Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 5 additions & 3 deletions .github/workflows/verify-release-notes.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,9 +10,10 @@ name: Verify Release Notes
#
# `edited` re-runs the check when the description changes and `labeled` and
# `unlabeled` when the release label does. There is no branch or label filter: the
# gate itself only checks pull requests into the default branch that carry exactly
# one of major, minor or patch, and passes the rest (no release label yet,
# no-release, Dependabot) with a notice.
# gate itself checks pull requests into the default branch, fails one that carries
# major, minor or patch, warns on one labelled no-release or not labelled yet, and
# passes Dependabot's with a notice. `pull-requests: read` lets it read the pull
# request as it is now, so a re-run sees the current labels and description.
#
# The job is named release-notes so the check reads `release-notes / verify` and
# does not collide with other `verify / verify` gates.
Expand All @@ -29,6 +30,7 @@ on:

permissions:
contents: read
pull-requests: read

jobs:
release-notes:
Expand Down
25 changes: 23 additions & 2 deletions .github/workflows/verify-semver-label.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,16 @@ name: Verify Semver Label
# labels are accepted and what the errors say - lives in
# Cratis/Workflows/.github/workflows/verify-release-intent.yml. Thirty diverging
# per-repository copies of that logic are how the 2026-08-25 unintended releases
# happened; do not reintroduce logic here.
# happened; do not reintroduce logic here. Installed through this repository's own reviewed change because
# Cratis/Workflows' bootstrap-common-workflows ignores it (it deliberately customizes update-packages.yml).
#
# A Dependabot pull request first has its labels corrected: Dependabot adds major,
# minor or patch on its own, and a Dependabot pull request only ever carries
# no-release. The gate then reads the labels as they are now, so it sees the
# correction although a label change made with GITHUB_TOKEN starts no new run.
#
# The job is named release-intent so the check reads `release-intent / verify` and
# does not collide with `verify / verify` from verify-no-work-records.
concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
Expand All @@ -22,5 +31,17 @@ permissions:
contents: read

jobs:
verify:
dependabot-labels:
if: github.event.pull_request.user.login == 'dependabot[bot]'
uses: Cratis/Workflows/.github/workflows/normalize-dependabot-labels.yml@main
permissions:
pull-requests: write

release-intent:
needs: dependabot-labels
# Also after a failed or skipped correction: the gate then reports the labels as they are.
if: ${{ !cancelled() }}
uses: Cratis/Workflows/.github/workflows/verify-release-intent.yml@main
permissions:
contents: read
pull-requests: read
Loading