Validate release PR #795
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Validate release PR | |
| on: | |
| pull_request: | |
| types: [opened, reopened, synchronize, edited] | |
| merge_group: | |
| types: [checks_requested] | |
| permissions: | |
| contents: read | |
| jobs: | |
| validate: | |
| name: Validate release state transition | |
| # Only the new bot-authored minor-release path uses this validator. Existing manual | |
| # releases (including patch releases) keep their current checks; patch automation is | |
| # separate work. Keep this trigger broad: vdev owns branch-format and version validation. | |
| # Post-release housekeeping never opens a PR; it validates its own commit before | |
| # pushing to master, so this workflow only sees preparation PRs. | |
| # Release PRs must be directly squash-merged during the freeze, never queued. | |
| # Skipped merge-group runs emit the required check for ordinary queued PRs only. | |
| if: >- | |
| github.event_name == 'pull_request' && | |
| github.event.pull_request.user.login == 'vectordotdev-bot[bot]' && | |
| startsWith(github.head_ref, 'prepare') | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 15 | |
| steps: | |
| - name: Validate release target | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| with: | |
| script: | | |
| const pr = context.payload.pull_request; | |
| if (pr.base.ref !== 'master' || pr.head.repo.full_name !== context.repo.owner + '/' + context.repo.repo) { | |
| throw new Error('Automated minor release PRs must come from this repository and target master.'); | |
| } | |
| - name: Checkout trusted base | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| ref: ${{ github.event.pull_request.base.sha }} | |
| fetch-depth: 0 | |
| persist-credentials: false | |
| - name: Set up vdev | |
| uses: ./.github/actions/setup | |
| with: | |
| cargo-cache: true | |
| rust: true | |
| vdev: true | |
| # Install the base's pinned vdev before inspecting PR-controlled files. | |
| - name: Checkout PR head | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| ref: ${{ github.event.pull_request.head.sha }} | |
| fetch-depth: 0 | |
| persist-credentials: false | |
| - name: Validate files, base, and version | |
| env: | |
| BASE_SHA: ${{ github.event.pull_request.base.sha }} | |
| HEAD_REF: ${{ github.head_ref }} | |
| run: >- | |
| "$VDEV" release workflow pr-check | |
| --base-sha "$BASE_SHA" | |
| --head-ref "$HEAD_REF" |