PR Review: Update release workflow to keep single source of truth for release version number
Summary
This PR modifies the merge-develop-to-main job to read the version from pyproject.toml using poetry version -s instead of relying on the new_version workflow input.
Strengths
Single Source of Truth: Reading from pyproject.toml ensures consistency
Python/Poetry Setup: Correctly adds Python 3.13 and Poetry installation steps
Clear Documentation: Inline comment explains the change
Critical Issue: Incomplete Implementation
The PR only updates merge-develop-to-main job (line 382), but does NOT update other jobs that still use github.event.inputs.new_version at lines 68, 112, 140, and 167.
The bump-version job runs BEFORE merge-develop-to-main and requires new_version input. This creates inconsistency where bump-version needs manual input but merge-develop-to-main reads from pyproject.toml.
Recommendations
Option A: If keeping manual input - The current change is good but update PR description to clarify this only affects the develop-to-main merge PR title. Add error handling for poetry version -s.
Option B: If removing manual input - Extend changes to all jobs and redesign version input handling.
Missing Error Handling
Add error handling for poetry version -s command in case pyproject.toml is malformed or Poetry fails.
Security
No security concerns identified.
Verdict
Conditional Approval - The change is technically correct for the specific job but PR title suggests broader scope than implemented. Please clarify intent before merging.
Great work improving the workflow!
## PR Review: Update release workflow to keep single source of truth for release version number
### Summary
This PR modifies the merge-develop-to-main job to read the version from pyproject.toml using poetry version -s instead of relying on the new_version workflow input.
### Strengths
1. Single Source of Truth: Reading from pyproject.toml ensures consistency
2. Python/Poetry Setup: Correctly adds Python 3.13 and Poetry installation steps
3. Clear Documentation: Inline comment explains the change
### Critical Issue: Incomplete Implementation
The PR only updates merge-develop-to-main job (line 382), but does NOT update other jobs that still use github.event.inputs.new_version at lines 68, 112, 140, and 167.
The bump-version job runs BEFORE merge-develop-to-main and requires new_version input. This creates inconsistency where bump-version needs manual input but merge-develop-to-main reads from pyproject.toml.
### Recommendations
**Option A**: If keeping manual input - The current change is good but update PR description to clarify this only affects the develop-to-main merge PR title. Add error handling for poetry version -s.
**Option B**: If removing manual input - Extend changes to all jobs and redesign version input handling.
### Missing Error Handling
Add error handling for poetry version -s command in case pyproject.toml is malformed or Poetry fails.
### Security
No security concerns identified.
### Verdict
Conditional Approval - The change is technically correct for the specific job but PR title suggests broader scope than implemented. Please clarify intent before merging.
Great work improving the workflow!
All the remaining github.event.inputs.new_version entries are under the bump version job, which is expected.
The error handling feedback for a possible malformed pyproject.toml is valid, will update.
- All the remaining `github.event.inputs.new_version` entries are under the bump version job, which is expected.
- The error handling feedback for a possible malformed pyproject.toml is valid, will update.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Does what it says on the tin.
PR Review: Update release workflow to keep single source of truth for release version number
Summary
This PR modifies the merge-develop-to-main job to read the version from pyproject.toml using poetry version -s instead of relying on the new_version workflow input.
Strengths
Critical Issue: Incomplete Implementation
The PR only updates merge-develop-to-main job (line 382), but does NOT update other jobs that still use github.event.inputs.new_version at lines 68, 112, 140, and 167.
The bump-version job runs BEFORE merge-develop-to-main and requires new_version input. This creates inconsistency where bump-version needs manual input but merge-develop-to-main reads from pyproject.toml.
Recommendations
Option A: If keeping manual input - The current change is good but update PR description to clarify this only affects the develop-to-main merge PR title. Add error handling for poetry version -s.
Option B: If removing manual input - Extend changes to all jobs and redesign version input handling.
Missing Error Handling
Add error handling for poetry version -s command in case pyproject.toml is malformed or Poetry fails.
Security
No security concerns identified.
Verdict
Conditional Approval - The change is technically correct for the specific job but PR title suggests broader scope than implemented. Please clarify intent before merging.
Great work improving the workflow!
github.event.inputs.new_versionentries are under the bump version job, which is expected.