Files
orca/.github/workflows/release-policy.yml
T
Jinjing 95a16e3f67 fix(release): stop the release policy from deleting pipeline-cut releases (#23669)
* fix(release): stop the release policy from deleting pipeline-cut releases

The policy judged a release by who created the release object. Cut Release
reuses an existing draft, so a CI-built v1.4.216 whose draft a person had
created was deleted (tag included) when its notes were edited, and Latest
fell back to v1.4.214 because v1.4.215 was also published by a person.

- Authorize a desktop release when its annotated tag was created by the
  release pipeline and points at its `release: vX` commit, not only by author.
- Only delete on `published`; an edit never deletes a release or tag.
- Pick Latest from the highest authorized stable using the same check.
- Move the policy into config/scripts/release-policy.mjs with tests.

* fix(release): load the policy module from the tagged commit

Release events run the workflow file from the tag's commit, so checking out
the default branch could pair an old workflow with a newer module.
2026-09-28 12:03:58 -07:00

37 lines
1011 B
YAML

name: Release Policy
on:
release:
types:
- published
- edited
permissions:
contents: write
concurrency:
group: release-policy
cancel-in-progress: false
jobs:
enforce:
if: github.repository == 'stablyai/orca'
runs-on: ubuntu-slim
timeout-minutes: 5
steps:
# Why: release events run this file from the tagged commit, so load the module from the same commit.
- uses: actions/checkout@v6
with:
sparse-checkout: config/scripts/release-policy.mjs
sparse-checkout-cone-mode: false
persist-credentials: false
- name: Enforce release policy
uses: actions/github-script@v8
with:
script: |
const { pathToFileURL } = await import("node:url")
const { enforceReleasePolicy } = await import(
pathToFileURL(`${process.env.GITHUB_WORKSPACE}/config/scripts/release-policy.mjs`).href
)
await enforceReleasePolicy({ github, context, core })