Skip to content

build(release): stamp gate + workflow-created tags; stamps to 1.6.0 - #582

Merged
FumingPower3925 merged 2 commits into
mainfrom
feat/release-gate
Sep 13, 2026
Merged

FumingPower3925 merged 2 commits into
mainfrom
feat/release-gate

Conversation

@FumingPower3925

Copy link
Copy Markdown
Contributor

Closes the "I forgot to bump the version again" class for good.

What was stale: server.go Version said 1.5.5 through three releases, the four middleware/*/go.mod pins said 1.5.8, the README headline said 1.5.8. Nothing checked any of them and the release was cut by hand.

Now

  • mage CheckRelease: every hand-written stamp must agree with VERSION (or with each other when unset). Runs in CI on every PR (ci.yml, lint job), so the stamps cannot drift apart between releases.
  • VERSION=vX.Y.Z mage PrepRelease: moves all stamps at once, leaves a placeholder under the README heading that CheckRelease refuses until the prose is written.
  • release.yml gains workflow_dispatch with a version input: from main, it runs CheckRelease against the input, runs CI, then creates the tag and the GitHub Release itself (gh release create --target $GITHUB_SHA --generate-notes), then the sub-module tags and the proxy ping from the same run. A stale stamp means no tag is created; nothing to delete.
  • A release created by hand still runs the same gate first and stops before sub-module tags and the proxy. GOVERNANCE.md carries the recovery recipe: while proxy.golang.org still answers 404 for the version, gh release delete vX.Y.Z --cleanup-tag is harmless; once served, the version is burned and the next patch ships.

Verified locally: on the stale tree CheckRelease failed naming all five mismatches; after PrepRelease and the README prose it passes; negative controls: one stale pin → fail, VERSION disagreeing with the tree → fail, a duplicated heading → fail. actionlint clean on both workflows. The CI job on this PR is the first run of the check itself.

Stamps are at 1.6.0 with the release section written; the validation sentence is added at release time once the soak and bench are in.

…rkflow creates the tag, not the maintainer

celeris.Version sat at 1.5.5 through three releases, the sub-module pins
at 1.5.8, and the README headline at 1.5.8, because nothing checked them
and the release was cut by hand.

mage CheckRelease verifies that every hand-written stamp (server.go
Version, the four middleware/*/go.mod pins, the README "What's new"
heading) agrees with VERSION, or with each other when VERSION is unset.
CI runs the second form on every PR, so the stamps cannot drift apart.
VERSION=vX.Y.Z mage PrepRelease moves all of them at once and leaves a
placeholder under the README heading that CheckRelease refuses until the
release prose exists.

The Release workflow gains a workflow_dispatch input: from main it runs
CheckRelease against the requested version, runs CI, and only then
creates the tag and the GitHub Release itself, so a stale stamp means no
tag exists and nothing has to be deleted. A release created by hand still
goes through the same gate and stops before sub-module tags and the proxy
ping; GOVERNANCE.md records the recovery recipe (delete while the proxy
still answers 404, otherwise the version is burned).

Stamps moved to 1.6.0 and the README section written for it.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant