Skip to content

fix(ci): repair staging promotion workflow behavior - #1091

Merged
henrypark133 merged 9 commits into
stagingfrom
fix/staging-ci-workflow-parsing
Mar 13, 2026
Merged

henrypark133 merged 9 commits into
stagingfrom
fix/staging-ci-workflow-parsing

Conversation

@henrypark133

Copy link
Copy Markdown
Collaborator

This fixes the staging promotion workflow regressions and adds release-note metadata plumbing for staged batch promotions.

Changes included:

  • repair the staging-ci.yml parse failure introduced by the commit-summary block
  • resolve promotion chaining against the latest open staging-promote/* branch instead of the repo default branch
  • write structured batch summaries into promotion merges to main
  • keep open staging-promotion PR bodies updated with cumulative current commits
  • add a release-plz PR augmentation workflow that reads structured staging batch summaries from main
  • add workflow_dispatch + dry_run support for the metadata workflows so they can be tested safely before merge
  • limit release summary tag fetching to version tags (v*)

Validation:

  • actionlint -ignore 'SC2001|SC2129' on the affected workflows\n- bash -n on the new helper scripts\n- dry-run checks against staging-promotion PR #1032 and release-plz PR #973

Copilot AI review requested due to automatic review settings March 13, 2026 00:32
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Warning

You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again!

@github-actions github-actions Bot added scope: ci CI/CD workflows size: L 200-499 changed lines risk: medium Business logic, config, or moderate-risk modules contributor: core 20+ merged PRs labels Mar 13, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR repairs regressions in the staging promotion automation and introduces structured “batch summary” metadata so promotion PRs and release-plz PRs can stay up to date with the currently-promoted commit set.

Changes:

  • Fixes staging CI promotion chaining by resolving the base branch from the latest open staging-promote/* PR instead of the repo default branch.
  • Adds workflows + scripts to keep staging promotion PR bodies updated with a “current commits” section and to write a structured summary into merge commits to main.
  • Adds a release-plz augmentation workflow + script to read those structured merge summaries from main and update release-plz PR bodies (with workflow_dispatch + dry-run support).

Reviewed changes

Copilot reviewed 5 out of 5 changed files in this pull request and generated 2 comments.

Show a summary per file
File Description
.github/workflows/staging-ci.yml Resolves promotion base from latest open staging promotion PR; writes structured batch summaries into merge commits; removes prior commit-summary output that caused parsing issues.
.github/workflows/staging-promotion-metadata.yml New workflow to update staging promotion PR bodies (single PR on PR events / manual; all open PRs on push to main).
.github/workflows/release-plz-batch-summary.yml New workflow to update release-plz PR bodies with staging batch summaries (PR events / manual + dry-run).
.github/scripts/update-staging-promotion-body.sh New helper to recompute and upsert the “current commits” section in staging promotion PR bodies.
.github/scripts/update-release-plz-body.sh New helper to scan main merge commits for structured staging promotion summaries and upsert a release summary section into release-plz PR bodies.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread .github/workflows/staging-ci.yml Outdated
Comment thread .github/scripts/update-release-plz-body.sh Outdated

@zmanian zmanian left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Overview

This restructures the staging promotion workflow to fix the parse regression and adds structured release-note metadata. The core fix (hoisting resolve-promotion-base into its own job so all downstream steps use a consistent base) is the right approach.

Observations

1. pull_request_target on metadata workflows (worth verifying)

Both staging-promotion-metadata.yml and release-plz-batch-summary.yml trigger on pull_request_target, which grants write access from the base branch. The scripts call gh pr edit to update PR bodies. This is fine for trusted CI branches, but the release-plz-batch-summary.yml filter (startsWith(github.event.pull_request.head.ref, 'release-plz-')) could theoretically match a branch name from a fork PR. Worth verifying that fork PRs are restricted or that GITHUB_TOKEN permissions are scoped tightly enough.

2. Duplicate commit enumeration logic (non-blocking)

The commit listing pattern (log, count, cap at 50, format with sed 's/^/- /') appears in 3 places: inline in the workflow create-pr step, in update-staging-promotion-body.sh, and in the merge step. Could be extracted into a shared helper function to reduce maintenance surface.

3. Duplicate awk block for HTML comment replacement (non-blocking)

The awk block that replaces content between <!-- section:start --> / <!-- section:end --> markers is identical in both helper scripts. Another candidate for a shared utility.

4. fetch-depth: 0 in gate job

Changed from fetch-depth: 1 to fetch-depth: 0. Needed for computing the merge commit body from git history, but adds full clone time on every gate run. Acceptable tradeoff given this only runs on promotion PRs, just noting it.

5. mapfile -t assumes bash 4+ (minor)

The refresh-open-prs-after-main-push job uses mapfile -t. GitHub runners have bash 4+, so this works, but a comment would help future readers.

Copilot AI review requested due to automatic review settings March 13, 2026 03:24
@github-actions github-actions Bot added size: XL 500+ changed lines and removed size: L 200-499 changed lines labels Mar 13, 2026
@henrypark133

Copy link
Copy Markdown
Collaborator Author

Addressing review 3940846227:

  • Fixed the pull_request_target concern by requiring github.event.pull_request.head.repo.full_name == github.repository in both metadata workflows, so branch-name matches from forks do not qualify.
  • Deduped the repeated commit-summary and marked-section replacement logic into .github/scripts/pr-body-utils.sh, and reused it from the workflows/scripts that were carrying copies.
  • Kept fetch-depth: 0 in the gate job, but added an explicit comment documenting why the full history is needed there.
  • Added the requested note on mapfile, since this job is pinned to ubuntu-latest / bash 5.x.
  • Also fixed a related issue not called out in the review: the release-plz PR job now uses the GitHub App token, so downstream PR-triggered workflow behavior is consistent with the automation intent.

I validated the changes locally with bash -n, YAML parse, actionlint, shellcheck, and local-only DRY_RUN=true script simulations against a temporary local git remote so nothing was modified remotely during testing.

@henrypark133
henrypark133 requested a review from zmanian March 13, 2026 03:28

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Repairs regressions in the staging promotion CI flow and adds “structured batch summary” plumbing so staging-promotion metadata can be propagated into release-plz PR bodies.

Changes:

  • Updates staging-ci.yml to chain promotions off the newest open staging-promote/* branch, and to write a structured merge-body summary when promoting to main.
  • Adds workflows + scripts to keep staging-promotion PR bodies updated with a “current commits” section and to augment release-plz PRs with recent staged batch summaries from main.
  • Adds workflow_dispatch + dry_run support for the metadata update workflows and limits tag fetching to v* tags.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Show a summary per file
File Description
.github/workflows/staging-promotion-metadata.yml New workflow to update staging-promotion PR bodies (single PR events + refresh-all on main pushes).
.github/workflows/staging-ci.yml Fixes promotion base resolution, updates PR body composition, and emits structured merge-body summaries.
.github/workflows/release-plz.yml Switches release-plz PR job to use a GitHub App token so created PRs/tags can trigger workflows.
.github/workflows/release-plz-batch-summary.yml New workflow to update release-plz PR bodies with staged batch summaries (supports dry-run).
.github/scripts/update-staging-promotion-body.sh New helper to recompute/replace the “current commits” section in staging promotion PR bodies.
.github/scripts/update-release-plz-body.sh New helper to extract structured staging summaries from main merge commits and inject into release-plz PR bodies.
.github/scripts/pr-body-utils.sh New shared utilities for commit summary generation and marked-section replacement in PR bodies.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread .github/workflows/staging-ci.yml Outdated

@zmanian zmanian left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thorough review of the staging promotion workflow improvements. This is well-structured.

What's good:

  1. Shared utilities (pr-body-utils.sh): load_commit_summary and replace_marked_section are clean, reusable helpers. The awk-based section replacement handles edge cases (missing markers, empty body).

  2. Promotion base resolution: Moving the base branch lookup to a dedicated resolve-promotion-base job that runs once and feeds downstream via outputs is cleaner than the previous inline find-base step. Correctly chains onto existing open promotion branches.

  3. Structured merge commit metadata: The staging-promotion-summary-v1 format in merge bodies with machine-parseable fields (promotion-pr:, current-range:, etc.) is a good foundation for the release-plz batch summary extraction.

  4. Auto-refreshing PR bodies: Both staging-promotion-metadata.yml and release-plz-batch-summary.yml use HTML comment markers for idempotent section replacement. The push trigger on main to refresh all open promotion PRs is a nice touch.

  5. Severity parsing fix: Replacing sed regex with shell parameter expansion (${TAG#\[}, ${SEVERITY%%:*}) is more robust.

  6. Dry-run support: Both metadata workflows support workflow_dispatch with dry_run: true for safe testing.

Minor notes (non-blocking):

  • update-release-plz-body.sh line 21: git fetch origin "+refs/tags/v*:refs/tags/v*" -- the + force-update prefix is fine but unusual in CI where tags shouldn't diverge. No issue, just noting.

  • The mapfile usage in refresh-open-prs-after-main-push job has a comment noting bash 5.x availability on ubuntu-latest -- good defensive documentation.

  • fetch-depth: 0 in the gate job (changed from fetch-depth: 1) is needed for recomputing the final range before merge -- the comment explaining why is helpful.

LGTM

@henrypark133
henrypark133 merged commit 3c619b6 into staging Mar 13, 2026
9 of 10 checks passed
@henrypark133
henrypark133 deleted the fix/staging-ci-workflow-parsing branch March 13, 2026 03:34

@zmanian zmanian left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All feedback from the previous review has been addressed:

  • Commit enumeration and awk section-replacement logic deduped into pr-body-utils.sh with load_commit_summary() and replace_marked_section()
  • Fork PR guard added to both pull_request_target workflows (head.repo.full_name == github.repository)
  • mapfile bash version comment added
  • --repo passed explicitly to gh pr list in resolve-promotion-base

Good bonus cleanup: sed-to-parameter-expansion for tag parsing, grouped step summary writes, fetch-depth comment.

One note: release-plz.yml now uses a GitHub App token -- make sure GH_RELEASES_MANAGER_APP_ID and GH_RELEASES_MANAGER_APP_PRIVATE_KEY secrets are configured in the repo, otherwise the release-pr job will fail.

LGTM.

ilblackdragon pushed a commit that referenced this pull request Mar 14, 2026
* fix(ci): repair staging-ci workflow parsing

* fix(ci): chain staging promotion to latest open branch

* feat(ci): carry staging batch summaries into release PRs

* test(ci): add dry-run dispatch for promotion metadata workflows

* fix(ci): fetch only release tags for batch summaries

* fix(ci): address review feedback on batch summaries

* fix(ci): harden metadata workflows and dedupe body helpers

* fix(ci): pass repo explicitly to gh pr list
bkutasi pushed a commit to bkutasi/ironclaw that referenced this pull request Mar 28, 2026
* fix(ci): repair staging-ci workflow parsing

* fix(ci): chain staging promotion to latest open branch

* feat(ci): carry staging batch summaries into release PRs

* test(ci): add dry-run dispatch for promotion metadata workflows

* fix(ci): fetch only release tags for batch summaries

* fix(ci): address review feedback on batch summaries

* fix(ci): harden metadata workflows and dedupe body helpers

* fix(ci): pass repo explicitly to gh pr list
drchirag1991 pushed a commit to drchirag1991/ironclaw that referenced this pull request Apr 8, 2026
* fix(ci): repair staging-ci workflow parsing

* fix(ci): chain staging promotion to latest open branch

* feat(ci): carry staging batch summaries into release PRs

* test(ci): add dry-run dispatch for promotion metadata workflows

* fix(ci): fetch only release tags for batch summaries

* fix(ci): address review feedback on batch summaries

* fix(ci): harden metadata workflows and dedupe body helpers

* fix(ci): pass repo explicitly to gh pr list
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: medium Business logic, config, or moderate-risk modules scope: ci CI/CD workflows size: XL 500+ changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants