Skip to content

v0.6.5 - #177

Merged
samueltuyizere merged 9 commits into
mainfrom
releases
Sep 11, 2026
Merged

v0.6.5#177
samueltuyizere merged 9 commits into
mainfrom
releases

Conversation

@samueltuyizere

Copy link
Copy Markdown
Collaborator

No description provided.

samueltuyizere and others added 9 commits July 23, 2026 15:58
The 'secrets' context cannot be used in step-level if: conditions, which
made the Release workflow fail to parse on workflow_dispatch. Map the
secret to a job-level env var and check that instead.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Address security review: replace job-level SIGNPATH_API_TOKEN env (which
exposed the secret to all steps including the AI changelog) with a
preliminary boolean-check step. The token is now referenced only in the
check step and the SignPath action's with: block. Pin go-winres to v0.3.3
instead of @latest for supply-chain safety.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The submit-signing-request action does not accept input/output-artifact-path.
It requires the artifact uploaded via actions/upload-artifact (yielding a
numeric artifact-id) and writes signed output to output-artifact-directory.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Switch the signing gate from secret presence to an explicit USE_SIGNPATH
flag, so releases skip signing entirely while the SignPath certificate is
still pending. Set USE_SIGNPATH=true to enable once the cert is issued.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
USE_SIGNPATH is configured as a repository variable, not a secret.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The fallback path escaped the quotes around the revision range, passing
literal quotes to git ('"v0.6.1..HEAD"') and failing with exit 128 when
the AI changelog generation returned empty. Use normal shell quoting.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@samueltuyizere samueltuyizere self-assigned this Sep 11, 2026
@samueltuyizere
samueltuyizere merged commit 87bfbce into main Sep 11, 2026
3 of 4 checks passed
@samueltuyizere
samueltuyizere deleted the releases branch September 11, 2026 09:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant