name: Promote dev to main (prod) permissions: contents: write on: schedule: - cron: "0 8 * * *" workflow_dispatch: concurrency: group: promote-dev-to-main cancel-in-progress: false jobs: promote: runs-on: ubuntu-latest permissions: contents: write checks: read steps: - uses: actions/checkout@v6 with: ref: dev fetch-depth: 0 - name: Require dev HEAD fully green # Hard precondition: every check-run on the dev HEAD commit must be # completed + passing before we let it become prod. A red OR still-pending # check blocks the promotion. The promote job's own in-progress check-run # is excluded by name so the gate can't deadlock on itself. env: GH_TOKEN: ${{ github.token }} # exclude THIS run's own check-run by its run id (not by name). EXCLUDE_RUN_ID: ${{ github.run_id }} run: | SHA="$(git rev-parse HEAD)" echo "dev HEAD = ${SHA}" gh api --paginate "repos/${GITHUB_REPOSITORY}/commits/${SHA}/check-runs" \ -q '.check_runs[] | [.name, .status, (.conclusion // ""), (.details_url // "")] | join("\u001f")' \ | bash .github/scripts/check-dev-green.sh - name: Fast-forward main (PROD) to dev # main is the production branch; a plain ref push is fast-forward-only # (branch protection rejects non-FF), so a diverged main fails loudly. run: | git push origin HEAD:refs/heads/main