Skip to content

ci(release): tag releases from merged release PRs in CI - #51

Merged
jo16oh merged 1 commit into
mainfrom
ci/release-from-merged-pr
Sep 24, 2026
Merged

jo16oh merged 1 commit into
mainfrom
ci/release-from-merged-pr

Conversation

@jo16oh

@jo16oh jo16oh commented Sep 24, 2026 •

Copy link
Copy Markdown
Owner

Why

Release tags (v*, zed-v*) are now immutable via the release-tags-immutable ruleset, so a tag pushed by hand on the wrong commit or version can never be taken back. Tagging moves into CI, after the checks pass.

What

  • release.yml runs on pushes to main that touch packages/css-var-kit/package.json (and on workflow_dispatch, main only) instead of on tag pushes.
    • verify skips the run when v<version> already exists, fails unless the commit is a merged chore/release-<version> PR titled chore: release v<version>, and fails if the package versions disagree.
    • tag pushes the tag with the deploy key only after every build passes, then publish / publish-vscode / github-release run in the same run (a tag pushed with GITHUB_TOKEN does not trigger other workflows).
    • The file name is unchanged, so the npm / crates.io trusted publishing config still matches.
  • New release-zed.yml does the same for zed-v<version> (chore/release-zed-<version>, chore(zed): release v<version>), checking Cargo.toml against extension.toml.
  • just push-tag / just push-zed-tag are removed.

Rulesets and secrets

The GitHub Actions app cannot be a ruleset bypass actor on a personal-account repository (the API rejects it with 422), so tags are created with a deploy key instead:

  • release-tags (creation): the only bypass actor is deploy keys; Repository Admin no longer bypasses it.
  • A write deploy key, whose private half is the RELEASE_TAG_KEY secret of the release environment (deployment branches: main only).
  • The tag jobs run in that environment and push the tag over SSH; the key is loaded into an ssh-agent that ends with the step.

These are already in place.

Testing

  • actionlint and zizmor pass.
  • The PR check's jq expression was tested against a real commits/{sha}/pulls response: it matches after rewriting the branch and title to the release format, and fails as-is or with a mismatched version.
  • The workflows have not run on GitHub yet; the first release PR merge is the end-to-end test.

🤖 Generated with Claude Code

Release tags are now immutable, so a tag pushed by hand on the wrong commit
or version could never be taken back. Merging a release PR now triggers the
workflow, which checks the commit is that PR's merge and the versions agree,
builds, and only then creates the tag. This replaces `just push-tag` and
`just push-zed-tag`.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@jo16oh
jo16oh merged commit b6e9ee7 into main Sep 24, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant