headroom/.github
Tejas Chopra a8e3ae52e9 fix(release): sync generated version metadata on the release branch
The 0.33.0 release PR (#2339) has been blocked since 2026-07-17 in
changes-requested, because release-please only rewrites `pyproject.toml` and its
configured `extra-files`. `server.json` is asserted byte-for-byte against
`render_server_json()`, which reads the version from `pyproject.toml`, so the
bump alone fails `test_root_server_json_matches_builder` on the release PR —
the `test (2)` shard. Nothing in the repo regenerated `server.json` at all.

`release.yml` already runs `version-sync.py` before its own `verify-versions.py`
gate (lines 145/278), which is why `build` and `build-wheels` pass on the release
PR despite the drift — it syncs in the workspace, uncommitted. The regular CI test
job does not sync, so the fix has to be committed to the branch.

- `scripts/version-sync.py`: also write `server.json`. It was the one
  version-carrying file with no writer anywhere, so it fell behind every release.
  Values are rewritten in place so key order and formatting keep matching the
  builder's byte-for-byte output.
- `.github/workflows/release-metadata-sync.yml` (new): on a push to
  `release-please--branches--**`, run version-sync, gate on verify-versions, and
  commit if anything changed. Keyed off the branch push because release-please
  force-regenerates that branch on every merge to main — that is what repeatedly
  wiped the hand-pushed metadata fixes on #2339. Uses the same PAT as
  release-please.yml, since a GITHUB_TOKEN push would not re-trigger the release
  PR's checks. Idempotent, so the self-triggered rerun no-ops instead of looping.
- Corrected the pre-existing drift on main: the agent-hooks plugin manifests,
  both marketplace manifests, and `.releasemetadata` were stranded at 0.31.0 and
  were never bumped for 0.32.0 either. `verify-versions.py` now passes on main.

Chose running the script over adding ~13 `extra-files` jsonpath entries: the
script is the single place that knows these locations, and a jsonpath that fails
to match is silent — the same class of failure this removes. There is also no
precedent for nested jsonpath in the config today.

Tests: `test_server_json_version_is_synchronized`,
`test_release_metadata_sync_runs_on_release_please_branch`, and
`test_version_sync_covers_every_file_the_verifier_gates` (guards the two scripts
against drifting apart again).

Not addressed: PyPI is at 9.69GB of its 10GB project cap; the 0.21.x series alone
holds 6.58GB across 31 releases. Roughly 4 more releases fit before that blocks.
2026-07-29 14:57:39 -07:00
..
act Fix CI lint failure by formatting PR governance scripts (#933) 2026-06-12 17:11:39 -05:00
actions/headroom-e2e-setup fix(windows): pin UTF-8 encoding on text-mode subprocess calls (#1311) 2026-06-23 12:52:49 -05:00
ISSUE_TEMPLATE docs: fix dead contact links in issue templates and troubleshooting guide (#910) 2026-06-12 14:47:10 -07:00
plugin fix(release): sync generated version metadata on the release branch 2026-07-29 14:57:39 -07:00
pr-images fix(router): stop protecting passing build/test output as error traces (#1740) 2026-07-14 13:25:49 -04:00
scripts fix(codex): PR health label check state (#986) 2026-06-15 16:52:26 -05:00
workflows fix(release): sync generated version metadata on the release branch 2026-07-29 14:57:39 -07:00
CODEOWNERS chore: add CODEOWNERS with maintainer catch-all (#1622) 2026-06-30 21:52:29 -07:00
copilot-instructions.md Fix CI lint failure by formatting PR governance scripts (#933) 2026-06-12 17:11:39 -05:00
dependabot.yml feat(security): pilot hardening — stateless guarantee, model pinning, CI security gate (#1515) 2026-06-27 17:44:10 -07:00
PULL_REQUEST_TEMPLATE.md ci(changelog): stop the CHANGELOG cascade — release-please owns it (#2329) 2026-07-16 14:28:57 -07:00