refactor(ci): harden release follow-up jobs (force-with-lease, GH_REPO) - #51
Merged
Merged
Conversation
Follow-up to #50 with two review refinements: - update-docs pushes the changelog branch with --force-with-lease instead of --force, so a foreign commit that landed on docs/changelog-v<version> is not silently discarded on a re-run. - post-release-validation sets GH_REPO in the step env instead of passing -R on a single call. The job has no checkout, so gh cannot infer the repository from a git remote; setting it via env covers every gh call in the step and puts the explanatory comment where the root cause is. Deliberately does not add `if: startsWith(github.ref, 'refs/tags/')` guards to publish, create-github-release or post-release-validation. The workflow has a required `tag` input on workflow_dispatch and every job checks out `${{ inputs.tag || github.ref }}`, so a dispatch is the supported way to re-run the pipeline for an existing tag. During a dispatch github.ref is refs/heads/main, so such a guard would always be false and would silently skip those jobs - exactly the re-run path that v2.0.0 needed. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Contributor
🔍 PR Quality SummaryCI Status✅ Docs: success Metrics
Quality Checks
MCP Tools
🤖 Auto-generated by CI • Last updated: 2026-08-24 22:30 UTC |
This was referenced Aug 24, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #50 (merged as
a998c5a), applying two review refinements from thecomparison with the parallel PR #49.
1.
--force→--force-with-leaseupdate-docsoverwritesdocs/changelog-v<version>on a re-run of the same tag.--force-with-leasekeeps that idempotency but refuses to discard a foreigncommit that landed on the branch in the meantime. The lease basis is sound here:
the job checks out with
fetch-depth: 0, so remote-tracking refs for allbranches exist before the push.
2.
-Ron the call →GH_REPOin the step envpost-release-validationhas noactions/checkout, soghcannot infer therepository from a git remote — that was the root cause of the false
"❌ GitHub release missing". Setting it via the step env instead of a single
-Rflag covers everyghcall in the step and puts the explanatory commentwhere the cause actually is:
Deliberately not included: tag guards
PR #49 additionally adds
if: startsWith(github.ref, 'refs/tags/')topublish,create-github-releaseandpost-release-validation. That is not adopted here,on purpose.
This workflow has a required
taginput onworkflow_dispatch, and every jobchecks out
ref: ${{ inputs.tag || github.ref }}— a dispatch is the intended wayto re-run the pipeline for an existing tag. During a
workflow_dispatchrun,github.refisrefs/heads/main, so the condition would always evaluate tofalseand those three jobs would be silently skipped. That is precisely there-run path that v2.0.0 depended on (three attempts, because of the mypy/3.12
gate).
Validation
actionlint .github/workflows/release.yml— no findings in the changed jobs(remaining SC2086/SC2046 infos are pre-existing, in untouched jobs)
grep startsWith(github.refconfirms no tag guards were introduced[Unreleased] / ### Fixedwording updated to match theGH_REPOapproachOnly
update-docsandpost-release-validationare touched. No release run, notag created, release workflow not triggered.