Files
Mish Ushakov 034c503f1f ci: guard production releases to main, harden the itinerary step (#1662)
Three fixes found while porting this workflow to
`e2b-dev/code-interpreter`
([#327](https://github.com/e2b-dev/code-interpreter/pull/327)).

**`release.yml` can be dispatched from any branch.** It is dispatch-only
and `workflow_dispatch` offers every branch in the picker, so a feature
branch carrying changesets would publish real packages to npm and PyPI
and push the version bump to itself. `preflight` now fails fast unless
the run is on `main`; candidates cut from a branch already go through
`release-candidate.yml`.

**The itinerary step can block a release.** It only feeds the Slack
messages, but a `changeset status` hiccup — or a typo in a future edit
to that inline `node -e` block, which no YAML validation catches — fails
`preflight` and stops the release. It is now `continue-on-error` with a
placeholder fallback in both messages, and the transform moved to
`.github/scripts/build_release_itinerary.cjs` next to `is_release.sh`,
where it can be run against fixture JSON. A package missing from the
label map now shows under its workspace name instead of being dropped by
`order.filter`, so a fourth publishable package would not silently
vanish from the notification.

**`report-failure` did not list `preflight`**, so whether a broken
preflight pings `#monitoring-releases` rested on `failure()` looking
past the job's direct dependencies — not documented either way, so the
job now depends on it explicitly.

Verified: the extracted script reproduces the current output exactly for
`e2b` / `@e2b/python-sdk` / `@e2b/cli`, in the same order, and handles
the empty and unlabeled-package cases; workflow validated against the
Actions schema; the script matches the repo's prettier config.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-12 14:15:14 +02:00
..