Repository navigation
fix(ci): tap formula update via PR + auto-merge (branch protection on tap main) - #499
Merged
Merged
Conversation
…ted main Data-Wise/homebrew-tap enabled branch protection on main (PR-only + 2 required status checks), so the release workflow's direct push now fails with GH006. Push a bot/flow-cli-<version> branch, open a PR via gh, and enable auto-merge so it lands when the tap's required checks pass. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Data-Wise
added a commit
to Data-Wise/homebrew-tap
that referenced
this pull request
Aug 24, 2026
url + sha256 for the v7.17.0 tag. Done by hand because the automated path is broken: flow-cli's homebrew-release workflow pushes the formula directly to this repo's main, which is protected (PR required, 2 status checks), so it fails on every release with 'protected branch hook declined'. Data-Wise/flow-cli#499 has carried the fix since 2026-07-19 and is still open. flow-cli is marked "generated": false in generator/manifest.json, so hand-editing Formula/flow-cli.rb is the correct path here and does not trip the regen drift check. sha256 verified against the published tarball. Co-authored-by: Test User <test@example.com>
1 task
Data-Wise
added a commit
that referenced
this pull request
Sep 5, 2026
create-github-app-token was called with no permission-* inputs, so the minted token inherited EVERY permission the data-wise-homebrew-automation installation holds on homebrew-tap, for the duration of the job — a job that runs sed, git and gh against a live credential. The step needs exactly two things: commit and push the formula edit (contents: write), and open then auto-merge the bump PR (pull-requests: write) — the latter added by #499. Both are known-granted, not guessed: the App has authored 7 PRs on the tap (#215, #214, #213, #212, #210, #209, #207) and merged its own (#212, #210 show mergedBy = app/data-wise-homebrew-automation), which requires pull-requests: write; the formula pushes require contents: write. Least privilege on an existing credential — no behaviour change intended. create-github-app-token fails at mint time if a requested permission is not granted, so a mismatch surfaces immediately rather than silently. Verified: actionlint reports the same 2 pre-existing SC2086 infos before and after (different step, not introduced here); YAML parses and both keys land in the app-token step's with: block. Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Data-Wise
added a commit
that referenced
this pull request
Sep 5, 2026
Version bump for the 5 commits merged to dev since 7.17.1: 2 fixes (#513 PATH, #499 tap-push GH006), 3 CI/deps changes (#512, #514, #515). No feat commits -- patch bump. - package.json, package-lock.json, flow.plugin.zsh (FLOW_VERSION), CLAUDE.md, man/man1/*.1 (.TH version line) via scripts/release.sh - CHANGELOG.md + docs/CHANGELOG.md: new 7.17.2 entry (mirrored, per the project's dual-changelog convention) - docs/index.md: footer version stamp only. The "What's New in v7.17.1" banner is left as-is -- it describes actual 7.17.1 user-facing features, and 7.17.2 has none to add (pure CI/infra). Test-run side effects (.STATUS wins/streak counters, a test fixture's timestamp) surfaced as unrelated dirty files from running ./tests/run-all.sh and were excluded from this commit.
Merged
Data-Wise
added a commit
that referenced
this pull request
Sep 5, 2026
.STATUS had not been touched since 2026-07-07 (f740eb5): the header still read Phase: Released (v7.16.0) while v7.17.0, v7.17.1 and v7.17.2 had all shipped, and Focus: held the literal string "--help" -- a bad write, not a focus. - Header: Phase -> Released (v7.17.2); Focus -> a real one-line focus. - Added four session entries reconstructed from CHANGELOG.md, the merged PR bodies (#505, #506, #509, #513, #499, #514, #515) and the release tags: v7.17.0 (teach deploy safety + CI coverage), v7.17.1 (alias-proof pipelines), v7.17.2 (CI hardening + PATH fix), plus the 2026-07-08..07-19 housekeeping commits and a session entry for this resync itself. - Demoted the stale "Current Session (2026-07-07)" and two older headings that had been left as "Current Session" against the file's own convention. - Test baseline refreshed from evidence rather than carried forward: 84 passed / 0 failed / 0 timeout / 1 skipped across 85 registered suites, per CI run 33946019980 on dev. - Next Action re-verified against repo state: added stale-issue triage (#487/#488/#489), the PR #500 rebase decision, .gitignore for .token-optimizer, and the advisory markdown-lint backlog. Verified: scripts/check-status.zsh clean on the updated file (validator confirmed non-vacuous via a planted "Progress: banana" defect, which it caught); _flow_status_field reads all four header fields correctly. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Data-Wise/homebrew-tap enabled branch protection on
main(PR-only, 2 required status checks), so this repo's release workflow's direct push to tap main now fails with GH006 (first seen on atlas v0.14.0, 2026-07-19).The tap-push step now: commits on a per-version
bot/branch, opens a tap PR viagh(idempotent on re-runs), and enables auto-merge (squash) so it lands once the tap's required checks pass, with an immediate-merge fallback. Tap repo now hasallow_auto_merge+delete_branch_on_mergeenabled.Same fix applied ecosystem-wide: atlas#101, homebrew-tap#168 (reusable workflow, repairs the 6
auto_merge: truecallers), craft, flow-cli, folio, scribe.Test plan
actionlint: clean for the changed step (pre-existing infos in untouched steps are baseline)🤖 Generated with Claude Code