Skip to content

fix(release): a hand-created release must really stop before the sub-module tags and the proxy ping - #618

Merged
FumingPower3925 merged 3 commits into
mainfrom
fix/release-path-defects
Sep 14, 2026
Merged

FumingPower3925 merged 3 commits into
mainfrom
fix/release-path-defects

Conversation

@FumingPower3925

Copy link
Copy Markdown
Contributor

Two release-path defects the four-repo audit found, one of which I introduced yesterday.

1. The stop-early promise was inverted. release.yml's header and GOVERNANCE.md both say a hand-created release runs the gate and CI and then stops before the sub-module tags and the Go-proxy notification. It did the opposite: on that path the publish job is skipped, and the downstream jobs were gated on (publish == 'success' || publish == 'skipped'), so both ran. The sub-module tags got pushed and notify-proxy curled proxy.golang.org for all five modules — which burns the version number the documented recovery depends on. Both jobs now also require the dispatch path.

2. The dispatch path cannot create a tag today, and GOVERNANCE now says so. The Release tags ruleset (id 22357612, active) blocks creation on refs/tags/v* with OrganizationAdmin as its only bypass actor. gh release create in the publish job runs as github-actions[bot], which is not that actor, so it will be refused. Every release cut so far was hand-tagged, so this path has never executed once — the automation I added yesterday would have failed on first use, at the tag.

Granting the bypass is a security decision and an org-admin action, so it is documented here rather than changed: the maintainer either adds the Actions identity to that ruleset's bypass list, or keeps hand-tagging and accepts the stop-early path, which is now correct.

Neither change is testable end to end without cutting a release. What is verified: actionlint clean, and the conditions now name needs.resolve.outputs.dispatch explicitly on both jobs.

…module tags and the proxy ping

The header of release.yml and GOVERNANCE.md both promised that the
release:published path runs the gate and CI and then stops. It did not.
On that path the publish job is SKIPPED, and the downstream jobs were
gated on '(publish == success || publish == skipped)', so both ran: the
sub-module tags were pushed and notify-proxy curled proxy.golang.org for
all five modules — which burns the version number the documented recovery
depends on. Both jobs now additionally require the dispatch path.

Also records in GOVERNANCE what the audit established and nobody had
noticed: the Release tags ruleset blocks creation on refs/tags/v* with
OrganizationAdmin as its only bypass actor, so the workflow's own
gh release create, running as github-actions[bot], is refused. That path
has never executed — every release to date was hand-tagged.
@FumingPower3925 FumingPower3925 added this to the v1.6.0 milestone Sep 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant