Tag reviewed main in release workflow - #22
Conversation
Tiny Sweeper reviewUpdates the release workflow to tag an already-merged version on protected main instead of computing and pushing a version bump commit. Adds a new tagging script with validation and a test suite. Updates documentation to reflect the new process. State: Ready for maintainer review Review snapshot
Completeness: Complete What changedThe release workflow now accepts a release_version input and runs a script that validates the checkout is on main, the version matches, the commit is the current main commit, and creates or reuses an annotated tag. The CI workflow now runs the tag script's test suite. Documentation is updated. Features
Tests
Findings
Resolved this pass
Before mergeNone. Agent review detailscritique
security
tests
commits
description
e2e
Evidence and run details
|
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Warning Review limit reached
This review includes 7 billable files and costs up to $1.75. Or wait 41 minutes for your next included review. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (7)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (7)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe release workflow now takes a version already merged to protected ChangesReviewed release flow
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Bug fix Sequence Diagram(s)sequenceDiagram
participant ReleaseWorkflow
participant TagScript
participant OriginMain
participant GitHubOutput
ReleaseWorkflow->>TagScript: Pass EXPECTED_VERSION
TagScript->>OriginMain: Compare HEAD with current main
TagScript->>OriginMain: Create or verify version tag
TagScript->>GitHubOutput: Write crate, version, and tag
Merge Risk: ⚪ Minimal · up to The release flow is ready to merge after normal checks. Tagging stays tied to the reviewed main commit, and subsequent jobs use that tag. Architecture SummaryArchitecture risk: 🔵 Low · up to The change affects 2 systems. Changed systems: Architecture concerns Review detailsSystems and components
Before / after behavior
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files. (5 skipped: 5 unsupported.) A rabbit checks the tag with care Comment |
There was a problem hiding this comment.
Requesting changes: 1 lane(s) blocking, worst finding is high.
Fix or reply to the findings below and push. The next review clears this automatically once they are gone — you should not need to dismiss anything by hand.
$0.0169 · 505,743 in / 30,141 out · 33,293 cached (7%) · flash, ladder/vectors, gpt-5.6-luna, deepseek/deepseek-v4-flash, deepseek-v4-flash · 588 embedded
critique: $0.0096 · 302,552 in / 15,894 out · 26,003 cached (9%) · gpt-5.6-luna, deepseek/deepseek-v4-flash
security: $0.0047 · 179,680 in / 4,118 out · 7,290 cached (4%) · gpt-5.6-luna
description: $0.0003 · 11,699 in / 3,374 out · 0 cached (0%) · deepseek-v4-flash
There was a problem hiding this comment.
The previously-blocking findings are resolved. Clearing the changes request.
$0.0107 · 273,795 in / 23,575 out · 39,216 cached (14%) · ladder/vectors, gpt-5.6-luna, deepseek/deepseek-v4-flash · 591 embedded
critique: $0.0055 · 152,558 in / 10,771 out · 17,814 cached (12%) · gpt-5.6-luna, deepseek/deepseek-v4-flash
security: $0.0028 · 101,610 in / 4,792 out · 9,114 cached (9%) · gpt-5.6-luna
description: $0.0012 · 12,462 in / 5,159 out · 12,288 cached (99%) · deepseek/deepseek-v4-flash
Summary
Fix release preparation for protected main. Release run 36087226790 passed formatting, Clippy, build, tests, docs, and 90% per-file Chrome coverage, then created local v0.2.2 commit b59fa1c. GitHub rejected its direct HEAD:main push with GH013 because the new commit had no required Rust status; the workflow never pushed a tag or produced assets.
The workflow now accepts the version already merged through a normal PR. After all release checks pass, it verifies its checkout equals current protected main and Cargo metadata matches the requested version. It then creates an annotated tag on that exact commit, or reuses a tag only if it already points there. The workflow no longer creates or pushes a commit to main. The existing module matrices and immutable release steps continue from the tag.
After the separate v0.2.2 version PR is merged, dispatch with:
Related issue
Failed Release run 36087226790.
API or behavior changes
The manual release input changes from a semantic bump/current choice to the exact version already merged on main. No product API change.
Validation
The shell test uses a local bare Git remote to prove wrong version/branch, unreviewed local HEAD, and stale tag fail; tag creation pushes only refs/tags/v0.2.2; rerunning with the same tag is idempotent.
Tests
Added the protected-release tag script test and wired it into CI and release preparation. No live GitHub tag was created by this PR.
Documentation
Updated AGENTS.md and the release spec/plan for the reviewed version PR and tag-only workflow.
Checklist
Summary by CodeRabbit
Release Process
mainthrough a reviewed pull request. The release workflow tags that commit and builds the release without creating a version-update commit.Documentation
Tests