fix(ci): dispatch publish.yml on the release tag, fail if no Publish run starts - #255
Merged
Merged
Conversation
…the tag push A tag pushed with RELEASE_TOKEN did not start publish.yml for v0.3.3, leaving the release unpublished. auto-release now dispatches publish.yml on the tag ref when no push-triggered run appears and fails loudly if no Publish run exists after five minutes. publish.yml serializes runs per ref and skips a version that already has a Release or is already on Central, so a double trigger is a clean no-op. Fixes #253
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #253
Problem
auto-release.ymlpushed thev0.3.3tag withRELEASE_TOKEN, but noPublishrun ever started, so the release sat unpublished untilpublish.ymlwas dispatched on the tag by hand. Whether a pushed tag triggerson: push: tagsdepends on what kind of credential the secret holds, and the workflow can't see that.Change
Publishrun for the tag. If none appears, it runsgh workflow run publish.yml --ref "$TAG". Aworkflow_dispatchmade withGITHUB_TOKENalways triggers, and the job now hasactions: write. The step then waits up to 5 min for aPublishrun whose head branch is the tag. If none appears, the job fails with::error::and prints the manual command.concurrency: publish-${{ github.ref }},cancel-in-progress: false: runs for the same tag are serialized and never cancelled mid-deploy.refs/tags/v*ref, the credentials guard setsdeploy=false(clean no-op) when a GitHub Release for the tag already exists, or when the Central Portal's/api/v1/publisher/publishedreturns"published": trueforrift-java-core. Any other answer goes on to deploy, where a real duplicate still fails loudly.bump-snapshotis already idempotent.Validation
I couldn't run the full chain without cutting a release. Here is what I checked instead:
actionlint:auto-release.ymlis clean. The remaining findings are the same 4 shellcheck infos that are onmaster(dep-bump.yml,publish.yml's$flags,relocation-publish.yml).--ref v0.3.3), every tag-gated step ran (Releasing 0.3.3 from tag v0.3.3, Release created, snapshot bumped). Sogithub.ref/GITHUB_REF_NAMEarerefs/tags/v0.3.3/v0.3.3on a dispatch.gh run list --workflow publish.yml --branch v0.3.3returns thatworkflow_dispatchrun, and--branch v0.3.2returns thepushrun. So the filter matches both trigger kinds.v0.3.3givesdeploy=false(Release exists).v9.9.9givesdeploy=true. The Portal endpoint answeredInvalid tokento fake credentials, which confirms the endpoint exists and that a non-trueanswer proceeds.mastergivesdeploy=true.🤖 Generated with Claude Code