Skip to content

ci: block merges until the merged release is published - #1014

Merged
rcoh merged 2 commits into
mainfrom
codex/block-merges-before-publish
Oct 7, 2026
Merged

rcoh merged 2 commits into
mainfrom
codex/block-merges-before-publish

Conversation

@rcoh

@rcoh rcoh commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

After a release PR merges, later PRs can currently merge before the manual publish workflow runs, so a release can include changes that were not part of its preparation.

Add a 33-line Bash guard to the already-required CI Pass check. The Publish release workflow writes a lightweight release-published/ tag only after crate publication succeeds. PRs and merge groups fail while the latest merged release lacks that tag, and a merge group cannot contain another PR after a release PR. After publishing, rerun failed CI jobs on waiting PRs.

Make the generated release PR title explicit and document the workflow. Releases merged before the guard was introduced are exempt from completion tags. No branch-protection settings need to change.

Validation:

  • Eight focused tests using real Git repositories and remotes cover pending publication, successful publication, reruns, old tags, release PRs, merge groups, legacy releases, and remote failures.
  • Bash syntax checking, actionlint for CI and both release workflows, and git diff --check pass.
  • Rust tests, fmt, and clippy were not run locally: this changes only CI tooling, configuration, and documentation.

@rcoh
rcoh added this pull request to the merge queue Oct 7, 2026
Merged via the queue into main with commit 65be2ce Oct 7, 2026
30 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants