Skip to content

tag-bump: land bumps via PR + auto-merge instead of direct push - #19

Merged
TeoSlayer merged 1 commit into
mainfrom
feat/tag-bump-pr-flow
Jul 13, 2026
Merged

TeoSlayer merged 1 commit into
mainfrom
feat/tag-bump-pr-flow

Conversation

@TeoSlayer

Copy link
Copy Markdown
Contributor

Zone-1 mains all require PRs (0 approvals) + the test check, and the built-in github-actions app can't be granted a bypass (classic allowances silently drop it; rulesets reject it). So the cascade's direct-push auto-tag never worked anywhere.

New flow: branch → PR → auto-merge once test passes → tag the merge commit. Protection stays for humans; bumps get validated by the target repo's own CI before main moves. Callers need pull-requests: write — receiver wave ships separately.

🤖 Generated with Claude Code

Every zone-1 repo protects main with require-PR (0 approvals) + the
"test" check, and the built-in github-actions app cannot be granted a
bypass — classic protection allowances silently drop it and repo
rulesets reject it ("must be part of the owner organization"). Direct
pushes therefore never worked; the cascade's auto-tag has been dead on
arrival everywhere.

The bump now goes branch -> PR -> auto-merge (gated by the repo's own
"test" check) -> tag the merge commit. Protection stays intact for
humans, the bump gets validated by the target repo's CI before main
moves, and the changelog/release step tags the real merged SHA.
Requires pull-requests: write from callers (cascade.yml wave ships
separately).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@TeoSlayer
TeoSlayer merged commit c9184b5 into main Jul 13, 2026
@TeoSlayer
TeoSlayer deleted the feat/tag-bump-pr-flow branch July 13, 2026 07:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants