diff --git a/.agents/skills/release/SKILL.md b/.agents/skills/release/SKILL.md index 5ed4555..e2c2360 100644 --- a/.agents/skills/release/SKILL.md +++ b/.agents/skills/release/SKILL.md @@ -54,8 +54,10 @@ candidate and present its version, changes, and check results for approval. - Confirm the candidate is on the intended release branch and the tag does not already exist locally or remotely. Never move an existing release tag or force-push to resolve a rejection. -- Push the candidate branch before tagging. Trigger `release.yml` on that - exact commit with `tg pipeline trigger`; inspect its logs and verdict. +- Push the candidate commit to `release/vx.y.z` before tagging; this triggers + both `checks.yml` and the full `release.yml` without depending on CLI appview + freshness. Manual reruns use `tg pipeline trigger HEAD --workflow release.yml`. + Inspect the logs and verdicts. Run `checks/release-ready`, which requires a clean checkout and the latest successful `checks.yml` and `release.yml` runs for HEAD on the repository's selected spindle. Missing, pending, cancelled, and failed CI block publication. diff --git a/.tangled/workflows/release.yml b/.tangled/workflows/release.yml index 577d314..13b7f67 100644 --- a/.tangled/workflows/release.yml +++ b/.tangled/workflows/release.yml @@ -1,4 +1,6 @@ when: + - event: ["push"] + branch: ["release/**"] - event: ["manual"] engine: nixery diff --git a/docs/verification.md b/docs/verification.md index 68b4e36..b50306a 100644 --- a/docs/verification.md +++ b/docs/verification.md @@ -100,15 +100,25 @@ claims. CI is a reproducibility check, not production capacity certification. ## Tangled and releases `checks.yml` runs on every branch push, pull requests targeting main, version -tags, and manual triggers. `release.yml` runs manually before tagging and uses -the full profile. Tool downloads are versioned and SHA256-checked. The SDK +tags, and manual triggers. `release.yml` runs on `release/**` branch pushes +or manually before tagging and uses the full profile. Tool downloads are +versioned and SHA256-checked. The SDK repository must select `spindle.zzstoatzz.io`; workflow files alone do not enable CI. See [Tangled's workflow documentation](https://docs.tangled.org/spindles). -Prepare and commit all version/changelog changes first, push the candidate -branch, and trigger `release.yml` for that exact commit using `tg pipeline -trigger` (see its installed `--help`). Inspect verdicts with `tg pipeline -status` and logs with `tg pipeline logs`. Then run: +Prepare and commit all version/changelog changes first, then push that commit +on a `release/` branch. Both required workflows start automatically. +For example, after preparing version 0.1.6: + +```sh +git push origin HEAD:refs/heads/release/v0.1.6 +``` + +Manual reruns use `tg pipeline trigger HEAD --workflow release.yml`. Inspect +verdicts with `tg pipeline status` and logs with `tg pipeline logs`. The CLI's +appview can lag the owner PDS; the release-branch push and readiness check do +not depend on that cache. Never interpret a missing CLI result as success. +Then run: ```sh checks/release-ready