Skip to content

Add preset-style manual extension release trigger - #43

Merged
nicolehaugen merged 7 commits into
mainfrom
nicolehaugen-extension-release-trigger
Oct 1, 2026
Merged

nicolehaugen merged 7 commits into
mainfrom
nicolehaugen-extension-release-trigger

Conversation

@nicolehaugen

@nicolehaugen nicolehaugen commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Add Release Extension Trigger with extension ID and version inputs, accepting an optional v prefix. Call the reusable Release Extension publisher within the same run so GITHUB_TOKEN can create the tag and release without relying on a second push-triggered workflow or a PAT.
  • Apply the user-directed extension-<name> identity convention: extension-canvas-design package/directory/catalog key, extension-canvas-design.zip, extension-canvas-design-v0.1.0 tag, and extension-canvas-design v0.1.0 release title. Version remains 0.1.0. Command namespace becomes speckit.extension-canvas-design.load-page.
  • Preserve canvas-design discovery tags, canvas-settings-* templates, and Copilot provider/tool IDs. Wizard/Designer consumer changes remain separately coordinated in Add required Canvas Design extension and dynamic Designer pages #40.
  • Support any matching extension package. Manual/direct-tag runs select one extension; PR/main runs validate/package all extensions without publishing. Validate manifest/catalog identity, version, requirements and URL; reject missing declared assets; verify exact ZIP members/bytes before publication. Reuse only matching existing tags; never move mismatched tags or overwrite existing releases.
  • Exclude extension-* tags from the preset publisher with one negative tag filter. No other preset workflow changes.
  • At explicit user request, align scaffolding with the existing preset packages: retain directory-level and package README files, catalog, manifest and essential command/pages/schema payload; remove the Canvas Design package test suite, test requirements, test-only ignore file, unittest workflow steps and test documentation. Both copilot-sub-agents and copilot-assess-ask-questions have package README files and no package test suite. No replacement tests or infrastructure are added, and no Wizard/Designer integration tests are removed. PyYAML remains installed directly for generic manifest parsing; the test-only jsonschema dependency is removed.

Validation

  • Executed the current workflow's inline manifest/catalog validation and ZIP creation/verification against an isolated copy of the package: the expected tag and complete eight-file ZIP were verified without executing any tag or publication action.
  • Parsed all three relevant workflows and confirmed no unittest steps or stale references to the removed package tests remain.
  • git diff --check passed. Actionlint passed the three workflows before this final removal-only simplification; it was not rerun after that simplification.
  • Earlier package-test results are historical only; the suite has now been intentionally removed from the final tree.

Prepared on a separate branch from main, not stacked on #40. No version bump, release tag, publication, merge, marketplace change, or Wizard/Designer runtime change. GitHub-hosted manual/tag publication has not been executed.

Reuse the extension publisher directly so GITHUB_TOKEN tag creation does not rely on triggering another workflow. Preserve existing packaging and gh release create behavior.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings September 30, 2026 18:41
Use the requested extension ID for manifest and catalog validation, packaging, tags and release metadata. Validate all extension packages on PR and main runs, and clarify built-in token behavior in release instructions.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The new publication path has not run on GitHub-hosted Actions, and its tag safeguards lack committed regression tests.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

This PR adds a manual Actions trigger for publishing the Canvas Design extension through the existing release workflow.

Changes:

  • Accept an extension ID and version, including an optional v prefix.
  • Validate and package before creating or reusing a matching tag and publishing the release.
  • Document the UI steps and expand workflow contract tests.
File Description
spec-kit-extensions/​tests/​test_canvas_design.py Tests manual inputs and workflow wiring.
spec-kit-extensions/​README.md Documents manual release and retry steps.
.github/​workflows/​release-extension.yml Adds reusable publishing and tag handling.
.github/​workflows/​release-extension-trigger.yml Adds the manual Actions entry point.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/release-extension.yml
Copilot AI balanced review requested due to automatic review settings September 30, 2026 18:51

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The publisher can package missing declared assets, and its tag-and-release flow has not been exercised on GitHub-hosted runners.

Review effort: Balanced
Findings: 1 High severity · 1 Medium severity

Open (2)

Comment thread .github/workflows/release-extension.yml Outdated
Reject missing or non-file command, template, and configuration assets before ZIP creation. Supply declared assets in the generic extension fixture and add missing, directory, escaping-path, and invalid-value regressions.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings September 30, 2026 19:02

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Two release-validation issues remain, and the hosted tagging and publication path has not been exercised.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
Resolved since last review (1)
Previously missed (2)

In code that hasn't changed since last review

Medium severity Detect catalog entries missing corresponding extension manifests

.github/​workflows/​release-extension.yml:81

On PR/main runs, the validator iterates only directories with extension.yml and checks that each has a catalog entry. If an extension manifest is deleted but its catalog entry remains, these runs still pass and publish a catalog listing an extension that cannot be packaged. For all-extension runs, compare the discovered manifest IDs with the catalog IDs; leave manual and tag runs scoped to their selected extension.

Medium severity Include validated tag in concurrency group to prevent job replacement

.github/​workflows/​release-extension.yml:189

GitHub allows only one pending job per concurrency group, even with cancel-in-progress: false. Here all versions of the same extension share a group: if release A is running and release B is pending, queuing release C cancels B without publishing it. Include the validated tag in the group so different versions do not displace each other.

Rename Canvas Design to extension-canvas-design without a version bump. Use extension-<name>-vX.Y.Z tags and package-ID release titles, exclude extension tags from preset publication, and update catalog, commands, docs, and tests while preserving discovery and provider identities.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings September 30, 2026 21:45

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Tag creation and publication have not been exercised on GitHub-hosted runs, so final human review is warranted.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)

Remove the Canvas Design package test suite, test-only dependencies and workflow steps at user request. Retain README files following both preset packages and preserve generic manifest, declared-file and ZIP validation.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings September 30, 2026 22:14
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The described renamed test suite is absent, and package contract checks were removed from the release workflow.

Review effort: Balanced
Findings: 2 Medium severity

Open (2)

Comment thread .github/workflows/release-extension.yml
Focus on purpose, provided pages, requirements, installation, operation, and license. Remove detailed provider protocol and preset-authoring reference material; check retained identifiers and claims against the manifest, catalog, command, and page files.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings September 30, 2026 22:19

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Tag creation and release publication are operationally sensitive, and the GitHub-hosted publication paths remain unexecuted.

Review effort: Balanced
Findings: 2 Medium severity

Open (2)

@nicolehaugen
nicolehaugen merged commit d1e9670 into main Oct 1, 2026
11 checks passed
@mnriem
mnriem deleted the nicolehaugen-extension-release-trigger branch October 1, 2026 18:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants