Skip to content

V10.8.0/post ci refinement - #174

Merged
gimlichael merged 4 commits into
mainfrom
v10.8.0/post-ci-refinement
Oct 4, 2026
Merged

gimlichael merged 4 commits into
mainfrom
v10.8.0/post-ci-refinement

Conversation

@gimlichael

Copy link
Copy Markdown
Member

This pull request introduces a shared verification workflow so PR and release flows use one verification definition. PRs delegate proof to the shared workflow while release keeps authoritative build and pack products caller-owned and replays the same proof on canonical main.

Shared verification:

  • Single reusable definition covers build, pack, Linux and Windows tests, optional macOS tests, SQL Server integration, SonarCloud, Codecov, CodeQL and quality gates with fork and input aware privilege handling.
  • PRs delegate to the shared proof with preserved aggregate required check and optional macOS matrix.
  • Verification packages use separate artifact names so they do not mix with authoritative release products.

Release products:

  • Release builds, packs and validates authoritative NuGet products first with package version checked against the release tag.
  • Post release assurance reuses the shared proof on the exact released SHA with canonical main reporting and optional macOS replay.
  • Release summary and recovery messaging now report product results plus one shared verification outcome.

Consolidate duplicated build, test and analysis jobs into a reusable verify workflow so PR and release flows share one verification definition while keeping authoritative release products caller-owned.
@gimlichael gimlichael self-assigned this Oct 4, 2026
Add a concurrency group keyed by pull request so new pushes cancel outdated PR verification runs and save CI capacity.
@greptile-apps

greptile-apps Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[Critical risk] Restructures build and release CI pipelines.

The PR appears safe to merge based on the reviewed changes.

Summary

The PR moves PR and post-release checks into a shared verification workflow while keeping authoritative package build, validation, and publication in the release workflow.

  • The latest changes let post-release verification proceed after NuGet publication even if OCI finalization fails.
  • Canonical-main assurance now checks SonarCloud, Codecov, and CodeQL records for the released SHA.

Diagram

%%{init: {'theme': 'neutral'}}%%
flowchart LR
  A[PR] --> V[Shared verification]
  R[Release tag] --> B[Build and validate products]
  B --> N[Publish NuGet]
  N --> V
  N --> O[Finalize OCI assets]
  V --> S[Release status]
  O --> S
Loading

Reviews (2) · Last reviewed commit: "🐛 verify published packages independent..."

Comment thread .github/workflows/verify.yml
Comment thread .github/workflows/release.yml Outdated
@codecov

codecov Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 93.77%. Comparing base (33e6e75) to head (6eec298).
⚠️ Report is 1 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff             @@
##             main     #174      +/-   ##
==========================================
+ Coverage   90.06%   93.77%   +3.70%     
==========================================
  Files         606      608       +2     
  Lines       12884    19273    +6389     
  Branches     1819     1865      +46     
==========================================
+ Hits        11604    18073    +6469     
- Misses        781     1172     +391     
+ Partials      499       28     -471     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

aicia-bot and others added 2 commits October 4, 2026 21:30
Successful uploads do not prove that quality services recorded the released SHA on main. Require matching processed service records before release or replay assurance can pass.

Generated with Codebuff 🤖
Co-Authored-By: Codebuff <noreply@codebuff.com>
Published NuGet packages require automatic verification even when DocFX finalization fails. Start canonical-main assurance at the successful publication boundary rather than waiting for OCI attachment.

Generated with Codebuff 🤖
Co-Authored-By: Codebuff <noreply@codebuff.com>
@gimlichael
gimlichael merged commit 8540218 into main Oct 4, 2026
641 of 645 checks passed
@gimlichael
gimlichael deleted the v10.8.0/post-ci-refinement branch October 4, 2026 21:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants