Skip to content

ci(release): prepare safe main back-merges - #9

Merged
xllily merged 2 commits into
developfrom
codex/auto-sync-main-develop
Aug 3, 2026
Merged

xllily merged 2 commits into
developfrom
codex/auto-sync-main-develop

Conversation

@xllily

@xllily xllily commented Aug 3, 2026 •

Copy link
Copy Markdown
Owner

What changed

  • create a disposable sync/main-to-develop-<run>-<attempt> branch from the latest develop
  • merge main into that temporary branch so released history is retained without modifying main
  • open a draft pull request from the synchronization branch back to develop
  • admit only generated synchronization branch names through the develop branch policy
  • document approval, merge-only, stale-branch, and recovery behavior

Why

A direct main to develop pull request is permanently out of date whenever development has advanced. Updating that PR would modify main, which violates the repository's stable-branch contract. The temporary-branch model keeps both permanent branches protected and gives normal CI a reviewable merge result.

Security and behavior

  • the workflow writes only a unique temporary sync/* branch
  • main and develop are never pushed by the workflow
  • permissions are limited to contents: write and pull-requests: write
  • no repository scripts or untrusted pull-request code are executed
  • the workflow never approves checks or merges its draft PR
  • stale synchronization PRs are closed and regenerated, never rebased

Validation

  • all workflow YAML files parsed successfully
  • every embedded shell block passed bash -n
  • an isolated Git simulation produced a two-parent merge commit with both develop and main as ancestors
  • synchronization branch policy accepted valid generated/topic branches and rejected main, malformed sync, and release branches
  • npm test passed: 23 tests
  • git diff --check passed
  • actionlint and shellcheck were unavailable locally

- Open a draft main-to-develop PR after release or hotfix merges.
- Skip synchronized histories and reuse an existing sync PR.
- Document repository permissions and the non-squash review flow.
@xllily
xllily marked this pull request as ready for review August 3, 2026 07:04
- Create a disposable sync branch from the latest develop before merging main.
- Restrict develop synchronization PRs to generated branch names.
- Document approval, merge policy, and stale-branch recovery.
@xllily xllily changed the title ci(release): automate main back-merge proposals ci(release): prepare safe main back-merges Aug 3, 2026
@xllily
xllily merged commit 0855640 into develop Aug 3, 2026
20 checks passed
@xllily
xllily deleted the codex/auto-sync-main-develop branch August 3, 2026 07:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant