Skip to content

Commit 65ff85c

Browse files
author
hack-cli-tests
committed
fix(release): validate candidate workflows and next push checks
1 parent 43706f4 commit 65ff85c

6 files changed

Lines changed: 40 additions & 6 deletions

File tree

‎.ai/skills/hack-repo-verify/SKILL.md‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -37,6 +37,10 @@ For native setup use root `mise.toml`, the Bun pin in `package.json`, and
3737
`bun run test:local`. Add `--all-features` to equivalent Cargo commands for feature
3838
changes; the toolchain Rust tasks already enable all features. Keep default coverage.
3939

40+
For release workflow edits, run the pinned syntax/context check also enforced by CI:
41+
`mise x actionlint@1.7.12 -- actionlint -shellcheck= -pyflakes= .github/workflows/ci.yml .github/workflows/release.yml .github/workflows/prerelease.yml`.
42+
This validates event globs and reusable workflow contexts; Bun YAML parsing alone does not.
43+
4044
`bun run privacy:check` scans Git-tracked files. Stage reviewed new source/tests
4145
before the final gate, or rerun it after staging: an earlier pass does not cover
4246
untracked candidate additions. Keep private artifacts excluded from the index.

‎.github/actionlint.yaml‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
# Blacksmith runner labels used by this repository's CI and release workflows.
2+
self-hosted-runner:
3+
labels:
4+
- blacksmith-4vcpu-ubuntu-2404
5+
- blacksmith-6vcpu-macos-15

‎.github/workflows/ci.yml‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,9 @@ name: CI
22

33
on:
44
push:
5+
branches:
6+
- main
7+
- next
58
tags-ignore:
69
- "v*"
710
pull_request:
@@ -32,6 +35,8 @@ jobs:
3235
install: false
3336
cache: false
3437
env: false
38+
- name: Validate release workflow syntax
39+
run: mise x actionlint@1.7.12 -- actionlint -shellcheck= -pyflakes= .github/workflows/ci.yml .github/workflows/release.yml .github/workflows/prerelease.yml
3540
- name: Fetch pinned model checker
3641
run: curl --fail --location --retry 2 --max-time 60 https://github.com/tlaplus/tlaplus/releases/download/v1.7.4/tla2tools.jar --output "$RUNNER_TEMP/tla2tools.jar"
3742
- name: Check evidence validation and models

‎.github/workflows/prerelease.yml‎

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -63,10 +63,11 @@ jobs:
6363
timeout-minutes: 60
6464
permissions:
6565
contents: read
66-
env:
67-
HACK_PRERELEASE_BUNDLE: ${{ runner.temp }}/native-candidate
68-
HACK_PRERELEASE_OUTPUT: ${{ runner.temp }}/prerelease-assets
6966
steps:
67+
- name: Select isolated build directories
68+
run: |
69+
printf 'HACK_PRERELEASE_BUNDLE=%s/native-candidate\n' "$RUNNER_TEMP" >> "$GITHUB_ENV"
70+
printf 'HACK_PRERELEASE_OUTPUT=%s/prerelease-assets\n' "$RUNNER_TEMP" >> "$GITHUB_ENV"
7071
- uses: actions/checkout@v4
7172
with:
7273
ref: ${{ needs.plan.outputs.source_revision }}
@@ -111,9 +112,10 @@ jobs:
111112
statuses: read
112113
deployments: read
113114
env:
114-
HACK_PRERELEASE_OUTPUT: ${{ runner.temp }}/prerelease-assets
115115
GH_TOKEN: ${{ github.token }}
116116
steps:
117+
- name: Select isolated publication directory
118+
run: printf 'HACK_PRERELEASE_OUTPUT=%s/prerelease-assets\n' "$RUNNER_TEMP" >> "$GITHUB_ENV"
117119
- uses: actions/checkout@v4
118120
with:
119121
ref: ${{ needs.plan.outputs.source_revision }}

‎.github/workflows/release.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,7 @@ on:
2727
tags:
2828
- "v*"
2929
- "!v*-*"
30-
- "!v*+*"
30+
- '!v*\+*'
3131

3232
permissions:
3333
contents: read

‎tests/prerelease-plan.test.ts‎

Lines changed: 19 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -543,7 +543,7 @@ test("registered Release routes explicit prerelease to the same-commit reusable
543543
expect(release.on.workflow_dispatch.inputs.publish_prerelease?.default).toBe(
544544
false
545545
);
546-
expect(release.on.push.tags).toEqual(["v*", "!v*-*", "!v*+*"]);
546+
expect(release.on.push.tags).toEqual(["v*", "!v*-*", "!v*\\+*"]);
547547
expect(release.jobs.prerelease?.uses).toBe(
548548
"./.github/workflows/prerelease.yml"
549549
);
@@ -586,6 +586,24 @@ test("registered Release routes explicit prerelease to the same-commit reusable
586586
expect(JSON.stringify(prerelease)).not.toContain("RELEASE_PAT");
587587
});
588588

589+
test("CI admits next branch pushes while excluding release tags", async () => {
590+
const ci = Bun.YAML.parse(
591+
await Bun.file(".github/workflows/ci.yml").text()
592+
) as {
593+
on: { push: { branches?: string[]; "tags-ignore": string[] } };
594+
};
595+
expect(
596+
(ci.on.push.branches ?? []).some((pattern) =>
597+
new Bun.Glob(pattern).match("next")
598+
)
599+
).toBe(true);
600+
expect(
601+
ci.on.push["tags-ignore"].some((pattern) =>
602+
new Bun.Glob(pattern).match("v5.0.0-next.1")
603+
)
604+
).toBe(true);
605+
});
606+
589607
test("compiled CLI reports the embedded candidate version and ordinary source retains package version", async () => {
590608
const root = await mkdtemp(join(tmpdir(), "hack-prerelease-cli-"));
591609
try {

0 commit comments

Comments
 (0)