Publishes to Hex from a workflow on tag push - #42
Merged
Merged
Conversation
Adds .github/workflows/release.yml: on the push of a v*.*.* tag, and on nothing else, it checks that the tagged commit is on the default branch read from the push event, that the tag names the @Version in mix.exs there, and that Hex does not already show that version; then it runs the full gate on the toolchain ci.yml provisions (the steps copied from ci.yml) and publishes with mix hex.publish --yes, the HEX_API_KEY secret read by that one step only. A red gate or a failed check publishes nothing. CLAUDE.md's release-prep row, relay paragraph and Release preps paragraph, and .claude/wurk/release.md, now say an agent or a session never runs the publish: the workflow publishes on the tag push, and a failed workflow is re-run from its Actions page. Ruled by the operator, 2026-10-04. ADR-0003 records the decision at proposed. No lib/ change, no version bump, no changelog fragment (changelog.d/README.md excludes CI and ADR changes). The full gate ran green on this exact tree. Refs: sd-t8y
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this does
Adds a GitHub Actions workflow,
.github/workflows/release.yml, that publishes this package to Hex when a version tag is pushed, and only when three things hold at the tagged commit: it is on the default branch, the tag names the@versionthatmix.exsstates there, and the full quality gate is green there. The move to publishing on the tag push was ruled by the operator, 2026-10-04.pushof tags matchingv*.*.*, nothing else (no branch push, no pull request, noworkflow_dispatch).permissions: contents: read. One job,concurrencykeyed by the tag,cancel-in-progress: false.github.event.repository.default_branch, passed throughenv:, never a literal);git merge-base --is-ancestorof the tagged commit against it; the tag without itsvagainst@versioninmix.exs; and a check that stops the run when hex.pm already shows the version (reported, never published again; this also answers a re-run of a run that did publish).ci.yml(byte-identical to its block from the toolchain comment to the gate step's last line), so the gate isgate.fullfrom.claude/wurk.json, todaymix quality, run exactly as CI runs it. A red gate publishes nothing.mix hex.publish --yeswithHEX_API_KEY: ${{ secrets.HEX_API_KEY }}in that one step'senv:and nowhere else; the docs publish with the package (Hex's default). The last step prints the hex.pm and HexDocs addresses of the published version.CLAUDE.md(the release-prep row's publish clause, the relay paragraph's last clause, and the publish sentence of the "Release preps" paragraph, in the same edit) and the closing paragraph of.claude/wurk/release.mdnow say, in the maintainers' words: an agent or a session never runsmix hex.publish; the release workflow publishes on the tag push the release-prep row already allows; a failed workflow is re-run from its Actions page, never worked round by a local publish.ADR-0003 records the decision at proposed, with its index row in
docs/adr/README.md.No file under
lib/changes, no package behaviour changes, no version bump, no tag. No changelog fragment:changelog.d/README.mdexcludes "documentation, ADRs, or plans" and "quality gate, CI, or agent tooling changes".Provenance
mix.exsat the tagged commit, copy the toolchain fromci.ymlrather than share it, no manual trigger: decided by the conductor under a standing consent, 2026-10-03.docs/adr/README.mdasks new records for the typespecs and worked-example sections this family's records carry; this record decides no data shape and has neither, keeping the three sections (Context, Decision, Consequences).Checks
mix qualitygreen on this exact tree (format, compile with warnings as errors, credo, dependencies, 137 of 137 tests at 99.1% coverage, Docs with the new ADR as an ExDoc extra, doc links, dialyzer; doctor, gettext and sobelow skipped as not installed). The repo's carve-out for changes touching no Elixir code was not taken: the Docs stage buildsdocs/adr/0*.md.actionlintwas not run (not installed on the machine this was written on). The file was checked against GitHub's workflow-syntax reference, parses as YAML, and everyrun:script passesbash -n. The four check steps were run under bash, outside any runner, in a scratch clone atv0.5.0: fetch and ancestry passed, the version check passed, the Hex check stopped with "already on Hex"; a mismatched tag name stopped the version check; an extra commit offmainstopped the ancestry check. No step from the toolchain on, and no publish, has executed.Direction check of the record
Every claim in ADR-0003 was verified against the branch: the trigger, permissions and concurrency lines; the three condition steps and the Hex check by step name; the gate step reading
gate.fullfrom.claude/wurk.json; the publish step as the only reader ofHEX_API_KEY; the printed addresses; the authority-row and release-recipe wording inCLAUDE.mdand.claude/wurk/release.md; and the Docs stage building the record (mix.exsdocsextras). The record cites the workflow by step name, since that file exists only on this branch until merge.git diff origin/main -- docs/adr/shows zero removed lines (one record added, one index row added).