open-swe/.github/workflows/promote-dev-to-prod.yml
seahaven-openswe[bot] 3af0bd5e16
ci: align workflows with Sea Haven CI/CD handbook (#29)
* Align workflows with Sea Haven CI/CD handbook

Bring the workflow suite in line with the handbook: bump
actions/checkout to v7 (Node 24 runtime, already standardized),
kebab-case the two snake_case workflow filenames, and add the
org-standard Labeler caller and Dependency Review gate so vulnerable
or disallowed-license deps and unlabeled PRs are caught automatically.

File renames only — job/check display names are unchanged, so the
promotion gate's REQUIRED_CHECKS and branch-protection required
checks are unaffected.

Refs: INFRA-115

* Drop Agent prefix from CI workflow + job names

The handbook names workflows for what they do (CI, Deploy, Labeler),
not the component they run, matching .github and afterhours-shift-manager.
Rename the suite to CI and its jobs to Lint / Format check / Unit tests,
and keep the promotion gate's REQUIRED_CHECKS in sync.

Refs: INFRA-115

---------

Co-authored-by: seahaven-openswe[bot] <296972425+seahaven-openswe[bot]@users.noreply.github.com>
2026-06-27 21:47:25 -04:00

45 lines
1.5 KiB
YAML

name: Promote dev to main (prod)
permissions:
contents: write
on:
schedule:
- cron: "0 8 * * *"
workflow_dispatch:
concurrency:
group: promote-dev-to-main
cancel-in-progress: false
jobs:
promote:
runs-on: ubuntu-latest
permissions:
contents: write
checks: read
steps:
- uses: actions/checkout@v7
with:
ref: dev
fetch-depth: 0
- name: Require dev HEAD fully green
# Hard precondition: every check-run on the dev HEAD commit must be
# completed + passing before we let it become prod. A red OR still-pending
# check blocks the promotion. The promote job's own in-progress check-run
# is excluded by name so the gate can't deadlock on itself.
env:
GH_TOKEN: ${{ github.token }}
# exclude THIS run's own check-run by its run id (not by name).
EXCLUDE_RUN_ID: ${{ github.run_id }}
run: |
SHA="$(git rev-parse HEAD)"
echo "dev HEAD = ${SHA}"
gh api --paginate "repos/${GITHUB_REPOSITORY}/commits/${SHA}/check-runs" \
-q '.check_runs[] | [.name, .status, (.conclusion // ""), (.details_url // "")] | join("\u001f")' \
| bash .github/scripts/check-dev-green.sh
- name: Fast-forward main (PROD) to dev
# main is the production branch; a plain ref push is fast-forward-only
# (branch protection rejects non-FF), so a diverged main fails loudly.
run: |
git push origin HEAD:refs/heads/main