Conversation
Adds notify-wrappers.yml, which sends a native-sdk-release
repository_dispatch ({platform, version}) to Superwall-Flutter,
expo-superwall and Superwall-KMP so they can open a bump PR.
build+test+deploy.yml calls it after creating the GitHub release: that
release is created with GITHUB_TOKEN, which never fires release events,
so the existing on-release trigger would not see it. Prereleases are
skipped. Needs the WRAPPER_DISPATCH_TOKEN secret.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015S6mZpaJyu9J5v7NPv2WCS
There was a problem hiding this comment.
ℹ️ No blocking issues — two small hardening suggestions inline.
Reviewed changes
Initial review of the CI wiring that announces stable Android releases to the Flutter, Expo, and KMP wrapper repos.
buildjob outputs — exposesversion,released(GitHub release created in this run), andprereleasefor downstream jobs.notify_wrappersjob — calls the new reusable workflow only when a stable release was just created, sidestepping the fact thatGITHUB_TOKEN-created releases never firereleaseevents.notify-wrappers.yml— triggered byrelease: published,workflow_call, orworkflow_dispatch; normalizes and validates the version as strictx.y.z, then sends anative-sdk-releaserepository_dispatchto each wrapper repo viaWRAPPER_DISPATCH_TOKEN, continuing past per-repo failures.
The trigger logic checks out: inputs.version resolves for both workflow_call and workflow_dispatch, github.event_name inside a called workflow reflects the caller's push so the prerelease guard on L44 is a no-op there, gh api's client_payload[key]=value syntax produces the nested JSON body the dispatch API expects, and the contents: read downgrade is valid against the caller's contents: write. One rollout note: WRAPPER_DISPATCH_TOKEN has to exist before this merges, otherwise every release run on main will end red at the notify_wrappers job. Publishing itself is unaffected, since it is a separate job.
claude-opus-5.5 | 𝕏
| # `release` events for other workflows. | ||
| notify_wrappers: | ||
| needs: build | ||
| if: needs.build.outputs.released == 'true' && needs.build.outputs.prerelease == 'false' |
There was a problem hiding this comment.
This if: has no status function, so GitHub implicitly adds success(). If anything after Create GitHub release fails (today that is slack-send), build goes red and the job is skipped. The next push then sees release-exists=true, so released is never true again for that version, and the wrappers are never notified unless someone runs it by hand. Using !cancelled() gates the job on the release itself rather than on the Slack ping.
| if: needs.build.outputs.released == 'true' && needs.build.outputs.prerelease == 'false' | |
| if: ${{ !cancelled() && needs.build.outputs.released == 'true' && needs.build.outputs.prerelease == 'false' }} |
| uses: ./.github/workflows/notify-wrappers.yml | ||
| with: | ||
| version: ${{ needs.build.outputs.version }} | ||
| secrets: inherit |
There was a problem hiding this comment.
secrets: inherit forwards every repo secret (AWS keys, Maven Central credentials, GPG signing key) into a job that only needs WRAPPER_DISPATCH_TOKEN. Passing just that one secret keeps the called workflow least-privilege. It also needs a matching secrets: WRAPPER_DISPATCH_TOKEN: { required: false } declaration under workflow_call in notify-wrappers.yml.
| secrets: inherit | |
| secrets: | |
| WRAPPER_DISPATCH_TOKEN: ${{ secrets.WRAPPER_DISPATCH_TOKEN }} |

Changes in this pull request
notify-wrappers.ymlthat notifies cross-platform wrapper SDKs (Flutter, Expo, KMP) when a new native Android SDK release is publishedbuild+test+deploy.ymlto:version,released, andprereleaseoutputs from the build jobnotify-wrappers.ymlworkflow after successful stable releasesnative-sdk-releaseevents to wrapper repositories, allowing them to automatically bump their pinned native SDK versions and open PRsImplementation Details
The workflow handles the following scenarios:
release: publishedevent (only for stable versions)workflow_callfrombuild+test+deploy.ymlsince GitHub doesn't fire release events for GITHUB_TOKEN-created releasesThe workflow requires the
WRAPPER_DISPATCH_TOKENsecret (fine-grained PAT or GitHub App token) with "Contents: read & write" permissions on wrapper repositories, sinceGITHUB_TOKENcannot dispatch events to other repositories.Checklist
CHANGELOG.mdfor any breaking changes, enhancements, or bug fixes (N/A - CI/CD infrastructure change)ktlintin the main directory and fixed any issues (N/A - YAML workflow files)https://claude.ai/code/session_015S6mZpaJyu9J5v7NPv2WCS