Skip to content

chore: add toolkit settings migration - #1597

Merged
BYK merged 4 commits into
mainfrom
chore/toolkit-migration-admin
Sep 21, 2026
Merged

BYK merged 4 commits into
mainfrom
chore/toolkit-migration-admin

Conversation

@BYK

@BYK BYK commented Sep 18, 2026 •

Copy link
Copy Markdown
Member

Adds one-off migration tooling for the Toolkit move into getsentry/sentry-mcp.

Settings workflow security properties:

  • runs only through workflow_dispatch from the source default branch and pins both repositories by numeric ID
  • uses permissions: {} and never checks out or executes repository code
  • reads the short-lived destination-admin PAT only from SENTRY_MCP_MIGRATION_PAT, never from workflow inputs
  • fails before writing if any source value is missing
  • copies explicit repository and production environment settings without printing values
  • recreates and verifies the protected-branch production environment policy
  • verifies destination names and metadata after writing

Open-PR migration tooling:

  • defaults to a read-only plan and requires the reviewed plan for execution
  • pins source PR metadata, immutable pull refs, source targets, filtered import tips, destination bases, reconstructed commits, and exact mapped diff hashes
  • supports stale roots and stacks, forks, historical pre-monorepo paths with explicit verified lineage, and merge-containing PR histories
  • verifies path, mode, blob, metadata, branch, and PR state; resumes only recognized exact phases
  • revalidates live source targets and destination bases immediately before every GitHub write, including skipped stack ancestors
  • creates branches atomically with must-not-exist leases and never closes source PRs
  • stops until the filtered CLI and docs import tips are present on destination main

Validation:

  • 22 deterministic migration tests pass
  • Node module checks, Biome formatting/lint, and git diff --check pass
  • four independent review rounds resolved stale-base, historical-lineage, merge, recovery, collision, metadata, reproducibility, and target-drift defects; the final frozen artifact passed

After a successful settings run, delete SENTRY_MCP_MIGRATION_PAT, revoke the PAT, and remove the workflow. Review the generated open-PR migration plan before any execution.

Part of #1239.

@vercel

vercel Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
cli Ready Ready Preview Sep 18, 2026 9:48pm UTC
sentry-local Ready Ready Preview Sep 18, 2026 9:48pm UTC

Request Review

Comment thread .github/workflows/migrate-toolkit-settings.yml Outdated

@cursor cursor Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread .github/workflows/migrate-toolkit-settings.yml Outdated
Co-Authored-By: OpenAI Codex <noreply@openai.com>
Comment thread scripts/migrate-open-prs.mjs

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit c344c23. Configure here.

Comment thread scripts/migrate-open-prs.mjs
Co-Authored-By: OpenAI Codex <noreply@openai.com>
Comment thread scripts/migrate-open-prs.mjs
@github-actions github-actions Bot added the risk: medium PR risk score: medium label Sep 21, 2026
@BYK
BYK merged commit 2cd03fe into main Sep 21, 2026
32 checks passed
@BYK
BYK deleted the chore/toolkit-migration-admin branch September 21, 2026 13:05
BYK added a commit to getsentry/toolkit that referenced this pull request Sep 30, 2026
## Summary

- Import `packages/cli` and `apps/cli-docs` with their unsquashed
history from CLI release `0.45.0`, then advance the imported CLI history
to the latest `getsentry/cli` main.
- Add both packages to the pnpm workspace, restore root patch authority
under pnpm 11, and replace Turbo with pnpm-native orchestration and
affected-package PR validation.
- Keep MCP deployment, smoke, eval, and clean-consumer workflows scoped
to their product closures.

## Import provenance

- Release source: `03f636f8d1fe6553acf22595eb029ddc8efc79eb`; initial
filtered CLI tip: `d5ffbcefa8977382127dc752dd0c78e34fc90ccd`; initial
filtered docs tip: `6620138c1cb167babb45987cb2fc499adc00805a`.
- Initial import merges: CLI `7d81b40ab93b2f57240cdab3d1b813963c18b062`;
docs `86902bac7b2e4ac072ec667b4ab5b11d310450b0`. Both imported trees
were byte-identical to their source release trees. The release commit
made no docs-tree change, so the filtered docs tip is its parent.
- Earlier source-main refresh:
`fc1140092883409046438c8bb5d6f7f939eb9659`, with filtered CLI tip
`6b08e9029dc7e092bfebaa3870ca116e7dfdfc89` and filtered docs tip
`4358ec2729a60ef034f3866680fc5fd7bce62ce0`.
- **Latest CLI source main:**
`c1337081e382f28a67a0f7594b542e9429402d1c`, imported as filtered CLI
commit `5eb94845654fa8e3856a8b0473cb24261c3169d0` by merge
`8ff191c70201086a2b391ab3999ef63f6afaeb1d`. Its filtered parent
`e34a7c2b31f0501328ab43b4a5a5be31639b8322` maps to upstream
`6f9d32308b58633b00fbfe67f288d956d4419d9c`. The latest upstream commit
changes only CLI error reporting and its tests; the upstream docs tree
is unchanged. The filtered ancestry retains the earlier import history.
Toolkit-specific integration changes remain in the destination tree.

## Validation

- Frozen pnpm 11 offline install, workspace typecheck/build (`pnpm run
tsc`), and workspace lint pass. Lint reports two pre-existing warnings
outside this change.
- CLI unit suite passes: 479 files, 10,183 passed, 13 skipped. Focused
error-reporting tests pass: 92 tests.
- The workspace `pnpm run test` reached the MCP core suite after the CLI
suite passed, then hit the local command's 10-minute timeout. Exact-head
CI validates the remaining packages.
- Earlier import validation passed the CLI docs static build,
generated-definition and documentation checks, workflow YAML/actionlint
checks, the compiled Linux CLI binary, and the CLI E2E suite (144
passed, 3 skipped).

Full-range `git diff --check` reports trailing whitespace inherited from
the original byte-identical release import. Integration commits pass
`git diff --check`; preserving imported history avoids rewriting the
source commits.

Closes getsentry/cli#1239.

Administrative migration is tracked separately in getsentry/cli#1597.
The source repository must not be archived until that workflow has
migrated settings, open PRs have destination replacements, this
integration PR has merged, and release/deployment cutover gates pass.

This branch was successfully deployed

2 active deployments
Preview – sentry-local — 1ebf8ee3 Deployed Sep 18, 2026 by vercel[bot]
Preview – cli — 1ebf8ee3 Deployed Sep 18, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

risk: medium PR risk score: medium

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant