From 88d42944bab14b13df7103103a09f06434c63e33 Mon Sep 17 00:00:00 2001 From: woksin Date: Thu, 1 Oct 2026 16:08:52 +0200 Subject: [PATCH 1/2] Refresh release-intent and release-notes callers --- .github/workflows/verify-release-notes.yml | 8 ++++-- .github/workflows/verify-semver-label.yml | 32 ++++++++++++++++++++++ 2 files changed, 37 insertions(+), 3 deletions(-) create mode 100644 .github/workflows/verify-semver-label.yml diff --git a/.github/workflows/verify-release-notes.yml b/.github/workflows/verify-release-notes.yml index 33973a75..be1b95fd 100644 --- a/.github/workflows/verify-release-notes.yml +++ b/.github/workflows/verify-release-notes.yml @@ -13,9 +13,10 @@ name: Verify Release Notes # # `edited` re-runs the check when the description changes and `labeled` and # `unlabeled` when the release label does. There is no branch or label filter: the -# gate itself only checks pull requests into the default branch that carry exactly -# one of major, minor or patch, and passes the rest (no release label yet, -# no-release, Dependabot) with a notice. +# gate itself checks pull requests into the default branch, fails one that carries +# major, minor or patch, warns on one labelled no-release or not labelled yet, and +# passes Dependabot's with a notice. `pull-requests: read` lets it read the pull +# request as it is now, so a re-run sees the current labels and description. # # The job is named release-notes so the check reads `release-notes / verify` and # does not collide with other `verify / verify` gates. @@ -32,6 +33,7 @@ on: permissions: contents: read + pull-requests: read jobs: release-notes: diff --git a/.github/workflows/verify-semver-label.yml b/.github/workflows/verify-semver-label.yml new file mode 100644 index 00000000..c8c8625b --- /dev/null +++ b/.github/workflows/verify-semver-label.yml @@ -0,0 +1,32 @@ +# Copyright (c) Cratis. All rights reserved. +# Licensed under the MIT license. See LICENSE file in the project root for full license information. +name: Verify Semver Label + +# Installed through a reviewed change: the organization bootstrap ignores this repository. +# Correct Dependabot's dependency-version labels before reading the live release intent. +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} + cancel-in-progress: true + +on: + pull_request: + types: [opened, reopened, synchronize, labeled, unlabeled] + branches: [main] + +permissions: + contents: read + +jobs: + dependabot-labels: + if: github.event.pull_request.user.login == 'dependabot[bot]' + uses: Cratis/Workflows/.github/workflows/normalize-dependabot-labels.yml@main + permissions: + pull-requests: write + + release-intent: + needs: dependabot-labels + if: ${{ !cancelled() }} + uses: Cratis/Workflows/.github/workflows/verify-release-intent.yml@main + permissions: + contents: read + pull-requests: read From b210dab27f2907bcb21d1eda464d60e0add051b8 Mon Sep 17 00:00:00 2001 From: woksin Date: Thu, 1 Oct 2026 19:20:21 +0200 Subject: [PATCH 2/2] Describe when the release-notes gate fails or warns --- .github/workflows/verify-release-notes.yml | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/.github/workflows/verify-release-notes.yml b/.github/workflows/verify-release-notes.yml index be1b95fd..eca68626 100644 --- a/.github/workflows/verify-release-notes.yml +++ b/.github/workflows/verify-release-notes.yml @@ -13,9 +13,10 @@ name: Verify Release Notes # # `edited` re-runs the check when the description changes and `labeled` and # `unlabeled` when the release label does. There is no branch or label filter: the -# gate itself checks pull requests into the default branch, fails one that carries -# major, minor or patch, warns on one labelled no-release or not labelled yet, and -# passes Dependabot's with a notice. `pull-requests: read` lets it read the pull +# gate itself checks pull requests into the default branch: a description that breaks +# the release-note contract fails when the pull request carries major, minor or patch +# and is reported as a warning when it is labelled no-release or not labelled yet. +# Dependabot's pass with a notice. `pull-requests: read` lets it read the pull # request as it is now, so a re-run sees the current labels and description. # # The job is named release-notes so the check reads `release-notes / verify` and