Skip to content

ci: isolate release publishing permissions - #2099

Closed
eoinest wants to merge 3 commits into
mainfrom
e/release/isolate-release-oidc
Closed

eoinest wants to merge 3 commits into
mainfrom
e/release/isolate-release-oidc

Conversation

@eoinest

@eoinest eoinest commented Aug 14, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • separate routine Changesets release-PR maintenance from package publishing
  • publish only after a same-repository bot release PR is merged by Ernest, Brian, or Archie
  • remove general-purpose manual publishing and recover only by rerunning the exact authenticated release event
  • allow collision recovery only when an earlier attempt of that same run reached npm publishing

Testing

  • pnpm install
  • pnpm exec oxfmt --check .github/workflows/release.yml
  • actionlint .github/workflows/*.yml
  • parsed the workflow as YAML and asserted trigger, permission, and merger invariants
  • exercised validator success, first-attempt collision rejection, pre-publish retry rejection, and partial-publish retry recovery fixtures
  • exercised current-version and stale-version binary recovery fixtures for gt and gtx-cli
  • git diff --check

Notes

  • No changeset is needed because this only changes CI configuration.
  • The GitHub release environment is now restricted to the main branch.
  • After this PR merges, add Ernest, Brian, and Archie as environment reviewers before merging any Changesets release PR. Staging that approval rule avoids pausing today's combined release-PR job.
  • ci: verify release pull request provenance #2101 adds GitHub-signed release-PR provenance and accurate generated instructions as a separate child PR.

Greptile Summary

The release workflow now allows a rerun to continue after an earlier attempt reached package publishing, so it can recover a missing CLI binary release. The previously reported recovery failure was disproved by exercising the rerun path: the workflow reached the binary check and selected the missing binary for release.

Confidence Score: 5/5

No blocking failure remains.

The exercised recovery path continues after an earlier package-publishing attempt and correctly enables the missing binary release.

T-Rex T-Rex Logs

What T-Rex did

  • T-Rex completed the requested general contract validation verification, but local artifact references were not uploaded.

T-Rex Ran code and verified through T-Rex

Reviews (4): Last reviewed commit: "fix(ci): fail closed during release reco..." | Re-trigger Greptile

@eoinest
eoinest marked this pull request as ready for review August 14, 2026 18:43
@eoinest
eoinest requested a review from a team as a code owner August 14, 2026 18:43
@github-actions

Copy link
Copy Markdown
Contributor

size-limit report 📦

Path Size
generaltranslation 18.09 KB (0%)
generaltranslation/runtime 14.87 KB (0%)
generaltranslation/id 2.55 KB (0%)
generaltranslation/internal 7.34 KB (0%)
generaltranslation/types 115 B (0%)
generaltranslation/errors 81 B (0%)
@generaltranslation/format 9.5 KB (0%)
@generaltranslation/format/types 89 B (0%)
@generaltranslation/format/internal 880 B (0%)
gt-i18n 11.88 KB (0%)
gt-i18n/types 13 B (0%)
gt-i18n/internal 22.46 KB (0%)
gt-i18n/internal/types 13 B (0%)
@generaltranslation/react-core/pure 25.76 KB (0%)
@generaltranslation/react-core/hooks 20.66 KB (0%)
@generaltranslation/react-core/components 22.96 KB (0%)
@generaltranslation/react-core/components-rsc 26.41 KB (0%)
gt-react (client) 32.08 KB (0%)
gt-react (rsc) 28.86 KB (0%)
gt-react (server) 31.88 KB (0%)
gt-react/macros 8.81 KB (0%)
gt-next (client) 43.98 KB (0%)
gt-next (rsc) 48.12 KB (0%)
gt-next (server) 44.27 KB (0%)
gt-next/config 270.01 KB (0%)
gt-next/server 46.75 KB (0%)
gt-next/middleware 36.8 KB (0%)
gt-next/link 42.86 KB (0%)
gt-next/internal/_dictionary 144 B (0%)
gt-next/internal/_load-translations 144 B (0%)
gt-next/internal/_load-dictionary 144 B (0%)
gt-next/internal/_getLocale 125 B (0%)
gt-next/internal/_getRegion 122 B (0%)
gt-node 23.48 KB (0%)
gt-node/types 219 B (0%)
gt-node/internal 13.45 KB (0%)
gt-tanstack-start (client) 31.86 KB (0%)
gt-tanstack-start (server) 32.29 KB (0%)
gt-tanstack-start/server 10.24 KB (0%)
gt-react-native 30.29 KB (0%)
gt-react-native/plugin 4.6 KB (0%)
gt-react-native/internal 746 B (0%)

@eoinest
eoinest marked this pull request as draft August 14, 2026 18:47
Comment thread .github/workflows/release.yml Outdated
Base automatically changed from e/ci/pin-actions to main August 14, 2026 19:20
@eoinest
eoinest force-pushed the e/release/isolate-release-oidc branch from b501271 to dbf10f2 Compare August 14, 2026 19:20
@eoinest

eoinest commented Aug 14, 2026

Copy link
Copy Markdown
Contributor Author

@greptileai Please perform another review of the current PR head. During that review, resolve your own prior review threads when the issue is fixed or no longer applies. Do not resolve threads created by other reviewers.

@eoinest

eoinest commented Aug 14, 2026

Copy link
Copy Markdown
Contributor Author

@greptileai Please perform another review of the current PR head. During that review, resolve your own prior review threads when the issue is fixed or no longer applies. Do not resolve threads created by other reviewers.

@eoinest
eoinest marked this pull request as ready for review August 25, 2026 22:24
@eoinest
eoinest requested a review from a team as a code owner August 25, 2026 22:24
@eoinest

eoinest commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Closing this pull request automatically because it has been open for more than 14 days. Reopen it if the work is still active, and add the keep-open label to exempt it from this weekly cleanup.

@eoinest eoinest closed this Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant