Skip to content

ci: guard migration versions (next free version, open-PR collision) - #408

Merged
sylphx-desk-studio[bot] merged 5 commits into
mainfrom
ci/migration-order-guard
Oct 9, 2026
Merged

sylphx-desk-studio[bot] merged 5 commits into
mainfrom
ci/migration-order-guard

Conversation

@sylphx-desk-services

@sylphx-desk-services sylphx-desk-services Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

What

Add a migration-version guard to Migration Integrity. Added SQL files must sort above the base's newest version, have a unique version in their directory, and not collide with another open pull request. Diagnostics suggest the next free version.

Why

Parallel branches can choose the same version or land below a version already applied. Catch these cases before deployment rather than requiring deployment recovery.

Use immutable pull-request and merge-group base SHAs from the event and the existing full-history checkout, rather than fetching a mutable branch again. Guard-script changes select the migration lane too.

The failed Security Scan on the previous head rejected Next.js 16.3.6 for GHSA-cjq9-62q9-8jv4. Merged current main, which already pins Next.js 16.3.8 in both the manifest and lockfile. The audit remains unchanged and fail-closed; no duplicate dependency fix or audit exemption is added.

Testing

  • Fixture coverage includes ordered, older, duplicate and open-PR-colliding migrations, a moved base, API unavailability, an immutable base without an origin/main ref, and missing-base refusal.
  • Workflow-binding assertions and the regression suite run inside Migration Integrity without inheriting its GitHub credentials.
  • Preserved the previous PR head in ancestry and merged main b1926fd. The diff against main contains only the migration guard, fixture tests and workflow integration. Git diff --check passed and the working tree is clean.
  • Remote regression, frozen installation and production dependency audit could not start: Build reports no linked org/project/environment. Exact-head regression execution, Security Scan and full repository gates remain pending CI; no local test pass or new-head CI success is claimed.

No migrations or account data are modified by this PR. No production resources were changed during rework. Rollback is a source revert. Existing runner selection is unchanged.

A migration must sort above the base's newest version and must not share a version with another file or another open pull request.

@sylphx-desk-studio sylphx-desk-studio Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The migration guard checks added SQL versions against the immutable event base, catches duplicate and open-pull-request versions, and runs its regression fixtures in the selected migration lane. Migration Integrity, Security Scan and ci-ok succeeded at this head. No migrations or runtime account paths change.

@sylphx-desk-studio
sylphx-desk-studio Bot added this pull request to the merge queue Oct 9, 2026
Merged via the queue into main with commit c71c093 Oct 9, 2026
17 of 19 checks passed
@sylphx-desk-studio
sylphx-desk-studio Bot deleted the ci/migration-order-guard branch October 9, 2026 09:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant