Skip to content

fix(release): configure Git identity for beta finalize - #246

Merged
kattsushi merged 1 commit into
masterfrom
fix/finalize-git-identity
Aug 28, 2026
Merged

kattsushi merged 1 commit into
masterfrom
fix/finalize-git-identity

Conversation

@kattsushi

@kattsushi kattsushi commented Aug 28, 2026 •

Copy link
Copy Markdown
Contributor

Closes #245

Type

  • Bug fix
  • New feature
  • Documentation only
  • Code refactoring
  • Maintenance/tooling
  • Breaking change

Summary

Configure the GitHub Actions bot Git identity for both project-bearing PREPARE and FINALIZE modes. FINALIZE creates annotated tags, so it must have a tagger identity before git tag -a runs.

Root cause

Authorized FINALIZE run 33205123705 reached the exact merged beta path but failed with exit code 128 before creating any public artifact. Git identity setup was gated to PREPARE only.

Changes

  • Rename the configuration step from PREPARE-specific to release-write-specific.
  • Run it when selected projects exist and mode is either prepare or finalize.
  • Add behavior and mutation contract coverage for PREPARE, FINALIZE, suppress, no-project, and FINALIZE-removal cases.

Test plan

  • RED: contract failed because FINALIZE/project identity evaluated false.
  • GREEN: release policy contract passes 19/19.
  • Mutation removing FINALIZE from the predicate fails closed.
  • YAML parses successfully.
  • Nx affected lint passes.
  • Direct Oxfmt check and git diff --check pass.
  • Exactly two files changed: 40 insertions, 2 deletions.

Safety

  • No workflow dispatch, tag, GitHub Release, or npm publication occurred while preparing this PR.
  • The failed FINALIZE run left zero public partial mutations.
  • A fresh FINALIZE attempt remains separately gated on merge, post-merge suppression, exact-state verification, and human authorization bound to the new master SHA.

Summary by CodeRabbit

  • Release Improvements

    • Git release configuration now runs consistently during both beta release preparation and finalization when projects are available.
    • Improved validation helps ensure release workflows apply the required Git identity configuration in each supported mode.
  • Bug Fixes

    • Fixed an issue where finalization could proceed without the expected Git release configuration.

@kattsushi kattsushi added the type:bug Bug fix label Aug 28, 2026
@coderabbitai

coderabbitai Bot commented Aug 28, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: fdf065b7-3edd-46ba-8e75-8d464abee3f9

📥 Commits

Reviewing files that changed from the base of the PR and between 039f67f and 83b8c0b.

📒 Files selected for processing (2)
  • .github/workflows/cd.yml
  • scripts/release-policy-contract.test.mjs

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The beta release workflow now configures Git identity during FINALIZE as well as PREPARE when projects are selected. Release-policy contract tests validate the required modes, project condition, and regression behavior.

Changes

Beta release Git identity

Layer / File(s) Summary
Configure Git identity for beta release
.github/workflows/cd.yml
The Git identity step now runs for prepare and finalize modes when projects are present.
Enforce the Git identity condition
scripts/release-policy-contract.test.mjs
The contract checks the Git identity commands, required condition, supported modes, and project-selection cases. Tests cover PREPARE, FINALIZE, suppress, and empty-project paths.

Estimated code review effort: 2 (Simple) | ~10 minutes

Merge Risk: ⚪ Minimal · up to 83b8c

This change enables Git attribution for eligible PREPARE and FINALIZE release runs while preserving existing project, authorization, SHA, and concurrency gates. No actionable merge-blocking risk remains beyond normal checks and review.

Poem

A rabbit checks the release gate,
Git names wait for tags to state.
PREPARE hops, FINALIZE too,
Empty projects skip the queue.
The contract guards each step in view.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the release workflow fix: configuring Git identity for beta FINALIZE.
Linked Issues check ✅ Passed The changes satisfy the coding objectives in [#245]. The workflow configures Git identity for PREPARE and FINALIZE runs with projects, while the contract and mutation tests cover suppression, empty pr…
Out of Scope Changes check ✅ Passed All changes support [#245]. The workflow adjustment and release-policy contract tests are directly related to configuring Git identity for beta FINALIZE and preventing regression.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 1…
Full details: Linked Issues check

Explanation

The changes satisfy the coding objectives in [#245]. The workflow configures Git identity for PREPARE and FINALIZE runs with projects, while the contract and mutation tests cover suppression, empty projects, and removal of FINALIZE from the predicate.

Full details: Docstring Coverage

Explanation

No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 1 files. (1 skipped: 1 unsupported.)

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/finalize-git-identity

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@kattsushi
kattsushi merged commit 4d65c7a into master Aug 28, 2026
7 checks passed
@kattsushi
kattsushi deleted the fix/finalize-git-identity branch August 28, 2026 21:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type:bug Bug fix

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(release): configure Git identity for beta finalize

1 participant