Release workflow: skip the duplicate tag-push run and pin the App token action - #321
Merged
anandhu-eng merged 2 commits intoSep 29, 2026
Conversation
|
MLCommons CLA bot All contributors have signed the MLCommons CLA ✍️ ✅ |
🤖 AI PR Review SummaryThis PR updates the GitHub Actions workflow to prevent duplicate release builds triggered by the GitHub App token push by adding a condition to the job's if clause. It also pins the 'actions/create-github-app-token' action to a specific commit SHA instead of a version tag. Corresponding tests are added or updated to verify these changes. The main risk is ensuring the condition correctly prevents duplicate runs without blocking legitimate builds. The pinning to commit SHAs improves reproducibility but requires maintenance to update SHAs when actions are updated. |
anandhu-eng
added this pull request to stack #322
September 23, 2026 19:36
…action A manual release pushes its tag with the mlc-automations App token, and App-token pushes start workflows, so the same release was built and uploaded a second time by a tag-push run. Skip push events whose actor is mlc-automations[bot]; tags pushed by people and all workflow_dispatch runs (including tag retries) are unaffected. Also pin actions/create-github-app-token to a commit SHA (v3.2.0), like the other actions in this workflow, and test that every action is pinned. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
anandhu-eng
force-pushed
the
release-workflow-skip-bot-tag-runs
branch
from
September 29, 2026 13:30
ec7d613 to
c119ba5
Compare
arjunsuresh
approved these changes
Sep 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #320, targeting its branch.
Problem
The manual release now pushes its tag with the
mlc-automationsApp token. UnlikeGITHUB_TOKEN, App-token pushes start workflows, so thev*tag push starts a second run ofbuild_wheels.yml. That run waits for the manual run to finish (concurrency group), then rebuilds and re-publishes the same version:skip-existing: true)--clobber) with the second build, which may not match what is on PyPI byte for byteChanges
format.ymluses:workflow_dispatchrun still works, including retries from a tag. The skipped run shows as "Skipped" in the Actions tab.actions/create-github-app-tokentobcd2ba49…(v3.2.0), like every other action in the workflow. It was on the floating@v1tag.app-idstill works on v3 (it's deprecated in favour ofclient-id), so the existing secrets are unchanged.@v1has been relaxed.pytest tests/test_build_wheels_workflow.py tests/test_release_version.py: 18 passed.Still needed outside this PR
mlc-automationsmust be added as a bypass actor on themainruleset. The API currently shows none, sogit push origin HEAD:mainin "Prepare release from main" would be rejected.mainis fast-forwarded after publishing. It now pushes theVERSIONbump tomainbefore tagging.🤖 Generated with Claude Code