Skip to content

Automate dispatcher pin stamping after a stable dispatcher release #2463

Description

@hatayama

Problem

Packages/src/project-runner-pin.json resolves which dispatcher release install.sh, install.ps1, and the Unity Install CLI button download (dispatcherReleaseTag + dispatcherArchiveManifest). Stamping that field is a manual step today: after a dispatcher release is published, someone must run go run ./cmd/stamp-dispatcher-pin --tag dispatcher-vX.Y.Z in cli/release-automation, mirror the file to .uloop/project-runner-pin.json, and open a PR.

During the 3.0.0 release this step was missed at first: dispatcher-v3.0.0 was published while the pin still pointed at dispatcher-v3.0.0-beta.31, so a fresh install.sh run installed a beta dispatcher (which then follows the beta self-update channel forever). It was caught by the post-release install check and fixed in #2461, but nothing in the pipeline would have flagged it.

Proposal

Automate the stamp as a post-publish workflow step that keeps the evidence gate intact:

  1. After dispatcher-publish finishes and the release is published (attestations present), run stamp-dispatcher-pin --tag <released tag> in a workflow job. The tool already verifies the attestation before writing, so the gate stays evidence-based.
  2. Mirror the result to .uloop/project-runner-pin.json (byte-identical, check-dispatcher-pin enforces this) and open a chore: PR with the two-file diff. Human review + merge remains the only manual action.
  3. Add a CI check (or a step in the same workflow) that fails when the newest published dispatcher-v* stable release is newer than the pinned tag on main, so a skipped stamp is visible instead of silent.

Constraints to respect: minimumDispatcherVersion stays hand-maintained (do not auto-raise it); the pin evolves additively; pre-releases must not be stamped onto main (see docs/dispatcher-pin-release-order.md).

Acceptance

  • Publishing a stable dispatcher release produces a pin-stamp PR without manual commands.
  • A stale pin (stable dispatcher release newer than the pinned tag) fails CI on main.
  • Documentation in docs/dispatcher-pin-release-order.md and docs/project-runner-pin.md reflects the automated flow.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions