Repository navigation
chore: Stable dispatcher releases now open the pin-stamp pull request automatically - #2473
Conversation
…equests The release-please check runner could only dispatch workflows for a pull request it had found by the release-please head-ref naming convention, so no other automated pull request could reuse it. A pull request created with GITHUB_TOKEN never triggers pull_request workflows, and the upcoming dispatcher pin pull request needs the same treatment. Move the dispatch loop and the gh body-file helper behind an entry point that takes an explicit head ref and a caller-supplied description, and let the release-please path pass its own description so its log output is unchanged. Claude-Session: https://claude.ai/code/session_01XbhSMKK4LFud57iAmowDz7
Fresh installs resolve the dispatcher named by the package pin, so a published stable release does not reach new users until the pin records it. Both stable stamps so far were hand-made pull requests, which is exactly the step that gets forgotten while a stale release keeps being installed. The command branches from the base tip, stamps the package pin with the attestation-verified manifest, mirrors it byte-identically to the project pin, re-verifies it offline and against the published release subjects, then commits as the workflow bot, pushes, and opens or refreshes the review pull request. A pre-release tag is refused up front so a pre-release can never become the pin on a stable branch, and minimumDispatcherVersion is left untouched because raising the floor would lock out working installs. A run with nothing to change opens no pull request, so retries stay harmless. Claude-Session: https://claude.ai/code/session_01XbhSMKK4LFud57iAmowDz7
The pin stamp was a manual step that nothing reminded anyone to perform, so a published stable dispatcher could stay unreachable for fresh installs indefinitely. Run open-dispatcher-pin-pr from post-publish whenever a stable release was published, exposing the resolver's prerelease flag as a build output so pre-releases are skipped at the workflow level as well as inside the command. The job now needs pull-requests: write to open the pull request and actions: write to dispatch its required checks, and gh auth setup-git supplies the push credential the credential-free checkout does not keep. Claude-Session: https://claude.ai/code/session_01XbhSMKK4LFud57iAmowDz7
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (10)
💤 Files with no reviewable changes (1)
Included review availability: Your plan provides up to 4 included reviews per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe release workflow now invokes ChangesDispatcher pin automation
Estimated code review effort: 4 (Complex) | ~45 minutes Merge Risk: ⚪ Minimal · up to This change automates creation of the stable dispatcher pin pull request without introducing an actionable merge-blocking risk at the current head. Sequence Diagram(s)sequenceDiagram
participant DispatcherPublish
participant OpenDispatcherPinPR
participant GitHub
DispatcherPublish->>OpenDispatcherPinPR: Invoke for a published stable tag
OpenDispatcherPinPR->>OpenDispatcherPinPR: Stamp and validate pin files
OpenDispatcherPinPR->>GitHub: Push pin branch
OpenDispatcherPinPR->>GitHub: Create or edit pull request
OpenDispatcherPinPR->>GitHub: Dispatch required check workflows
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 20.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 40 functions across 6 files. (3 skipped: 3 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Part 1 of #2463.
Summary
main, andminimumDispatcherVersionis never touchedUser Impact
dispatcher-vX.Y.Zwas published, someone had to remember to runstamp-dispatcher-pin, mirror the file to.uloop/, and open a PR. During the 3.0.0 release this was missed, so freshinstall.shruns kept installing a beta dispatcher until chore: update dispatcher pin to the 3.0.0 stable release #2461dispatcher-publishworkflow'spost-publishjob openschore: update dispatcher pin to the X.Y.Z stable releasewith the two-file diff, verified the same way the manual command verifies it. The stamp still goes through attestation verification before anything is writtenChanges
cli/release-automation/cmd/open-dispatcher-pin-pr(new) backed byinternal/automation/dispatcher_pin_pr.go: rejects pre-release tags up front; brancheschore/dispatcher-pin-<tag>from the currentmaintip; runsStampDispatcherPin; mirrorsPackages/src/project-runner-pin.jsonbyte-identically to.uloop/project-runner-pin.json; re-verifies offline and against the published release subjects; exits 0 without a PR when the pin already records the tag; commits asgithub-actions[bot]; pushes (plain for a new branch,--force-with-leasepinned to the observed remote SHA otherwise); creates or updates the open PR for that head; then dispatches the required check workflowsinternal/automation/pull_request_checks.go(new):DispatchPullRequestChecksForHeadshared by the release-please check dispatcher and the new command, because a PR created withGITHUB_TOKENnever triggerspull_requestworkflows. The release-please path keeps its draft → watch → ready flow unchanged; the pin PR only dispatches and returns sopost-publishdoes not wait on Unity CI.github/workflows/dispatcher-publish.yml:buildexposesrelease_prerelease;post-publishgainspull-requests: writeandactions: writeand a final step gated onshould_publish == 'true' && release_prerelease != 'true'that runsgh auth setup-git(the checkout keeps no credentials) and the new command. No newuses:refsdocs/dispatcher-pin-release-order.md,docs/project-runner-pin.md: describe the automated flow and keepstamp-dispatcher-pinas the manual fallbackNot in this PR
mainwhen a newer stable dispatcher release exists than the pinned tag (acceptance item 2 of Automate dispatcher pin stamping after a stable dispatcher release #2463) lands in a follow-up PRVerification
cli/release-automation:gofmt -l .clean,go vet ./...,go test ./...pass;golangci-lint runwith both.golangci.ymland.golangci-complexity.ymlreport 0 issuesscripts/check-go-cli.shexit 0;go run ./cmd/check-release-triggers --base origin/main --head HEAD→ "Release trigger guard passed.";go run ./cmd/check-file-lengthreports no file over 500 SLOCactionlint .github/workflows/dispatcher-publish.ymlexit 0~DEFAULT_BRANCHandv3-betaonly, so the workflow token can pushchore/dispatcher-pin-*https://claude.ai/code/session_01XbhSMKK4LFud57iAmowDz7