DEVX-165: feat(ci): manifest-aware dependency PRs and cleanup protection
Post-merge / detect-and-configure (push) Successful in 15s
Post-merge / release-and-maintain (push) Successful in 1m24s

This commit was merged in pull request #327.
This commit is contained in:
2026-09-19 02:48:24 +00:00
parent 7268c2b4ac
commit 49ad1868bc
7 changed files with 388 additions and 47 deletions
+91 -8
View File
@@ -22,6 +22,7 @@ from __future__ import annotations
import re
import subprocess # nosec B404
import tempfile
from datetime import UTC, datetime
from pathlib import Path
import click
@@ -143,6 +144,54 @@ def resolve_container_digest(api_url: str, owner: str, name: str, tag: str, toke
)
def update_manifest(file_path: str, section: str, fields: dict[str, str]) -> bool:
"""Update a release-manifest JSON section in place. Returns True if changed.
Implements REQ-1: manifest fields record the immutable release contract
(version, git ref, image tag, resolved OCI digest) in the target repo.
"""
import json as _json
path = Path(file_path)
if not path.exists():
raise click.ClickException(_("Manifest file not found: {file}", file=file_path))
try:
manifest = _json.loads(path.read_text(encoding="utf-8"))
except _json.JSONDecodeError as e:
raise click.ClickException(_("Manifest file {file} is not valid JSON: {error}", file=file_path, error=e)) from e
existing = manifest.get(section)
if not isinstance(existing, dict):
raise click.ClickException(
_("Manifest file {file} has no object section {section}", file=file_path, section=section)
)
changed = False
for k, v in fields.items():
if existing.get(k) != v:
existing[k] = v
changed = True
if changed:
path.write_text(_json.dumps(manifest, indent=2) + "\n", encoding="utf-8")
return changed
def read_manifest_version(file_path: str, section: str) -> str | None:
"""Read the currently pinned version from a release manifest section."""
import json as _json
path = Path(file_path)
if not path.exists():
return None
try:
manifest = _json.loads(path.read_text(encoding="utf-8"))
except _json.JSONDecodeError:
return None
existing = manifest.get(section)
if isinstance(existing, dict):
version = existing.get("version")
return str(version) if version is not None else None
return None
def create_vikunja_task(title: str, description: str) -> str | None:
"""Create a Vikunja task and return its identifier (e.g., OBL-INFRA-531)."""
try:
@@ -163,15 +212,28 @@ def create_vikunja_task(title: str, description: str) -> str | None:
@click.option("--new-version", required=True, help=_("New version to pin"))
@click.option("--source-repo", required=True, help=_("Source repo that published (owner/name)"))
@click.option("--source-run-id", default="", help=_("CI run ID that triggered the publish"))
@click.option(
"--manifest",
"manifest_path",
default="",
help=_(
"Path to a release-manifest JSON in the target repo. When set, the PR updates "
"the manifest section named after --package instead of a regex version bump."
),
)
@click.option(
"--verify-container",
default="",
help=_(
"Container to verify before opening the PR (owner/name). Resolves the OCI "
"digest of the tag matching --new-version (or --container-tag); the PR is "
"refused when the artifact is missing or unreadable."
"digest of the tag matching --new-version and records it in the manifest."
),
)
@click.option(
"--source-ref",
default="",
help=_("Git ref of the producer release (default: v<new-version>), recorded in the manifest."),
)
@click.option(
"--container-tag",
default="",
@@ -188,7 +250,9 @@ def cli(
new_version: str,
source_repo: str,
source_run_id: str,
manifest_path: str,
verify_container: str,
source_ref: str,
container_tag: str,
dry_run: bool,
) -> None:
@@ -234,11 +298,15 @@ def cli(
# Find current pinned version
old_version = None
changed_file = None
for f in [PYPROJECT_PATH, IMAGES_YML_PATH, ROLE_DEFAULTS_PATH]:
old_version = find_pinned_version(package, str(workdir / f))
if old_version:
changed_file = f
break
if manifest_path:
old_version = read_manifest_version(str(workdir / manifest_path), package)
changed_file = manifest_path if old_version else None
else:
for f in [PYPROJECT_PATH, IMAGES_YML_PATH, ROLE_DEFAULTS_PATH]:
old_version = find_pinned_version(package, str(workdir / f))
if old_version:
changed_file = f
break
if not old_version:
click.echo(_("[dep-pr] Could not find pinned version for {pkg} in infra repo.", pkg=package))
@@ -291,8 +359,23 @@ def cli(
subprocess.run(["git", "fetch", "origin", f"{branch_name}"], check=False, capture_output=True, cwd=workdir) # nosec B603 B607
subprocess.run(["git", "checkout", branch_name], check=False, capture_output=True, cwd=workdir) # nosec B603 B607
if not changed_file or not update_pinned_version(str(workdir / changed_file), package, old_version, new_version):
if manifest_path:
fields = {
"version": new_version,
"git_ref": source_ref or f"v{new_version}",
"image_tag": container_tag or new_version,
"updated_at": datetime.now(UTC).strftime("%Y-%m-%dT%H:%M:%SZ"),
}
if image_digest:
fields["image_digest"] = image_digest
if source_run_id:
fields["source_run_id"] = source_run_id
if not update_manifest(str(workdir / manifest_path), package, fields):
raise click.ClickException(_("Failed to update {file}", file=manifest_path))
elif not changed_file or not update_pinned_version(str(workdir / changed_file), package, old_version, new_version):
raise click.ClickException(_("Failed to update {file}", file=changed_file))
assert changed_file is not None # nosec B101 — narrowed by the early exit above
subprocess.run(["git", "add", changed_file], check=True, cwd=workdir) # nosec B603 B607
commit_msg = f"deps: bump {package} from {old_version} to {new_version}"
subprocess.run(["git", "commit", "-m", commit_msg], check=True, cwd=workdir) # nosec B603 B607
+14 -2
View File
@@ -150,15 +150,20 @@ def sort_versions_by_date(
def select_for_deletion(
versions: list[dict[str, Any]],
keep: int,
protect: frozenset[str] = frozenset(),
) -> list[dict[str, Any]]:
"""Select versions to delete, keeping the most recent ``keep`` versions.
Versions named ``latest`` are always preserved.
Versions named ``latest`` and any version listed in ``protect`` are
always preserved. Implements REQ-2 (DEVX-165): tags/digests that a
release manifest still pins must survive registry cleanup.
"""
sorted_versions = sort_versions_by_date(versions)
to_delete = sorted_versions[keep:]
# Always preserve 'latest' tag
to_delete = [v for v in to_delete if v.get("version") != "latest"]
# Preserve explicitly protected versions (e.g., pinned by a release manifest)
to_delete = [v for v in to_delete if v.get("version") not in protect]
return to_delete
@@ -182,6 +187,12 @@ def select_for_deletion(
show_default=True,
help="Number of recent versions to keep (excluding 'latest').",
)
@click.option(
"--protect",
"protect",
multiple=True,
help="Version/tag to never delete (e.g., pinned by a release manifest). Can be repeated.",
)
@click.option(
"--dry-run",
is_flag=True,
@@ -197,6 +208,7 @@ def main(
owner: str | None,
names: tuple[str, ...],
keep: int,
protect: tuple[str, ...],
dry_run: bool,
api_url: str | None,
) -> None:
@@ -238,7 +250,7 @@ def main(
_(" {version} (created: {created})", version=v.get("version", "?"), created=v.get("created_at", "?"))
)
to_delete = select_for_deletion(versions, keep)
to_delete = select_for_deletion(versions, keep, frozenset(protect))
kept_count = len(versions) - len(to_delete)
click.echo(_("\nKeeping {kept}, would delete {count}", kept=kept_count, count=len(to_delete)))
+47 -7
View File
@@ -1359,13 +1359,13 @@
"ru": "Тег контейнера для проверки с --verify-container (по умолчанию: --new-version). Используйте, когда тег образа отличается от версии релиза, например тег __version__ пакета против git-тега релиза.",
"zh": "用 --verify-container 验证的容器标签(默认:--new-version)。当镜像标签与发布版本不同时使用,例如包的 __version__ 标签与发布 git 标签。"
},
"Container to verify before opening the PR (owner/name). Resolves the OCI digest of the tag matching --new-version (or --container-tag); the PR is refused when the artifact is missing or unreadable.": {
"bg": "Контейнер за проверка преди отваряне на PR (собственик/име). Разрешава OCI дайджеста на тага, отговарящ на --new-version (или --container-tag); PR се отказва, ако артефактът липсва или е нечетим.",
"de": "Container zur Verifizierung vor dem Öffnen des PR (owner/name). Löst den OCI-Digest des zu --new-version (oder --container-tag) passenden Tags auf; der PR wird abgelehnt, wenn das Artefakt fehlt oder unlesbar ist.",
"en": "Container to verify before opening the PR (owner/name). Resolves the OCI digest of the tag matching --new-version (or --container-tag); the PR is refused when the artifact is missing or unreadable.",
"pl": "Kontener do weryfikacji przed otwarciem PR (właściciel/nazwa). Rozwiązuje skrót OCI tagu pasującego do --new-version (lub --container-tag); PR jest odrzucany, gdy artefakt nie istnieje lub jest nieczytelny.",
"ru": "Контейнер для проверки перед открытием PR (владелец/имя). Разрешает OCI-дайджест тега, соответствующего --new-version (или --container-tag); PR отклоняется, если артефакт отсутствует или недоступен.",
"zh": "在打开 PR 前要验证的容器(所有者/名称)。解析与 --new-version(或 --container-tag匹配标签的 OCI 摘要;当工件缺失或不可读时拒绝创建 PR。"
"Container to verify before opening the PR (owner/name). Resolves the OCI digest of the tag matching --new-version and records it in the manifest.": {
"bg": "Контейнер за проверка преди отваряне на PR (owner/name). Разрешава OCI дайджеста на тага, съвпадащ с --new-version, и го записва в манифеста.",
"de": "Container, der vor dem Öffnen des PR verifiziert wird (owner/name). Ermittelt den OCI-Digest des zu --new-version passenden Tags und trägt ihn ins Manifest ein.",
"en": "Container to verify before opening the PR (owner/name). Resolves the OCI digest of the tag matching --new-version and records it in the manifest.",
"pl": "Kontener do zweryfikowania przed otwarciem PR (owner/name). Rozwiązuje skrót OCI tagu pasującego do --new-version i zapisuje go w manifeście.",
"ru": "Контейнер для проверки перед открытием PR (owner/name). Разрешает OCI-дайджест тега, соответствующего --new-version, и записывает его в манифест.",
"zh": "在打开 PR 前要验证的容器 (owner/name)。解析与 --new-version 匹配标签的 OCI 摘要并记录到清单中。"
},
"Could not detect PR number. Use --pr to specify it explicitly,\nor run this command from a branch with an open PR.": {
"bg": "Не може да се определи номерът на PR. Използвайте --pr, за да го зададете изрично,\nили изпълнете командата от клон с отворен PR.",
@@ -1847,6 +1847,14 @@
"ru": "Генерация значков в {out}...",
"zh": "正在 {out} 中生成徽章..."
},
"Git ref of the producer release (default: v<new-version>), recorded in the manifest.": {
"bg": "Git референция на продуцентското издание (по подразбиране: v<new-version>), записана в манифеста.",
"de": "Git-Ref des Producer-Releases (Standard: v<new-version>), im Manifest verzeichnet.",
"en": "Git ref of the producer release (default: v<new-version>), recorded in the manifest.",
"pl": "Referencja git wydania producenta (domyślnie: v<new-version>), zapisana w manifeście.",
"ru": "Git-ссылка релиза производителя (по умолчанию: v<new-version>), записанная в манифест.",
"zh": "生产者发布的 git 引用(默认:v<new-version>),记录在清单中。"
},
"Git tag or ref that was deployed": {
"bg": "Git таг или референция, която беше разгърната",
"de": "Git-Tag oder Ref, der bereitgestellt wurde",
@@ -2103,6 +2111,14 @@
"ru": "Цикл с {count} итерациями в тесте '{test}' — используйте property-based тестирование (hypothesis) или уменьшите до <= {max} итераций.",
"zh": "测试 '{test}' 中有 {count} 次迭代的循环 — 考虑使用基于属性的测试 (hypothesis) 或减少到 <= {max} 次迭代。"
},
"Manifest file not found: {file}": {
"bg": "Файлът на манифеста не е намерен: {file}",
"de": "Manifest-Datei nicht gefunden: {file}",
"en": "Manifest file not found: {file}",
"pl": "Nie znaleziono pliku manifestu: {file}",
"ru": "Файл манифеста не найден: {file}",
"zh": "未找到清单文件:{file}"
},
"Manifest file not found: {path}": {
"bg": "Файлът на манифеста не е намерен: {path}",
"de": "Manifestdatei nicht gefunden: {path}",
@@ -2111,6 +2127,22 @@
"ru": "Файл манифеста не найден: {path}",
"zh": "未找到清单文件:{path}"
},
"Manifest file {file} has no object section {section}": {
"bg": "Файлът на манифеста {file} няма обектна секция {section}",
"de": "Manifest-Datei {file} hat keinen Objektabschnitt {section}",
"en": "Manifest file {file} has no object section {section}",
"pl": "Plik manifestu {file} nie ma sekcji obiektu {section}",
"ru": "Файл манифеста {file} не содержит объектного раздела {section}",
"zh": "清单文件 {file} 没有对象节 {section}"
},
"Manifest file {file} is not valid JSON: {error}": {
"bg": "Файлът на манифеста {file} не е валиден JSON: {error}",
"de": "Manifest-Datei {file} ist kein gültiges JSON: {error}",
"en": "Manifest file {file} is not valid JSON: {error}",
"pl": "Plik manifestu {file} nie jest prawidłowym JSON: {error}",
"ru": "Файл манифеста {file} не является допустимым JSON: {error}",
"zh": "清单文件 {file} 不是有效的 JSON{error}"
},
"Manifest must be a JSON list": {
"bg": "Манифестът трябва да е JSON списък",
"de": "Manifest muss eine JSON-Liste sein",
@@ -2703,6 +2735,14 @@
"ru": "Извлечён owner={owner}, repo={repo} из DEVX_REPO_NAME",
"zh": "从 DEVX_REPO_NAME 解析 owner={owner}, repo={repo}"
},
"Path to a release-manifest JSON in the target repo. When set, the PR updates the manifest section named after --package instead of a regex version bump.": {
"bg": "Път към release-manifest JSON в целевото хранилище. Когато е зададен, PR актуализира секцията на манифеста, наречена след --package, вместо regex bump на версията.",
"de": "Pfad zu einer Release-Manifest-JSON im Ziel-Repo. Wenn gesetzt, aktualisiert der PR den nach --package benannten Manifest-Abschnitt statt eines Regex-Versionsbumps.",
"en": "Path to a release-manifest JSON in the target repo. When set, the PR updates the manifest section named after --package instead of a regex version bump.",
"pl": "Ścieżka do pliku JSON manifestu wydania w docelowym repozytorium. Po ustawieniu PR aktualizuje sekcję manifestu nazwaną po --package zamiast podbicia wersji regexem.",
"ru": "Путь к JSON манифеста релиза в целевом репозитории. Если задан, PR обновляет раздел манифеста, названный по --package, вместо повышения версии по regex.",
"zh": "目标仓库中发布清单 JSON 的路径。设置后,PR 更新以 --package 命名的清单节,而不是正则版本提升。"
},
"Path to pyproject.toml (default: pyproject.toml in CWD).": {
"bg": "Път до pyproject.toml (по подразбиране: pyproject.toml в CWD).",
"de": "Pfad zu pyproject.toml (Standard: pyproject.toml im CWD).",