Skip to content

Commit 1f508f1

Browse files
committed
fix(release): the workflow that published v0.1.0 still said nothing had been released
release.yml opened with "NOT YET USED: no version of ExitDrill has been tagged or released. This workflow is prepared ahead of the first tag". It ran three times on 2026-09-07 and published v0.1.0 on the third. The claim scan reads .yml and had that file in hand; no vocabulary entry matched. The wording is now an entry, so the next one is caught rather than read past. The header records what the first real run found instead: both earlier dispatches failed in the publish job with `failed to run git: fatal: not a git repository`, because that job never checks out code and gh had no remote to infer a repository from.
1 parent 4639236 commit 1f508f1

3 files changed

Lines changed: 18 additions & 4 deletions

File tree

‎.github/workflows/release.yml‎

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,12 @@ name: release
22

33
# Trusted-main, signed-tag, split-authority release, dispatch only.
44
#
5-
# NOT YET USED: no version of ExitDrill has been tagged or released. This
6-
# workflow is prepared ahead of the first tag so cutting v0.1.0 does not also
7-
# require writing a release pipeline under time pressure. It runs only when a
8-
# maintainer dispatches it with an existing signed annotated tag. The shared
5+
# First used on 2026-09-07, when it published v0.1.0 on its third dispatch: the
6+
# first two failed in the publish job, which never checks out code and so had no
7+
# git remote for `gh` to infer a repository from. Machinery that has never run
8+
# is not machinery that works, and this is the record of what running it found.
9+
# It runs only when a maintainer dispatches it with an existing signed annotated
10+
# tag. The shared
911
# authorization workflow checks out trusted main, requires stable SemVer,
1012
# verifies the annotated tag object and its SSH signature against
1113
# .github/allowed_signers, and requires the tagged commit to be an ancestor of

‎CHANGELOG.md‎

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -29,6 +29,17 @@ All notable changes will be documented here.
2929
`docs/RELEASE.md` now says the asset exists, how to use it, that it is
3030
transport tamper-evidence rather than a signature, and that `v0.1.0`'s copy
3131
carries the build-directory prefix. Nothing rewrites the published asset.
32+
- **A fifth false sentence, in the header of the workflow that released
33+
v0.1.0.** `release.yml` opened with "NOT YET USED: no version of ExitDrill
34+
has been tagged or released. This workflow is prepared ahead of the first tag
35+
so cutting v0.1.0 does not also require writing a release pipeline under time
36+
pressure." It ran three times on 2026-09-07 and published `v0.1.0` on the
37+
third. The scan reads `.yml` and had that file in hand; no vocabulary entry
38+
matched, which is the denylist limit named in the entry below, found again
39+
one file over. The wording is now an entry, and the header records what the
40+
first real run found: both earlier dispatches failed in the publish job with
41+
`failed to run git: fatal: not a git repository`, because that job never
42+
checks out code and `gh` had no remote to infer a repository from.
3243
- **The scan added last night read four false sentences and reported clean.**
3344
`test_no_document_says_this_repository_is_untagged_once_it_is` applies the
3445
README rule to every tracked file, which is the right generalisation and was

‎tests/test_release_versions.py‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -264,6 +264,7 @@ def test_the_citation_dates_no_release_that_was_never_cut() -> None:
264264
"has held only `## [Unreleased]`",
265265
"asserts nothing about the changelog",
266266
"has not cut its first release",
267+
"no version of ExitDrill has been tagged or released",
267268
)
268269

269270
#: Suffixes worth reading. A binary, a lockfile or a captured fixture does not

0 commit comments

Comments
 (0)