From 8f3473cbe9ab70f13362f8db6117c62849fbeadc Mon Sep 17 00:00:00 2001 From: Hongbin Li Date: Wed, 2 Sep 2026 15:20:34 -0700 Subject: [PATCH 1/2] One package: the action installs @vosjs/cli alone The take pipeline and the vos.so verbs ship inside @vosjs/cli since 0.9.0; @vosso/vos-plugin is a forwarding shim. --- README.md | 2 +- action.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/README.md b/README.md index 5bcca11..faf39be 100644 --- a/README.md +++ b/README.md @@ -72,6 +72,6 @@ Outputs: `kit`, `vos-id`, `version`, `watch-url`. `vos record --strict` fails the job on a skipped selector instead of shipping around it. A push against a stale base fails with the changelog of what changed on the shelf. A kit that fails its own verifier (`vos validate`) fails the job after the comment says why. Store uploads stay yours: the kit is an artifact on the run, never uploaded to a store. -MIT. The CLI pair it installs, `@vosjs/cli` and `@vosso/vos-plugin`, is MIT too. +MIT. The CLI it installs, `@vosjs/cli`, is MIT too. The action dogfoods itself: every pull request here runs it against vos.so and carries the comment it produces. diff --git a/action.yml b/action.yml index dccf94d..138d7f0 100644 --- a/action.yml +++ b/action.yml @@ -69,7 +69,7 @@ runs: - name: install the vos CLI shell: bash - run: npm i -g @vosjs/cli @vosso/vos-plugin + run: npm i -g @vosjs/cli - name: record the product shell: bash From 5e37c1a155302f9ce9f7d02c3c1789904373a278 Mon Sep 17 00:00:00 2001 From: Hongbin Li Date: Wed, 2 Sep 2026 15:28:54 -0700 Subject: [PATCH 2/2] The push writes the new base back to the tracking file; the dogfood pushes from main only and commits it Every keyed run moved the tracked vos one version ahead of test/vos.json, so the next run, on any branch, was refused as a stale base. Now the action copies the take's vos.json back to the tracking path after a push (a workflow commits it), the dogfood hands the key to push events only so two branches never race for one base, and main commits the moved base right after. The tracked base moves to the version the last keyed run created. --- .github/workflows/ci.yml | 20 +++++++++++++++----- README.md | 2 +- action.yml | 7 +++++++ test/vos.json | 2 +- 4 files changed, 24 insertions(+), 7 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index c160b5c..00e3174 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -4,14 +4,16 @@ on: push: branches: [main] permissions: - contents: read + contents: write # the dogfood commits the tracked base back after a push pull-requests: write jobs: dogfood: # The action run on itself: record vos.so's own CLI page, deliver the - # store set, verify it, push a version onto the tracked vos in - # test/vos.json (the dogfood take on the vos.so shelf) and, on a pull - # request, keep the comment. + # store set, verify it, and on a pull request keep the comment. Only a + # push to main versions the tracked vos in test/vos.json (the dogfood + # take on the vos.so shelf): a pull request run gets no key, so two + # branches never race for the same base, and the base main pushes from + # is committed back right after. runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 @@ -24,4 +26,12 @@ jobs: channels: cws,og release: ci-${{ github.run_number }} tracking: test/vos.json - key: ${{ secrets.VOS_API_KEY }} # absent on a fork's pull request, so the push is skipped there + key: ${{ github.event_name == 'push' && secrets.VOS_API_KEY || '' }} + - name: commit the tracked base the push moved + if: github.event_name == 'push' + run: | + if git diff --quiet -- test/vos.json; then exit 0; fi + git config user.name 'github-actions[bot]' + git config user.email 'github-actions[bot]@users.noreply.github.com' + git commit -m 'Track the dogfood take at the version this run pushed' -- test/vos.json + git push diff --git a/README.md b/README.md index faf39be..e79c7fe 100644 --- a/README.md +++ b/README.md @@ -62,7 +62,7 @@ Start with the [launch-kit skill](https://github.com/vosjs/skills) (`npx skills | `shot-time` | | The take moment (output seconds) baked into the poster. | | `release` | tag, or `pr-` | The name on the kit and the push label. | | `key` | | A vos.so content key. Without one the take is not pushed; the kit and the comment still land. | -| `tracking` | `media/vos.json` | Which vos the pushes version. | +| `tracking` | `media/vos.json` | Which vos the pushes version. After a push the action writes the new base back to this file; commit it (a step in your workflow, or a bot commit) or the next push is refused as a stale base. | | `comment` | `true` | Keep the sticky comment (needs `pull-requests: write`). | | `take` | runner temp | Where the take is recorded. | diff --git a/action.yml b/action.yml index 138d7f0..fb68178 100644 --- a/action.yml +++ b/action.yml @@ -109,6 +109,13 @@ runs: if [ -f "${{ inputs.tracking }}" ]; then cp "${{ inputs.tracking }}" "${{ inputs.take }}/vos.json"; fi vos push "${{ inputs.take }}" --label "${{ steps.name.outputs.release }} launch" --note "Release media from ${{ github.repository }} (${{ github.event_name }} ${{ github.sha }})" --yes --json | tee "${{ runner.temp }}/push.ndjson" node "${{ github.action_path }}/scripts/outputs.mjs" "${{ runner.temp }}/push.ndjson" >> "$GITHUB_OUTPUT" + # The push moved the base: the take's vos.json now names the version + # it created. Write it back to the tracking path so the workflow can + # commit it, or the next push is refused as a stale base. + if [ -n "${{ inputs.tracking }}" ] && [ -f "${{ inputs.take }}/vos.json" ]; then + mkdir -p "$(dirname "${{ inputs.tracking }}")" + cp "${{ inputs.take }}/vos.json" "${{ inputs.tracking }}" + fi - name: attach the kit uses: actions/upload-artifact@v4 diff --git a/test/vos.json b/test/vos.json index 73ad4fa..e6e86b6 100644 --- a/test/vos.json +++ b/test/vos.json @@ -1,5 +1,5 @@ { - "versionId": "da231319-46a1-41c8-baaf-06e3f1416fae", + "versionId": "6ad9d212-f1f9-4d17-a8e8-d3f291376d49", "vosId": "2299c89d-4268-4063-a4bb-dad9be8e9e9d", "pushedAt": "2026-09-02T19:11:09.307Z", "title": "Take smoke 2026-09-02",