Skip to content

fix(ci): tap formula update via PR + auto-merge (branch protection on tap main) - #499

Merged
Data-Wise merged 1 commit into
devfrom
feature/tap-pr-flow
Sep 5, 2026
Merged

Data-Wise merged 1 commit into
devfrom
feature/tap-pr-flow

Conversation

@Data-Wise

Copy link
Copy Markdown
Owner

Summary

Data-Wise/homebrew-tap enabled branch protection on main (PR-only, 2 required status checks), so this repo's release workflow's direct push to tap main now fails with GH006 (first seen on atlas v0.14.0, 2026-07-19).

The tap-push step now: commits on a per-version bot/ branch, opens a tap PR via gh (idempotent on re-runs), and enables auto-merge (squash) so it lands once the tap's required checks pass, with an immediate-merge fallback. Tap repo now has allow_auto_merge + delete_branch_on_merge enabled.

Same fix applied ecosystem-wide: atlas#101, homebrew-tap#168 (reusable workflow, repairs the 6 auto_merge: true callers), craft, flow-cli, folio, scribe.

Test plan

  • actionlint: clean for the changed step (pre-existing infos in untouched steps are baseline)
  • PR-path viability verified live by tap PR chore: release v4.8.1 #167 (same flow done manually: both required checks passed, merged)
  • Full E2E on the next release run

🤖 Generated with Claude Code

…ted main

Data-Wise/homebrew-tap enabled branch protection on main (PR-only + 2
required status checks), so the release workflow's direct push now
fails with GH006. Push a bot/flow-cli-<version> branch, open a PR via gh,
and enable auto-merge so it lands when the tap's required checks pass.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Data-Wise added a commit to Data-Wise/homebrew-tap that referenced this pull request Aug 24, 2026
url + sha256 for the v7.17.0 tag.

Done by hand because the automated path is broken: flow-cli's
homebrew-release workflow pushes the formula directly to this repo's main,
which is protected (PR required, 2 status checks), so it fails on every
release with 'protected branch hook declined'. Data-Wise/flow-cli#499 has
carried the fix since 2026-07-19 and is still open.

flow-cli is marked "generated": false in generator/manifest.json, so
hand-editing Formula/flow-cli.rb is the correct path here and does not
trip the regen drift check.

sha256 verified against the published tarball.

Co-authored-by: Test User <test@example.com>
@Data-Wise
Data-Wise merged commit 915fae9 into dev Sep 5, 2026
2 checks passed
@Data-Wise
Data-Wise deleted the feature/tap-pr-flow branch September 5, 2026 01:45
Data-Wise added a commit that referenced this pull request Sep 5, 2026
create-github-app-token was called with no permission-* inputs, so the
minted token inherited EVERY permission the data-wise-homebrew-automation
installation holds on homebrew-tap, for the duration of the job — a job
that runs sed, git and gh against a live credential.

The step needs exactly two things: commit and push the formula edit
(contents: write), and open then auto-merge the bump PR
(pull-requests: write) — the latter added by #499.

Both are known-granted, not guessed: the App has authored 7 PRs on the tap
(#215, #214, #213, #212, #210, #209, #207) and merged its own (#212, #210
show mergedBy = app/data-wise-homebrew-automation), which requires
pull-requests: write; the formula pushes require contents: write.

Least privilege on an existing credential — no behaviour change intended.
create-github-app-token fails at mint time if a requested permission is not
granted, so a mismatch surfaces immediately rather than silently.

Verified: actionlint reports the same 2 pre-existing SC2086 infos before
and after (different step, not introduced here); YAML parses and both keys
land in the app-token step's with: block.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Data-Wise added a commit that referenced this pull request Sep 5, 2026
Version bump for the 5 commits merged to dev since 7.17.1: 2 fixes
(#513 PATH, #499 tap-push GH006), 3 CI/deps changes (#512, #514, #515).
No feat commits -- patch bump.

- package.json, package-lock.json, flow.plugin.zsh (FLOW_VERSION),
  CLAUDE.md, man/man1/*.1 (.TH version line) via scripts/release.sh
- CHANGELOG.md + docs/CHANGELOG.md: new 7.17.2 entry (mirrored, per the
  project's dual-changelog convention)
- docs/index.md: footer version stamp only. The "What's New in
  v7.17.1" banner is left as-is -- it describes actual 7.17.1
  user-facing features, and 7.17.2 has none to add (pure CI/infra).

Test-run side effects (.STATUS wins/streak counters, a test fixture's
timestamp) surfaced as unrelated dirty files from running
./tests/run-all.sh and were excluded from this commit.
@Data-Wise Data-Wise mentioned this pull request Sep 5, 2026
Data-Wise added a commit that referenced this pull request Sep 5, 2026
.STATUS had not been touched since 2026-07-07 (f740eb5): the header still
read Phase: Released (v7.16.0) while v7.17.0, v7.17.1 and v7.17.2 had all
shipped, and Focus: held the literal string "--help" -- a bad write, not a
focus.

- Header: Phase -> Released (v7.17.2); Focus -> a real one-line focus.
- Added four session entries reconstructed from CHANGELOG.md, the merged PR
  bodies (#505, #506, #509, #513, #499, #514, #515) and the release tags:
  v7.17.0 (teach deploy safety + CI coverage), v7.17.1 (alias-proof
  pipelines), v7.17.2 (CI hardening + PATH fix), plus the 2026-07-08..07-19
  housekeeping commits and a session entry for this resync itself.
- Demoted the stale "Current Session (2026-07-07)" and two older headings
  that had been left as "Current Session" against the file's own convention.
- Test baseline refreshed from evidence rather than carried forward:
  84 passed / 0 failed / 0 timeout / 1 skipped across 85 registered suites,
  per CI run 33946019980 on dev.
- Next Action re-verified against repo state: added stale-issue triage
  (#487/#488/#489), the PR #500 rebase decision, .gitignore for
  .token-optimizer, and the advisory markdown-lint backlog.

Verified: scripts/check-status.zsh clean on the updated file (validator
confirmed non-vacuous via a planted "Progress: banana" defect, which it
caught); _flow_status_field reads all four header fields correctly.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant