Conversation
|
Beide Root Causes sind hier richtig getroffen, und Die neuen Tag-Guards deaktivieren den
|
Ergänzt: kein PyPI-Upload aus
|
| Job | Bedingung |
|---|---|
publish |
startsWith(github.ref, 'refs/tags/') && needs.validate-release.outputs.is-prerelease == 'false' |
create-github-release |
always() && startsWith(github.ref, 'refs/tags/') && … |
post-release-validation |
always() && startsWith(github.ref, 'refs/tags/') |
post-release-validation war ebenfalls nötig — mit if: always() hätte es bei jedem Dispatch am Ende "GitHub release missing" gemeldet. Ein manueller Dispatch ist damit ein sauberer Dry-Run aus Build + Quality Gates.
pre-release.yml: Tag-Guard bewusst nicht angewendet
Der Workflow hat ausschließlich workflow_dispatch als Trigger und erzeugt die rc/alpha/beta-Version selbst (inkl. Auto-Detection). Ein startsWith(github.ref, 'refs/tags/') würde ihn vollständig deaktivieren. Das Duplikat-Risiko auf TestPyPI besteht dort nur, wenn zweimal dieselbe Version generiert wird — eine andere Fragestellung als der Dispatch-Guard, die separat entschieden werden sollte.
Stattdessen dort die gleiche Least-Privilege-Lücke geschlossen, die in release.yml bereits behoben war — id-token: write stand workflow-weit:
# vorher (Workflow-Ebene) # nachher (Workflow-Ebene)
permissions: permissions:
contents: write contents: read
id-token: write # test-pypi-upload: { id-token: write }
packages: write # create-prerelease: { contents: write }packages: write war ungenutzt und ist entfernt.
Validierung
actionlint auf beiden Dateien mit identischer Befundzahl wie main (release.yml 7/7, pre-release.yml 5/5 — alle vorbestehend in unveränderten Zeilen). Alle drei if-Ausdrücke per YAML-Parse gegengeprüft.
`release.yml` accepts `workflow_dispatch`, but `publish` was only gated on `is-prerelease`. A manual run therefore proceeded all the way to the upload and would always fail, because PyPI rejects re-uploading an existing version. - `publish`, `create-github-release` and `post-release-validation` are now additionally gated on `startsWith(github.ref, 'refs/tags/')`. A manual dispatch becomes a dry run of build + quality gates with no upload attempt and no "GitHub release missing" failure at the end. - `pre-release.yml` is dispatch-only by design (it generates the rc/alpha/beta version itself), so a tag guard would disable it outright and is deliberately not applied. Its workflow-level `id-token: write` / `contents: write` / `packages: write` is rescoped instead: the default is now `contents: read`, `id-token: write` lives only in `test-pypi-upload` and `contents: write` only in `create-prerelease`. Unused `packages: write` removed. Matches the guard already present in trsdn/paperless-mcp and trsdn/obsidian-mcp. The post-publish job fixes previously in this branch landed via #50; this branch was rebuilt on top of main to keep only the remaining change. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
39a2480 to
40666d1
Compare
|
Überholt durch #50, das inzwischen gemergt ist und beide Root Causes behebt (fehlender Repo-Kontext für Die zwei Details, die hier sauberer gelöst waren, sind übernommen und liegen als #51 zum Merge bereit: Nicht übernommen wurden bewusst die zusätzlichen Danke — hier geht nichts verloren, nur konsolidiert. |
🔍 PR Quality SummaryCI Status🔄 Workflows in progress... Metrics
Quality Checks
MCP Tools
🤖 Auto-generated by CI • Last updated: 2026-08-24 22:30 UTC |
Follow-up to #48. The v2.0.0 release published to PyPI successfully via Trusted Publishing (trsdn-markitdown-mcp 2.0.0), and the GitHub release was created with both artifacts. Two jobs after the publish failed, though — this PR fixes both.
1.
update-docspushed to a protected branchThe job generated the changelog correctly and committed it, then tried
git push origin main.GITHUB_TOKENcannot bypass branch protection. It now pushes adocs/changelog-v<version>branch and opens a PR (idempotent — reuses an existing PR if the branch is already open). Addedpull-requests: writeto the job.Deliberately not done: weakening branch protection or adding a bypass.
2.
post-release-validationreported a release that exists as missingThe release was published at
22:17:21Z; this check ran at22:17:35Zandgh release view v2.0.0still failed. Root cause: the job has no checkout step, soghhad no git remote to infer the repository from. Fixed withGH_REPO: ${{ github.repository }}.Verified locally that the release does exist:
3. Drive-by in the same step:
pip index versionsThat command is explicitly experimental and would have been the next failure in the same job. Replaced with a PyPI JSON API query, verified both directions:
Validation
actionlint .github/workflows/release.yml→ 7 shellcheck findings, identical to the same file onmain(all pre-existing, in untouched lines).