Skip to content

engineering: one cicd revision, vendored and called alike - #16

Merged
nicodes merged 1 commit into
mainfrom
chore/cicd-v0.2.0
Sep 29, 2026
Merged

nicodes merged 1 commit into
mainfrom
chore/cicd-v0.2.0

Conversation

@nicodes

@nicodes nicodes commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

This repository consumed nicodes/cicd twice, and the two disagreed:

  • helpers vendored into scripts/engineering (SOURCE.json.revision)
  • reusable workflows called with @<sha>

Neither half is wrong on its own, which is why it went unnoticed — "which revision of cicd is this product on" had no answer. Across the portfolio, products ran helper code from one revision while their backup and vulnerability workflows came from another; one pinned three at once.

Both halves now name cicd v0.2.0, and helpers/pins.mjs refuses a product where they differ (nicodes/cicd#64), so they can only move together from here.

Why the pin is still a commit

The workflow pins carry the version in a trailing comment, but the pin itself stays the 40-hex commit. A tag can be deleted and recreated; SOURCE.json records a commit, so a tag there could not be compared with it at all. The comment is what makes the SHA legible in review.

What v0.2.0 is

cicd's second release, and the first releases that repository has ever had. Its reusable workflows check cicd out again for helpers/, and GitHub resolves only the caller's ref — so until now a product that carefully pinned backup.yml by SHA still ran helpers from whatever commit was written inside it: 24 to 34 commits behind, at two different revisions. Cutting a release repins those mechanically, replacing the manual bump-along rule that had already failed once in production.

🤖 Generated with Claude Code


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@vercel

vercel Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
aviorstudio-web Ready Ready Preview Sep 29, 2026 12:33pm UTC

This repository consumed nicodes/cicd twice and the two disagreed: the
helpers under scripts/engineering came from one revision, and the reusable
workflows called with @<sha> came from another. Neither half is wrong on its
own, which is why it went unnoticed -- "which revision of cicd is this
product on" had no answer.

Both now name nicodes/cicd v0.2.1, and pins.mjs refuses a product where they
differ, so they can only move together from here.

The workflow pins carry the version in a trailing comment. The pin is still
the commit -- a tag can be deleted and recreated, and SOURCE.json records a
commit so a tag there could not be compared with it at all -- and the
comment is what makes the SHA legible in review.

v0.2.1 is also the first cicd release with its own helper checkouts pinned
consistently. Those reusable workflows check cicd out again for helpers/,
and GitHub resolves only the caller's ref; until now a product that pinned
backup.yml by SHA still ran helpers from whatever commit was written inside
it, 24 to 34 commits behind, at two different revisions.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@nicodes
nicodes merged commit f0a4e15 into main Sep 29, 2026
6 checks passed
@nicodes
nicodes deleted the chore/cicd-v0.2.0 branch September 29, 2026 12:54

This branch was successfully deployed

1 active deployment
Preview — 30443599 Deployed Sep 29, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant