Skip to content

Harden GitHub release workflow - #4

Merged
Leoncl2025 merged 1 commit into
mainfrom
fix/release-workflow
Aug 22, 2026
Merged

Leoncl2025 merged 1 commit into
mainfrom
fix/release-workflow

Conversation

@Leoncl2025

Copy link
Copy Markdown
Owner

Summary

  • validate monotonically increasing numeric release versions and reject reused tags
  • atomically push the version commit and annotated tag, then dispatch the tagged Windows build with the ephemeral GitHub token
  • verify tag/version consistency and create or update only a draft GitHub Release with explicit repository context

Why

The repository has no published releases. The existing tag release job ran without repository context, so gh release could not reliably create the draft. The release workflow also depended on an unverified long-lived secret and did not guard against malformed versions, reused tags, or overwriting published assets.

Validation

  • actionlint v1.7.12 .github/workflows/create_release.yml .github/workflows/build.yml
  • YAML parse and PowerShell AST parse
  • version validation fixtures: 0.14 -> 0.15 passes; malformed, non-increasing, and reused-tag cases fail
  • git diff --check

After merge

Run Actions > Create Release from main with an unused version such as 0.15. The workflow creates the version commit and tag, dispatches the tagged Windows build, and creates a Draft Release containing Setup, Portable, source, and checksum assets. Review the draft and applicable signing/GPL/security gates before publishing it.

@Leoncl2025
Leoncl2025 merged commit e58210e into main Aug 22, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant