Repository navigation
chore: new release processes - #899
joaodordio wants to merge 8 commits into
Conversation
Replaces the existing ad-hoc release workflows with a two-step process: - Prepare Release: bumps version, updates changelog, opens PR, creates GitHub draft release - Publish Release: promotes draft, tags main, publishes to npm, posts Slack Ref: SDK release process team agreement 2026-09-11
|
Coverage Impact This PR will not change total coverage. 🚦 See full report on Qlty Cloud »🛟 Help
|
|
This PR vs Changelog Check is failing. What the code does What the spec/rule says Why it conflicts Suggested action Satisfy Changelog Check before merge. |
… grep
- Add ref: master/main to actions/checkout in all prepare/publish workflows
so workflows always operate on the default branch regardless of dispatch ref
- Replace shell-injection-prone ${{ steps...outputs.notes }} pattern with
--notes-file using $RUNNER_TEMP/release-notes.md (safe from backticks/quotes
in changelog content)
- Treat empty [Unreleased] section as a hard error in prepare-release
- Fix CHANGELOG verification grep: grep -qE "^## \[VERSION\]" (anchored,
prevents substring matches and prefix collisions like 3.1.0 vs 3.1.0-rc1)
Replace SDK_RELEASE_TOKEN (iOS) and GITHUB_TOKEN (all repos) with a short-lived installation token from the iterable-sdk-release GitHub App, generated via actions/create-github-app-token@v1. Benefits: - App token triggers CI on PRs it creates (GITHUB_TOKEN cannot) - 1h TTL vs long-lived PAT - Workflow-scoped permissions so we can push .github/workflows/ files Required credentials (repo variable + secret, or set at org level): vars.ITERABLE_SDK_RELEASE_APP_ID secrets.ITERABLE_SDK_RELEASE_APP_PRIVATE_KEY
Add docs_pr input for validate-release, verify version identity at master HEAD before publish, validate publish version format, publish GitHub release before npm with idempotent retries, and run format validation before checkout.
Restrict Prepare/Publish to X.Y.Z, validate docs_pr digits, refresh GitHub release notes from CHANGELOG at publish, verify tag matches master HEAD on retry, and align Node/Yarn/npm with repo CI pins.
Use git ls-remote for origin tag SHA so Publish retries work without fetch-tags, validate Prepare inputs via job env, and point yarn release and release_next_version.sh at the GitHub Actions workflows.
Read both peeled and direct refs/tags lines from origin so GitHub release tags match master HEAD before npm publish.

Summary
Replaces the existing ad-hoc release workflows with a standardized two-step process.
No customer facing changes
Workflow 1: Prepare Release (
workflow_dispatch)Inputs:
version,ticket,docs_pr(iterable-docs PR number for Validate Release PR)masteronlypackage.json+ regeneratessrc/itblBuildInfo.tsviascripts/autoCreatePackageInfo.jsmaster) with checklist and docs PR linkWorkflow 2: Publish Release (
workflow_dispatch)Input:
versionmasteronlymasterHEAD matches the input (CHANGELOGtop header,package.json,itblBuildInfo.ts)masterat HEAD (skipped if already published)@iterable/react-native-sdk) via OIDC trusted publishing (skipped if version already on npm)#eng-sdk-teamon SlackFiles changed
.github/workflows/prepare-release.yml.github/workflows/publish-release.ymlSecrets to add
SLACK_WEBHOOKmust be configured in repo Settings > Secrets > Actions before the first Publish Release run.No customer facing changes