From 575662e6ba478d4497abf76373594f7a5deaf223 Mon Sep 17 00:00:00 2001 From: Claude Date: Fri, 2 Oct 2026 13:04:34 +0000 Subject: [PATCH 1/2] Notify wrapper SDKs of new releases Adds notify-wrappers.yml, which sends a native-sdk-release repository_dispatch ({platform, version}) to Superwall-Flutter, expo-superwall and Superwall-KMP so they can open a bump PR. build+test+deploy.yml calls it after creating the GitHub release: that release is created with GITHUB_TOKEN, which never fires release events, so the existing on-release trigger would not see it. Prereleases are skipped. Needs the WRAPPER_DISPATCH_TOKEN secret. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_015S6mZpaJyu9J5v7NPv2WCS --- .github/workflows/build+test+deploy.yml | 16 ++++++ .github/workflows/notify-wrappers.yml | 69 +++++++++++++++++++++++++ 2 files changed, 85 insertions(+) create mode 100644 .github/workflows/notify-wrappers.yml diff --git a/.github/workflows/build+test+deploy.yml b/.github/workflows/build+test+deploy.yml index d36c6532..d8e6f221 100644 --- a/.github/workflows/build+test+deploy.yml +++ b/.github/workflows/build+test+deploy.yml @@ -25,6 +25,11 @@ jobs: runs-on: android-large-runner + outputs: + version: ${{ steps.version.outputs.prop }} + released: ${{ steps.release.outcome == 'success' }} + prerelease: ${{ steps.prerelease.outputs.status }} + steps: - uses: actions/checkout@v3 with: @@ -174,3 +179,14 @@ jobs: env: SLACK_WEBHOOK_URL: ${{ secrets.SLACK_WEBHOOK }} SLACK_WEBHOOK_TYPE: INCOMING_WEBHOOK + + # Lets Flutter, Expo and KMP open a bump PR for this version. Called directly + # because the release above is created with GITHUB_TOKEN, which never fires + # `release` events for other workflows. + notify_wrappers: + needs: build + if: needs.build.outputs.released == 'true' && needs.build.outputs.prerelease == 'false' + uses: ./.github/workflows/notify-wrappers.yml + with: + version: ${{ needs.build.outputs.version }} + secrets: inherit diff --git a/.github/workflows/notify-wrappers.yml b/.github/workflows/notify-wrappers.yml new file mode 100644 index 00000000..b05b7728 --- /dev/null +++ b/.github/workflows/notify-wrappers.yml @@ -0,0 +1,69 @@ +# Tells the cross-platform wrappers (Flutter, Expo, KMP) that a new native SDK +# release exists. Each wrapper's native-sdk-bump.yml picks the event up, bumps +# its pinned native version, and opens a PR (with any integration work done by +# an agent on top). +# +# Android releases are created by build+test+deploy.yml with GITHUB_TOKEN, and +# GitHub never fires `release` events for GITHUB_TOKEN-created releases — so that +# workflow calls this one directly (workflow_call). `release: published` only +# covers releases made by hand; a duplicate dispatch is harmless, the wrappers +# skip versions they already have a PR for. +# +# Requires the WRAPPER_DISPATCH_TOKEN secret: a fine-grained PAT (or GitHub App +# token) with "Contents: read & write" on every repo in WRAPPER_REPOS — that is +# the permission the repository_dispatch API checks. GITHUB_TOKEN cannot +# dispatch into other repositories. +name: Notify wrapper SDKs + +on: + release: + types: [published] + workflow_call: + inputs: + version: + required: true + type: string + workflow_dispatch: + inputs: + version: + description: Released version to announce (e.g. 2.8.5) + required: true + type: string + +permissions: + contents: read + +env: + PLATFORM: android + WRAPPER_REPOS: superwall/Superwall-Flutter superwall/expo-superwall superwall/Superwall-KMP + +jobs: + dispatch: + runs-on: ubuntu-latest + # Wrappers only ship stable native versions. + if: github.event_name != 'release' || !github.event.release.prerelease + steps: + - name: Dispatch native-sdk-release + env: + GH_TOKEN: ${{ secrets.WRAPPER_DISPATCH_TOKEN }} + VERSION: ${{ inputs.version || github.event.release.tag_name }} + run: | + VERSION="${VERSION#v}" + if ! [[ "$VERSION" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]; then + echo "::notice::'$VERSION' is not a stable x.y.z version, not notifying wrappers." + exit 0 + fi + failed=0 + for repo in $WRAPPER_REPOS; do + # One wrapper being unreachable must not stop the others. + if gh api "repos/$repo/dispatches" \ + -f event_type=native-sdk-release \ + -f "client_payload[platform]=$PLATFORM" \ + -f "client_payload[version]=$VERSION"; then + echo "Notified $repo of $PLATFORM $VERSION" + else + echo "::error::Could not dispatch to $repo" + failed=1 + fi + done + exit $failed From 2a9cc37be4d810fae85eb8bf505f3fa146cde4c2 Mon Sep 17 00:00:00 2001 From: Ian Rumac Date: Fri, 9 Oct 2026 11:30:21 +0200 Subject: [PATCH 2/2] Harden wrapper release dispatch and clarify manual runs --- .github/workflows/build+test+deploy.yml | 5 +++-- .github/workflows/notify-wrappers.yml | 6 +++++- 2 files changed, 8 insertions(+), 3 deletions(-) diff --git a/.github/workflows/build+test+deploy.yml b/.github/workflows/build+test+deploy.yml index d8e6f221..7c6a37e3 100644 --- a/.github/workflows/build+test+deploy.yml +++ b/.github/workflows/build+test+deploy.yml @@ -185,8 +185,9 @@ jobs: # `release` events for other workflows. notify_wrappers: needs: build - if: needs.build.outputs.released == 'true' && needs.build.outputs.prerelease == 'false' + if: ${{ !cancelled() && needs.build.outputs.released == 'true' && needs.build.outputs.prerelease == 'false' }} uses: ./.github/workflows/notify-wrappers.yml with: version: ${{ needs.build.outputs.version }} - secrets: inherit + secrets: + WRAPPER_DISPATCH_TOKEN: ${{ secrets.WRAPPER_DISPATCH_TOKEN }} diff --git a/.github/workflows/notify-wrappers.yml b/.github/workflows/notify-wrappers.yml index b05b7728..e62dd7f1 100644 --- a/.github/workflows/notify-wrappers.yml +++ b/.github/workflows/notify-wrappers.yml @@ -14,6 +14,7 @@ # the permission the repository_dispatch API checks. GITHUB_TOKEN cannot # dispatch into other repositories. name: Notify wrapper SDKs +run-name: Notify wrapper SDKs of ${{ inputs.version || github.event.release.tag_name }} on: release: @@ -23,10 +24,13 @@ on: version: required: true type: string + secrets: + WRAPPER_DISPATCH_TOKEN: + required: false workflow_dispatch: inputs: version: - description: Released version to announce (e.g. 2.8.5) + description: Released version to announce from main (e.g. 2.8.5) required: true type: string