From 05ecab7c40555a4abe0b69e1892f9c750dc26a35 Mon Sep 17 00:00:00 2001 From: woksin Date: Thu, 1 Oct 2026 16:08:50 +0200 Subject: [PATCH 1/2] Refresh release-intent and release-notes callers --- .github/workflows/verify-release-notes.yml | 8 +++++--- .github/workflows/verify-semver-label.yml | 14 +++++++++++++- 2 files changed, 18 insertions(+), 4 deletions(-) diff --git a/.github/workflows/verify-release-notes.yml b/.github/workflows/verify-release-notes.yml index 3a131d3e..5627203e 100644 --- a/.github/workflows/verify-release-notes.yml +++ b/.github/workflows/verify-release-notes.yml @@ -10,9 +10,10 @@ name: Verify Release Notes # # `edited` re-runs the check when the description changes and `labeled` and # `unlabeled` when the release label does. There is no branch or label filter: the -# gate itself only checks pull requests into the default branch that carry exactly -# one of major, minor or patch, and passes the rest (no release label yet, -# no-release, Dependabot) with a notice. +# gate itself checks pull requests into the default branch, fails one that carries +# major, minor or patch, warns on one labelled no-release or not labelled yet, and +# passes Dependabot's with a notice. `pull-requests: read` lets it read the pull +# request as it is now, so a re-run sees the current labels and description. # # The job is named release-notes so the check reads `release-notes / verify` and # does not collide with other `verify / verify` gates. @@ -29,6 +30,7 @@ on: permissions: contents: read + pull-requests: read jobs: release-notes: diff --git a/.github/workflows/verify-semver-label.yml b/.github/workflows/verify-semver-label.yml index 4807b1ef..e942d904 100644 --- a/.github/workflows/verify-semver-label.yml +++ b/.github/workflows/verify-semver-label.yml @@ -22,5 +22,17 @@ permissions: contents: read jobs: - verify: + dependabot-labels: + if: github.event.pull_request.user.login == 'dependabot[bot]' + uses: Cratis/Workflows/.github/workflows/normalize-dependabot-labels.yml@main + permissions: + pull-requests: write + + release-intent: + needs: dependabot-labels + # Also after a failed or skipped correction: the gate reports the live labels. + if: ${{ !cancelled() }} uses: Cratis/Workflows/.github/workflows/verify-release-intent.yml@main + permissions: + contents: read + pull-requests: read From fb87bf6ec87f8f915d9a1793dc2f611a54b24ccc Mon Sep 17 00:00:00 2001 From: woksin Date: Thu, 1 Oct 2026 19:51:42 +0200 Subject: [PATCH 2/2] Restore release-intent caller template comments --- .github/workflows/verify-semver-label.yml | 13 +++++++++++-- 1 file changed, 11 insertions(+), 2 deletions(-) diff --git a/.github/workflows/verify-semver-label.yml b/.github/workflows/verify-semver-label.yml index e942d904..04ad7b02 100644 --- a/.github/workflows/verify-semver-label.yml +++ b/.github/workflows/verify-semver-label.yml @@ -4,7 +4,16 @@ name: Verify Semver Label # labels are accepted and what the errors say - lives in # Cratis/Workflows/.github/workflows/verify-release-intent.yml. Thirty diverging # per-repository copies of that logic are how the 2026-08-25 unintended releases -# happened; do not reintroduce logic here. +# happened; do not reintroduce logic here. Installed through this repository's own reviewed change because +# Cratis/Workflows' bootstrap-common-workflows ignores it (it deliberately customizes update-packages.yml). +# +# A Dependabot pull request first has its labels corrected: Dependabot adds major, +# minor or patch on its own, and a Dependabot pull request only ever carries +# no-release. The gate then reads the labels as they are now, so it sees the +# correction although a label change made with GITHUB_TOKEN starts no new run. +# +# The job is named release-intent so the check reads `release-intent / verify` and +# does not collide with `verify / verify` from verify-no-work-records. concurrency: group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} cancel-in-progress: true @@ -30,7 +39,7 @@ jobs: release-intent: needs: dependabot-labels - # Also after a failed or skipped correction: the gate reports the live labels. + # Also after a failed or skipped correction: the gate then reports the labels as they are. if: ${{ !cancelled() }} uses: Cratis/Workflows/.github/workflows/verify-release-intent.yml@main permissions: