Stagger weekly package updates by repository - #131
Conversation
|
Local requested gates passed:
The checksum is POSIX Based on origin/main, independent of |
|
Deployment approval is still required before merge: changing .github/scripts/bootstrap-common-workflows.sh triggers Bootstrap Common Workflows on main. It writes directly to default branches across non-archived, non-ignored Cratis repositories, installs their weekly package-update offsets, and can overwrite other wrapper drift. Ignored/custom-owned repositories remain excluded. Please explicitly approve that organization-wide write before merging; no merge or live bootstrap dispatch was performed. The release-note wording and partial issue reference are corrected. The requested CI test step, both event path filters, README offline-check entry, and scheduled-update wording are prepared locally but not pushed: bootstrap-package-update-safety.test.py fails against this PR's actual base-to-head diff with "Changed files would trigger organization-wide writes" for the bootstrap script. Wiring the new paths into Verify Package Updates exposes that existing guard in CI. A decision is needed on how the separately reviewed bootstrap rollout should interact with the narrow package-update implementation guard; it has not been weakened or bypassed. Actionlint and git diff --check passed. The schedule suite passed all three tests through pi-phase (120-second execution budget, 600-second queue budget). The safety suite failed one of five tests with PACKAGE_UPDATE_DIFF_BASE set to the real PR comparison base; a clean-HEAD run is not evidence for this PR's write boundary. |
Changed