diff --git a/.github/workflows/nix.yml b/.github/workflows/nix.yml index 68105cfd..a6f148fb 100644 --- a/.github/workflows/nix.yml +++ b/.github/workflows/nix.yml @@ -65,3 +65,25 @@ jobs: exit 1 fi grep -q 'tarball CHANGELOG.md differs' sabotage.log + + release-plan-evidence: + name: release plan phase through the dev shell (temporary evidence) + runs-on: ubuntu-latest + timeout-minutes: 60 + steps: + - uses: actions/checkout@v7 + with: + fetch-depth: 0 + fetch-tags: true + - uses: cachix/install-nix-action@v31 + - name: Pack the workspace through the caller's flake + run: echo "TARBALLS=$(nix build --no-link --print-out-paths .#workspace-tarballs)" >> "$GITHUB_ENV" + - id: plan + name: Decide release phase from repository state + env: + GITHUB_TOKEN: ${{ github.token }} + run: | + echo "host pnpm: $(command -v pnpm || echo absent)" + nix develop --command pnpm --version + nix develop --command github-release-management plan --tarballs "$TARBALLS" --output "$GITHUB_OUTPUT" + - run: echo "phase=${{ steps.plan.outputs.phase }} pending_intents=${{ steps.plan.outputs.pending_intents }}" diff --git a/flake.nix b/flake.nix index b458e5c7..91ddea14 100644 --- a/flake.nix +++ b/flake.nix @@ -71,9 +71,10 @@ assert clashes == [ ] || throw "flake.nix: workspace packages ${lib.concatStringsSep ", " clashes} collide with flake packages"; workspace // own); - # pnpm is deliberately absent: `packageManager` pins pnpm@11.27.0 and - # corepack is the one thing allowed to resolve it. A second pnpm on PATH - # would answer `pnpm install` with a version the lockfile never saw. + # pnpm_11 is the pnpm `workspaceOf` builds with, and mkPnpmWorkspacePackages + # fails evaluation unless `packageManager` pins that exact version, so the + # shell's pnpm is the pinned one. The reusable release workflow needs it: + # its workspace reader spawns `pnpm ls` and `pnpm config get`. devShells = forEachSystem (pkgs: { default = pkgs.mkShell { packages = [ @@ -83,6 +84,7 @@ pkgs.nodejs_24 pkgs.deno pkgs.process-compose + pkgs.pnpm_11 # version-management and github-release-management, which the # reusable release workflow runs through `nix develop --command` pnpm-release-management.packages.${pkgs.stdenv.hostPlatform.system}.release-tools