Repository navigation
Share the release workflows, and release the template with them - #8
Conversation
…callers prepare-release.yml and release-on-merge.yml now live in this repo as workflow_call workflows, and generated projects get callers pinned to @v1, as with python-ci.yml. Release fixes then reach every project when v1 moves, instead of needing a copier update and a merge in each repo. Both take version-source: pyproject (generated projects; uv version --bump) or tags (the next vX.Y.Z from the latest tag, for a repo with no package version). release-on-merge takes dispatch-workflow, which a PyPI library sets to publish.yml; publishing stays in the project's own workflow because PyPI trusted publishing can't run from a reusable one. The reusable workflows declare no permissions, so a caller that grants less (an app, without actions: write) doesn't fail at startup. prepare-release also keeps Keep-a-Changelog compare links current where a CHANGELOG.md has them, and runs mdformat only where a project's pre-commit config has it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Prepare template release and Template release on merge call the reusable workflows from this checkout in tags mode, so each template release runs them before v1 moves. release-on-merge then starts bump-v1.yml on the tag: a release created with the default token raises no release event, so bump-v1 now also accepts a dispatch on a v1.* tag ref, and still runs on a release published by hand. The template's own changelog moves to scriv: changelog.d/scriv.ini (this repo has no pyproject.toml), a TEMPLATE.md with an Upgrading category, the insert marker, and the [Unreleased] entries in one fragment, rewritten for the shared workflows and with the --trust upgrade step from the review of #7. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The README describes the reusable release workflows, the template's own release steps, and `copier update --trust`, which a migration now needs. It and the template-update PR body no longer say GitHub skips CI on PRs opened with the default token: it holds them for "Approve workflows to run". Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Review of b0f995aI reviewed this in a fresh clone with all tags. I rendered the app, the PyPI library and the non-PyPI library, and ran the extracted workflow steps locally. Each point says how I checked it: ran (executed locally), docs (GitHub docs), or reasoning (couldn't run outside GitHub). The design holds up. Three findings matter before the first release. The rest are small. Findings, most important first1. Prepare template release will fail on this repo as it is configured now (ran, read-only API)
2. A busy moment can silently cancel the release run (docs)
3. scriv silently drops fragment text above any line that quotes the insert marker (ran)
4. zizmor reports more than the PR description says (ran)
5. The dispatch path of bump-v1 skips two guards the release path has (reasoning)
6. Nits
What I checked and found fine
Posted by Claude Code on Matt's behalf. |
- Key the release-on-merge concurrency group on the branch. Every closed PR runs it, and a shared group lets a newer pending run cancel a pending release run, leaving no tag, release or v1 move. - Refuse a fragment that quotes scriv's insert or end marker: scriv 1.8.0 starts a fragment after any line containing it, even in backticks, and silently drops the lines above. - bump-v1's dispatch path refuses anything but the newest final v1.X.Y tag, so a dispatch on an older tag can't move v1 backwards. - prepare-release declares its job permissions, with none at workflow level; release-on-merge keeps inheriting the caller's grant (actions: write is conditional) and says so with a zizmor ignore. zizmor's auditor persona is clean apart from that. - Pin scriv and pre-commit in tags mode, and fix the caller comment's wrap. From the review on #8. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…feguards From the review on #8. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Thanks. Actioned in bf0218b and cd317c7:
The dunamai sorting note is useful. The flow's gap between merge and annotation makes it safe in practice, so I left bump-v1's comment as is for now. After the fixes, the template CI render step, the rendered hooks (actionlint and zizmor) and the tags-mode dry run all pass locally. The dry run gives 1.10.0, and bump-v1's changelog guard passes on it. Posted by Claude Code on Matt's behalf. |
Why
#6 put the release steps into each generated project as scaffolded workflows. Every fix to them would then need a
copier updateand a merge in each repo. This PR moves the steps into reusable workflows here, likepython-ci.yml, so fixes reach every project whenv1moves. The template also releases itself with them, so each template release exercises them first.What changes
Reusable workflows (18cfc59)
.github/workflows/prepare-release.ymlandrelease-on-merge.ymlareworkflow_callworkflows, and the scaffolded files become thin callers pinned to@v1.version-source: pyproject(generated projects): the version is[project] version, bumped withuv version --bump, and scriv runs from the dev group.version-source: tags(this repo): the next version comes from the latestvX.Y.Ztag, and scriv runs withuvx.dispatch-workflowstarts a workflow on the new tag. A PyPI library's caller setspublish.yml. Publishing stays in the project's own workflow, since PyPI trusted publishing can't run from a reusable workflow.actions: write.The template releases itself (68abdda)
template-prepare-release.ymlandtemplate-release-on-merge.ymlcall the reusable workflows from this checkout (./) in tags mode.bump-v1.ymlon the tag. A release created with the default token raises no release event, sobump-v1.ymlgains a dispatch trigger forv1.*tag refs. A release published by hand from the UI still triggers it.changelog.d/scriv.ini(there's no pyproject.toml here), aTEMPLATE.mdwith anUpgradingcategory, and the insert marker.[Unreleased]entries move into one fragment, rewritten for the shared workflows. It includes the--trustupgrade step from the review of Release 1.10.0 #7.Docs (b0f995a)
uvx copier update --trust.Testing
$/…over./…../is GitHub's documented syntax.autopicks minor and computes 1.10.0 from v1.9.1. scriv collects the fragment usingscriv.ini, and the compare links gain[1.10.0]. bump-v1's own changelog guard then passes for v1.10.0.actions: writeand passespublish.yml.Review fixes (bf0218b, cd317c7)
v1.X.Ytag.After merge
gh pr create, though a re-run is safe once it's on.auto(orminor, neverpatch: the migration is keyed to v1.10.0). It should open "Release v1.10.0".v1moved.🤖 Generated with Claude Code