Skip to content

release(runway): cherry-pick fix(ci): restrict AMO flask/production to release/*; block flask dispatch - #45326

Merged
sleepytanya merged 1 commit into
release/13.43.0from
runway-cherry-pick-13.43.0-1786123031
Aug 7, 2026
Merged

sleepytanya merged 1 commit into
release/13.43.0from
runway-cherry-pick-13.43.0-1786123031

Conversation

@runway-github

@runway-github runway-github Bot commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

Description

Align AMO production and flask to release/* only (not
main) so uploads use the same workflow version as the cut.

Flask remains orchestrator-only: flask is removed from
workflow_dispatch target options, and the sender check rejects any
human/non-Runway flask dispatch. Do not gate on github.event_name
— in a reusable workflow that value is the caller's trigger, so a Runway
orchestrator workflow_call (itself workflow_dispatch) would falsely
fail. Keep workflow_call for Runway Phase 3.

Companion: infra PR
#19

(amo-submission-flask + amo-submission-production OIDC release/*
only). Docs:
releases#32.

GitHub Environment config (done):

  • Remove required reviewers on amo-flask
  • Set amo-flask and amo-production deployment branches to
    release/* only (remove main)

Changelog

CHANGELOG entry: null

Related issues

Fixes: INFRA-3769

Manual testing steps

  1. On release/X.Y.Z, Actions → Upload extension to Firefox AMO —
    targets are production and dev only (flask not offered).
  2. target=production on release/* passes the branch guard (then
    waits on amo-production approval).
  3. target=production on main fails the branch guard.
  4. Orchestrator workflow_call with target=flask still succeeds
    (sender = Runway; no env reviewers on amo-flask).
  5. Human attempt at flask (API/workflow_call from a user) fails the
    sender check before AWS creds.

Screenshots/Recordings

N/A

Before

N/A

After

N/A

Pre-merge author checklist

Pre-merge reviewer checklist

  • I've manually tested the PR (e.g. pull and build branch, run the
    app, test code being changed).
  • I confirm that this PR addresses all acceptance criteria described
    in the ticket it closes and includes the necessary testing evidence such
    as recordings and or screenshots.

Co-authored-by: Cursor cursoragent@cursor.com bc18c5c

…o release/*; block flask dispatch (#45302)

## **Description**

Align AMO **production** and **flask** to **`release/*` only** (not
`main`) so uploads use the same workflow version as the cut.

Flask remains orchestrator-only: `flask` is removed from
`workflow_dispatch` target options, and the sender check rejects any
human/non-Runway flask dispatch. Do **not** gate on `github.event_name`
— in a reusable workflow that value is the caller's trigger, so a Runway
orchestrator `workflow_call` (itself `workflow_dispatch`) would falsely
fail. Keep `workflow_call` for Runway Phase 3.

**Companion:** [infra PR
#19](https://github.com/consensys-vertical-apps/va-mmc-extension-submission-infra/pull/19)
(`amo-submission-flask` + `amo-submission-production` OIDC `release/*`
only). Docs:
[releases#32](https://github.com/MetaMask/releases/pull/32).

**GitHub Environment config (done):**
- [x] Remove required reviewers on `amo-flask`
- [x] Set `amo-flask` and `amo-production` deployment branches to
**`release/*` only** (remove `main`)

## **Changelog**

CHANGELOG entry: null

## **Related issues**

Fixes: INFRA-3769

## **Manual testing steps**

1. On `release/X.Y.Z`, Actions → Upload extension to Firefox AMO —
targets are `production` and `dev` only (`flask` not offered).
2. `target=production` on `release/*` passes the branch guard (then
waits on `amo-production` approval).
3. `target=production` on `main` fails the branch guard.
4. Orchestrator `workflow_call` with `target=flask` still succeeds
(sender = Runway; no env reviewers on `amo-flask`).
5. Human attempt at flask (API/`workflow_call` from a user) fails the
sender check before AWS creds.

## **Screenshots/Recordings**

N/A

### **Before**

N/A

### **After**

N/A

## **Pre-merge author checklist**

- [x] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask
Extension Coding
Standards](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [x] I've completed the PR template to the best of my ability
- [x] I've included tests if applicable
- [x] I've documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [x] I've applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
@runway-github
runway-github Bot requested review from a team as code owners August 7, 2026 17:17
@github-actions

github-actions Bot commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

CLA Signature Action: All authors have signed the CLA. You may need to manually re-run the blocking PR check if it doesn't pass in a few minutes.

@metamask-ci metamask-ci Bot added the team-bots Bot team (for MetaMask Bot, Runway Bot, etc.) label Aug 7, 2026
@sleepytanya
sleepytanya enabled auto-merge (squash) August 7, 2026 17:17
@sonarqubecloud

sonarqubecloud Bot commented Aug 7, 2026

Copy link
Copy Markdown

@sleepytanya
sleepytanya merged commit eab4097 into release/13.43.0 Aug 7, 2026
72 of 73 checks passed
@sleepytanya
sleepytanya deleted the runway-cherry-pick-13.43.0-1786123031 branch August 7, 2026 17:35
@github-actions github-actions Bot locked and limited conversation to collaborators Aug 7, 2026
@metamaskbot metamaskbot added the release-13.43.0 Issue or pull request that will be included in release 13.43.0 label Aug 10, 2026
@gauthierpetetin

Copy link
Copy Markdown
Contributor

No release label on PR. Adding release label release-13.43.0 on PR, as PR was cherry-picked in branch 13.43.0.

This branch had an error being deployed

1 failed deployment
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

release-13.43.0 Issue or pull request that will be included in release 13.43.0 risk:medium team-bots Bot team (for MetaMask Bot, Runway Bot, etc.)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants