Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 5 additions & 9 deletions .github/workflows/documentation.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,7 @@
name: Trigger documentation build

# Thin caller of the organization-wide documentation dispatcher in
# Cratis/Workflows/.github/workflows/trigger-documentation-build.yml.
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
Expand All @@ -17,12 +19,6 @@ permissions:

jobs:
trigger:
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- name: Trigger Documentation Build
uses: peter-evans/repository-dispatch@v3
with:
token: ${{ secrets.PAT_DOCUMENTATION }}
repository: Cratis/Documentation
event-type: build-docs
uses: Cratis/Workflows/.github/workflows/trigger-documentation-build.yml@main
secrets:
PAT_DOCUMENTATION: ${{ secrets.PAT_DOCUMENTATION }}
38 changes: 6 additions & 32 deletions .github/workflows/verify-semver-label.yml
Original file line number Diff line number Diff line change
@@ -1,15 +1,10 @@
name: Verify Semver Label

# A merged pull request with no major/minor/patch label produces a Publish run that reports success while
# skipping every publish step, because the release action resolves should-publish to false. That reads as a
# release having happened when nothing was published. Requiring the label here turns a silent non-release into
# a visible failure before the merge, where it costs nothing to fix.
#
# It also closes a race the publish workflow cannot: a label added moments after the merge may land too late
# for the release to pick it up. Demanding the label before the merge means there is nothing to race.
#
# Triggered on labeled/unlabeled as well as the usual events, so adding the label re-runs the check rather than
# leaving a red cross behind that only a push would clear.
# Thin caller of the organization-wide release-intent gate. The policy - which
# labels are accepted and what the errors say - lives in
# Cratis/Workflows/.github/workflows/verify-release-intent.yml. Thirty diverging
# per-repository copies of that logic are how the 2026-08-25 unintended releases
# happened; do not reintroduce logic here.
concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
Expand All @@ -28,25 +23,4 @@ permissions:

jobs:
verify:
runs-on: ubuntu-latest
timeout-minutes: 15

steps:
- name: Require exactly one semantic version label
env:
LABELS: ${{ toJSON(github.event.pull_request.labels.*.name) }}
run: |
count=$(printf '%s' "$LABELS" | jq '[.[] | select(. == "major" or . == "minor" or . == "patch" or . == "no-release")] | length')

if [ "$count" -eq 1 ]; then
echo "Found one semantic version label."
exit 0
fi

if [ "$count" -eq 0 ]; then
echo "::error::This pull request has no release intent label. Add exactly one of major, minor, patch, or no-release. Without one, merging produces a Publish run that succeeds while skipping every publish step, so no release is cut and nothing is published."
else
echo "::error::This pull request carries $count release intent labels. Exactly one of major, minor, patch, or no-release is required, since the release intent cannot be derived from more than one."
fi

exit 1
uses: Cratis/Workflows/.github/workflows/verify-release-intent.yml@main
Loading