Skip to content

ci: release.yml publishes on every push to main without waiting for Validate or Blender Smoke #290

Description

@TMHSDigital

Why it matters

release.yml runs on every push to main and cuts a version, tag and release without depending on Validate or Blender Smoke. #192 records that main cannot enforce required status checks. Together, a red PR merged to main gets published as a release.

The same job also holds broad write permissions while running a third-party action referenced by a movable tag, which is supply-chain exposure. This is hardening, not a known exploit.

Evidence

  • .github/workflows/release.yml:3-6: on: push: branches: [main] plus workflow_dispatch, with no workflow_run dependency on Validate or Smoke.
  • release.yml:8-10: workflow-wide permissions: contents: write, actions: write.
  • release.yml:~120: uses: …/release-doc-sync@v1, a mutable major tag, running with that write token. Other actions are pinned to tags (actions/checkout@v7), and none are pinned to commit SHAs. drift-check@v1.15 vs release-doc-sync@v1 is also inconsistent.
  • release.yml:~152: git add -A commits whatever the action wrote. The repo's own CLAUDE.md § Git Staging forbids bulk adds for exactly this reason.

Related: #192 (no required checks), #226 (release push race).

Suggested approach

  1. Trigger release from workflow_run on successful Validate and Blender Smoke for the same head_sha. Alternatively, keep push and add a first step that polls the check-suite for the SHA and exits early unless everything is green.
  2. Move permissions: to job level, with the minimum per job.
  3. Pin third-party actions (at least the non-actions/* ones) to full commit SHAs with a # vX.Y comment. Dependabot github-actions already exists and will keep SHA pins current.
  4. Replace git add -A with the explicit files the action owns: VERSION, CHANGELOG.md, CLAUDE.md, ROADMAP.md, .cursor-plugin/plugin.json.

Done when

  • A push to main whose Validate or Smoke run fails produces no tag or release. Prove it once with a deliberately failing check.
  • No workflow grants write permissions at workflow level, and third-party actions are SHA-pinned.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions