fix(ci): single-quote tag-integrity if expression (double quotes are invalid in GHA expressions) - #60
Conversation
…invalid in GHA expressions)
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
ManningWorks
left a comment
There was a problem hiding this comment.
Verdict: APPROVE — Standards PASS / Spec PASS
0 blocking findings, 0 non-blocking findings. All four DoD items independently re-verified (not taken on coder evidence).
Note: posted as a COMMENT-state review because the authenticated account (ManningWorks) authored this PR, and GitHub rejects a formal APPROVE on one's own PR. The verdict below is the reviewer's — the maintaining human applies the formal approval at merge time.
DoD verification
- Diff scope —
git diff --stat origin/master...HEAD= exactly 1 file / +1/−1:.github/workflows/release-check.yml:38,if: startsWith(github.ref, "refs/tags/v")→ single quotes.tags: ['v*'](L9) and every other line byte-identical to base. No scope creep. - actionlint v1.7.7 gate — binary tarball sha256
023070a2…matches upstream checksums. GREEN on branch: exit 0. RED on baseorigin/master(7d964d1):L38:32: got unexpected character '"' … only single quotes are available for string delimiter [expression], exit 1. Coder's RED→GREEN evidence reproduced independently. - No-bump state —
VERSIONon branch =0.9.2(identical to base).v0.9.2is an annotated tag, still peelsd493f307… → 2dcd223b863dead3b2899df0d15c194df040cf7e(unchanged). No CHANGELOG delta in the diff. - CI — 6/6 required checks SUCCESS on head
04350ee: smoke, install-positive, install-negative, install-regression-fix1, integration-seeded, integration-seeded-regression.mergeable=MERGEABLE,mergeStateStatus=CLEAN.
Defect context verified
Push run 36445969064 on the #59 merge commit 7d964d1 (release-check.yml, event=push): 0 jobs, conclusion=failure — confirms the zero-dispatch claim. The literal is YAML-valid (double quotes fine in YAML) but invalid in the GHA expression dialect inside the value, which is why YAML parsing missed it and actionlint is the required teeth.
Findings
None (blocking or non-blocking). The one-line change is the minimal correct fix for the dead tag-integrity gate; no adjacent issues in the file (actionlint exit 0 covers the whole workflow).
Post-merge (maintainer tail, NOT reviewer)
Merge MERGE-ONLY; confirm tag-current GREEN on the merge push; two-phase tag verification then runs on the linked card t_ed187616.
What
One-line fix: single-quote the
if:string literal on thetag-integrityjob in
.github/workflows/release-check.yml(L38):Nothing else changes. No VERSION bump, no CHANGELOG, no tag, no behavior
change.
tags: ['v*']on L8 was already single-quoted and valid.Why (regression source)
PR #59 (merged to master as merge commit
7d964d1, 2026-09-28) introducedthis file with the double-quoted literal. GitHub's expression language
accepts ONLY single quotes for string literals, so the push run
https://github.com/ManningWorks/box-audit/actions/runs/36445969064
failed in 0s with ZERO jobs: "This run likely failed because of a workflow
file issue" (not retryable). Consequence while merged: the workflow
dispatched no jobs on ANY trigger, so the
tag-currentgate was dead andthe new
tag-integrityjob could never run — every master push carried apermanently-red release-check.
All required checks on #59's merge commit passed (smoke,
install-positive, install-negative, install-regression-fix1,
integration-seeded, integration-seeded-regression) — release-check itself
was dispatch-broken, which is what this PR fixes.
New pre-PR gate (lesson recorded)
Run
actionlint(v1.7.7, https://github.com/rhysd/actionlint) on everychanged workflow file — exit 0 required. YAML parsing alone does not
catch GitHub-expression-language defects: this file was YAML-valid
(double quotes are fine in YAML), which is why "YAML parses" review
verification missed it. Evidence for this PR:
actionlint .github/workflows/release-check.yml→ exit 1,L38:32: got unexpected character '"' while lexing expression ... only single quotes are available for string delimiter.Verification
actionlint .github/workflows/release-check.yml→ exit 0 (1.7.7,sha256-verified binary).
0.9.2(untouchable —no-bump fix); v0.9.2 tag
d493f307...→2dcd223...untouched.Post-merge (maintainer tail, t_ed187616 — not this PR)
Once merged: tag-current must run GREEN on the merge push (v0.9.2 is on
origin, VERSION stays 0.9.2), and the two-phase live verification
(negative
v0.9.99-testteeth proof + positivev0.9.2re-push PASS)that #59's merge could not run is then executable. Coordinated on the
board — see t_ed187616.