Skip to content

chore(ci): require upstreamImage in catalog sync and skip superseded hotfixes - #6926

Merged
jgoux merged 2 commits into
developfrom
juliengoux/slim-catalog-review-followups
Oct 1, 2026
Merged

jgoux merged 2 commits into
developfrom
juliengoux/slim-catalog-review-followups

Conversation

@jgoux

@jgoux jgoux commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Follows up the non-blocking review notes on #6883.

  • Required fetchers. RevisionIo.fetchManifest and fetchProvenance are now required, and refreshCatalogPin always resolves upstreamImage. The serializer only accepts a pin type where that field is required, so a rewritten Artifacts.ts always typechecks.

  • One update per release line. When a line upgrades, planSlimUpdates skips that line's hotfix. It emits a warning that --service <svc> --release <U>-r<N> can pin the hotfix alone. Otherwise the slim-hotfix/<svc>[-<line>] PR would conflict once the upgrade merges. Separate lines, such as postgres 17 and 15, stay independent.

  • Docs over comments. The sync script's mode docs and the slim-release-published.yml header move into ADR 0026:

    • a new "Invocations" section;
    • "Hotfix and upgrade pickup" now covers payload trust, the per-line rule, line assignment and app-token handling.

    Provenance, narration and over-long comments are trimmed across the files feat(stack): pin slim artifacts by revision and make the catalog the single version table #6883 changed.

  • Listing tests. services.shared.unit.test.ts covers two supabase services cases against the real catalog again:

    • the default slim listing;
    • a catalog-pinned postgres 15 override.

    The auth-only fixture stays the default for the other tests.

…hotfixes

- RevisionIo's manifest and provenance fetchers are required, and every
  refreshed pin carries upstreamImage, so a written Artifacts.ts always
  typechecks.
- planSlimUpdates skips a line's hotfix when that line upgrades, warning
  that manual --release can pin it alone, instead of opening a hotfix PR
  that conflicts once the upgrade merges.
- The sync script's mode docs and the slim-release-published workflow
  header move into ADR 0026; provenance and narration comments are
  trimmed across the slim catalog files.
- supabase services listing tests run against the real catalog again.
@jgoux
jgoux requested a review from a team as a code owner September 30, 2026 20:49
@jgoux jgoux self-assigned this Sep 30, 2026

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 AI Review

Both independent reviews were available; Codex reported no findings. Code inspection confirms Claude's minor hotfix-suppression concern and documentation formatting nit. The warning also creates a GitHub Actions annotation, so it is not strictly log-only. Tests were not run.

Findings

Severity Location Category Sources Claim
🟡 MINOR .github/scripts/sync-artifacts-catalog.ts:867 design claude An available same-line upgrade suppresses automatic pickup of the pinned upstream's hotfix for as long as the upgrade remains unmerged, unless someone intervenes manually. Any previously opened same-line hotfix PR is left untouched and can still conflict after the upgrade merges. These operational consequences are not explicitly covered by the new ADR explanation.
⚪ NIT docs/adr/0026-slim-artifact-mirrors.md:103 docs claude The edited paragraph contains a 139-character line, exceeding the surrounding ADR prose's approximately 100-column wrapping.

Stats

Claude findings: 2 · Codex findings: 0 · Confirmed: 2 · Refuted: 0 · Uncertain: 0


Models: claude-opus-5-5 + gpt-6.1-sol · Trigger: auto · Workflow run

This review runs once per PR. A maintainer can request another with a /ai-review comment.

Comment thread .github/scripts/sync-artifacts-catalog.ts
Comment thread docs/adr/0026-slim-artifact-mirrors.md Outdated
@jgoux
jgoux enabled auto-merge October 1, 2026 07:18
@jgoux
jgoux added this pull request to the merge queue Oct 1, 2026
Merged via the queue into develop with commit 91319c9 Oct 1, 2026
48 checks passed
@jgoux
jgoux deleted the juliengoux/slim-catalog-review-followups branch October 1, 2026 07:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants