From 31837ba2efa1edfa7dbb991314a3e661cf840ef4 Mon Sep 17 00:00:00 2001 From: Aaron Sachs <898627+asachs01@users.noreply.github.com> Date: Tue, 8 Sep 2026 16:49:51 -0400 Subject: [PATCH] ci(release): stop semantic-release from pushing version bumps to protected main MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The Release job has failed with GH006 ("Changes must be made through a pull request") since the WYRE-AI org migration (1.0.6) tightened branch protection on main. @semantic-release/git's prepare step tries to commit package.json/package-lock.json/CHANGELOG.md back to main directly, which that protection now correctly rejects — blocking every release since, including this session's threatlocker org-scoping-header fix (#29). Removes @semantic-release/git and @semantic-release/changelog from the plugin pipeline (changelog's local file write is pointless without git to persist it). @semantic-release/npm still bumps and publishes the package version correctly on its own; only the commit-back is gone. Same fix conduit's own release pipeline already adopted for this exact GH006 class — release notes move to GitHub Releases, this file becomes hand-maintained going forward. Claude-Session: https://claude.ai/code/session_01DYZ5f9GLKpF8Cke9Xoh3a8 --- .releaserc.json | 13 ------------- CHANGELOG.md | 2 ++ 2 files changed, 2 insertions(+), 13 deletions(-) diff --git a/.releaserc.json b/.releaserc.json index dc96bab..920cd26 100644 --- a/.releaserc.json +++ b/.releaserc.json @@ -13,20 +13,7 @@ "plugins": [ "@semantic-release/commit-analyzer", "@semantic-release/release-notes-generator", - [ - "@semantic-release/changelog", - { - "changelogFile": "CHANGELOG.md" - } - ], "@semantic-release/npm", - [ - "@semantic-release/git", - { - "assets": ["package.json", "package-lock.json", "CHANGELOG.md"], - "message": "chore(release): ${nextRelease.version} [skip ci]\n\n${nextRelease.notes}" - } - ], "@semantic-release/github" ] } \ No newline at end of file diff --git a/CHANGELOG.md b/CHANGELOG.md index 236eed0..29d2e07 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,3 +1,5 @@ +> Release notes from 1.0.7 onward are published on the [GitHub Releases page](https://github.com/WYRE-AI/node-threatlocker/releases) instead of here. `@semantic-release/git` was removed from `.releaserc.json` because it tried to push the version bump directly to `main`, which branch protection (added as part of the WYRE-AI org migration, 1.0.6) correctly rejects — semantic-release still bumps and publishes the package version correctly, it just no longer commits that bump back to this file. The history below (1.0.6 and earlier) is kept as the record. + ## [1.0.6](https://github.com/WYRE-AI/node-threatlocker/compare/v1.0.5...v1.0.6) (2026-08-25)