Repository navigation
Skip duplicate checks in release; require main's check before publishing - #218
Merged
Merged
Conversation
A green bump PR doesn't prove the released commit was tested: an admin can merge past a red check, and without a merge queue the squashed commit on main isn't the one the PR tested. The push to main runs check on exactly github.sha, so publish now waits for that run to succeed before tagging. This is the gate that would let the build skip its own check.sh on the merged-bump path. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The push to main already runs check on the release commit, and publish now refuses to tag until that run passes, so the build's own check.sh run was pure duplication. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
alexkroman
enabled auto-merge (squash)
September 30, 2026 04:32
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
The bump PR already ran
scripts/check.sh, andreleaseran it again on the merged commit, about 18 more minutes of macOS time. But a green PR alone doesn't prove the released commit was tested:check(enforce_adminsis off onmain).strictunset, the squashed commit onmainmay never have been tested as a whole.The push to
mainrunscheckon exactly that commit anyway, so that run is the gate.What
build: on the merged-bump (push) path, pass--skip-checks. On a dispatch,skip_checksis still an opt-in escape hatch, off by default.publish: new first step, Require check to have passed on this commit.checkrun ongithub.shaand proceeds only oncompleted/success.checkis still running.github-actionsapp, since any app withchecks: writecan post a run namedcheck.publishgainschecks: readfor the lookup.The gate runs after the human approves
release-publishand before anything is tagged. Build + notarization + testing the DMG outlastscheck, so it's normally green already.Test plan
actionlintand prettier passchecks skipped (--skip-checks), and the publish log showscheck passed on <sha>before tagging🤖 Generated with Claude Code