From dc420c4886ad7e2968cd0b97b38eda78e142b3d9 Mon Sep 17 00:00:00 2001 From: woksin Date: Wed, 26 Aug 2026 10:21:13 +0200 Subject: [PATCH] chore: adopt the organization reusable workflows Converts copied workflow logic to thin callers of Cratis/Workflows: release-intent gate and/or documentation-build trigger. Per-repository copies of the gate drifted apart and caused the 2026-08-25 unintended releases; the policy now lives in one place. Where this repository has never produced a workflow artifact, the cleanup-pr-artifacts workflow is removed as dead weight. --- .github/workflows/cleanup-pr-artifacts.yml | 12 ------- .github/workflows/verify-semver-label.yml | 38 ++++------------------ 2 files changed, 6 insertions(+), 44 deletions(-) delete mode 100644 .github/workflows/cleanup-pr-artifacts.yml diff --git a/.github/workflows/cleanup-pr-artifacts.yml b/.github/workflows/cleanup-pr-artifacts.yml deleted file mode 100644 index 448a2d3..0000000 --- a/.github/workflows/cleanup-pr-artifacts.yml +++ /dev/null @@ -1,12 +0,0 @@ -name: Cleanup PR Artifacts - -on: - pull_request: - types: [closed] - -jobs: - cleanup: - uses: Cratis/Workflows/.github/workflows/cleanup-pr-artifacts.yml@main - with: - pull_request: ${{ github.event.pull_request.number }} - secrets: inherit diff --git a/.github/workflows/verify-semver-label.yml b/.github/workflows/verify-semver-label.yml index b5efe05..4807b1e 100644 --- a/.github/workflows/verify-semver-label.yml +++ b/.github/workflows/verify-semver-label.yml @@ -1,15 +1,10 @@ name: Verify Semver Label -# A merged pull request with no major/minor/patch label produces a Publish run that reports success while -# skipping every publish step, because the release action resolves should-publish to false. That reads as a -# release having happened when nothing was published. Requiring the label here turns a silent non-release into -# a visible failure before the merge, where it costs nothing to fix. -# -# It also closes a race the publish workflow cannot: a label added moments after the merge may land too late -# for the release to pick it up. Demanding the label before the merge means there is nothing to race. -# -# Triggered on labeled/unlabeled as well as the usual events, so adding the label re-runs the check rather than -# leaving a red cross behind that only a push would clear. +# Thin caller of the organization-wide release-intent gate. The policy - which +# labels are accepted and what the errors say - lives in +# Cratis/Workflows/.github/workflows/verify-release-intent.yml. Thirty diverging +# per-repository copies of that logic are how the 2026-08-25 unintended releases +# happened; do not reintroduce logic here. concurrency: group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} cancel-in-progress: true @@ -28,25 +23,4 @@ permissions: jobs: verify: - runs-on: ubuntu-latest - timeout-minutes: 15 - - steps: - - name: Require exactly one semantic version label - env: - LABELS: ${{ toJSON(github.event.pull_request.labels.*.name) }} - run: | - count=$(printf '%s' "$LABELS" | jq '[.[] | select(. == "major" or . == "minor" or . == "patch" or . == "no-release")] | length') - - if [ "$count" -eq 1 ]; then - echo "Found one semantic version label." - exit 0 - fi - - if [ "$count" -eq 0 ]; then - echo "::error::This pull request has no release intent label. Add exactly one of major, minor, patch, or no-release. Without one, merging produces a Publish run that succeeds while skipping every publish step, so no release is cut and nothing is published." - else - echo "::error::This pull request carries $count release intent labels. Exactly one of major, minor, patch, or no-release is required, since the release intent cannot be derived from more than one." - fi - - exit 1 + uses: Cratis/Workflows/.github/workflows/verify-release-intent.yml@main