Merge master back into testing after 20260917-001 GA - #172
Merged
Merged
Conversation
Publishing the release images was the one manual step in the release, and nothing failed if it was skipped -- :latest simply stayed on the previous release while every monitored stage reported green. Fire on a master push instead, path-filtered to simplerisk-minimal/Dockerfile (the file carrying the `ENV version=` this job promotes). workflow_dispatch stays for heals. Auto-firing is safe precisely BECAUSE nothing is rebuilt. The 20260820-001 failure came from rebuilding on a master push and racing the GA bundle upload; a retag touches no bundle. The deliberate release gate moves to where the release decision is actually made -- the code-development testing -> master merge, restricted to release owners -- rather than a second dispatch nobody is prompted to run. This reverses the "manual workflow_dispatch" line in the 2026-07-10 design on purpose. Adds an idempotence guard so the automatic path is safe to re-enter: if :latest already resolves to the digest we would promote for every image, all five mutating steps skip. A dispatch always runs in full. The guard fails loudly when the minimal RC tag is ABSENT rather than treating it as "nothing to do" -- that condition means the release has no images to promote, which must not surface as a green no-op run. Guard logic exercised offline across 8 scenarios (already-promoted, new release, each image differing alone, minimal RC missing, full RC missing, both skip_full paths): correct verdict and exit status in every case, no set -e traps in the && chains. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Merge testing into master to reset the merge base
Fire the GA promote on the master merge instead of a manual dispatch
SimpleRisk 20260828-001 Release
SimpleRisk 20260909-001 Release
SimpleRisk 20260917-001 Release
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Merge
masterback intotestingafter the 20260917-001 GA promotion (#171).masteris 8 commits ahead oftestingand 0 behind. The only file difference is.github/workflows/promote-latest.yml, changed directly onmasterby #166 (firepromote-lateston the GA merge). The other commits are merge commits from earlier release promotions (#164, #167, #168, #171) with no file differences.Why
testingnever receivedpromote-latest.yml, so everyrelease-<version>branch cut from it is BEHINDmaster. TheProtect masterruleset requires an up-to-date branch, so auto-merge of the release PR cannot land it. #171 needed an admin-bypass merge for exactly this reason. Mergingmasterback stops it recurring.Testing Results
No code change beyond
promote-latest.yml, which is unchanged from what already runs onmaster. No new tests apply.🤖 Generated with Claude Code
https://claude.ai/code/session_01RWsGdgn3khwahjF4C96HM9