ci: use shared release-please caller workflow - #22
Conversation
Replaces the inline release-please workflow with a short caller delegating to mark-brannan/.github/.github/workflows/release-please.yml, per mark-brannan/.github#37. This repo has no publish.yml, so the caller passes publish: false. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Claude finished @mark-brannan's task in 2m 32s —— View job Review complete
What I checked:
Findings (posted inline too):
Not a finding: the unpinned Verification gap, disclosed rather than papered over: this sandbox only has Also attempted to post a top-level |
| cancel-in-progress: false | ||
| contents: write | ||
| pull-requests: write | ||
| actions: write |
There was a problem hiding this comment.
actions: write is new — the workflow it replaces only carried contents: write and pull-requests: write. I can't reach mark-brannan/.github from this sandbox (repo isn't attached to this review session) to confirm the reusable workflow actually needs it. If it's required by the callee, fine, but it's worth a one-line comment saying why (mirrors the existing comment style in this file, which explains every other permission/config choice) rather than a bare addition — otherwise it reads as scope creep past least-privilege.
| jobs: | ||
| release-please: | ||
| runs-on: ubuntu-latest | ||
| steps: | ||
| # release-please's own commits, PR and tag are all authored through | ||
| # whatever token we hand it. The default GITHUB_TOKEN doesn't fire | ||
| # other workflows for anything it creates -- GitHub's own loop | ||
| # prevention -- so a release PR opened with it never gets CI to run | ||
| # against it. Minting an installation token for a repo-scoped GitHub | ||
| # App gives it a real actor identity instead, so the PR's | ||
| # `pull_request` event fires CI normally. | ||
| - uses: actions/create-github-app-token@v3 | ||
| id: app-token | ||
| with: | ||
| client-id: ${{ secrets.RELEASE_PLEASE_APP_CLIENT_ID }} | ||
| private-key: ${{ secrets.RELEASE_PLEASE_APP_PRIVATE_KEY }} | ||
|
|
||
| - uses: googleapis/release-please-action@v5 | ||
| id: release | ||
| with: | ||
| token: ${{ steps.app-token.outputs.token }} | ||
| config-file: release-please-config.json | ||
| manifest-file: .release-please-manifest.json | ||
| release: | ||
| uses: mark-brannan/.github/.github/workflows/release-please.yml@main | ||
| with: | ||
| publish: false | ||
| secrets: | ||
| RELEASE_PLEASE_APP_CLIENT_ID: ${{ secrets.RELEASE_PLEASE_APP_CLIENT_ID }} | ||
| RELEASE_PLEASE_APP_PRIVATE_KEY: ${{ secrets.RELEASE_PLEASE_APP_PRIVATE_KEY }} |
There was a problem hiding this comment.
The concurrency: {group: release-main, cancel-in-progress: false} block from the old file is dropped, with nothing replacing it here. Every other push-to-main workflow in this repo sets one explicitly at the call site (pages.yml has group: pages), so this is a departure from local convention, not just a line count reduction.
A job that calls a reusable workflow via uses: can still carry its own concurrency: key:
jobs:
release:
concurrency:
group: release-main
cancel-in-progress: false
uses: mark-brannan/.github/.github/workflows/release-please.yml@mainWorth doing unless the shared workflow itself sets an equivalent concurrency group internally — I couldn't verify that from here since the .github repo isn't attached to this sandbox. Two rapid pushes to main without some concurrency guard risk overlapping release-please runs racing on the manifest/release PR.
Summary
Replaces this repo's standalone
.github/workflows/release-please.ymlwith a short caller that delegates to the shared reusable workflow extracted in mark-brannan/.github#37 (mark-brannan/.github/.github/workflows/release-please.yml@main).wire-wright has no
publish.ymlworkflow, so the caller passespublish: false— no publish dispatch to wire up here.Test plan
git diff --statconfirms only.github/workflows/release-please.ymlchanged, shrinking from ~72 to ~28 linesmain(opens/updates the release PR as before)🤖 Generated with Claude Code