Publish only commits that pass CI - #388
Merged
Merged
Conversation
deploy.yml ran on every push to main in parallel with CI and never waited for it, so a commit that failed build, lint or tests was still tagged and uploaded to the registry. It now calls ci.yml and web-app.yml as reusable workflows and tags nothing unless both pass on that commit; the two no longer run their own push triggers, so main isn't checked twice. The web-app job also type-checks with tsc, since lint and node --test strip types without checking them. It runs on every PR and skips its work when web-app/ is untouched, so it can be made a required check. CI now fails on an untidy go.mod with `go mod tidy -diff`, and `make setup` downloads modules instead of tidying them, so neither CI nor the registry build rewrites the committed module graph. deploy.yml defaults to read-only, grants contents: write only to the job that pushes the rc tag, checks out without persisted credentials, passes expression values to shell through env, and serialises runs so two pushes can't compute the same rc tag. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Deploy now runs CI and the web-app checks on the exact commit it publishes, and tags nothing unless both pass. Before, it ran in parallel with CI on every main push, so a red commit was still tagged and uploaded to the registry as an rc.
Changes
ci.ymlandweb-app.ymlare called as reusable workflows, andcompute-versionneeds bothtsc --noEmit, because lint andnode --teststrip types without checking themgo mod tidy -diff;make setupnow runsgo mod download, so neither CI nor the registry build rewrites the module graphcontents: writeonly on the rc-tagging job, no persisted credentials, expression values passed to shell throughenvconcurrencygroup, so two quick pushes can't compute the same-rc.NTesting
actionlintis clean, andgo mod tidy -diffis clean on current main.changesjob). The Deploy path runs on the first push to main after merge; watch that run.Claude Code prompts used
🤖 Generated with Claude Code