diff --git a/.github/workflows/publish.yaml b/.github/workflows/publish.yaml index 27de564..84b0133 100644 --- a/.github/workflows/publish.yaml +++ b/.github/workflows/publish.yaml @@ -31,6 +31,26 @@ jobs: config-file: release-please-config.json manifest-file: .release-please-manifest.json + # Merging the release PR here, from a push-triggered job, is what makes a + # release land without a human. A pull_request-triggered workflow cannot + # do it: GitHub holds runs on bot-authored PRs as action_required, and it + # never starts CI on a PR the GITHUB_TOKEN opened, so waiting on checks + # would wait forever. + - name: Merge the release PR + env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + run: | + PR=$(gh pr list --repo "$GITHUB_REPOSITORY" --state open --label 'autorelease: pending' \ + --json number,author --jq '[.[] | select(.author.is_bot)] | .[0].number // empty') + + if [ -z "$PR" ]; then + echo "No pending release PR to merge." + exit 0 + fi + + echo "Merging release PR #$PR" + gh pr merge "$PR" --squash --repo "$GITHUB_REPOSITORY" + publish: needs: release-please if: ${{ needs.release-please.outputs.release_created }} diff --git a/.github/workflows/release-auto-merge.yaml b/.github/workflows/release-auto-merge.yaml deleted file mode 100644 index 8bece1a..0000000 --- a/.github/workflows/release-auto-merge.yaml +++ /dev/null @@ -1,40 +0,0 @@ -name: Release Auto-Merge - -# Makes the release itself zero-touch: once a merged api-sync (or any other) -# PR lands a conventional-commit change on main, release-please-action (in -# publish.yaml) opens/updates its own "chore(main): release X.Y.Z" PR. That PR -# still has to be merged by a human today. This workflow enables GitHub's -# native auto-merge on it instead, so it merges itself as soon as the -# existing required checks (lint, typecheck, tests, contract-check, -# api-sync-check, snyk) pass -- nothing here bypasses those checks. -# -# Gating is intentionally strict and narrow: only a PR opened by the -# release-please bot itself (github-actions[bot]), carrying release-please's -# own "autorelease: pending" label. Both conditions must hold, so this never -# touches a human-authored PR or a release-please PR that already failed -# something (release-please clears the label / the PR gets closed in that -# case). Enabling auto-merge does not merge anything immediately; GitHub -# still waits for every required check to succeed first. - -on: - pull_request: - types: [opened, labeled, synchronize, reopened] - branches: [main] - -permissions: - pull-requests: write - contents: write - -jobs: - auto-merge-release-pr: - name: Enable auto-merge on the release-please PR - runs-on: ubuntu-latest - if: > - github.event.pull_request.user.login == 'github-actions[bot]' && - contains(github.event.pull_request.labels.*.name, 'autorelease: pending') - steps: - - name: Enable auto-merge - env: - GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} - run: | - gh pr merge "${{ github.event.pull_request.number }}" --auto --squash --repo "${{ github.repository }}"