feat(release)!: publish next from the release-PR hook and drop the post-green verdict - #408
Merged
Merged
Conversation
Contributor
File size check0 over a hard cap (fails), 31 warning(s).
Split the file, wrap the line, shorten or exempt the comment, or list the path in 5 managed file(s) skipped; repo-platform owns them. |
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The production-only release trigger and npm OIDC publishing path cannot be verified end to end before its first live run.
Review effort: Balanced
Findings: None
What changed in this PR
Moves next npm publishing from every qualifying green push to release-please’s release-PR refresh hook.
Changes:
- Adds
publish-nextto the release-PR workflow and removes it from post-green. - Simplifies the npm verdict to registry-state safeguards.
- Updates tests and documentation for the new cadence.
| File | Description |
|---|---|
.github/actionlint.yaml |
Updates publisher references. |
.github/scripts/release-pipeline.ts |
Removes shipped-surface decisions. |
.github/workflows/post-green.yml |
Removes next publishing. |
.github/workflows/update-release-pr.yml |
Adds the next publisher. |
.github/workflows/update-release.yml |
Updates shared-lane references. |
README.md |
Documents the new next cadence. |
docs/reference/library.md |
Revises versioning details. |
docs/upgrading/v2-to-v3.md |
Adds the cadence breaking change. |
test/docs/npm-publish-workflows.test.ts |
Tests the relocated publisher. |
test/docs/post-green-workflow.test.ts |
Tests trigger, grants, and wiring. |
test/package-json.test.ts |
Updates workflow references. |
test/scripts/release-pipeline.test.ts |
Removes surface-verdict cases and retains safeguards. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Vivswan
force-pushed
the
wt/next-from-release-pr
branch
from
September 22, 2026 08:05
6d8b02e to
d3f8931
Compare
Vivswan
force-pushed
the
wt/next-from-release-pr
branch
from
September 22, 2026 08:13
d3f8931 to
d74dd3b
Compare
Vivswan
marked this pull request as ready for review
September 22, 2026 08:52
…st-green verdict The next pre-release publishes exactly when release-please creates or refreshes the release PR, and nowhere else: update-release-pr.yml, the hook the managed ci.yml calls on prs_created, gains a publish-next job beside anchor. release-please refreshes the PR only when the release notes change (always-update is off), so a releasable commit publishes, a push of hidden types alone refreshes nothing and publishes nothing, and no check of the repository's own decides a publish. post-green.yml loses its publish-next job and keeps the build job; the commit the hook publishes is github.sha, the caller's sha inside a called workflow, so ci.yml needs no new input. release-pipeline.ts drops the npm-verdict next decision: the merge walk over the shipped surface, NEXT_BUILD_INPUTS, shippedPaths, shippedChanges, ships, ALWAYS_PACKED, and the never-packed exclusion list NEXT_BUILD_UNPACKED that matched nothing. npm-verdict next stays as the pre-publish guard on npm state: a version already on the registry or a descendant's published pre-release exits skip, so a rerun or a stale retry never moves next back; prerelease-version and npm-confirm stay. The pipeline test drops the surface cases and keeps the placement, no-backward, and confirm cases; the workflow-shape tests follow the publish job to the release-PR hook and learn the release-PR refresh as a trigger. The README, the library page, and the v3 upgrading guide state the new cadence: a next build appears on a release-PR refresh, a merge of hidden types alone publishes nothing, and the guard keeps next from moving back.
Vivswan
force-pushed
the
wt/next-from-release-pr
branch
from
September 22, 2026 09:11
d74dd3b to
0650dfb
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Before / After
Before: a check of our own decided every
nextpublish, on every green push.After: release-please's refresh of the release PR is the publish signal; nothing of ours decides.
The skip notice, before and after:
How
.github/workflows/update-release-pr.yml: apublish-nextjob besideanchor, independent of it. The steps are the ones post-green held: OIDC check (same warning shape, naming this call), checkout ofgithub.shawith full history and no persisted credentials, setup, setup-node with the registry, the npm floor,bun run build:lib, the publish step (guard,npm version,npm pkg delete scripts.prepare,npm publish --tag next), thennpm-confirm. Samenpm-publishlane. The header says why the publish lives here..github/workflows/post-green.yml: thepublish-nextjob is gone;buildstays. Header fixed..github/workflows/update-release.yml: two comments that named post-green's publisher now name the hook's..github/scripts/release-pipeline.ts: the surface walk is deleted (NEXT_BUILD_INPUTS,shippedPaths,shippedChanges,ships,ALWAYS_PACKED,NextBase,mainChainOf, and theNEXT_BUILD_UNPACKEDexclusion the closed PR removed).npm-verdict nextstays as the pre-publish guard: version already on the registry, or a descendant's pre-release published, exitsskip; a source the checkout cannot place is a notice.prerelease-version,npm-confirm, and everything about stable releases, packaging, and anchoring are untouched. Header table updated.test/scripts/release-pipeline.test.ts: the surface cases (docs-only skip, test-only skip, shipped paths, reverted and moved files, files-list shapes, build inputs) are deleted. The placement, no-backward (rerun, descendant published, unplaceable base), and confirm cases stay, with the wording they pin updated.test/docs/post-green-workflow.test.ts: the publish-job wiring and grant controls follow the job to the hook; the library-page claim check learns the third trigger (a release-PR refresh, byprs_created); a control pins that claimingnextback on the green push fails; a new relation pins that the hook's checkout, publish, and confirmation all namegithub.sha.test/docs/npm-publish-workflows.test.ts: the pre-release publisher is read from the hook.docs/reference/library.md: thenextrow and bullets state the cadence.docs/upgrading/v2-to-v3.md: row and section 59 with a before/after.README.md: the library line points at Versioning..github/actionlint.yaml,test/package-json.test.ts: comments naming the publisher.Proof
env -u NODE_OPTIONS bun run typecheck: clean.bun run knip: clean.bun run lint: clean.bun run lint:yaml: clean.bun test test/scripts/release-pipeline.test.ts test/docs --timeout 120000: 489 pass, 0 fail.bun test test/scripts/release-pipeline-build.test.ts --timeout 120000(imports the changed script): 37 pass, 0 fail.bun run build:check: 13 generated files match their generators.Update Release PR / anchorandUpdate Release PR / publish-nextin that run.Line accounting by kind
git diff --numstat origin/main...HEAD(the closed PR's commit is folded in, so its lines count here)Net deletion: 361 lines.
Reviewer note
always-updateis off inrelease-please-config.json).npm-verdict nextremains, as a safety on npm state: a rerun or a stale retry must not movenextback. Its output shape is unchanged, so the publish step stays the twin of the stable publisher's and the shared-steps test keeps holding.NEXT_BUILD_UNPACKEDis folded in.github.shais the caller's sha, the push release-please judged, which theanchorjob already relies on. The managedci.ymlis untouched.depsis not a releasable type. Dependabot landsbuild(deps)andci(deps), both hidden, so a dependency bump alone refreshes no PR and publishes nonext. The docs say so.nextnames the last pre-release belowlatestuntil the next cycle's first releasable commit; the docs say so.Update Release PR / publish-nextrunsnpm publish --tag next(npm's output names the version) and the confirmation step ends with asettlednotice;npm view @vivswan/github-settings-as-code@nextthen names that version. On a test-only or docs-only merge, noUpdate Release PRcall appears in the run at all.Post Greenin that same run shows only thebuildjob, no publish job.BEGIN_COMMIT_OVERRIDE
feat(release)!: publish next from the release-PR hook and drop the post-green verdict
The next pre-release publishes exactly when release-please creates or refreshes the release PR, and nowhere else: update-release-pr.yml, the hook the managed ci.yml calls on prs_created, gains a publish-next job beside anchor.
release-please refreshes the PR only when the release notes change (always-update is off), so a releasable commit publishes, a push of hidden types alone refreshes nothing and publishes nothing, and no check of the repository's own decides a publish.
post-green.yml loses its publish-next job and keeps the build job; the commit the hook publishes is github.sha, the caller's sha inside a called workflow, so ci.yml needs no new input.
release-pipeline.ts drops the npm-verdict next decision: the merge walk over the shipped surface, NEXT_BUILD_INPUTS, shippedPaths, shippedChanges, ships, ALWAYS_PACKED, and the never-packed exclusion list NEXT_BUILD_UNPACKED that matched nothing.
npm-verdict next stays as the pre-publish guard on npm state: a version already on the registry or a descendant's published pre-release exits skip, so a rerun or a stale retry never moves next back; prerelease-version and npm-confirm stay.
The pipeline test drops the surface cases and keeps the placement, no-backward, and confirm cases; the workflow-shape tests follow the publish job to the release-PR hook and learn the release-PR refresh as a trigger.
The README, the library page, and the v3 upgrading guide state the new cadence: a next build appears on a release-PR refresh, a merge of hidden types alone publishes nothing, and the guard keeps next from moving back.
END_COMMIT_OVERRIDE