ci: notify qBraid/docs when a release reaches PyPI - #443
Conversation
Argus reviewAuto-review is off for this repo. Tick the box below to run a review on this PR.
Estimated cost
Tip: you can also comment |
|
Important Review skippedAuto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Repository: qBraid/pyqasm/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
CodeQL flagged the new notify-docs job for not limiting the GITHUB_TOKEN (actions/missing-workflow-permissions, alert 96). The job needs none of it: the step authenticates with DOCS_DISPATCH_TOKEN and there is no checkout, so the permissions block is empty rather than a narrowed grant. Adds the matching Unreleased entry under Other, which the changelog reminder asked for. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
main reset the changelog after the v1.2.1 release, which conflicted with the new Unreleased entry on this branch. Resolved by keeping main's reset content and re-adding the notify-docs entry under Other. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Adds a
notify-docsjob that runs afterpypi-publish. It tells qBraid/docs which version just reached PyPI, and qBraid/docs then opens a PR bumping itsversions.json. Merging that PR moves this release's docs from Latest (tracksmain) into Stable (latest PyPI release). See qBraid/docs#336 for the Stable/Latest setup.continue-on-error: true, and it skips cleanly if the secret is missing, so it can never fail or block a release.Needs an org or repo secret
DOCS_DISPATCH_TOKEN: a fine-grained token, or a GitHub App token, with Contents: read and write onqBraid/docs. The GitHub API requires that permission to send arepository_dispatch. Until the secret exists, the job logs a skip.