Skip to content

feat(ci): Immutable release & Cosign - #2725

Merged
tangge233 merged 15 commits into
devfrom
feat/ci-immutable-release
Oct 4, 2026
Merged

tangge233 merged 15 commits into
devfrom
feat/ci-immutable-release

Conversation

@tangge233

@tangge233 tangge233 commented Apr 18, 2026 •

Copy link
Copy Markdown
Contributor

Support Immutable release and cosign.

Sourcery 摘要

围绕可配置的草稿版本发布,统一发布自动化流程,支持手动触发或由已合并的发布 PR 触发。

新功能:

  • 添加由合并触发的发布工作流,根据已合并的拉取请求标题确定发布版本和类型,并启动统一的发布工作流。
  • 支持手动配置发布,包括可选择的构建配置、版本、预发布状态以及草稿版本处理方式。

改进:

  • 将 beta 版和稳定版发布整合到一个工作流中,构建 x64 和 ARM64 两种构件,将其暂存到 GitHub 草稿版本中,并在上传完成后发布该草稿版本。
  • 根据所选发布配置,通过统一的发布流程处理 MirrorChyan 上传和发布说明。

CI:

  • 使用统一的 release-publish 和 release-trigger 工作流,替代独立的 beta 版和稳定版发布工作流。

杂项:

  • 更新可复用的构建工作流,以使用更新版本的 checkout action。
Original summary in English

Sourcery 总结

围绕可配置且不可变的草稿版本,统一发布自动化流程;发布可由手动操作或合并后的发布拉取请求触发。

新功能:

  • 添加发布触发器,可根据已合并的发布拉取请求标题推导版本和预发布状态。
  • 添加统一的手动调度发布工作流,可配置构建类型、版本和预发布状态。

增强功能:

  • 将 Beta 和稳定版发布整合到一个工作流中,通过分阶段的 GitHub 草稿发布流程构建、签名并发布 x64 和 ARM64 构建产物。
  • 根据所选发布配置,通过统一的发布流程处理 MirrorChyan 上传和发布说明。
  • 将与发布相关的操作固定到特定版本,并移除过时的发布变更日志键信息。

构建:

  • 将可复用构建工作流中的 checkout、.NET 设置和构建产物上传操作更新到较新的固定版本。

CI:

  • 使用统一的 release-publish 和 release-trigger 工作流替代独立的 Beta 和稳定版发布工作流。
Original summary in English

Sourcery 摘要

将 beta 和 stable 发布统一到可配置、不可变的 GitHub 发布流水线中,并支持自动触发和 Cosign 签名。

新功能:

  • 添加统一的、可手动配置的发布工作流,用于构建、签名和发布 x64 与 ARM64 构件。
  • 根据 PR 标题中解析出的版本和发布类型,在 PR 合并后自动触发发布。

增强功能:

  • 将 beta 和 stable 发布整合到分阶段的不可变草稿发布流程中,支持生成变更日志、签名构件以及上传后的发布。
  • 根据所选构建配置,通过统一的发布流程处理 MirrorChyan 上传和发布说明。
  • 将发布和构建操作固定到特定版本,以实现可复现的 CI 执行。

构建:

  • 更新可复用构建工作流中的 checkout、.NET 设置和构件上传操作。

CI:

  • 使用统一的 release-publish 和 release-trigger 工作流替代单独的 beta 与 stable 发布工作流。

杂项:

  • 从生成的发布说明中移除已过时的 GPG 公钥部分。
Original summary in English

Sourcery 摘要

通过可配置的不可变草稿、自动触发合并 PR 以及使用 Cosign 签名的多架构构建产物,统一发布自动化流程。

新功能:

  • 添加统一的发布工作流,用于构建 x64 和 ARM64 构建产物、创建 GitHub 草稿发布、使用 Cosign 对二进制文件进行签名,并在上传完成后发布版本。
  • 根据标准化的 PR 标题推导版本和预发布状态,在拉取请求合并后自动触发发布。

增强功能:

  • 在单一可配置流水线中统一 beta 和 stable 发布流程,包括按架构上传构建产物以及 MirrorChyan 集成。
  • 将发布和构建操作固定到特定版本,以实现更具可重复性的 CI 执行。
  • 从生成的发布说明中移除已过时的 GPG 公钥部分。

构建:

  • 将可复用的构建工作流更新为更新版本的 checkout、.NET setup 和 artifact upload 操作,并固定其版本。

CI:

  • 使用统一的 release-publish 和 release-trigger 工作流,替代独立的 beta 和 stable 发布工作流。
Original summary in English

Sourcery 摘要

将 Beta 版和稳定版发布流程统一为可配置的、由 Cosign 签名的多架构 GitHub 发布流水线,支持草稿发布和自动触发已合并 PR。

新功能:

  • 添加统一的发布工作流,用于构建 x64 和 ARM64 制品、创建不可变的 GitHub 发布草稿、使用 Cosign 为二进制文件签名,并在上传完成后发布版本。
  • 通过解析已合并拉取请求标题中的发布类型和语义化版本,自动触发发布。

增强功能:

  • 将 Beta 版和稳定版的发布处理合并到单一的可配置流水线中,包括特定架构的 MirrorChyan 上传和发布说明。
  • 将发布、构建和 MirrorChyan 操作固定到特定版本,以提高 CI 运行的可复现性。
  • 从生成的发布说明中移除过时的 GPG 公钥信息。

构建:

  • 将可复用构建工作流更新为较新的、已固定版本的 checkout、.NET 设置和制品上传操作。

CI:

  • 使用统一的 release-publish 和 release-trigger 工作流替代独立的 Beta 版和稳定版发布工作流。
Original summary in English

Sourcery 摘要

将 Beta 版和稳定版发布流程统一为可配置的、由 Cosign 签名的多架构 GitHub 发布流水线,支持草稿发布以及自动响应已合并 PR 的触发机制。

新功能:

  • 添加统一且可手动配置的发布工作流,用于构建 x64 和 ARM64 架构的产物、创建 GitHub 草稿发布版本、使用 Cosign 对二进制文件进行签名,并在上传完成后发布版本。
  • 通过从标准化 PR 标题中提取版本和预发布状态,自动根据已合并的拉取请求触发发布。

增强:

  • 将 Beta 版和稳定版的发布处理整合到单一流水线中,包括针对不同架构的 MirrorChyan 上传和发布说明。
  • 将发布、构建和 MirrorChyan 操作固定到特定版本,以实现更可复现的 CI 执行。
  • 从生成的发布说明中移除过时的 GPG 公钥信息。

构建:

  • 将可复用构建工作流更新为固定版本的 checkout、.NET setup 和 artifact upload 操作。

CI:

  • 使用统一的 release-publish 和 release-trigger 工作流替代独立的 Beta 版和稳定版发布工作流。
Original summary in English

Summary by Sourcery

Unify beta and stable releases into a configurable, Cosign-signed multi-architecture GitHub release pipeline with draft publishing and automatic merged-PR triggers.

New Features:

  • Add a unified, manually configurable release workflow that builds x64 and ARM64 artifacts, creates a draft GitHub release, signs binaries with Cosign, and publishes the release after uploads complete.
  • Automatically trigger releases from merged pull requests by deriving the version and prerelease status from standardized PR titles.

Enhancements:

  • Consolidate beta and stable release handling into a single pipeline, including architecture-specific MirrorChyan uploads and release notes.
  • Pin release, build, and MirrorChyan actions to specific versions for more reproducible CI execution.
  • Remove outdated GPG public-key information from generated release notes.

Build:

  • Update the reusable build workflow to pinned versions of the checkout, .NET setup, and artifact upload actions.

CI:

  • Replace the separate beta and stable release workflows with unified release-publish and release-trigger workflows.

新功能:

  • 新增一个发布触发工作流,用于解析已合并 PR 的标题以推导版本号和发布类型,然后携带合适的参数触发发布(publish)工作流。
  • 通过 workflow dispatch 输入支持可配置的发布构建,包括配置项、版本号和预发布(prerelease)标记,并支持创建草稿版本以及后续的正式发布。

增强:

  • 将 beta 和 stable 发布整合为单一的发布工作流,将构建产物上传到 GitHub 草稿版本,并同时处理两种架构。
  • 更新 GitHub Release 步骤,使用最新的 softprops/action-gh-release 动作,并将发布管理为草稿,待最终发布。
  • 将 MirrorChyan 上传和发布说明(release-note)工作流通过新的统一发布和草稿发布步骤进行路由,发布渠道由构建配置决定。

CI:

  • 使用统一的 release-publish 工作流加上基于 PR 合并的 release-trigger 工作流,替换之前的 beta 和 stable 发布工作流。
Original summary in English

@pcl-ce-automation pcl-ce-automation Bot added 🛠️ 等待审查 Pull Request 已完善,等待维护者或负责人进行代码审查 size: L PR 大小评估:大型 labels Apr 18, 2026
@sourcery-ai

sourcery-ai Bot commented Apr 18, 2026 •

Copy link
Copy Markdown
Contributor

审查者指南

此 PR 将 beta 和 stable 发布流程整合为一个可手动配置且可自动触发的发布流水线。该流水线会构建 x64 和 ARM64 构件,将其暂存于不可变的 GitHub 草稿发布中,使用 Cosign 对其签名,发布该版本,并调用 MirrorChyan 集成,同时固定 CI actions 版本以确保可复现性。

不可变发布流水线的时序图

sequenceDiagram
    actor Maintainer
    participant PR as Merged release PR
    participant Trigger as release-trigger.yml
    participant Publish as release-publish.yml
    participant Build as reusable-build.yml
    participant GitHub as GitHub Release
    participant Cosign as sigstore action
    participant Mirror as MirrorChyan workflows

    PR->>Trigger: pull_request closed
    Trigger->>Trigger: Extract version from PR title
    Trigger->>Publish: gh workflow run release-publish.yml
    par Build x64
        Publish->>Build: reusable build configuration and x64
        Build-->>Publish: Build artifact
    and Build ARM64
        Publish->>Build: reusable build configuration and ARM64
        Build-->>Publish: Build artifact
    end
    Publish->>GitHub: Create or update draft release
    par Sign and upload x64
        Publish->>Cosign: sigstore action
        Cosign-->>Publish: Signed x64 binary
        Publish->>GitHub: Upload binary and signature
    and Sign and upload ARM64
        Publish->>Cosign: sigstore action
        Cosign-->>Publish: Signed ARM64 binary
        Publish->>GitHub: Upload binary and signature
    end
    Publish->>GitHub: Publish Draft
    Publish->>Mirror: gh workflow run mirrorchyan_uploading.yml
    Publish->>Mirror: gh workflow run mirrorchyan_release_note.yml
Loading

可配置发布调度的流程图

flowchart TD
    A[workflow_dispatch configuration version prerelease] --> B[Build x64 and ARM64]
    B --> C[Create draft GitHub release]
    C --> D[Rename binaries]
    D --> E[Sign binaries with Cosign]
    E --> F[Upload binaries and sigstore files]
    F --> G[Publish draft release]
    G --> H[Trigger MirrorChyan uploading]
    G --> I[Trigger MirrorChyan release note]
Loading

文件级变更

变更 详情 文件
将 beta 和 stable 发布统一为可配置的分阶段发布流水线,为两种架构构建、签名、上传并发布不可变的 GitHub 发布资产。
  • 添加了用于构建配置、版本和预发布状态的手动输入项。
  • 通过可复用的构建工作流构建 x64 和 ARM64 构件。
  • 创建或更新草稿发布,重命名构件,使用 OIDC 验证生成 Cosign 签名,上传二进制文件和签名包,然后发布草稿。
  • 发布完成后,触发特定架构的 MirrorChyan 上传和发布说明生成。
.github/workflows/release-publish.yml
cliff.toml
添加了从已合并的发布 pull request 自动触发发布的功能。
  • 添加了对 stable/beta PR 标题和 SemVer 版本的解析。
  • 在调度统一发布工作流之前,将发布类型映射为配置和预发布输入项。
.github/workflows/release-trigger.yml
使用统一发布流程替代原先分离的 beta 和 stable 工作流。
  • 移除了旧版 beta 发布工作流。
  • 移除了旧版 stable 发布工作流。
.github/workflows/release-beta_publish.yml
.github/workflows/release-stable_publish.yml
固定并更新 CI actions,以确保发布和构建执行的可复现性。
  • 将 MirrorChyan、checkout、.NET setup、artifact upload、download、release 和 Sigstore actions 固定到特定提交版本。
  • 更新可复用构建工作流以使用固定版本的 actions。
.github/workflows/mirrorchyan_release_note.yml
.github/workflows/mirrorchyan_uploading.yml
.github/workflows/reusable-build.yml
.github/workflows/release-publish.yml

提示和命令

与 Sourcery 交互

  • 触发新的审查: 在 pull request 中评论 @sourcery-ai review。
  • 继续讨论: 直接回复 Sourcery 的审查评论。
  • 根据审查评论生成 GitHub issue: 回复审查评论,请 Sourcery 根据该评论创建 issue。你也可以回复审查评论并使用 @sourcery-ai issue,根据该评论创建 issue。
  • 生成 pull request 标题: 在 pull request 标题的任意位置输入 @sourcery-ai,即可随时生成标题。你也可以在 pull request 中评论 @sourcery-ai title,以随时生成或重新生成标题。
  • 生成 pull request 摘要: 在 pull request 正文中任意位置输入 @sourcery-ai summary,即可在指定位置随时生成 PR 摘要。你也可以在 pull request 中评论 @sourcery-ai summary,以随时生成或重新生成摘要。
  • 生成审查者指南: 在 pull request 中评论 @sourcery-ai guide,即可随时生成或重新生成审查者指南。
  • 解决所有 Sourcery 评论: 在 pull request 中评论 @sourcery-ai resolve,即可解决所有 Sourcery 评论。如果你已经处理完所有评论且不想再看到它们,此功能非常有用。
  • 忽略所有 Sourcery 审查: 在 pull request 中评论 @sourcery-ai dismiss,即可忽略所有现有的 Sourcery 审查。如果你想从全新的审查开始,这项功能尤其有用——别忘了评论 @sourcery-ai review 来触发新的审查!

自定义你的使用体验

访问你的控制面板来:

  • 启用或禁用审查功能,例如 Sourcery 生成的 pull request 摘要、审查者指南等。
  • 更改审查语言。
  • 添加、移除或编辑自定义审查指令。
  • 调整其他审查设置。

获取帮助

Original review guide in English

Reviewer's Guide

This PR consolidates beta and stable publishing into a manually configurable and automatically triggerable release pipeline that builds x64 and ARM64 artifacts, stages them in an immutable draft GitHub release, signs them with Cosign, publishes the release, and invokes MirrorChyan integrations, while pinning CI actions for reproducibility.

Sequence diagram for the immutable release pipeline

sequenceDiagram
    actor Maintainer
    participant PR as Merged release PR
    participant Trigger as release-trigger.yml
    participant Publish as release-publish.yml
    participant Build as reusable-build.yml
    participant GitHub as GitHub Release
    participant Cosign as sigstore action
    participant Mirror as MirrorChyan workflows

    PR->>Trigger: pull_request closed
    Trigger->>Trigger: Extract version from PR title
    Trigger->>Publish: gh workflow run release-publish.yml
    par Build x64
        Publish->>Build: reusable build configuration and x64
        Build-->>Publish: Build artifact
    and Build ARM64
        Publish->>Build: reusable build configuration and ARM64
        Build-->>Publish: Build artifact
    end
    Publish->>GitHub: Create or update draft release
    par Sign and upload x64
        Publish->>Cosign: sigstore action
        Cosign-->>Publish: Signed x64 binary
        Publish->>GitHub: Upload binary and signature
    and Sign and upload ARM64
        Publish->>Cosign: sigstore action
        Cosign-->>Publish: Signed ARM64 binary
        Publish->>GitHub: Upload binary and signature
    end
    Publish->>GitHub: Publish Draft
    Publish->>Mirror: gh workflow run mirrorchyan_uploading.yml
    Publish->>Mirror: gh workflow run mirrorchyan_release_note.yml
Loading

Flow diagram for configurable release dispatch

flowchart TD
    A[workflow_dispatch configuration version prerelease] --> B[Build x64 and ARM64]
    B --> C[Create draft GitHub release]
    C --> D[Rename binaries]
    D --> E[Sign binaries with Cosign]
    E --> F[Upload binaries and sigstore files]
    F --> G[Publish draft release]
    G --> H[Trigger MirrorChyan uploading]
    G --> I[Trigger MirrorChyan release note]
Loading

File-Level Changes

Change Details Files
Unified beta and stable publishing into a configurable, staged release pipeline that builds, signs, uploads, and publishes immutable GitHub release assets for both architectures.
  • Added manual inputs for build configuration, version, and prerelease status.
  • Built x64 and ARM64 artifacts through the reusable build workflow.
  • Created or updated a draft release, renamed artifacts, generated Cosign signatures with OIDC verification, uploaded binaries and signature bundles, then published the draft.
  • Triggered architecture-specific MirrorChyan uploads and release-note generation after publication.
.github/workflows/release-publish.yml
cliff.toml
Added automatic release triggering from merged release pull requests.
  • Added parsing for stable/beta PR titles and SemVer versions.
  • Mapped release type to configuration and prerelease inputs before dispatching the unified publish workflow.
.github/workflows/release-trigger.yml
Replaced separate beta and stable workflows with the unified release flow.
  • Removed the legacy beta publishing workflow.
  • Removed the legacy stable publishing workflow.
.github/workflows/release-beta_publish.yml
.github/workflows/release-stable_publish.yml
Pinned and updated CI actions for reproducible release and build execution.
  • Pinned MirrorChyan, checkout, .NET setup, artifact upload, download, release, and Sigstore actions to commit revisions.
  • Updated the reusable build workflow to use the pinned action versions.
.github/workflows/mirrorchyan_release_note.yml
.github/workflows/mirrorchyan_uploading.yml
.github/workflows/reusable-build.yml
.github/workflows/release-publish.yml

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - 我发现了 1 个问题,并给出了一些整体性的反馈:

  • 在 rename_and_release 这个 job 中,shell 赋值语句 MRC_CHANNEL = "stable" 因为在 = 两侧有空格而无效,会导致语法错误;应该写成 MRC_CHANNEL="stable"(其他类似的赋值语句也需要相应修改)。
  • 新增的 release-trigger.yml workflow 中调用了 gh workflow run,但该 workflow 的 permissions 目前只授予了 contents: read;你很可能需要再添加 actions: write(如果需要的话,可能还要加 contents: write),这样 gh 命令才能成功触发另一个 workflow。
给 AI Agent 的提示
请根据以下代码评审意见进行修改:

## 整体评论
- 在 `rename_and_release` 这个 job 中,shell 赋值语句 `MRC_CHANNEL = "stable"` 因为在 `=` 两侧有空格而无效,会导致语法错误;应该写成 `MRC_CHANNEL="stable"`(其他类似的赋值语句也需要相应修改)。
- 新增的 `release-trigger.yml` workflow 中调用了 `gh workflow run`,但该 workflow 的 `permissions` 目前只授予了 `contents: read`;你很可能需要再添加 `actions: write`(如果需要的话,可能还要加 `contents: write`),这样 `gh` 命令才能成功触发另一个 workflow。

## 单独评论

### 评论 1
<location path=".github/workflows/release-trigger.yml" line_range="3-12" />
<code_context>
-name: Publish (Beta)
+name: Release Beta (Actual)

 permissions:
-  contents: read
+  contents: write
</code_context>
<issue_to_address>
**issue (bug_risk):** 为了让 `gh workflow run` 成功执行,workflow 使用的 token 很可能需要 `actions: write` 权限。

这个 workflow 目前只设置了 `contents: write`,但 `gh workflow run` 需要 `GITHUB_TOKEN` 具备 `actions: write`(在某些配置下还需要 `workflow`)权限。请更新 `permissions` 配置块,至少包含:

```yaml
permissions:
  contents: write
  actions: write
```

否则 `gh workflow run` 调用很可能会因为权限不足而失败。
</issue_to_address>

Sourcery 对开源项目是免费的——如果你觉得我们的评审有帮助,请考虑分享 ✨
帮我变得更有用!请在每条评论上点击 👍 或 👎,我会根据你的反馈改进后续的评审。
Original comment in English

Hey - I've found 1 issue, and left some high level feedback:

  • In the rename_and_release job, the shell assignment MRC_CHANNEL = "stable" is invalid due to the spaces around =, which will cause a syntax error; it should be MRC_CHANNEL="stable" (and similarly for any other assignments).
  • The new release-trigger.yml workflow calls gh workflow run, but the workflow’s permissions only grant contents: read; you likely need to add actions: write (and possibly contents: write if required) so the gh command can successfully trigger the other workflow.
Prompt for AI Agents
Please address the comments from this code review:

## Overall Comments
- In the `rename_and_release` job, the shell assignment `MRC_CHANNEL = "stable"` is invalid due to the spaces around `=`, which will cause a syntax error; it should be `MRC_CHANNEL="stable"` (and similarly for any other assignments).
- The new `release-trigger.yml` workflow calls `gh workflow run`, but the workflow’s `permissions` only grant `contents: read`; you likely need to add `actions: write` (and possibly `contents: write` if required) so the `gh` command can successfully trigger the other workflow.

## Individual Comments

### Comment 1
<location path=".github/workflows/release-trigger.yml" line_range="3-12" />
<code_context>
-name: Publish (Beta)
+name: Release Beta (Actual)

 permissions:
-  contents: read
+  contents: write
</code_context>
<issue_to_address>
**issue (bug_risk):** The workflow token likely needs `actions: write` permission for `gh workflow run` to succeed.

This workflow currently only sets `contents: write`, but `gh workflow run` needs `actions: write` on `GITHUB_TOKEN` (and in some setups also `workflow`). Please update the permissions block to include at least:

```yaml
permissions:
  contents: write
  actions: write
```

Otherwise the `gh workflow run` call is likely to fail with insufficient permissions.
</issue_to_address>

Sourcery is free for open source - if you like our reviews please consider sharing them ✨
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.

Comment thread .github/workflows/release-trigger.yml
ruattd
ruattd previously approved these changes Apr 19, 2026
MoYuan-CN
MoYuan-CN previously approved these changes Apr 19, 2026
@pcl-ce-automation pcl-ce-automation Bot added 🕑 等待合并 已处理完毕,正在等待代码合并入主分支 and removed 🛠️ 等待审查 Pull Request 已完善,等待维护者或负责人进行代码审查 labels Apr 19, 2026
RyogiMutsuki
RyogiMutsuki previously approved these changes Apr 19, 2026
pynickle
pynickle previously approved these changes Apr 19, 2026
@tangge233
tangge233 dismissed stale reviews from pynickle, RyogiMutsuki, MoYuan-CN, and ruattd via 2eb6785 April 20, 2026 13:37
Add project_file and artifact_name_suffix inputs to the reusable
workflow, allowing the build matrix to compile both .csproj and .vbproj
targets. Artifact names now include a suffix to distinguish between
language variants.
@pcl-ce-automation pcl-ce-automation Bot added 🛠️ 等待审查 Pull Request 已完善,等待维护者或负责人进行代码审查 and removed 🕑 等待合并 已处理完毕,正在等待代码合并入主分支 labels Apr 28, 2026
@SALTWOOD

Copy link
Copy Markdown
Member

女娲,推错仓库了(

SALTWOOD
SALTWOOD previously approved these changes Apr 28, 2026

@tangge233 tangge233 left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@SALTWOOD 修改不完全,这样 MRC 那边文件名匹配会有问题

@SALTWOOD

Copy link
Copy Markdown
Member

@SALTWOOD 修改不完全,这样 MRC 那边文件名匹配会有问题

已 revert(

Comment thread .github/workflows/release-publish.yml Outdated
Comment thread .github/workflows/release-publish.yml Outdated
@MoYuan-CN
MoYuan-CN dismissed their stale review April 30, 2026 11:40

Resolved. As I don't have time to review the rest of this PR, I'm dismissing my self-review to keep the process better organized, rather than submitting an approval.

@Pigeon0v0

Copy link
Copy Markdown
Contributor

这个好了咩

@tangge233 tangge233 changed the title feat(ci): Immutable release feat(ci): Immutable release & Cosign Oct 4, 2026
@tangge233

Copy link
Copy Markdown
Contributor Author

@sourcery-ai review

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

嘿——我发现了 1 个问题

面向 AI 代理的提示
请处理本次代码审查中的评论:

## 单独评论

### 评论 1
<location path=".github/workflows/release-publish.yml" line_range="43" />
<code_context>
-    permissions:
-      contents: write
-    runs-on: ubuntu-latest
-    continue-on-error: true
-    if: ${{ github.event.release.prerelease }}
-    steps:
</code_context>
<issue_to_address>
**issue (bug_risk):** checkout、git-cliff 安装、变更日志生成或草稿发布创建过程中的失败会在作业级别被忽略,而下游发布作业仍可继续执行。随后,制品上传作业可能会在没有生成变更日志的情况下创建或发布版本,从而掩盖发布准备步骤失败的问题。

**触发条件:** 任何变更日志准备步骤失败时。

**建议修复:** 移除作业级别的 `continue-on-error`,仅对预期的可选变更日志失败进行明确处理;或者要求下游作业必须依赖一个成功完成的变更日志作业。

```suggestion

```
</issue_to_address>

Sourcery 对开源项目免费——如果您喜欢我们的审查,请考虑分享 ✨
Original comment in English

Hey - I've found 1 issue

Prompt for AI Agents
Please address the comments from this code review:

## Individual Comments

### Comment 1
<location path=".github/workflows/release-publish.yml" line_range="43" />
<code_context>
-    permissions:
-      contents: write
-    runs-on: ubuntu-latest
-    continue-on-error: true
-    if: ${{ github.event.release.prerelease }}
-    steps:
</code_context>
<issue_to_address>
**issue (bug_risk):** A failure in checkout, git-cliff installation, changelog generation, or draft-release creation is ignored at the job level, while the downstream release jobs can continue. The artifact-upload jobs can then create or publish a release without the generated changelog, hiding a failed release-preparation step.

**Triggers:** When any changelog-preparation step fails.

**Suggested fix:** Remove job-level `continue-on-error` and handle only the intended optional changelog failure explicitly, or make downstream jobs require a successful changelog job.

```suggestion

```
</issue_to_address>

Sourcery is free for open source - if you like our reviews please consider sharing them ✨

Comment thread .github/workflows/release-publish.yml Outdated
whitecat346
whitecat346 previously approved these changes Oct 4, 2026
Co-authored-by: sourcery-ai[bot] <58596630+sourcery-ai[bot]@users.noreply.github.com>
@tangge233
tangge233 merged commit 9756cb2 into dev Oct 4, 2026
3 checks passed
@pcl-ce-automation pcl-ce-automation Bot added 👌 完成 相关问题已修复或功能已实现,计划在下次版本更新时正式上线 and removed 🛠️ 等待审查 Pull Request 已完善,等待维护者或负责人进行代码审查 labels Oct 4, 2026
@tangge233
tangge233 deleted the feat/ci-immutable-release branch October 4, 2026 14:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size: L PR 大小评估:大型 👌 完成 相关问题已修复或功能已实现,计划在下次版本更新时正式上线

Projects

None yet

Development

Successfully merging this pull request may close these issues.

9 participants