fix(release): drive the composite install from a manifest so overrides apply #133
Closed
ryangr0
wants to merge 1 commit from
fix/composite-manifest-install into main
pull from: fix/composite-manifest-install
merge into: webgrip:main
webgrip:main
webgrip:chore/renovate-approve-patch-minor
webgrip:feat/agent-runner-dhi-alpine
webgrip:feat/techdocs-builder-dhi
webgrip:feat/semrel-family-dhi-alpine
webgrip:feat/semantic-release-monorepo-dhi-base
webgrip:feat/semantic-release-dhi-base
webgrip:feat/node-ci-runner-dhi-base
webgrip:feat/helm-deploy-dhi-base
webgrip:feat/act-runner-dhi-base
webgrip:fix/promote-dash-candidate
webgrip:perf/consolidate-release-plumbing
webgrip:fix/helm-deploy-tool-bumps
webgrip:fix/candidate-keyed-by-version
webgrip:feat/promote-by-digest
webgrip:feat/cve-budgets-measured
webgrip:diag/measure-cve-budgets
webgrip:fix/techdocs-builder-zensical-conflict
webgrip:fix/semantic-release-rust-signed-reentry
webgrip:fix/node-ci-runner-signed-reentry
webgrip:docs/hardening-wave3-plan
webgrip:fix/techdocs-runner-pin-parent
webgrip:fix/mkdocs-runner-pin-parent
webgrip:fix/tauri-ci-runner-pin-parent
webgrip:fix/ci-runner-signed-cve-gate
webgrip:fix/helm-deploy-verify-downloads
webgrip:fix/techdocs-builder-annotate-stages
webgrip:fix/rust-ci-runner-pin-build-stage
webgrip:fix/rust-releaser-pin-toolchain
webgrip:fix/semantic-release-rust-pin-base
webgrip:fix/semantic-release-monorepo-pin-base
webgrip:fix/semantic-release-pin-base
webgrip:fix/playwright-runner-pin-base
webgrip:fix/act-runner-pin-act
webgrip:fix/node-ci-runner-pin-base
webgrip:fix/bump-workflows-pin-codeberg-bash
webgrip:fix/renovate-digest-aware-args
webgrip:docs/upstream-vex-in-harbor
webgrip:fix/harbor-sbom-honest-report
webgrip:fix/vex-aliases-and-unmatched-guard
webgrip:fix/gate-stderr-not-a-tty
webgrip:perf/drop-installer-actions
webgrip:fix/release-matrix-multiline-output
webgrip:fix/cve-gate-header-accuracy
webgrip:feat/release-manual-trigger
webgrip:fix/ci-runner-claude-code-and-renovate-annotation
webgrip:docs/adr-buildkitd-and-gate-as-step
webgrip:perf/release-verify-uses-buildkitd
webgrip:perf/cve-gate-as-a-step
webgrip:perf/ci-runner-bake-gate
webgrip:fix/cve-gate-volume-ownership
webgrip:fix/ci-runner-verify-helm-yq
webgrip:fix/cve-gate-scan-space
webgrip:chore/oci-labels-batch1
webgrip:perf/build-check-cli
webgrip:chore/forgejo-git-throughput-probe
webgrip:perf/ci-runner-bake-cosign-syft
webgrip:fix/cve-gate-seccomp-clone
webgrip:fix/cve-gate-pin-existing-version
webgrip:fix/cve-gate-readonly-inputs
webgrip:fix/cve-gate-moby-floor
webgrip:feat/cve-gate-static
webgrip:fix/cve-gate-vex-and-budget
webgrip:fix/cve-gate-staging-root
webgrip:ci/build-check-on-branches
webgrip:fix/cve-gate-dhi-registry
webgrip:feat/cve-gate
webgrip:feat/harden-supply-chain
webgrip:fix/semrel-toolchain-one-source
webgrip:fix/semrel-fork-direct-binary
webgrip:renovate/actions-attest-build-provenance-3.x
webgrip:renovate/sigstore-cosign-installer-4.x
webgrip:renovate/github-codeql-action-4.x
webgrip:renovate/docker-login-action-4.x
webgrip:renovate/actions-create-github-app-token-3.x
webgrip:renovate/actions-attest-build-provenance-4.x
webgrip:copilot/fix-docker-build-and-push
webgrip:copilot/fix-1
No reviewers
No labels
pull-request
released
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set.
Reference
webgrip/infrastructure!133
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "fix/composite-manifest-install"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Unblocks every image release, and reverts my own bad fix.
What was wrong
npm install --no-save --no-package-lockhas no manifest, so anoverridesblock cannot apply to it. That diagnosis was right. The fix I pushed for it (e57b6f2, addingconventional-changelog-conventionalcommits@^9.3.1as an install argument) was wrong in two independent ways.It could not work.
15.0.0-beta.2does not satisfy semantic-release's^14, so npm must nest, and the nested copy is the one semantic-release loads:semantic-release/lib/plugins/utils.jsresolvesresolveFrom.silent(__dirname, name) || resolveFrom(cwd, name)— its own directory wins. Onlyoverridesrewrites that dependency edge.It was actively unsafe. The generator and preset are a pair and both mismatches throw. Verified by rendering real commits through
generateNotes():requires conventional-changelog-writer@9 or newerheaderPartial is not a function^9.3.1next to the config's generator 15 is that last row.The fix
Install into a scratch prefix against a real manifest, then link the tree back into the package dir. Same install, driven by a manifest with
overrides, collapses to one copy of each:The manifest is derived from
ops/docker/semantic-release-monorepo/package.json— the image that already ships this exact toolchain, and that Renovate'ssemantic-release toolchainrule already keeps current — with only@webgrip/semantic-release-configoverlaid from the action input. One source of truth, so the composite cannot drift from the image. Thegot/tar/globbyoverrides ride along, which the old form also silently dropped.The image's own
package.jsonis never touched; it stays the release manifest@semantic-release/gitcommits.Guards
The failure this replaces was silent for months, so the install now asserts:
release-notes-generatorsurvived the overrides.Verification
Locally, against the real derived manifest (private config package dropped, everything else identical): single copies, guard passes, nothing nested, and
generateNotes()renders a populated changelog. The live check is the first image release off this branch — notes must be non-empty.This preserves the toolchain decision from webgrip/semantic-release-config#10 rather than reversing it.
Pull request closed