Skip to content

Retire the bugfix branch: every release is cut from dev - #16086

Open
Maffooch wants to merge 3 commits into
devfrom
chore/dev-master-release-pipeline
Open

Maffooch wants to merge 3 commits into
devfrom
chore/dev-master-release-pipeline

Conversation

@Maffooch

@Maffooch Maffooch commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Description

Retires the bugfix branch. From 3.4.0 on, every release comes from dev: the weekly patch (x.y.100, x.y.200, ...) and the monthly minor (x.y.0) alike. The schedule stays the same. All PRs, bug fixes and features, target dev, and a merged PR ships in the next scheduled release.

Release workflows:

  • release-1-create-pr.yml: from_branch now has one option, dev. The input stays so existing callers that pass -f from_branch=dev keep working. One version check accepts both x.y.0 and x.y.<1-3 digits>.
  • release-3-master-into-dev.yml: the job that opened the master -> bugfix merge-back is removed. The chart version flow already works for every release: the release strips -dev, and the merge-back bumps the patch and adds -dev again.
  • release_drafter_valentijn.yml: input help text only. The patch-range workaround existed because patches came from a separate branch.

CI and docs deploy:

  • bugfix is dropped from the branch filters in unit-tests.yml, test-helm-chart.yml, ci-warm-caches.yml, migration-graph.yml, ruff.yml, detect-merge-conflicts.yaml and renovate.yaml.
  • gh-pages.yml now deploys on pushes to master and dev, so docs go live when they merge. A concurrency group stops a master deploy and a dev deploy from racing.

Contributor docs:

  • PR template, readme-docs/CONTRIBUTING.md and readme-docs/RELEASING.md describe the single branch.
  • The branching model page and its 7 translations now show dev -> release/x.y.z -> master, with master merged back into dev. The dead workflow links now point at the real release-1/2/3 files. The translations were edited by hand and have not been checked by native speakers.
  • AGENTS.md, the branch-guard hook and the two Claude skills now say all work goes to dev. The guard still blocks edits on master until someone confirms.

CI on release merges

Release PRs and merge-backs are now merged as soon as they are conflict-free, without waiting for CI, to save time and runner cost.

  • Branch names: the release branches now follow the same naming as the other DefectDojo repositories. The release PR comes from release/merge-dev-into-master-<version> (was release/<version>), and the merge-back from release/merge-master-into-dev-<version> (was master-into-dev/<version>-<dev>).
  • Pull request events: the test and lint workflows skip when the head starts with release/merge- AND the PR has the release-management label. Both conditions must hold. release-1 and release-3 already add that label.
  • Push events: labels don't exist there, so ruff.yml and migration-graph.yml skip a push to such a branch, or GitHub's merge commit for such a PR.
  • Unit Tests Complete now skips too, instead of failing, when its inputs were skipped this way.
  • ci-warm-caches.yml still runs, since it only builds the cache that later PRs use.

Rollout

This should merge into dev before the 3.4.0 release (due 2026-10-05). Two things stay the same until then:

  • The 3.4.0 release itself runs the current workflows from master, including the last bugfix -> dev merge. Its release PR is what carries these changes to master.
  • The first release on the new flow is 3.4.100.

After 3.4.0, a maintainer needs to change some repository settings:

  • Retarget open bugfix PRs to dev before rebasing them.
  • Point the "Merge Queue" ruleset at dev.
  • Drop bugfix from the "Branch Protection" ruleset.
  • Once no PR targets bugfix, lock it, then delete it.

Checks

  • actionlint passes on the edited workflows. With shellcheck enabled it reports the same info/style findings as before, minus three that went away with the deleted job.
  • bash -n passes on the hook, and I ran the hook by hand in session, edit and commit modes against dev, a topic branch, and a detached HEAD at master.

Every release, the weekly patch (x.y.100, x.y.200, ...) and the monthly
minor (x.y.0), is now cut from dev and merged into master. There is no
separate bugfix line and no hotfix path off master. All PRs target dev.

Workflows:
- release-1: from_branch keeps its input for existing callers but only
  offers dev; one version check accepts x.y.0 and x.y.100; drop the dead
  release/ guard on the push step; reword the chart -dev strip messages.
- release-3: remove the master-into-bugfix merge-back job.
- Drop bugfix from branch filters and conditions in test-helm-chart,
  unit-tests, ci-warm-caches, migration-graph, ruff,
  detect-merge-conflicts and renovate.
- gh-pages: publish on pushes to master and dev, with a concurrency
  group so the two deploys queue instead of racing.
- release_drafter_valentijn: the previous release tag is now the normal
  changeset start; update the input help text.

Docs and agent guidance:
- PR template, CONTRIBUTING and RELEASING describe the single dev line.
- branching-model page and its 7 translations: dev -> release -> master
  diagram, patch releases from dev, fixed workflow links.
- AGENTS.md, branch-guard.sh and the repo skills: all work on dev,
  master stays gated behind explicit confirmation, one milestone query.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Maffooch Maffooch added this to the 3.4.0 milestone Sep 24, 2026
@github-actions github-actions Bot added the docs label Sep 24, 2026
Maffooch and others added 2 commits September 24, 2026 23:27
Release PRs (release/<version>) and merge-backs
(master-into-dev/<version>-<dev>) are merged as soon as they are
conflict-free, without waiting for CI. Guard the root jobs of the test,
lint and verification workflows so they skip on those PRs when the
release-management label is present, and on pushes of such branches or
of GitHub's merge commit for such a PR. Unit Tests Complete skips with
them instead of reporting a failure. RELEASING.md drops the "wait for
the tests" steps.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The release PR head is now release/merge-dev-into-master-<version> (was
release/<version>) and the merge-back head is
release/merge-master-into-dev-<version> (was master-into-dev/<version>-<dev>).
The version suffix keeps each release's branches unique.

CI now skips on the same rule as the other DefectDojo repositories: a pull
request whose head starts with release/merge- AND that has the
release-management label, or on push a release/merge-* branch or GitHub's
merge commit for such a PR. RELEASING.md and the branching-model pages use
the new names.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant