You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
auto-release pushes the version tag but publish.yml never runs (v0.3.3 was left unpublished) #253
The auto-release chain cut v0.3.3 but did not publish it. publish.yml never ran for the tag, so the release sat unpublished until someone ran publish.yml on the tag ref by hand.
pom 0.3.3-SNAPSHOT -> release 0.3.3 (tag v0.3.3).
* [new tag] v0.3.3 -> v0.3.3
Pushed v0.3.3; publish.yml will deploy it and bump the snapshot.
No Publish run was created, neither for the v0.3.3 tag push nor for the squash-merge push to master (the merge was made with GITHUB_TOKEN, which is expected not to trigger). gh run list --workflow publish.yml still showed v0.3.2 as the newest run 15+ minutes later.
A manual gh workflow run publish.yml --ref v0.3.3 (run 36541397283) succeeded and published 0.3.3 to Maven Central.
Likely cause
A tag pushed with RELEASE_TOKEN should trigger on: push: tags. It didn't, so the token is probably:
a GITHUB_TOKEN-equivalent (for example an Actions-issued installation token), or
a PAT without the permission to trigger workflows, or
expired or rotated to a different kind of credential.
Check what RELEASE_TOKEN currently holds.
Suggested fix
Either fix the secret, or make auto-release.yml dispatch publish.yml explicitly after pushing the tag: gh workflow run publish.yml --ref "$TAG", with actions: write permission. That doesn't depend on tag-push event propagation at all. Also consider failing the auto-release job if no Publish run for the tag appears within a few minutes, so a silent no-publish can't recur.
Found while releasing for EtaCassiopeia/rift-conformance (picking up rift 0.18.1 natives for its embedded leg).
Summary
The auto-release chain cut v0.3.3 but did not publish it.
publish.ymlnever ran for the tag, so the release sat unpublished until someone ranpublish.ymlon the tag ref by hand.What happened (2026-09-29)
engine-bump.yml(dispatched) opened chore(deps): bump rift engine to 0.18.1 #252 (engine 0.18.1).CI on chore(deps): bump rift engine to 0.18.1 #252 went green, and
Auto-release on green bump(run 36535471664) merged it. The run log shows it pushed the tag:No
Publishrun was created, neither for thev0.3.3tag push nor for the squash-merge push tomaster(the merge was made withGITHUB_TOKEN, which is expected not to trigger).gh run list --workflow publish.ymlstill showed v0.3.2 as the newest run 15+ minutes later.A manual
gh workflow run publish.yml --ref v0.3.3(run 36541397283) succeeded and published 0.3.3 to Maven Central.Likely cause
A tag pushed with
RELEASE_TOKENshould triggeron: push: tags. It didn't, so the token is probably:GITHUB_TOKEN-equivalent (for example an Actions-issued installation token), orCheck what
RELEASE_TOKENcurrently holds.Suggested fix
Either fix the secret, or make
auto-release.ymldispatchpublish.ymlexplicitly after pushing the tag:gh workflow run publish.yml --ref "$TAG", withactions: writepermission. That doesn't depend on tag-push event propagation at all. Also consider failing the auto-release job if no Publish run for the tag appears within a few minutes, so a silent no-publish can't recur.Found while releasing for EtaCassiopeia/rift-conformance (picking up rift 0.18.1 natives for its embedded leg).