Harden release workflow validation

This commit is contained in:
Kasra Bigdeli committed 2026-09-06 10:35:44 -07:00
1 parent 686428fb96
commit 6cdfe81424
4 files changed
+16 -7

No files matched your search

+2 -2
View File
@@ -12,7 +12,7 @@ Merging into `master` never publishes a production image.
`release/release.conf`.
4. Add a matching `## [X.Y.Z]` section to `CHANGELOG.md`.
5. Open `Release vX.Y.Z` targeting `release`.
6. Merge the PR after its checks pass.
6. Use a regular merge commit after the PR checks pass.
The resulting push to `release` publishes the production image and creates the
draft GitHub release. After publication succeeds, automation opens a
@@ -27,7 +27,7 @@ created. Later commits to `master` are left for the next release.
2. Apply the fix.
3. Update `release/release.conf` and `CHANGELOG.md` as described above.
4. Open `Hotfix vX.Y.Z` targeting `release`.
5. Merge the PR after its checks pass.
5. Use a regular merge commit after the PR checks pass.
This publishes the previous production code plus the hotfix, without including
unreleased work from `master`. The automated backmerge carries the fix and
+2 -2
View File
@@ -17,8 +17,8 @@ EXISTING_PR_URL="$(
--base master \
--head release \
--state open \
--json url \
--jq '.[0].url // empty'
--json url,isCrossRepository \
--jq 'map(select(.isCrossRepository == false)) | .[0].url // empty'
)"
if [ -n "$EXISTING_PR_URL" ]; then
+2 -1
View File
@@ -39,7 +39,8 @@ if [ "$TITLE_VERSION" != "$CAPROVER_VERSION" ]; then
exit 1
fi
if ! grep --extended-regexp --quiet "^## \[$CAPROVER_VERSION\]( |$)" CHANGELOG.md; then
ESCAPED_CAPROVER_VERSION="${CAPROVER_VERSION//./\\.}"
if ! grep --extended-regexp --quiet "^## \[$ESCAPED_CAPROVER_VERSION\]( |$)" CHANGELOG.md; then
echo "CHANGELOG.md is missing the heading ## [$CAPROVER_VERSION]." >&2
exit 1
fi
+10 -2
View File
@@ -15,7 +15,7 @@ for attempt in 1 2 3; do
gh api \
-H "Accept: application/vnd.github+json" \
"/repos/$GITHUB_REPOSITORY/commits/$GITHUB_SHA/pulls" \
--jq '.[] | select(.merged_at != null and .base.ref == "release") | [.title, .head.ref, .head.repo.full_name, .base.sha] | @tsv'
--jq ".[] | select(.merged_at != null and .base.ref == \"release\" and .merge_commit_sha == \"$GITHUB_SHA\") | [.title, .head.ref, .head.repo.full_name] | @tsv"
)
if [ "${#MATCHING_PRS[@]}" -gt 0 ]; then
@@ -32,7 +32,15 @@ if [ "${#MATCHING_PRS[@]}" -ne 1 ]; then
exit 1
fi
IFS=$'\t' read -r PR_TITLE PR_HEAD_REF PR_HEAD_REPOSITORY PR_BASE_SHA <<< "${MATCHING_PRS[0]}"
IFS=$'\t' read -r PR_TITLE PR_HEAD_REF PR_HEAD_REPOSITORY <<< "${MATCHING_PRS[0]}"
read -r -a COMMIT_AND_PARENTS <<< "$(git rev-list --parents --max-count=1 "$GITHUB_SHA")"
if [ "${#COMMIT_AND_PARENTS[@]}" -ne 3 ]; then
echo "Release PRs must use a regular merge commit." >&2
exit 1
fi
PR_BASE_SHA="${COMMIT_AND_PARENTS[1]}"
export PR_TITLE PR_HEAD_REF PR_HEAD_REPOSITORY PR_BASE_SHA
export REPOSITORY="$GITHUB_REPOSITORY"