chore(ci): require upstreamImage in catalog sync and skip superseded hotfixes - #6926
Merged
Merged
Conversation
…hotfixes - RevisionIo's manifest and provenance fetchers are required, and every refreshed pin carries upstreamImage, so a written Artifacts.ts always typechecks. - planSlimUpdates skips a line's hotfix when that line upgrades, warning that manual --release can pin it alone, instead of opening a hotfix PR that conflicts once the upgrade merges. - The sync script's mode docs and the slim-release-published workflow header move into ADR 0026; provenance and narration comments are trimmed across the slim catalog files. - supabase services listing tests run against the real catalog again.
Contributor
There was a problem hiding this comment.
🤖 AI Review
Both independent reviews were available; Codex reported no findings. Code inspection confirms Claude's minor hotfix-suppression concern and documentation formatting nit. The warning also creates a GitHub Actions annotation, so it is not strictly log-only. Tests were not run.
Findings
| Severity | Location | Category | Sources | Claim |
|---|---|---|---|---|
| 🟡 MINOR | .github/scripts/sync-artifacts-catalog.ts:867 |
design |
claude | An available same-line upgrade suppresses automatic pickup of the pinned upstream's hotfix for as long as the upgrade remains unmerged, unless someone intervenes manually. Any previously opened same-line hotfix PR is left untouched and can still conflict after the upgrade merges. These operational consequences are not explicitly covered by the new ADR explanation. |
| ⚪ NIT | docs/adr/0026-slim-artifact-mirrors.md:103 |
docs |
claude | The edited paragraph contains a 139-character line, exceeding the surrounding ADR prose's approximately 100-column wrapping. |
Stats
Claude findings: 2 · Codex findings: 0 · Confirmed: 2 · Refuted: 0 · Uncertain: 0
Models: claude-opus-5-5 + gpt-6.1-sol · Trigger: auto · Workflow run
This review runs once per PR. A maintainer can request another with a /ai-review comment.
…hotfix skip consequences
jgoux
enabled auto-merge
October 1, 2026 07:18
avallete
approved these changes
Oct 1, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follows up the non-blocking review notes on #6883.
Required fetchers.
RevisionIo.fetchManifestandfetchProvenanceare now required, andrefreshCatalogPinalways resolvesupstreamImage. The serializer only accepts a pin type where that field is required, so a rewrittenArtifacts.tsalways typechecks.One update per release line. When a line upgrades,
planSlimUpdatesskips that line's hotfix. It emits a warning that--service <svc> --release <U>-r<N>can pin the hotfix alone. Otherwise theslim-hotfix/<svc>[-<line>]PR would conflict once the upgrade merges. Separate lines, such as postgres 17 and 15, stay independent.Docs over comments. The sync script's mode docs and the
slim-release-published.ymlheader move into ADR 0026:Provenance, narration and over-long comments are trimmed across the files feat(stack): pin slim artifacts by revision and make the catalog the single version table #6883 changed.
Listing tests.
services.shared.unit.test.tscovers twosupabase servicescases against the real catalog again:The auth-only fixture stays the default for the other tests.