Consolidate publish gating into gatekeeper workflow - #11
Merged
Merged
Conversation
- Run publish detection from gatekeeper on main - Convert publish.yml to a reusable workflow - Preserve release-surface and AGW client verification before publish
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8c0b0a75c5
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
- Set `contents: read` and `id-token: write` on the reusable publish job - Allow gatekeeper to invoke the publish workflow with the required token scope
- Add the new `detect-publishable` job to gatekeeper dependencies - Include its result in the workflow failure/cancellation check
coffee-the-dev
added a commit
that referenced
this pull request
Apr 18, 2026
Resolve conflicts with main's PRs #9-#12 (publish build fix, root docs, publish gating consolidation into gatekeeper, thirdweb adapter split). - publish.yml: adopt main's workflow_call structure (#11 consolidation) while preserving this branch's switch to `changesets/action@v1` for publishing so GitHub releases are created alongside the GitHub-formatted changelog. Keep the `!./packages/contracts` build filter from main (#9). - gatekeeper.yml: keep main's detect-publishable + reusable publish call orchestration, but grant `contents: write` to the publish job so the inherited permissions allow the reusable workflow to create GitHub releases. - pnpm-lock.yaml: regenerated via `pnpm install` so the lockfile reflects both main's new `@abstract-foundation/agw-thirdweb` workspace and this branch's `@changesets/changelog-github` dev dependency.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
gatekeeper.ymlso main-branch pushes decide whether release jobs should run.publish.ymlinto a reusableworkflow_callworkflow and removed its standalone push trigger and duplicate verification steps.Testing
ifconditions forchanges,detect-publishable,agw-client,release-surface, andpublish.publish.ymlnow only exposes the npm publish job viaworkflow_calland retains the requiredid-token: writepermission.