ci: configure release-please with GitHub Actions authentication - #5222
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8256b6a389
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 94746f0ad3
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Simplified the changelog configuration to just |
markstuart-oai
left a comment
There was a problem hiding this comment.
Reviewed the complete change at a8a42bd95a349fda547eb3aa30d00b1991aa7cd0, including the simplified changelog configuration. No actionable findings.
The workflow limits Release Please to draft PR preparation on main and preserves manual tagging/publication. The manual candidate helper, its exact-path validation, and both review/preparation instructions consistently include the version manifest. The documented pause through tag/release creation addresses the duplicate-proposal window, while the existing publishing provenance checks remain intact. I also checked the new change-detection and release-boundary tests and used an independent source review of the release lifecycle.
Hosted CI on this exact commit: 19 checks passed, 4 still running/pending. The earlier b8b3c19 revision had all 23 checks passing; its only subsequent source change is the smaller changelog section list. Source-only review: no local tests, builds, release automation, or publication was run. Live Actions permissions, repository protections, and PyPI configuration remain rollout checks.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a8a42bd95a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 0198f7049d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Summary
This pull request adds Release Please to maintain draft release PRs on
mainusingGITHUB_TOKEN, following theopenai-pythonPython release configuration. Changelog entries are limited to features and bug fixes. It seeds the manifest at0.22.3and updates the editable package's lockfile version through a targeted TOML selector that survives lockfile regeneration.Maintainers regenerate and review the public API snapshot before completing each release PR. Tags and GitHub Releases remain manual so publication still triggers the existing provenance-checked PyPI workflow. The maintainer guide covers bot CI approval, pending/tagged labels, and the later App migration. Release configuration changes now trigger the existing SDK checks. The standalone manual release helper also updates and validates the manifest and source-checkout version fallback, with matching preparation and final-review guidance. For standalone manual releases, maintainers pause Release Please until the matching tag and GitHub Release exist, preventing duplicate proposals during that interval.
Test plan
0.22.4, a feature proposes0.23.0, both draft; only the expected changelog and project version fields change.feat/fixentries appear in the changelog.Rollout
Verify GitHub Actions can create and update release PRs without relaxing existing protections. Maintainers regenerate and push the API snapshot using their own credentials to start normal PR CI, approve bot-triggered CI when prompted, obtain code-owner review, publish the reviewed tag and GitHub Release, then transition the merged PR from
autorelease: pendingtoautorelease: tagged. GitHub App credentials are a separate follow-up; this workflow does not require them.Checks
.agents/skills/code-change-verification/scripts/run.shwith the documented Codex sandbox environment andUV_FROZEN=1.