Skip to content

Release workflow: skip the duplicate tag-push run and pin the App token action - #321

Merged
anandhu-eng merged 2 commits into
copilot/automate-release-processfrom
release-workflow-skip-bot-tag-runs
Sep 29, 2026
Merged

anandhu-eng merged 2 commits into
copilot/automate-release-processfrom
release-workflow-skip-bot-tag-runs

Conversation

@anandhu-eng

Copy link
Copy Markdown
Contributor

Follow-up to #320, targeting its branch.

Problem

The manual release now pushes its tag with the mlc-automations App token. Unlike GITHUB_TOKEN, App-token pushes start workflows, so the v* tag push starts a second run of build_wheels.yml. That run waits for the manual run to finish (concurrency group), then rebuilds and re-publishes the same version:

  • PyPI: the upload is silently skipped (skip-existing: true)
  • GitHub Release: the assets are replaced (--clobber) with the second build, which may not match what is on PyPI byte for byte

Changes

  • Skip tag-push runs started by the bot, the same approach format.yml uses:
    if: >-
      github.repository_owner == 'mlcommons'
      && !(github.event_name == 'push' && github.actor == 'mlc-automations[bot]')
    Tags pushed by people still publish. Every workflow_dispatch run still works, including retries from a tag. The skipped run shows as "Skipped" in the Actions tab.
  • Pin actions/create-github-app-token to bcd2ba49… (v3.2.0), like every other action in the workflow. It was on the floating @v1 tag. app-id still works on v3 (it's deprecated in favour of client-id), so the existing secrets are unchanged.
  • Tests: added a test for the job condition, and one that checks every action is pinned to a 40-character commit SHA. The test that asserted @v1 has been relaxed.

pytest tests/test_build_wheels_workflow.py tests/test_release_version.py: 18 passed.

Still needed outside this PR

  • mlc-automations must be added as a bypass actor on the main ruleset. The API currently shows none, so git push origin HEAD:main in "Prepare release from main" would be rejected.
  • Automate workflow-dispatched PyPI and GitHub releases #320's description still says main is fast-forwarded after publishing. It now pushes the VERSION bump to main before tagging.

🤖 Generated with Claude Code

@anandhu-eng
anandhu-eng requested a review from a team as a code owner September 23, 2026 19:36
@github-actions

Copy link
Copy Markdown

MLCommons CLA bot All contributors have signed the MLCommons CLA ✍️ ✅

@github-actions

Copy link
Copy Markdown

🤖 AI PR Review Summary

This PR updates the GitHub Actions workflow to prevent duplicate release builds triggered by the GitHub App token push by adding a condition to the job's if clause. It also pins the 'actions/create-github-app-token' action to a specific commit SHA instead of a version tag. Corresponding tests are added or updated to verify these changes. The main risk is ensuring the condition correctly prevents duplicate runs without blocking legitimate builds. The pinning to commit SHAs improves reproducibility but requires maintenance to update SHAs when actions are updated.

Comment thread .github/workflows/build_wheels.yml
Comment thread .github/workflows/build_wheels.yml
Comment thread tests/test_build_wheels_workflow.py
Comment thread tests/test_build_wheels_workflow.py
@anandhu-eng
anandhu-eng added this pull request to stack #322 September 23, 2026 19:36
anandhu-eng and others added 2 commits September 29, 2026 19:00
…action

A manual release pushes its tag with the mlc-automations App token, and
App-token pushes start workflows, so the same release was built and
uploaded a second time by a tag-push run. Skip push events whose actor is
mlc-automations[bot]; tags pushed by people and all workflow_dispatch
runs (including tag retries) are unaffected.

Also pin actions/create-github-app-token to a commit SHA (v3.2.0), like
the other actions in this workflow, and test that every action is pinned.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@anandhu-eng
anandhu-eng force-pushed the release-workflow-skip-bot-tag-runs branch from ec7d613 to c119ba5 Compare September 29, 2026 13:30
@anandhu-eng
anandhu-eng merged commit aa1014d into main Sep 29, 2026
64 checks passed
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 29, 2026
@anandhu-eng
anandhu-eng deleted the release-workflow-skip-bot-tag-runs branch September 29, 2026 13:42
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants