Repository navigation
Conversation
…ated on a docs diff MIP-0076 §5.5 step 1's half for notify-umbrella.yml. Until now every repo's notify-umbrella sent only submodule-docs-updated, and only because the caller's paths: filter made that the only trigger — pointer-sync.yml listens for submodule-updated too, but nothing has ever sent it (MIP-0076 §2, confirmed 2026-10-03). The workflow now checks out the caller's own repo and diffs github.event.before..github.sha itself to decide: submodule-updated goes on every call, submodule-docs-updated goes too when that range touches README.md or docs/** — so a caller drops its paths: filter and runs on every push. A zero or unreachable before (a branch's first push, or history rewritten out from under it) counts as a docs change, so both events go rather than silently dropping one. event-type stays declared, now unused, instead of being dropped: GitHub fails a reusable-workflow call outright if the caller still passes an input the called workflow no longer declares, and today's five callers are updated to drop paths: in later rows of this MIP, not this one. Closes #27 Tested: actionlint ok (repo-wide); shellcheck --severity=error ok; ruff check/format ok (uvx ruff 0.16.9, no nix); bash tests/self-tests.sh all ok; scripts/agents-check.sh ok; python3 scripts/docs_lint.py clean; claude plugin validate . passed Cost: ~$5.14 est. · ~2.6M tokens est. (diff-size model, 88 lines, no session log, IQR 0.6M-13.5M tokens for this diff from 75 calibrated commits) · scripts/cost-split.py --estimate 2026-10-05 Co-Authored-By: Claude <noreply@anthropic.com>
…a checkout
A reusable workflow's effective permissions can only keep or lower what the
caller granted, never raise it, and all five current callers set
permissions: {} with no override on the notify: job — so the checkout
added in the previous commit would have failed every one of them once
rows 6-10 bump to this tag.
Drop the checkout and git diff; call GET
/repos/$REPO/compare/$BEFORE...$SHA with github.token instead (a
no-permission token can still read a public repo over the API) and read
.files[].filename from the response with jq. changed=true on a README.md
or docs/ filename, same as before, plus now also on a non-200 response
(before unknown to the API, e.g. a force-push) and on a truncated compare
(the API caps its file list at 300). Restores permissions: {},
timeout-minutes: 2 and the header's "no checkout needed on either side".
Closes #27
Tested: actionlint ok (repo-wide); shellcheck --severity=error ok; ruff check/format ok (uvx ruff 0.16.9, no nix); bash tests/self-tests.sh all ok; scripts/agents-check.sh ok; python3 scripts/docs_lint.py clean; claude plugin validate . passed; jq filter checked by hand against four fixture compare responses (match on docs/, match on README.md, no match, empty files)
Cost: ~$3.40 est. · ~1.7M tokens est. (diff-size model, 48 lines, no session log, IQR 0.4M-8.9M tokens for this diff from 75 calibrated commits) · scripts/cost-split.py --estimate 2026-10-05
Co-Authored-By: Claude <noreply@anthropic.com>
Collaborator
Author
|
Live test in a throwaway caller,
This also confirms that a no-permission |
h0ffmann
pushed a commit
that referenced
this pull request
Oct 8, 2026
One command, run twice around a human merge. On a main whose versions are not X.Y.Z it writes the version into plugin.json, flake.nix and every documented pin, adds a CHANGELOG heading with the commits since the last tag, and pushes chore/release-vX.Y.Z for a PR. On a main that already says X.Y.Z everywhere it tags vX.Y.Z and pushes the tag; release.yml checks the versions against the tag and publishes the GitHub release. `just quality` now fails when the versions disagree. The consumer pin-bump PRs from #47 wait on the token decision there. Part of #47. Tested: release.py --self-test; --check on main (29 locations at 0.6.0) and against 0.5.1 (fails); --dry-run of both paths in a fresh clone; ruff, actionlint, tests/self-tests.sh, docs-lint, agents-check; trial merge with #32 and #33 passes the same gates Cost: n/a (no measured figure in this cloud session) Co-Authored-By: Claude <noreply@anthropic.com>
h0ffmann
added a commit
that referenced
this pull request
Oct 8, 2026
One command, run twice around a human merge. On a main whose versions are not X.Y.Z it writes the version into plugin.json, flake.nix and every documented pin, adds a CHANGELOG heading with the commits since the last tag, and pushes chore/release-vX.Y.Z for a PR. On a main that already says X.Y.Z everywhere it tags vX.Y.Z and pushes the tag; release.yml checks the versions against the tag and publishes the GitHub release. `just quality` now fails when the versions disagree. The consumer pin-bump PRs from #47 wait on the token decision there. Part of #47. Tested: release.py --self-test; --check on main (29 locations at 0.6.0) and against 0.5.1 (fails); --dry-run of both paths in a fresh clone; ruff, actionlint, tests/self-tests.sh, docs-lint, agents-check; trial merge with #32 and #33 passes the same gates Cost: n/a (no measured figure in this cloud session) Co-authored-by: Claude <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Every caller sets
permissions: {}, so this keepspermissions: {}and reads the compare API withgithub.tokeninstead of checking the repo out.event-typestays declared (deprecated, ignored), so a caller still passing it doesn't fail input validation.The scratch-repo live test (human, not done here) — updated for the fix
The brief's test case — "a code-only push sends only
submodule-updated, a docs push sends both,a first push sends both" — needs a real GitHub push/Actions run, which this task may not do.
Steps for whoever runs it (the PAT scope needed changed: no checkout happens now, so the caller's
own repo needs no Contents grant beyond its default — only the scratch umbrella needs a PAT):
scratch-notify-callerandscratch-notify-umbrella.scratch-notify-umbrella: Settings → Developer settings → fine-grained PAT scoped to justthat repo, Contents: read & write. Add it as a repo secret on
scratch-notify-caller, e.g.SCRATCH_PAT. (A scratch umbrella, notmarola-dev/marola, so the test can't dispatch into thereal umbrella.)
scratch-notify-caller, add.github/workflows/notify-umbrella.yml:uses:ref accepts a branch name, not only a tag, so this can point atthe unreleased branch directly — no devkit release needed to test it.
permissions: {}at thetop, matching today's five real callers, is fine to add too — it's exactly the case this fix
round makes work.)
main):github.event.beforeis the all-zero SHA. Expect the run's log to show bothdispatched submodule-updated for …anddispatched submodule-docs-updated for …, and thedocsstep's output to bechanged=true.src/placeholder.txt).Expect only
dispatched submodule-updated …, nosubmodule-docs-updatedline,docsstepoutput
changed=false.README.md(or add a file underdocs/). Expect bothdispatch lines again,
docsstep outputchanged=true.I did not create any repo or push anything — this is left as the human-run step the brief calls
out.