Skip to content

Set the release version in the repo instead of in CI - #106

Merged
bradymholt merged 1 commit into
mainfrom
brady/publish-from-main
Aug 20, 2026
Merged

bradymholt merged 1 commit into
mainfrom
brady/publish-from-main

Conversation

@bradymholt

@bradymholt bradymholt commented Aug 19, 2026 •

Copy link
Copy Markdown
Member

The publish workflow bumped the version itself, then leaned on bundler's release task to push that commit to main. The tier-1-repos org ruleset blocks that push for the github-actions app, which is the only reason the GH_API_TOKEN PAT exists. It also left Gemfile.lock a release behind, since bundle install runs before the bump, so main has been sitting at ynab (5.1.0) against version 5.2.0.

The version now comes from lib/ynab/version.rb on main, set by the same PR that regenerates the client. rake generate takes an optional major/minor/patch argument (defaulting to minor), and bump_version_number re-resolves Gemfile.lock so the two can't drift again. Publish only runs the specs, pushes the gem, and tags the commit it checked out, all of which GITHUB_TOKEN can do, so GH_API_TOKEN can be deleted from repo secrets once this lands.

Same change as ynab/ynab-sdk-js#232, with the lockfile step that has no npm equivalent.

The publish workflow bumped the version itself and relied on bundler's
release task to push the bump commit to main, which the tier-1-repos org
ruleset blocks for the github-actions app -- hence the GH_API_TOKEN PAT.
It also left Gemfile.lock a release behind, since bundle install ran
before the bump.

The version now comes from lib/ynab/version.rb on main, set by the same
PR that regenerates the client. rake generate takes an optional
major/minor/patch argument (defaulting to minor) and bump_version_number
re-resolves Gemfile.lock so the two stay in sync. Publish only runs the
specs, pushes the gem, and tags the commit it checked out, all of which
GITHUB_TOKEN can do, so GH_API_TOKEN can be deleted from repo secrets.

The release tag is now the annotated v-prefixed tag rather than a second
bare one created by action-gh-release alongside it.
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedgem/​ynab@​5.1.0 ⏵ 5.2.099 +1100100100100

View full report

@bradymholt
bradymholt marked this pull request as ready for review August 19, 2026 22:38
@bradymholt
bradymholt requested review from a team and Alan-Peters and removed request for a team August 19, 2026 22:41
@bradymholt
bradymholt merged commit db004d8 into main Aug 20, 2026
3 checks passed
@bradymholt
bradymholt deleted the brady/publish-from-main branch August 20, 2026 01:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants