feat(release)!: resolve the toolkit from the reusable workflow's own commit - #18
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
BREAKING CHANGE: removes the
workflows-repository/workflows-refinputs from all three release reusables. Callers that pass them fail with an invalid-input error - delete theworkflows-ref:line from the stubs when bumping theuses:pin to v4.The toolkit checkout in prepare, validate, and release now uses
job.workflow_repository/job.workflow_sha- the reusable workflow's own commit - and the attestation signer identity derives fromjob.workflow_repository+job.workflow_file_path. GitHub's contexts documentation shows exactly this reusable-workflow self-checkout pattern.This eliminates the two-pins-in-lockstep footgun for SHA-pinning consumers: previously a Dependabot bump of the
uses:SHA leftworkflows-refbehind, silently running new workflow logic against old toolkit scripts (or failing on a missing script). Now theuses:ref is the single version pin and workflow + scripts are always the same commit, so Dependabot bumps are self-consistent by construction.Also documents the fail-closed recovery behavior for releases cut under an older
release-policy(observed on NoteTweet 0.6.6, a chore-only release from the v2-era rules: the stage-3 recompute correctly refuses with "Release plan version is none").Ships as v4; v3 stays in place for unmigrated consumers.