Repository navigation
ci: guard migration versions (next free version, open-PR collision) - #408
Merged
Merged
Conversation
A migration must sort above the base's newest version and must not share a version with another file or another open pull request.
…igration-order-13304
Contributor
There was a problem hiding this comment.
The migration guard checks added SQL versions against the immutable event base, catches duplicate and open-pull-request versions, and runs its regression fixtures in the selected migration lane. Migration Integrity, Security Scan and ci-ok succeeded at this head. No migrations or runtime account paths change.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Add a migration-version guard to Migration Integrity. Added SQL files must sort above the base's newest version, have a unique version in their directory, and not collide with another open pull request. Diagnostics suggest the next free version.
Why
Parallel branches can choose the same version or land below a version already applied. Catch these cases before deployment rather than requiring deployment recovery.
Use immutable pull-request and merge-group base SHAs from the event and the existing full-history checkout, rather than fetching a mutable branch again. Guard-script changes select the migration lane too.
The failed Security Scan on the previous head rejected Next.js 16.3.6 for GHSA-cjq9-62q9-8jv4. Merged current main, which already pins Next.js 16.3.8 in both the manifest and lockfile. The audit remains unchanged and fail-closed; no duplicate dependency fix or audit exemption is added.
Testing
No migrations or account data are modified by this PR. No production resources were changed during rework. Rollback is a source revert. Existing runner selection is unchanged.