mirror of
https://github.com/stablyai/orca.git
synced 2026-10-07 16:02:29 +00:00
Orca downloads a newer agent-state-rules.json from a fixed GitHub release (stable or next channel), validates it like the bundled rules, and applies it without a restart; a local override wins over the download, which wins over the bundled rules. A hand-started workflow from main is the only publisher; merging publishes nothing.
39 lines
1.1 KiB
YAML
39 lines
1.1 KiB
YAML
name: Release Policy
|
|
|
|
on:
|
|
release:
|
|
types:
|
|
- published
|
|
- edited
|
|
|
|
permissions:
|
|
contents: write
|
|
|
|
concurrency:
|
|
group: release-policy
|
|
cancel-in-progress: false
|
|
|
|
jobs:
|
|
enforce:
|
|
if: github.repository == 'stablyai/orca'
|
|
runs-on: ubuntu-slim
|
|
timeout-minutes: 5
|
|
steps:
|
|
# Why: release events run this file from the tagged commit, so load the module from the same commit.
|
|
- uses: actions/checkout@v6
|
|
with:
|
|
sparse-checkout: |
|
|
config/scripts/release-policy.mjs
|
|
config/scripts/release-tag-patterns.mjs
|
|
sparse-checkout-cone-mode: false
|
|
persist-credentials: false
|
|
- name: Enforce release policy
|
|
uses: actions/github-script@v8
|
|
with:
|
|
script: |
|
|
const { pathToFileURL } = await import("node:url")
|
|
const { enforceReleasePolicy } = await import(
|
|
pathToFileURL(`${process.env.GITHUB_WORKSPACE}/config/scripts/release-policy.mjs`).href
|
|
)
|
|
await enforceReleasePolicy({ github, context, core })
|