Commit f98c313
authored
fix(ci): validate the dispatch tag in release.yml (#71)
* fix(ci): validate the dispatch tag in release.yml
Gap I introduced in #63, caught in review of the same port to hotdata-ibis
(hotdata-dev/hotdata-ibis#44). publish.yml got a pre-checkout guard on the
dispatch input; release.yml did not, despite needing it more.
release.yml holds contents: write, and action-gh-release CREATES a tag when
tag_name does not resolve to one. So an unvalidated `tag: main` checks out
cleanly and then leaves refs/tags/main plus a release named for it, both needing
manual cleanup. publish.yml at worst wastes a run. The push path is constrained
by the v[0-9]* tag filter; the dispatch path had no constraint at all.
Same guard and same strict form as publish.yml, so the input contract matches in
both. sdk-python already had this -- its dispatch predates this work.
* fix(ci): give publish.yml the same strict dispatch guard
My description claimed parity between the two workflows and it was not true. In
this repo publish.yml never gained a pre-checkout step -- #63 only switched its
existing "Verify tag matches pyproject version" check to $TAG, which runs AFTER
checkout and is looser (^v[0-9]). So `-f tag=v1.2` or `v1.2.3rc1` was accepted
there and rejected in release.yml.
Tightening publish.yml rather than loosening release.yml, since release.sh only
ever produces X.Y.Z -- it enforces ^[0-9]+\.[0-9]+\.[0-9]+$ on explicit versions,
so the strict form is the correct contract. Both workflows now validate the same
input the same way, before fetching an arbitrary ref.
The post-checkout version match stays: it catches a tag that is well-formed but
does not match pyproject.1 parent 14bcf5d commit f98c313
2 files changed
Lines changed: 33 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
31 | 31 | | |
32 | 32 | | |
33 | 33 | | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
34 | 49 | | |
35 | 50 | | |
36 | 51 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
25 | 25 | | |
26 | 26 | | |
27 | 27 | | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
28 | 46 | | |
29 | 47 | | |
30 | 48 | | |
| |||
0 commit comments