Repository navigation
Withhold application notifications for prereleases - #43
Merged
Merged
Conversation
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
The fanout oracle now expects a prerelease to reach the offline and hosted consumers only, with the application leg green, no App token, no dispatch and the hand-off line; a stable release still reaches all three. The failure controls run for both the prerelease and the stable publish, the skipped-dispatch control rewrites the existing guard instead of adding a second if key, and a new control breaks the decision so the application dispatches on a prerelease. test_wfrun.py and the README follow. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
luisleo526
marked this pull request as ready for review
October 9, 2026 21:53
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
For a prerelease, the publish workflow no longer sends a repository dispatch to the application; the application receives a prerelease by hand-off instead. Every other combination behaves exactly as before. The release dry-run harness is updated in a second commit so that it checks the new behavior.
Workflow behavior (
.github/workflows/publish.yml, jobnotify-consumers)All three matrix legs stay visible, and the job, environment, permissions and target expression are unchanged:
Decide consumer notification, reads the consumer and thepublishjob'sprereleaseoutput. It accepts only exactlytrueorfalse. Anything else fails the leg, for every consumer, with the existing error (publish job gave no prerelease flag) before any repository check, token or dispatch.applicationleg withprerelease=trueit recordsdispatch=falseand logs one line:Application is not notified for a prerelease; it receives the release by hand-off.The leg ends green: no token is minted and no dispatch is sent.dispatch=true:offlineandhosted: dispatched as before, payload unchanged;steps.notify.outputs.dispatch == 'true'. (A job-levelifcannot read thematrixcontext, so the decision is a step.)Tests (
tests/test_release_workflows.py)Extended, standard library only:
dispatch=falseand logs the single hand-off line; the other five writedispatch=true), and for missing or malformed flags for each consumer (non-zero exit, nothing written);test_prerelease_flag_reaches_every_consumeris renamedtest_prerelease_flag_is_in_every_dispatch_payload, since the application no longer receives a dispatch for a prerelease.Docs (
README.md)One sentence in the
publish.ymlbullet: a prerelease reaches the application by hand-off, with no repository dispatch and no App token, while stable releases still notify it and the other two roles are notified for every release.Release dry-run harness (
tools/release-dry-run/, second commit)The harness replays the real workflows offline and checks what they would send. It is updated for the new behavior without changing the workflow, the runner (
wfrun.py) or the shims:dry_run.py: the fanout oracle expects a prerelease to reach the offline and hosted consumers only, keeps all three consumer legs green, and requires the application leg to log the hand-off line once, mint no App token and send no dispatch. A stable release still reaches all three, with the same payload, JSON type, hostname, endpoint, owner and scope checks as before.false(an edit that finds no target, or several, is an error) instead of adding a secondif:key.test_wfrun.py: the consumer-leg helper keepsprerelease=falseas its default and takes an optional flag. New tests cover the withheld application (green, no token, no dispatch, even with an invalid target), the stable application with an invalid target still failing before the token, offline and hosted still dispatching on a prerelease, malformed flags failing before any token, the step condition being evaluated by the existing runner, the oracle for both channels and the new control, and the synthetic-edit helpers.README.mdof the harness: the prerelease fanout, the private-configuration prose and the list of negative controls are updated.Not changed
The payload, the event type, the secrets, the token scope, the other two consumers, the tag rules,
handle-upstream.yml,wfrun.pyand the shims.Validation
Run at this head (
aad2033) on a clean Linux machine, from a real git checkout of the branch:release-rulescommands: exit 0 (75 tests);test_wfrun.py): exit 0 (25 tests);test_only_the_application_on_a_prerelease_is_withheld).An independent review of the diff and of the raw outputs recommended merging, with no blocking finding. Two follow-ups from it are kept for a later change: the CI test does not yet forbid
continue-on-erroron the decision step (only the dry-run tool's test catches it), and on a prerelease the application leg also skips the target-repository check, so a broken application target would show only at the next stable release.Not run: the full five-world dry run (it needs Node, which the test machine did not have) and a real publish.
🤖 Generated with Claude Code