From 16da5b592d081c6f4e955704815c55380959150f Mon Sep 17 00:00:00 2001 From: foxnne Date: Thu, 8 Oct 2026 10:29:26 -0500 Subject: [PATCH] sdk-tag: a new SDK asks the store plugins to repin After publishing a new sdk-v* release, sdk-tag.yml sends `fizzy-sdk-release` (with the version) to every fizzyedit plugin the store registry lists, read from fizzyedit/plugins by each entry's homepage, so a new plugin needs no edit here. Each plugin's sdk-repin.yml runs plugin-build-action's repin.yml, which builds it against the new SDK and opens a PR when the plugin needs a release. Nothing tags a plugin. `repository_dispatch` needs a token with Contents write on the plugin repos: PLUGIN_DISPATCH_TOKEN. Without it, or without a readable registry, the step warns and the release is otherwise unaffected. CONTRIBUTING.md's release train says what follows a release. Co-Authored-By: Claude Opus 5.5 --- .github/workflows/sdk-tag.yml | 44 +++++++++++++++++++++++++++++++++++ CONTRIBUTING.md | 8 ++++--- 2 files changed, 49 insertions(+), 3 deletions(-) diff --git a/.github/workflows/sdk-tag.yml b/.github/workflows/sdk-tag.yml index d6ea408d..a3649847 100644 --- a/.github/workflows/sdk-tag.yml +++ b/.github/workflows/sdk-tag.yml @@ -205,3 +205,47 @@ jobs: echo "Published $asset on $tag" gh release view "$tag" --json assets --jq '.assets[].name' + + # Each fizzyedit plugin in the store registry (fizzyedit/plugins, by its homepage) repins + # itself: its sdk-repin.yml runs plugin-build-action's repin.yml, which builds it against + # this SDK and opens a PR when the plugin needs a release (its fingerprint moved, or it no + # longer builds). Nothing here tags a plugin. + # + # `repository_dispatch` needs PLUGIN_DISPATCH_TOKEN: a fine-grained token on the fizzyedit + # organization with Contents read/write on the plugin repos. Without it this warns, and a + # plugin can still be repinned by hand (`gh workflow run sdk-repin.yml --repo fizzyedit/`). + - name: Ask the store plugins to repin + if: steps.tag.outputs.publish == 'true' + shell: bash + env: + GH_TOKEN: ${{ secrets.PLUGIN_DISPATCH_TOKEN }} + READ_TOKEN: ${{ github.token }} + VERSION: ${{ steps.ver.outputs.version }} + run: | + set -euo pipefail + if [ -z "${GH_TOKEN:-}" ]; then + echo "::warning::PLUGIN_DISPATCH_TOKEN is not set: no plugin was asked to repin to $VERSION" + exit 0 + fi + # The registry is public: read it with this run's own token. + if ! names=$(GH_TOKEN="$READ_TOKEN" gh api repos/fizzyedit/plugins/contents/registry \ + --jq '.[] | select(.name | endswith(".json")) | .name'); then + echo "::warning::could not read fizzyedit/plugins' registry: no plugin was asked to repin to $VERSION" + exit 0 + fi + repos="" + for name in $names; do + homepage=$(GH_TOKEN="$READ_TOKEN" gh api "repos/fizzyedit/plugins/contents/registry/$name" \ + --jq '.content | @base64d | fromjson | .homepage // ""') + case "$homepage" in + https://github.com/fizzyedit/*) repo=${homepage#https://github.com/fizzyedit/}; repos="$repos ${repo%/}" ;; + esac + done + for repo in $repos; do + if gh api "repos/fizzyedit/$repo/dispatches" -f event_type=fizzy-sdk-release \ + -f "client_payload[version]=$VERSION" >/dev/null; then + echo "asked fizzyedit/$repo to repin to $VERSION" + else + echo "::warning::could not ask fizzyedit/$repo to repin (is sdk-repin.yml there, and the token scoped to it?)" + fi + done diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 0b8f1d4c..7cc2886c 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -91,9 +91,11 @@ The open PR list is the board of who is working on what. The plugin boundary has two numbers. `recorded_sdk_shape_fingerprint` (`sdk/src/version.zig`) must match the boundary's live shape, or the build fails. `sdk_version` (`sdk/sdk_version.zig`) is what plugins pin, and **a new `sdk_version` merged to `main` is a release**: `sdk-tag.yml` -tags `sdk-v*` and publishes the tarball, and every store plugin is repinned to load against it. -A merge that leaves the version alone publishes nothing: a released tarball is pinned by hash, -so it is never replaced. +tags `sdk-v*` and publishes the tarball, then asks each `fizzyedit` store plugin to repin. Each +builds against the new SDK and opens a `sdk: repin to fizzy SDK ` PR in its own repo +when it needs a release (its fingerprint moved, or it no longer builds, as a draft); merge it and +tag the version it names. A merge that leaves the version alone publishes nothing: a released +tarball is pinned by hash, so it is never replaced. - **A feature PR records the fingerprint and leaves `sdk_version` alone.** When the shape moves, the build fails with the new value; record it, label the PR `sdk`, and say in the template's