fix(ci): fetch release tags where the range base reads them (#703)

Review r1 (High): actions/checkout passes `git fetch --no-tags` unless
`fetch-tags: true`, even with fetch-depth 0, so releaseTaggedShas() was always
empty in CI and a candidate outside the 100-run API window fell back to
event.before instead of the last release tag. Preflight and changes now fetch
tags; the workflow contract pins the option. The AC2 dev-push case now uses its
own input (dev runs only, an older `before`) instead of repeating the main call
(review r1, Low).

Issue: #703
User-Visible: no
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018qZfe7YS4rqEMKoVeS3GKd
This commit is contained in:
Claude
2026-09-30 18:27:54 +00:00
committed by claude[bot]
parent 204e728097
commit 3d99f261ff
3 changed files with 16 additions and 6 deletions
+7 -3
View File
@@ -68,8 +68,10 @@ jobs:
# Коммиты и деревья скачиваются целиком, поэтому диапазоны и `merge-base`
# работают как раньше. Единственная догрузка по требованию здесь —
# `git show origin/main:.github/workflows/<тонкий файл>`: по блобу на файл.
# `fetch-tags: true` (#703): теги релиза — граница проверенного материала
# для базы диапазона, а checkout по умолчанию качает с `--no-tags`.
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with: { fetch-depth: 0, filter: 'blob:none' }
with: { fetch-depth: 0, filter: 'blob:none', fetch-tags: true }
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7
with: { node-version: 22 }
@@ -338,9 +340,11 @@ jobs:
range_base: ${{ steps.base.outputs.range_base }}
steps:
# `git diff --name-only` содержимого файлов не читает вовсе, поэтому
# блобы истории этой job не нужны ни на одном шаге (#345).
# блобы истории этой job не нужны ни на одном шаге (#345). Теги — нужны:
# они граница проверенного материала для `range_base` (#703), а checkout
# по умолчанию передаёт `git fetch --no-tags`.
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with: { fetch-depth: 0, filter: 'blob:none' }
with: { fetch-depth: 0, filter: 'blob:none', fetch-tags: true }
# База диапазона — самый новый предок с УСПЕШНО завершённым Validate
# (#387). Прежде бралась голова предыдущего пуша (`github.event.before`),
# то есть допущение «до этого всё проверено». Concurrency отменяет прогон
+3 -1
View File
@@ -128,7 +128,9 @@ test('#703 AC2: новое нарушение после границы крас
const found = privateWrites(fx, onMain.base, hotfix);
assert.equal(found.length, 1);
assert.equal(found[0].field, '_tool');
const onDev = rangeBase(fx, hotfix, { dev, main }, fx.candidate);
// Пуш в dev: другой вход — только прогоны dev и `before` раньше кандидата.
const onDev = rangeBase(fx, hotfix, { dev }, fx.beta3);
assert.equal(onDev.base, fx.candidate);
assert.equal(privateWrites(fx, onDev.base, hotfix).length, 1);
});
});
+6 -2
View File
@@ -372,8 +372,12 @@ test('#703 AC3: на пуше в main база диапазона видит п
assert.match(range, /other=dev; \[ "\$BRANCH" = "dev" \] && other=main/);
assert.match(range, /-f branch="\$other" -f status=completed/);
assert.match(range, /--runs=\/tmp\/validate-runs\.json --runs=\/tmp\/validate-runs-other\.json/);
// Теги релиза читаются из истории: обе job клонируют её целиком.
for (const job of [preflight, changes]) assert.match(job, /fetch-depth: 0/);
// Теги релиза — граница материала. `actions/checkout` по умолчанию качает с
// `--no-tags` даже при `fetch-depth: 0` (r1 ревью #703): без `fetch-tags`
// `releaseTaggedShas()` в CI всегда пуст.
for (const job of [preflight, changes]) {
assert.match(job, /with: \{ fetch-depth: 0, filter: 'blob:none', fetch-tags: true \}/);
}
});
/** Ставит ли workflow python-зависимости — по собственному содержимому.