Skip to content

fix(ci): single-quote tag-integrity if expression (double quotes are invalid in GHA expressions) - #60

Merged
ManningWorks merged 1 commit into
masterfrom
fix/release-check-if-quote
Sep 28, 2026
Merged

ManningWorks merged 1 commit into
masterfrom
fix/release-check-if-quote

Conversation

@ManningWorks

Copy link
Copy Markdown
Owner

What

One-line fix: single-quote the if: string literal on the tag-integrity
job in .github/workflows/release-check.yml (L38):

-    if: startsWith(github.ref, "refs/tags/v")
+    if: startsWith(github.ref, 'refs/tags/v')

Nothing else changes. No VERSION bump, no CHANGELOG, no tag, no behavior
change. tags: ['v*'] on L8 was already single-quoted and valid.

Why (regression source)

PR #59 (merged to master as merge commit 7d964d1, 2026-09-28) introduced
this file with the double-quoted literal. GitHub's expression language
accepts ONLY single quotes for string literals, so the push run
https://github.com/ManningWorks/box-audit/actions/runs/36445969064
failed in 0s with ZERO jobs: "This run likely failed because of a workflow
file issue" (not retryable). Consequence while merged: the workflow
dispatched no jobs on ANY trigger, so the tag-current gate was dead and
the new tag-integrity job could never run — every master push carried a
permanently-red release-check.

All required checks on #59's merge commit passed (smoke,
install-positive, install-negative, install-regression-fix1,
integration-seeded, integration-seeded-regression) — release-check itself
was dispatch-broken, which is what this PR fixes.

New pre-PR gate (lesson recorded)

Run actionlint (v1.7.7, https://github.com/rhysd/actionlint) on every
changed workflow file — exit 0 required.
YAML parsing alone does not
catch GitHub-expression-language defects: this file was YAML-valid
(double quotes are fine in YAML), which is why "YAML parses" review
verification missed it. Evidence for this PR:

  • Before (master file, 7d964d1):
    actionlint .github/workflows/release-check.yml → exit 1,
    L38:32: got unexpected character '"' while lexing expression ... only single quotes are available for string delimiter.
  • After (this branch): exit 0.

Verification

  • actionlint .github/workflows/release-check.yml → exit 0 (1.7.7,
    sha256-verified binary).
  • Diff is exactly 1 file / 1 line; VERSION stays 0.9.2 (untouchable —
    no-bump fix); v0.9.2 tag d493f307... → 2dcd223... untouched.

Post-merge (maintainer tail, t_ed187616 — not this PR)

Once merged: tag-current must run GREEN on the merge push (v0.9.2 is on
origin, VERSION stays 0.9.2), and the two-phase live verification
(negative v0.9.99-test teeth proof + positive v0.9.2 re-push PASS)
that #59's merge could not run is then executable. Coordinated on the
board — see t_ed187616.

@coderabbitai

coderabbitai Bot commented Sep 28, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 9187fcfd-2761-4b40-bca6-80c3a4b940a2


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@ManningWorks ManningWorks left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict: APPROVE — Standards PASS / Spec PASS

0 blocking findings, 0 non-blocking findings. All four DoD items independently re-verified (not taken on coder evidence).

Note: posted as a COMMENT-state review because the authenticated account (ManningWorks) authored this PR, and GitHub rejects a formal APPROVE on one's own PR. The verdict below is the reviewer's — the maintaining human applies the formal approval at merge time.

DoD verification

  1. Diff scope — git diff --stat origin/master...HEAD = exactly 1 file / +1/−1: .github/workflows/release-check.yml:38, if: startsWith(github.ref, "refs/tags/v") → single quotes. tags: ['v*'] (L9) and every other line byte-identical to base. No scope creep.
  2. actionlint v1.7.7 gate — binary tarball sha256 023070a2… matches upstream checksums. GREEN on branch: exit 0. RED on base origin/master (7d964d1): L38:32: got unexpected character '"' … only single quotes are available for string delimiter [expression], exit 1. Coder's RED→GREEN evidence reproduced independently.
  3. No-bump state — VERSION on branch = 0.9.2 (identical to base). v0.9.2 is an annotated tag, still peels d493f307… → 2dcd223b863dead3b2899df0d15c194df040cf7e (unchanged). No CHANGELOG delta in the diff.
  4. CI — 6/6 required checks SUCCESS on head 04350ee: smoke, install-positive, install-negative, install-regression-fix1, integration-seeded, integration-seeded-regression. mergeable=MERGEABLE, mergeStateStatus=CLEAN.

Defect context verified

Push run 36445969064 on the #59 merge commit 7d964d1 (release-check.yml, event=push): 0 jobs, conclusion=failure — confirms the zero-dispatch claim. The literal is YAML-valid (double quotes fine in YAML) but invalid in the GHA expression dialect inside the value, which is why YAML parsing missed it and actionlint is the required teeth.

Findings

None (blocking or non-blocking). The one-line change is the minimal correct fix for the dead tag-integrity gate; no adjacent issues in the file (actionlint exit 0 covers the whole workflow).

Post-merge (maintainer tail, NOT reviewer)

Merge MERGE-ONLY; confirm tag-current GREEN on the merge push; two-phase tag verification then runs on the linked card t_ed187616.

@ManningWorks
ManningWorks merged commit be9b242 into master Sep 28, 2026
8 of 9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant