fix(release): a hand-created release must really stop before the sub-module tags and the proxy ping - #618
Merged
Conversation
…module tags and the proxy ping The header of release.yml and GOVERNANCE.md both promised that the release:published path runs the gate and CI and then stops. It did not. On that path the publish job is SKIPPED, and the downstream jobs were gated on '(publish == success || publish == skipped)', so both ran: the sub-module tags were pushed and notify-proxy curled proxy.golang.org for all five modules — which burns the version number the documented recovery depends on. Both jobs now additionally require the dispatch path. Also records in GOVERNANCE what the audit established and nobody had noticed: the Release tags ruleset blocks creation on refs/tags/v* with OrganizationAdmin as its only bypass actor, so the workflow's own gh release create, running as github-actions[bot], is refused. That path has never executed — every release to date was hand-tagged.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two release-path defects the four-repo audit found, one of which I introduced yesterday.
1. The stop-early promise was inverted.
release.yml's header and GOVERNANCE.md both say a hand-created release runs the gate and CI and then stops before the sub-module tags and the Go-proxy notification. It did the opposite: on that path thepublishjob is skipped, and the downstream jobs were gated on(publish == 'success' || publish == 'skipped'), so both ran. The sub-module tags got pushed andnotify-proxycurled proxy.golang.org for all five modules — which burns the version number the documented recovery depends on. Both jobs now also require the dispatch path.2. The dispatch path cannot create a tag today, and GOVERNANCE now says so. The
Release tagsruleset (id 22357612, active) blockscreationonrefs/tags/v*withOrganizationAdminas its only bypass actor.gh release createin the publish job runs asgithub-actions[bot], which is not that actor, so it will be refused. Every release cut so far was hand-tagged, so this path has never executed once — the automation I added yesterday would have failed on first use, at the tag.Granting the bypass is a security decision and an org-admin action, so it is documented here rather than changed: the maintainer either adds the Actions identity to that ruleset's bypass list, or keeps hand-tagging and accepts the stop-early path, which is now correct.
Neither change is testable end to end without cutting a release. What is verified:
actionlintclean, and the conditions now nameneeds.resolve.outputs.dispatchexplicitly on both jobs.