 7.8 KiB ✅
Codex Live turn WebSocket decoded — 50.3 KiB — 66.4 KiB ✅
Codex Live turn messages — 9 — 21 ✅
Claude Total thread wire — 11.4 KiB — 15.1 KiB ✅
Claude Thread snapshot wire — 5.7 KiB — 7.3 KiB ✅
Claude Live turn WebSocket wire — 5.7 KiB — 7.8 KiB ✅
Claude Live turn WebSocket decoded — 51.2 KiB — 66.4 KiB ✅
Claude Live turn messages — 9 — 21 ✅

Baseline: unavailable · PR result: ab3fce6 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 95.6 KiB
  • Claude decoded thread snapshot: 96.3 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@tusharbhardwaj-bk
tusharbhardwaj-bk merged commit d9b2774 into expbkmain Aug 19, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant