diff --git a/.github/workflows/canary.yml b/.github/workflows/canary.yml index a27d73ea8..5dc88d0f1 100644 --- a/.github/workflows/canary.yml +++ b/.github/workflows/canary.yml @@ -1,3 +1,12 @@ +# Release stream policy: +# dev → @canary (this workflow — preview builds for the long-lived integration branch) +# main → @next (RC train, see release.yml) +# main → @latest (stable cuts, see release.yml) +# +# Streams do not mix. The publish/tag steps below gate on `refs/heads/dev` so a +# workflow_dispatch run on any other branch (including main) completes the +# build/test/dry-run validation but does not publish or tag. + name: Canary on: @@ -80,7 +89,7 @@ jobs: NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} - name: Tag and push - if: ${{ github.ref == 'refs/heads/main' && !inputs.dry_run }} + if: ${{ github.ref == 'refs/heads/dev' && !inputs.dry_run }} env: CANARY_VERSION: ${{ steps.canary.outputs.canary_version }} run: | @@ -88,19 +97,19 @@ jobs: git push origin "v${CANARY_VERSION}" - name: Publish to npm (canary) - if: ${{ github.ref == 'refs/heads/main' && !inputs.dry_run }} + if: ${{ github.ref == 'refs/heads/dev' && !inputs.dry_run }} run: npm publish --provenance --access public --tag canary env: NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} - name: Publish SDK to npm (canary) - if: ${{ github.ref == 'refs/heads/main' && !inputs.dry_run }} + if: ${{ github.ref == 'refs/heads/dev' && !inputs.dry_run }} run: cd sdk && npm publish --provenance --access public --tag canary env: NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} - name: Verify publish - if: ${{ github.ref == 'refs/heads/main' && !inputs.dry_run }} + if: ${{ github.ref == 'refs/heads/dev' && !inputs.dry_run }} env: CANARY_VERSION: ${{ steps.canary.outputs.canary_version }} run: | @@ -132,10 +141,14 @@ jobs: env: CANARY_VERSION: ${{ steps.canary.outputs.canary_version }} DRY_RUN: ${{ inputs.dry_run }} + PUBLISH_ELIGIBLE: ${{ github.ref == 'refs/heads/dev' && !inputs.dry_run }} + BRANCH_REF: ${{ github.ref }} run: | echo "## Canary v${CANARY_VERSION}" >> "$GITHUB_STEP_SUMMARY" if [ "$DRY_RUN" = "true" ]; then echo "**DRY RUN** — npm publish, tagging, and push skipped" >> "$GITHUB_STEP_SUMMARY" + elif [ "$PUBLISH_ELIGIBLE" != "true" ]; then + echo "**VALIDATION ONLY** — publish/tag skipped for \`${BRANCH_REF}\`; canary publish is gated to \`refs/heads/dev\`." >> "$GITHUB_STEP_SUMMARY" else echo "- Published to npm as \`canary\`" >> "$GITHUB_STEP_SUMMARY" echo "- SDK also published: \`@gsd-build/sdk@${CANARY_VERSION}\` on \`canary\`" >> "$GITHUB_STEP_SUMMARY" diff --git a/CHANGELOG.md b/CHANGELOG.md index 47d64c3ec..7c25d7cfa 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -36,6 +36,12 @@ Format follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/). optional `dry_run` boolean and the same publish-verification gate as `release.yml`. (#2828) ### Changed +- **Canary release workflow now publishes from `dev` branch only** — `.github/workflows/canary.yml` + swaps its four publish-step guards from `refs/heads/main` to `refs/heads/dev`. Aligns the + workflow with the new branch→dist-tag policy (`dev` → `@canary`, `main` → `@next`/`@latest`). + Added a header comment documenting the policy. `workflow_dispatch` runs on `main` (or any + other branch) now complete build/test/dry-run validation but skip publish + tag, instead + of the previous behaviour where `main` published and `dev` silently no-op'd. (#2868) - **Skill descriptions trimmed to ≤ 100 chars across all `commands/gsd/*.md`** — three anti-patterns eliminated: flag documentation already present in `argument-hint:` (e.g. `discuss-phase` was 380 chars, now 76), `Triggers:` keyword-stuffing lists, and