-
Notifications
You must be signed in to change notification settings - Fork 7
116 lines (109 loc) · 5.93 KB
/
Copy pathchangelog.yml
File metadata and controls
116 lines (109 loc) · 5.93 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
name: Auto Changelog
# Dispatch-only, deliberately (objectui#5409).
#
# This lane also declared `release: types: [published]` until 2026-08-23. That
# trigger was dead configuration, not a fallback: every release in this
# repository is authored by `github-actions[bot]`, created by the Changesets
# action in `changeset-release.yml` using `secrets.GITHUB_TOKEN`, and GitHub
# does not start workflow runs from events raised with that token (the
# recursive-trigger guard). Measured before removal: this workflow had 0 runs
# across the repository's whole life, against `changeset-release.yml`'s 4049
# through the identical API call — so the zero was the trigger, not the query.
#
# When to run it: at release time, as part of cutting the release. Nothing else
# invokes this workflow. The root CHANGELOG.md is a periodically hand-curated
# summary; the per-package CHANGELOG.md files that Changesets writes on the
# release commit are the source of truth for granular and current history.
on:
workflow_dispatch:
permissions:
contents: write
pull-requests: read
jobs:
changelog:
runs-on: ubuntu-latest
# ── NO job ceiling, and that is the DECISION, not its absence (objectui#7956) ──
# This job runs under GitHub's 360-minute default. objectui#7956 asked for a
# ceiling DERIVED from this job's own measured run-time distribution, in the
# shape objectui#7270 left beside `lint.yml::lint`. It is recorded here
# instead, because this job has no distribution to derive one from.
#
# - Population: every run of this workflow, no status filter, whole
# retained history — `GET /actions/workflows/changelog.yml/runs` reports
# `total_count: 0`. Re-measured 2026-09-06T17:22Z.
# - Control, so that zero is a reading rather than a broken query: the
# identical call against `changeset-release.yml` reports a `total_count`
# of 5010 completed runs. The endpoint answers; this workflow has never
# produced a run for it to answer with.
# - The header above already recorded this same zero once, measured before
# 2026-08-23 against the same endpoint while removing the dead `release`
# trigger. It has not moved: this workflow is dispatch-only, and it has
# never been dispatched.
#
# ⛔ Do NOT put a number here derived from another job, from the apparent
# cost of a checkout plus git-cliff, or from what these steps "should" take.
# A ceiling set under a job's honest slowest run converts a working job into
# a permanently red one (objectui#7048), and this job has produced no honest
# run to sit above; objectstack#16173 is the live counter-example, where a
# distribution mis-estimated by ~2.6x killed a test shard while the rollup
# read green. An invented ceiling is worse than the default it replaces,
# because it looks derived.
#
# ⚠️ The accepted cost, stated plainly: a hang in a dispatched run occupies
# a runner for six hours before reporting `cancelled`. That is the same
# exposure objectui#7956 closed on four of its six jobs. It is accepted here
# only because the alternative is a guess, and it is bounded in practice by
# the fact that nothing starts this workflow except a maintainer, who is by
# construction watching when they do.
#
# What would change this: one real dispatch. Measure that run the way
# `lint.yml::lint` documents, write the derivation here, and move this job
# out of the accept-360 table and into the `derived` table in
# `scripts/__tests__/workflow-cache-save-bound.test.ts` in the same commit —
# that pin holds this job's UNBOUNDED state deliberately, so adding a
# ceiling has to be an edit someone makes on purpose rather than a silent
# one.
steps:
- name: Checkout code
uses: actions/checkout@v7
with:
fetch-depth: 0
submodules: true
# No lockfile merge driver here, deliberately (objectui#6358).
#
# This job configured one until 2026-08-25. A merge driver is invoked by
# git only when git actually has to MERGE the attributed path, and this
# job never merges: it checks out, runs git-cliff, stages exactly
# CHANGELOG.md, commits, and pushes. There is no merge, rebase, pull,
# cherry-pick or revert in it, and it never touches `pnpm-lock.yaml` at
# all. The stated reason for the step -- that it "commits back to a branch
# that may have moved" -- does not reach a driver: a push to a branch that
# moved is REJECTED, not merged, and nothing here resolves that rejection.
#
# So the step was dead configuration rather than a missing-toolchain bug.
# Note the disposition did NOT turn on the workflow being unreachable: it
# is `workflow_dispatch`, a maintainer can start it any time, and it is
# meant to be run at release time. It had 0 runs when this was measured,
# but "never dispatched" is not "cannot run" -- the driver would not fire
# even on a successful manual dispatch, which is the reason acted on.
#
# Restoring it needs a real merge in this job first, not the instinct that
# every workflow touching git wants the driver. If one is ever added, add
# `corepack enable` + `actions/setup-node` ahead of it the way
# `changeset-release.yml` and `dependabot-auto-merge.yml` do -- the driver
# shells out to pnpm, and this workflow pins no toolchain.
- name: Generate changelog
uses: orhun/git-cliff-action@v4
id: changelog
with:
config: cliff.toml
args: --verbose --latest
env:
OUTPUT: CHANGELOG.md
- name: Commit changelog
run: |
git config --local user.email "github-actions[bot]@users.noreply.github.com"
git config --local user.name "github-actions[bot]"
git add CHANGELOG.md
git commit -m "docs: update CHANGELOG.md" || echo "No changes to commit"
git push