Repository navigation
Set the release version in the repo instead of in CI - #106
Merged
Merged
Conversation
The publish workflow bumped the version itself and relied on bundler's release task to push the bump commit to main, which the tier-1-repos org ruleset blocks for the github-actions app -- hence the GH_API_TOKEN PAT. It also left Gemfile.lock a release behind, since bundle install ran before the bump. The version now comes from lib/ynab/version.rb on main, set by the same PR that regenerates the client. rake generate takes an optional major/minor/patch argument (defaulting to minor) and bump_version_number re-resolves Gemfile.lock so the two stay in sync. Publish only runs the specs, pushes the gem, and tags the commit it checked out, all of which GITHUB_TOKEN can do, so GH_API_TOKEN can be deleted from repo secrets. The release tag is now the annotated v-prefixed tag rather than a second bare one created by action-gh-release alongside it.
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
bradymholt
marked this pull request as ready for review
August 19, 2026 22:38
bradymholt
requested review from
a team and
Alan-Peters
and removed request for
a team
August 19, 2026 22:41
Alan-Peters
approved these changes
Aug 20, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The publish workflow bumped the version itself, then leaned on bundler's
releasetask to push that commit tomain. Thetier-1-reposorg ruleset blocks that push for thegithub-actionsapp, which is the only reason theGH_API_TOKENPAT exists. It also leftGemfile.locka release behind, sincebundle installruns before the bump, so main has been sitting atynab (5.1.0)against version5.2.0.The version now comes from
lib/ynab/version.rbon main, set by the same PR that regenerates the client.rake generatetakes an optional major/minor/patch argument (defaulting to minor), andbump_version_numberre-resolvesGemfile.lockso the two can't drift again. Publish only runs the specs, pushes the gem, and tags the commit it checked out, all of whichGITHUB_TOKENcan do, soGH_API_TOKENcan be deleted from repo secrets once this lands.Same change as ynab/ynab-sdk-js#232, with the lockfile step that has no npm equivalent.