Skip to content

fix(ci): 发版工作流改用 RELEASE_TOKEN 以绕过 main 分支保护 - #3

Merged
Aparencia merged 1 commit into
mainfrom
dev
Jul 30, 2026
Merged

Aparencia merged 1 commit into
mainfrom
dev

Conversation

@Aparencia

Copy link
Copy Markdown
Owner

概要

修复 Version & Release 工作流两次失败(GH013)的发版链路:semantic-release 的发版推送改用 RELEASE_TOKEN(细粒度 PAT)+ ruleset Bypass(Repository admin),实现受控绕过 main 的 PR 强制规则。

变更内容

  • .github/workflows/version-release.yml
    • checkout 的 token 改为 secrets.RELEASE_TOKEN || github.token
    • semantic-release 步骤 GITHUB_TOKEN 改为 secrets.RELEASE_TOKEN || secrets.GITHUB_TOKEN
    • 未配置 secret 时回退内置 token,行为不劣化

根因

main 的 ruleset 强制 "Changes must be made through a pull request",把 semantic-release 自身的发版推送(chore(release) 提交 + CHANGELOG + tag → HEAD:main)一并拦截:

remote: error: GH013: Repository rule violations found for refs/heads/main.
remote: - Changes must be made through a pull request.

配套(已完成的仓库侧手工配置)

  1. 细粒度 PAT(仅本仓库,Contents: RW)
  2. Actions secret RELEASE_TOKEN
  3. main-protection ruleset Bypass list 添加 Repository admin

验证

合并本 PR 后 Version & Release 应成功产出 v0.25.0(CHANGELOG + tag + GitHub Release)。

前两次 Version & Release 均失败于 GH013:main 的 ruleset 强制
"Changes must be made through a pull request",把 semantic-release
自身的发版推送(chore(release) 提交 + CHANGELOG + tag → HEAD:main)
一并拦截。

修复:checkout 与 semantic-release 环境改用 secrets.RELEASE_TOKEN
(细粒度 PAT,Contents:RW,持有者为仓库 admin),配合 ruleset
Bypass list(Repository admin)实现发版链路的受控绕过;
未配置该 secret 时回退内置 token,行为与现状一致(不劣化)。

需要仓库侧配套(手工步骤):
1) 创建细粒度 PAT(仅 Entropydecrease 仓库,Contents: Read and write)
2) 仓库 Settings → Secrets → Actions 新建 RELEASE_TOKEN
3) main-protection ruleset → Bypass list 添加 Repository admin
@Aparencia
Aparencia merged commit f16db96 into main Jul 30, 2026
5 checks passed
@Aparencia

Copy link
Copy Markdown
Owner Author

🎉 This PR is included in version 0.25.0 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

Aparencia added a commit that referenced this pull request Aug 4, 2026
- #1: JWT algorithm now injected via SUPABASE_JWT_ALGORITHM (default
  HS256, aligned with Supabase default signing); placeholder detection
  prevents 'configured' false impression causing whole-site 401
- #2: remove double rollback on streaming rate-limit overrun - the Lua
  script already atomically DECRs, manual rollback let users drain
  their own quotas into negative counts
- #3: error_pattern chain/router defensive validation - missing fields
  from LLM JSON output filtered instead of 500 (ValidationError)
- #4: GLM generate_vision returns actual clamped max_tokens; vision
  chain logs truncation warning when output approaches the limit
Aparencia added a commit that referenced this pull request Sep 13, 2026
批 8 T16(欠账 #3 + 控制方新增的 T13 实测两条)。

- app/src/utils/markdownLine.ts(100 → 106):① 更正头部边界段的档位名 —— 配图行
  - ![alt](src) 落 li 档而非段落档(T13 实测 + 本单元 esbuild 复现,逐字
  <div style="font-size:12px;color:#4b5563">• ![画面要点](…)</div>);② 登记 T13 的另一条
  发现:工作台链(utils/refineDiff.ts)没有 NotePreviewView.tsx:52-67 那道配图拦截 ⇒
  配图行在工作台渲染成字面文本(只登记、不改行为);③ 登记 6 个原始 hex(utils/** 不在
  零颜色字面量守卫域,style-seams.test.ts:248)⇒ 只登记、不改值。
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant