Skip to content

Add workflow to notify wrapper SDKs of native releases - #473

Open
ianrumac wants to merge 1 commit into
developfrom
ir/cool-thompson-kpjizz
Open

ianrumac wants to merge 1 commit into
developfrom
ir/cool-thompson-kpjizz

Conversation

@ianrumac

@ianrumac ianrumac commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator

Changes in this pull request

  • Added new GitHub Actions workflow notify-wrappers.yml that notifies cross-platform wrapper SDKs (Flutter, Expo, KMP) when a new native Android SDK release is published
  • Modified build+test+deploy.yml to:
    • Export version, released, and prerelease outputs from the build job
    • Call the new notify-wrappers.yml workflow after successful stable releases
  • The notification workflow dispatches native-sdk-release events to wrapper repositories, allowing them to automatically bump their pinned native SDK versions and open PRs

Implementation Details

The workflow handles the following scenarios:

  • Manual releases: Triggered by release: published event (only for stable versions)
  • Automated releases: Called directly via workflow_call from build+test+deploy.yml since GitHub doesn't fire release events for GITHUB_TOKEN-created releases
  • Manual dispatch: Supports manual triggering with a version input for testing
  • Prerelease filtering: Only notifies wrappers for stable x.y.z versions, skipping prerelease versions
  • Fault tolerance: Continues notifying other wrapper repos even if one dispatch fails

The workflow requires the WRAPPER_DISPATCH_TOKEN secret (fine-grained PAT or GitHub App token) with "Contents: read & write" permissions on wrapper repositories, since GITHUB_TOKEN cannot dispatch events to other repositories.

Checklist

  • All unit tests pass (no code changes to SDK logic)
  • All UI tests pass (no code changes to SDK logic)
  • Demo project builds and runs (no code changes to SDK logic)
  • I added/updated tests or detailed why my change isn't tested (workflow automation, no unit tests needed)
  • I added an entry to the CHANGELOG.md for any breaking changes, enhancements, or bug fixes (N/A - CI/CD infrastructure change)
  • I have run ktlint in the main directory and fixed any issues (N/A - YAML workflow files)
  • I have updated the SDK documentation as well as the online docs (N/A - CI/CD infrastructure change)
  • I have reviewed the contributing guide

https://claude.ai/code/session_015S6mZpaJyu9J5v7NPv2WCS

Adds notify-wrappers.yml, which sends a native-sdk-release
repository_dispatch ({platform, version}) to Superwall-Flutter,
expo-superwall and Superwall-KMP so they can open a bump PR.

build+test+deploy.yml calls it after creating the GitHub release: that
release is created with GITHUB_TOKEN, which never fires release events,
so the existing on-release trigger would not see it. Prereleases are
skipped. Needs the WRAPPER_DISPATCH_TOKEN secret.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015S6mZpaJyu9J5v7NPv2WCS

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ℹ️ No blocking issues — two small hardening suggestions inline.

Reviewed changes

Initial review of the CI wiring that announces stable Android releases to the Flutter, Expo, and KMP wrapper repos.

  • build job outputs — exposes version, released (GitHub release created in this run), and prerelease for downstream jobs.
  • notify_wrappers job — calls the new reusable workflow only when a stable release was just created, sidestepping the fact that GITHUB_TOKEN-created releases never fire release events.
  • notify-wrappers.yml — triggered by release: published, workflow_call, or workflow_dispatch; normalizes and validates the version as strict x.y.z, then sends a native-sdk-release repository_dispatch to each wrapper repo via WRAPPER_DISPATCH_TOKEN, continuing past per-repo failures.

The trigger logic checks out: inputs.version resolves for both workflow_call and workflow_dispatch, github.event_name inside a called workflow reflects the caller's push so the prerelease guard on L44 is a no-op there, gh api's client_payload[key]=value syntax produces the nested JSON body the dispatch API expects, and the contents: read downgrade is valid against the caller's contents: write. One rollout note: WRAPPER_DISPATCH_TOKEN has to exist before this merges, otherwise every release run on main will end red at the notify_wrappers job. Publishing itself is unaffected, since it is a separate job.

Pullfrog  | Fix all ➔ | Fix 👍s ➔ | View workflow run | Using claude-opus-5.5 | 𝕏

# `release` events for other workflows.
notify_wrappers:
needs: build
if: needs.build.outputs.released == 'true' && needs.build.outputs.prerelease == 'false'

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This if: has no status function, so GitHub implicitly adds success(). If anything after Create GitHub release fails (today that is slack-send), build goes red and the job is skipped. The next push then sees release-exists=true, so released is never true again for that version, and the wrappers are never notified unless someone runs it by hand. Using !cancelled() gates the job on the release itself rather than on the Slack ping.

Suggested change
if: needs.build.outputs.released == 'true' && needs.build.outputs.prerelease == 'false'
if: ${{ !cancelled() && needs.build.outputs.released == 'true' && needs.build.outputs.prerelease == 'false' }}

uses: ./.github/workflows/notify-wrappers.yml
with:
version: ${{ needs.build.outputs.version }}
secrets: inherit

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

secrets: inherit forwards every repo secret (AWS keys, Maven Central credentials, GPG signing key) into a job that only needs WRAPPER_DISPATCH_TOKEN. Passing just that one secret keeps the called workflow least-privilege. It also needs a matching secrets: WRAPPER_DISPATCH_TOKEN: { required: false } declaration under workflow_call in notify-wrappers.yml.

Suggested change
secrets: inherit
secrets:
WRAPPER_DISPATCH_TOKEN: ${{ secrets.WRAPPER_DISPATCH_TOKEN }}

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants