ci: 每晚安检查构建,自动打 tag 并发布 patch release - #100
Merged
Merged
Conversation
Nightly releases are now driven by change detection instead of a manual tag: a scheduled workflow inspects main against the latest stable release tag and, when there are new commits, creates the next patch tag and publishes through the same signed pipeline as the tag workflow. release.yml keeps its tag trigger as a manual fallback. Extract the sign/verify/publish job into the reusable release-artifact.yml so both entry points cannot drift, add scripts/nightly-release-plan.sh for change detection and patch bumping with shell tests wired into ci-basic-checks.sh, and record the change in docs/sdlc/changes/2026-09-18-nightly-release-pipeline/. Co-authored-by: multica-agent <github@multica.ai>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
变更
把发布方向反过来:每晚安检查
main→ 有变更则自动打 tag 并发布正式 patch release。手动 tag 触发的release.yml保留为兜底。三个层次
.github/workflows/nightly-release.yml(新增)schedule: cron "0 12 * * *"(= 每天 20:00 Asia/Shanghai)+workflow_dispatchconcurrency: group: nightly-release,cancel-in-progress: false(不会取消正在发布的那次)plan(ubuntu)→validate(仓库检查 +swift test)→ 复用发布流水线并create_tag: truechanged=false时后两个 job 直接跳过,并在 log + step summary 写明原因(无新提交、最新 tag 等).github/workflows/release-artifact.yml(新增,workflow_call)把
release.yml的 Sign/Verify/Publish 整段抽成 reusable workflow,两处入口共用,避免漂移:凭证校验 → 证书导入(OpenSSL 3-legacy回退)→ Metal toolchain → 签名构建 →verify-release-artifact.sh→ Developer ID 公证(适用时)→ 校验和 → draft 发布 → 回下载校验 → 转正式 release。job 名仍是Sign, Verify & Publish。输入version/tag/create_tag/require_ancestor。HEAD == origin/maintip、远程无同名 tag,然后创建附注 tag 并 push;不移动/不删除/不覆盖任何已发布资产。scripts/nightly-release-plan.sh(新增,只读规划器)取最高稳定版 tag(数值序,忽略 prerelease/build)→ 与分支 tip 比较 → 输出
changed/version(patch 递增)/latest_tag/head_sha/commit_count/commit_summary/reason。输出的版本再过一遍release-version.sh校验。release.yml只保留validatejob(SemVer + main ancestry、仓库检查、单测)并改为调用 reusable workflow;v*触发不变。SDLC(高风险)
新增
docs/sdlc/changes/2026-09-18-nightly-release-pipeline/:intent / spec / plan / verification。spec 记录了标签写入、并发、无变更夜、密钥与失败containment 的设计与拒绝过的替代方案;rollback = 关掉/回滚 nightly workflow,手动 tag 流程不受影响。需要确认的两个假设
0 12 * * *UTC)实现。nightly-*预发布包,改动很小(把version/tag换成nightly-<date>,gh release create加--prerelease)。测试与验证
bash scripts/tests/test_nightly_release_plan.sh→ passed(首次 0.0.1 / 无变更跳过并给 reason / patch 递增 0.0.46 / 9→10 进位 0.1.10 / 数值序 v0.0.10 > v0.0.9 / 忽略 prerelease tag / 未知分支与缺参 fail closed / workflow 接线断言 / 共享流水线护栏断言)bash scripts/tests/test_release_version.sh、test_build_version.sh→ passed(护栏断言改指release-artifact.yml)bash scripts/sdlc-checks.sh→ passed;bash scripts/ci-basic-checks.sh→ passed[validate, release]、artifact[release]、nightly[plan, validate, release])swift build+ 聚焦swift test→ 397 passed / 8 skipped / 0 failures(无 App 代码改动)真实发布路径无法在 PR 上演练:
production环境限制了 tag 部署,且 workflow 的改动只有合并后在默认分支才生效。合并后可用workflow_dispatch观察规划输出/跳过原因;注意若当时main有新提交,dispatch 会真的发布。交付
agent/qa/nightly-release-workflow(从最新main)efec93e—ci: add scheduled nightly release pipelinemain,未 merge)单条命令均 <8 分钟。