The canonical workflow does not fetch tags, though the policy says a tag-derived version needs them #110

Open
opened 2026-10-06 04:14:28 +02:00 by clawbot · 1 comment
Collaborator

Found in review of sneak/smallwebwaf#67. prompts/REPO_POLICIES.md and prompts/EXISTING_REPO_CHECKLIST.md say a repository whose version comes from git tags needs fetch-depth: 0 on its CI checkout step, because the checkout clones shallow and fetches no tags. Every repository's version comes from git describe --tags --always (script/cibuild, and the Dockerfile example), but the canonical .gitea/workflows/check.yml, which repositories vendor byte-identically, does not set it. So a tagged repository either deviates from the canonical file or stamps a bare short commit id in CI where a local build stamps the tag.

Fix

Add fetch-depth: 0 to the checkout step's with: in the canonical workflow, with a one-line comment saying why, and make the two sentences above describe the canonical file instead of asking each repository to add it. Start after #109 has merged, since it edits the same step.

Definition of done

  • The canonical workflow sets fetch-depth: 0, and no canonical sentence tells a repository to add it itself (git grep -n fetch-depth -- prompts/).
  • make check passes.

Model: opus-5-5

Found in review of https://git.eeqj.de/sneak/smallwebwaf/pulls/67. `prompts/REPO_POLICIES.md` and `prompts/EXISTING_REPO_CHECKLIST.md` say a repository whose version comes from git tags needs `fetch-depth: 0` on its CI checkout step, because the checkout clones shallow and fetches no tags. Every repository's version comes from `git describe --tags --always` (`script/cibuild`, and the `Dockerfile` example), but the canonical `.gitea/workflows/check.yml`, which repositories vendor byte-identically, does not set it. So a tagged repository either deviates from the canonical file or stamps a bare short commit id in CI where a local build stamps the tag. ## Fix Add `fetch-depth: 0` to the checkout step's `with:` in the canonical workflow, with a one-line comment saying why, and make the two sentences above describe the canonical file instead of asking each repository to add it. Start after https://git.eeqj.de/sneak/prompts/pulls/109 has merged, since it edits the same step. ## Definition of done - The canonical workflow sets `fetch-depth: 0`, and no canonical sentence tells a repository to add it itself (`git grep -n fetch-depth -- prompts/`). - `make check` passes. Model: opus-5-5
clawbot self-assigned this 2026-10-06 04:14:28 +02:00
Author
Collaborator

#117 sets fetch-depth: 0 on the checkout step of the canonical workflow and makes the two sentences say the canonical file sets it.

Model: opus-5-5

https://git.eeqj.de/sneak/prompts/pulls/117 sets `fetch-depth: 0` on the checkout step of the canonical workflow and makes the two sentences say the canonical file sets it. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/prompts#110