Skip to content

Commit 4e5da1f

Browse files
authored
Harden release post-publication workflows (#134)
Prevent false-red release bookkeeping by writing JSON through an explicit UTF-8 file, retrying GitHub Release visibility and checksum download, and running the legacy artifact publisher only for an explicit verified publication request.
2 parents f3548b3 + 583ace5 commit 4e5da1f

3 files changed

Lines changed: 38 additions & 9 deletions

File tree

‎.github/workflows/publish-verified-release.yml‎

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5,8 +5,6 @@ on:
55
branches: [ main ]
66
paths:
77
- ".release/publish-verified.json"
8-
- "landing/release-notes.json"
9-
- ".github/workflows/publish-verified-release.yml"
108
push:
119
branches: [ main ]
1210
paths:

‎.github/workflows/release-windows.yml‎

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -450,5 +450,10 @@ jobs:
450450
if ($existingSha) { $body.sha = $existingSha }
451451
452452
$request = $body | ConvertTo-Json -Compress
453-
$request | gh api --method PUT $apiPath --input - *> $null
453+
$requestPath = Join-Path $env:RUNNER_TEMP "arsas-published-release-request.json"
454+
[System.IO.File]::WriteAllText(
455+
$requestPath,
456+
$request,
457+
[System.Text.UTF8Encoding]::new($false))
458+
gh api --method PUT $apiPath --input $requestPath *> $null
454459
if ($LASTEXITCODE -ne 0) { throw "Failed to record verified release publication." }

‎.github/workflows/sync-release-documentation.yml‎

Lines changed: 32 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -47,12 +47,38 @@ jobs:
4747
run: |
4848
set -euo pipefail
4949
mkdir -p _release-sync
50-
gh api "repos/$GITHUB_REPOSITORY/releases/tags/$RELEASE_TAG" > _release-sync/release.json
51-
gh release download "$RELEASE_TAG" \
52-
--repo "$GITHUB_REPOSITORY" \
53-
--dir _release-sync \
54-
--pattern 'ARSAS-Windows-x64-SHA256SUMS.txt' \
55-
--clobber
50+
release_ready=false
51+
for attempt in $(seq 1 30); do
52+
if gh api "repos/$GITHUB_REPOSITORY/releases/tags/$RELEASE_TAG" > _release-sync/release.tmp.json 2>/dev/null; then
53+
mv _release-sync/release.tmp.json _release-sync/release.json
54+
release_ready=true
55+
break
56+
fi
57+
echo "Release $RELEASE_TAG is not visible yet (attempt $attempt/30); retrying in 10 seconds."
58+
sleep 10
59+
done
60+
if [[ "$release_ready" != "true" ]]; then
61+
echo "Published release $RELEASE_TAG did not become visible within the synchronization window." >&2
62+
exit 1
63+
fi
64+
65+
checksum_ready=false
66+
for attempt in $(seq 1 12); do
67+
if gh release download "$RELEASE_TAG" \
68+
--repo "$GITHUB_REPOSITORY" \
69+
--dir _release-sync \
70+
--pattern 'ARSAS-Windows-x64-SHA256SUMS.txt' \
71+
--clobber; then
72+
checksum_ready=true
73+
break
74+
fi
75+
echo "Checksum asset is not downloadable yet (attempt $attempt/12); retrying in 10 seconds."
76+
sleep 10
77+
done
78+
if [[ "$checksum_ready" != "true" ]]; then
79+
echo "Checksum asset for $RELEASE_TAG did not become downloadable." >&2
80+
exit 1
81+
fi
5682
git fetch --tags --force
5783
source_commit="$(git rev-list -n 1 "$RELEASE_TAG")"
5884
if [[ ! "$source_commit" =~ ^[0-9a-f]{40}$ ]]; then

0 commit comments

Comments
 (0)