Skip to content

chore: new release processes - #899

Open
joaodordio wants to merge 8 commits into
masterfrom
chore/new-release-processes
Open

joaodordio wants to merge 8 commits into
masterfrom
chore/new-release-processes

Conversation

@joaodordio

@joaodordio joaodordio commented Sep 11, 2026 •

Copy link
Copy Markdown
Member

Summary

Replaces the existing ad-hoc release workflows with a standardized two-step process.

No customer facing changes

Workflow 1: Prepare Release (workflow_dispatch)

Inputs: version, ticket, docs_pr (iterable-docs PR number for Validate Release PR)

  • Checks out master only
  • Updates CHANGELOG.md (inserts new version header at top)
  • Bumps package.json + regenerates src/itblBuildInfo.ts via scripts/autoCreatePackageInfo.js
  • Opens a release PR (base master) with checklist and docs PR link
  • Creates a GitHub draft release (no tag yet, nothing published)

Workflow 2: Publish Release (workflow_dispatch)

Input: version

  • Checks out master only
  • Validates version format and that master HEAD matches the input (CHANGELOG top header, package.json, itblBuildInfo.ts)
  • Publishes the draft GitHub release and tags master at HEAD (skipped if already published)
  • Publishes to npm (@iterable/react-native-sdk) via OIDC trusted publishing (skipped if version already on npm)
  • Posts to #eng-sdk-team on Slack

Files changed

  • Added .github/workflows/prepare-release.yml
  • Added .github/workflows/publish-release.yml

Secrets to add

SLACK_WEBHOOK must be configured in repo Settings > Secrets > Actions before the first Publish Release run.

No customer facing changes

Replaces the existing ad-hoc release workflows with a two-step process:
- Prepare Release: bumps version, updates changelog, opens PR, creates GitHub draft release
- Publish Release: promotes draft, tags main, publishes to npm, posts Slack

Ref: SDK release process team agreement 2026-09-11
@joaodordio
joaodordio requested a review from a team as a code owner September 11, 2026 18:07
@github-actions

github-actions Bot commented Sep 11, 2026 •

Copy link
Copy Markdown
Lines Statements Branches Functions
Coverage: 72%
71.92% (579/805) 61.22% (229/374) 67.18% (174/259)

@qltysh

qltysh Bot commented Sep 11, 2026

Copy link
Copy Markdown

Qlty


Coverage Impact

This PR will not change total coverage.

🚦 See full report on Qlty Cloud »

🛟 Help
  • Diff Coverage: Coverage for added or modified lines of code (excludes deleted files). Learn more.

  • Total Coverage: Coverage for the whole repository, calculated as the sum of all File Coverage. Learn more.

  • File Coverage: Covered Lines divided by Covered Lines plus Missed Lines. (Excludes non-executable lines including blank lines and comments.)

    • Indirect Changes: Changes to File Coverage for files that were not modified in this PR. Learn more.

@jferrao-itrbl

Copy link
Copy Markdown
Collaborator

This PR vs .github/workflows/changelog-check.yml

Changelog Check is failing.

What the code does
Diff does not touch CHANGELOG.md. The PR body has no “No customer facing changes”. Actions: Changelog Check runs 12 and 13 failed.

What the spec/rule says
PRs must update CHANGELOG.md or include that opt-out sentence (changelog-check.yml lines 19–42; PR template Changelog section).

Why it conflicts
The repo’s own release-hygiene check is red. Adjacent PR #893 (same kind of work) passed this check.

Suggested action Satisfy Changelog Check before merge.

Comment thread .github/workflows/publish-release.yml
Comment thread .github/workflows/prepare-release.yml Outdated
… grep

- Add ref: master/main to actions/checkout in all prepare/publish workflows
  so workflows always operate on the default branch regardless of dispatch ref
- Replace shell-injection-prone ${{ steps...outputs.notes }} pattern with
  --notes-file using $RUNNER_TEMP/release-notes.md (safe from backticks/quotes
  in changelog content)
- Treat empty [Unreleased] section as a hard error in prepare-release
- Fix CHANGELOG verification grep: grep -qE "^## \[VERSION\]" (anchored,
  prevents substring matches and prefix collisions like 3.1.0 vs 3.1.0-rc1)
Replace SDK_RELEASE_TOKEN (iOS) and GITHUB_TOKEN (all repos) with a
short-lived installation token from the iterable-sdk-release GitHub App,
generated via actions/create-github-app-token@v1.

Benefits:
- App token triggers CI on PRs it creates (GITHUB_TOKEN cannot)
- 1h TTL vs long-lived PAT
- Workflow-scoped permissions so we can push .github/workflows/ files

Required credentials (repo variable + secret, or set at org level):
  vars.ITERABLE_SDK_RELEASE_APP_ID
  secrets.ITERABLE_SDK_RELEASE_APP_PRIVATE_KEY
Comment thread .github/workflows/publish-release.yml Outdated
Comment thread .github/workflows/prepare-release.yml
Comment thread .github/workflows/publish-release.yml
Comment thread .github/workflows/publish-release.yml Outdated
Add docs_pr input for validate-release, verify version identity at master
HEAD before publish, validate publish version format, publish GitHub release
before npm with idempotent retries, and run format validation before checkout.
Restrict Prepare/Publish to X.Y.Z, validate docs_pr digits, refresh GitHub
release notes from CHANGELOG at publish, verify tag matches master HEAD on
retry, and align Node/Yarn/npm with repo CI pins.
Use git ls-remote for origin tag SHA so Publish retries work without
fetch-tags, validate Prepare inputs via job env, and point yarn release
and release_next_version.sh at the GitHub Actions workflows.
Read both peeled and direct refs/tags lines from origin so GitHub release
tags match master HEAD before npm publish.
@jferrao-itrbl
jferrao-itrbl self-requested a review October 6, 2026 13:47
@joaodordio joaodordio mentioned this pull request Oct 8, 2026
4 of 6 tasks

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants