From f2ada8500c8ab6e600c738d53a4ab10bcc62ce2b Mon Sep 17 00:00:00 2001 From: Tom Boucher Date: Wed, 29 Apr 2026 17:43:30 -0400 Subject: [PATCH] chore(#2868): switch canary publish from main to dev branch (#2871) * chore(#2868): switch canary publish from main to dev branch Swaps the four `if:` guards in `.github/workflows/canary.yml` from `refs/heads/main` to `refs/heads/dev` so the canary stream is owned by the new long-lived integration branch. Adds a policy comment at the top of the workflow documenting the branch->dist-tag mapping (dev=@canary, main=@next/@latest, no overlap). Closes #2868 * fix(#2868): summary block matches publish-step gate CodeRabbit caught: the Summary step keyed off DRY_RUN only, so a non-dry-run on main would falsely report "Published"/"Tagged" even though all four publish steps were skipped by the new dev-only gate. Add PUBLISH_ELIGIBLE env mirroring the publish-step `if:` expression and a VALIDATION ONLY branch in the summary so non-dev runs report honestly. --- .github/workflows/canary.yml | 21 +++++++++++++++++---- CHANGELOG.md | 6 ++++++ 2 files changed, 23 insertions(+), 4 deletions(-) diff --git a/.github/workflows/canary.yml b/.github/workflows/canary.yml index a27d73ea8..5dc88d0f1 100644 --- a/.github/workflows/canary.yml +++ b/.github/workflows/canary.yml @@ -1,3 +1,12 @@ +# Release stream policy: +# dev → @canary (this workflow — preview builds for the long-lived integration branch) +# main → @next (RC train, see release.yml) +# main → @latest (stable cuts, see release.yml) +# +# Streams do not mix. The publish/tag steps below gate on `refs/heads/dev` so a +# workflow_dispatch run on any other branch (including main) completes the +# build/test/dry-run validation but does not publish or tag. + name: Canary on: @@ -80,7 +89,7 @@ jobs: NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} - name: Tag and push - if: ${{ github.ref == 'refs/heads/main' && !inputs.dry_run }} + if: ${{ github.ref == 'refs/heads/dev' && !inputs.dry_run }} env: CANARY_VERSION: ${{ steps.canary.outputs.canary_version }} run: | @@ -88,19 +97,19 @@ jobs: git push origin "v${CANARY_VERSION}" - name: Publish to npm (canary) - if: ${{ github.ref == 'refs/heads/main' && !inputs.dry_run }} + if: ${{ github.ref == 'refs/heads/dev' && !inputs.dry_run }} run: npm publish --provenance --access public --tag canary env: NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} - name: Publish SDK to npm (canary) - if: ${{ github.ref == 'refs/heads/main' && !inputs.dry_run }} + if: ${{ github.ref == 'refs/heads/dev' && !inputs.dry_run }} run: cd sdk && npm publish --provenance --access public --tag canary env: NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} - name: Verify publish - if: ${{ github.ref == 'refs/heads/main' && !inputs.dry_run }} + if: ${{ github.ref == 'refs/heads/dev' && !inputs.dry_run }} env: CANARY_VERSION: ${{ steps.canary.outputs.canary_version }} run: | @@ -132,10 +141,14 @@ jobs: env: CANARY_VERSION: ${{ steps.canary.outputs.canary_version }} DRY_RUN: ${{ inputs.dry_run }} + PUBLISH_ELIGIBLE: ${{ github.ref == 'refs/heads/dev' && !inputs.dry_run }} + BRANCH_REF: ${{ github.ref }} run: | echo "## Canary v${CANARY_VERSION}" >> "$GITHUB_STEP_SUMMARY" if [ "$DRY_RUN" = "true" ]; then echo "**DRY RUN** — npm publish, tagging, and push skipped" >> "$GITHUB_STEP_SUMMARY" + elif [ "$PUBLISH_ELIGIBLE" != "true" ]; then + echo "**VALIDATION ONLY** — publish/tag skipped for \`${BRANCH_REF}\`; canary publish is gated to \`refs/heads/dev\`." >> "$GITHUB_STEP_SUMMARY" else echo "- Published to npm as \`canary\`" >> "$GITHUB_STEP_SUMMARY" echo "- SDK also published: \`@gsd-build/sdk@${CANARY_VERSION}\` on \`canary\`" >> "$GITHUB_STEP_SUMMARY" diff --git a/CHANGELOG.md b/CHANGELOG.md index 47d64c3ec..7c25d7cfa 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -36,6 +36,12 @@ Format follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/). optional `dry_run` boolean and the same publish-verification gate as `release.yml`. (#2828) ### Changed +- **Canary release workflow now publishes from `dev` branch only** — `.github/workflows/canary.yml` + swaps its four publish-step guards from `refs/heads/main` to `refs/heads/dev`. Aligns the + workflow with the new branch→dist-tag policy (`dev` → `@canary`, `main` → `@next`/`@latest`). + Added a header comment documenting the policy. `workflow_dispatch` runs on `main` (or any + other branch) now complete build/test/dry-run validation but skip publish + tag, instead + of the previous behaviour where `main` published and `dev` silently no-op'd. (#2868) - **Skill descriptions trimmed to ≤ 100 chars across all `commands/gsd/*.md`** — three anti-patterns eliminated: flag documentation already present in `argument-hint:` (e.g. `discuss-phase` was 380 chars, now 76), `Triggers:` keyword-stuffing lists, and