ci: release gate, stale-SHA stand-down, SHA-pinned actions, grouped dependabot - #312
Merged
Merged
Conversation
…tions, group dependabot - #290: new gate job requires Validate success on the pushed SHA and, for PR merges, every PR check green (Blender Smoke is PR-only); release job needs it. Job-level permissions (workflow default is read); explicit git add paths instead of -A - #226: release exits cleanly when origin/main moved past the checked-out SHA or the bump push is rejected; the queued newer run publishes the whole range - #306: every workflow action pinned to a full commit SHA with a # vX.Y comment; Validate fails on any unpinned uses: - #308: dependabot weekly, grouped, chore(deps) prefix Closes #290, closes #226, closes #306, closes #308 Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
gatejob (.github/scripts/release-gate.sh): Validate must be green on the pushed SHA; PR merges also need every PR check pass/skipping.version-and-releaseneeds: gate. Workflow permissions default to read; write scopes only on the release job.git add -Areplaced by the files the workflow owns.origin/mainmoved or the bump push is rejected.# vX.Ycomment); Validate fails on any unpinneduses:.chore(deps)prefix. Security updates toggled in repo settings after merge.Proven by live run
Gate script run locally against real history: merge SHA of #310 -> exit 0 (Validate success, 13 PR checks); PR run
ffc66f4(Validate failure) -> exit 1not releasing; SHA with no Validate run -> times out, exit 1. Pin check: clean tree prints nothing; reverting one action to@v10made it flag the line (falsifier, restored). YAML parses for all edited workflows.Established by inspection only
The stale-SHA branch and the PR-checks-failing branch of the gate were not exercised live. The first real run is the push after this merge, which will run the new release workflow end to end (no release is cut:
ci:prefix).Closes #290, closes #226, closes #306, closes #308
🤖 Generated with Claude Code