diff --git a/.woodpecker/ci.yml b/.woodpecker/ci.yml index 35acff9e..ac68ef1f 100644 --- a/.woodpecker/ci.yml +++ b/.woodpecker/ci.yml @@ -7,11 +7,20 @@ variables: - &enable_pnpm 'corepack enable' when: - # PR + manual CI run on any branch — the pull_request pipeline is the merge gate. - # push CI is restricted to protected branches (main) so a feature-branch push no - # longer fires a redundant SECOND pipeline alongside its PR pipeline. This ~halves - # CI load on the storage-constrained runner with zero loss of gating (branch - # protection requires no push/ci status context; main still gets full push CI). + # PR + manual CI run on any branch: the pull_request pipeline is the merge + # gate (required status check on next; next is protected and the DEFAULT + # branch since 2026-08-19). + # Push CI runs on main only. next deliberately runs NO push ci: post-merge + # verification on next is carried by publish.yml's `verify` step + # (pnpm verify:release), which mirrors this pipeline's complete mandatory + # set step-for-step, enforced by scripts/verify-release.test.mjs. The two + # things push-to-next does not re-run, the postgres-path test and a + # push-ci status context, duplicate pre-merge coverage: PR CI tests the + # merge ref, whose tree equals the landed squash commit. Measured + # 2026-08-19: the 21 most recent push events on next each ran exactly one + # pipeline (publish), zero ci. + # Keeping push ci off next also avoids a redundant second full-suite run + # per merge on the storage-constrained runner. - event: [pull_request, manual] - event: push branch: main