Skip to content

Skip duplicate checks in release; require main's check before publishing - #218

Merged
alexkroman merged 2 commits into
mainfrom
claude/release-skip-duplicate-checks
Sep 30, 2026
Merged

alexkroman merged 2 commits into
mainfrom
claude/release-skip-duplicate-checks

Conversation

@alexkroman

@alexkroman alexkroman commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Why

The bump PR already ran scripts/check.sh, and release ran it again on the merged commit, about 18 more minutes of macOS time. But a green PR alone doesn't prove the released commit was tested:

  • Admins can merge past a red check (enforce_admins is off on main).
  • With no merge queue and strict unset, the squashed commit on main may never have been tested as a whole.

The push to main runs check on exactly that commit anyway, so that run is the gate.

What

  • build: on the merged-bump (push) path, pass --skip-checks. On a dispatch, skip_checks is still an opt-in escape hatch, off by default.
  • publish: new first step, Require check to have passed on this commit.
    • It reads the check run on github.sha and proceeds only on completed/success.
    • It fails on any other conclusion, and waits up to 15 minutes if check is still running.
    • It only counts runs posted by the github-actions app, since any app with checks: write can post a run named check.
    • publish gains checks: read for the lookup.
  • RELEASE.md → What starts a release: updated to match.

The gate runs after the human approves release-publish and before anything is tagged. Build + notarization + testing the DMG outlasts check, so it's normally green already.

Test plan

  • actionlint and prettier pass
  • Next release: the build log shows checks skipped (--skip-checks), and the publish log shows check passed on <sha> before tagging

🤖 Generated with Claude Code

alexkroman-assembly and others added 2 commits September 29, 2026 21:30
A green bump PR doesn't prove the released commit was tested: an admin
can merge past a red check, and without a merge queue the squashed
commit on main isn't the one the PR tested. The push to main runs check
on exactly github.sha, so publish now waits for that run to succeed
before tagging. This is the gate that would let the build skip its own
check.sh on the merged-bump path.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The push to main already runs check on the release commit, and publish
now refuses to tag until that run passes, so the build's own check.sh
run was pure duplication.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@alexkroman alexkroman changed the title Require check to pass on the release commit before publishing Skip duplicate checks in release; require main's check before publishing Sep 30, 2026
@alexkroman
alexkroman enabled auto-merge (squash) September 30, 2026 04:32
@alexkroman
alexkroman merged commit f1e7dc3 into main Sep 30, 2026
10 checks passed
@alexkroman
alexkroman deleted the claude/release-skip-duplicate-checks branch September 30, 2026 04:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants