From b4148cb8f9c1e0b8a00269daa0ba176ef13fae26 Mon Sep 17 00:00:00 2001 From: 0x56696B Date: Mon, 4 May 2026 17:16:07 +0300 Subject: [PATCH 1/4] chore(ci): run release pipeline after CI succeeds, not in parallel --- .github/workflows/release.yml | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 0b94fd0..005d5d6 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -1,7 +1,9 @@ name: Release on: - push: + workflow_run: + workflows: [CI] + types: [completed] branches: [main] concurrency: @@ -12,7 +14,7 @@ jobs: release: name: Bump version and publish release runs-on: ubuntu-latest - if: "!startsWith(github.event.head_commit.message, 'chore: bump version')" + if: "github.event.workflow_run.conclusion == 'success' && !startsWith(github.event.workflow_run.head_commit.message, 'chore: bump version')" permissions: contents: write @@ -33,7 +35,7 @@ jobs: - name: Determine bump type id: bump run: | - MSG=$(echo "${{ github.event.head_commit.message }}" | head -1) + MSG=$(echo "${{ github.event.workflow_run.head_commit.message }}" | head -1) if echo "$MSG" | grep -qiE "(BREAKING CHANGE|^[a-z]+(\([^)]*\))?!:)"; then echo "type=major" >> "$GITHUB_OUTPUT" elif echo "$MSG" | grep -qE "^feat(\([^)]*\))?:"; then From e0a0ca04254072946872af31b3d153959cb69fcd Mon Sep 17 00:00:00 2001 From: 0x56696B Date: Mon, 4 May 2026 17:22:06 +0300 Subject: [PATCH 2/4] chore(ci): run CI on PRs only, release on merge to main --- .github/workflows/ci.yaml | 2 -- .github/workflows/release.yml | 8 +++----- 2 files changed, 3 insertions(+), 7 deletions(-) diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index cd6dd30..04e3866 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -1,8 +1,6 @@ name: CI on: - push: - branches: [main] pull_request: branches: [main] diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 005d5d6..0b94fd0 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -1,9 +1,7 @@ name: Release on: - workflow_run: - workflows: [CI] - types: [completed] + push: branches: [main] concurrency: @@ -14,7 +12,7 @@ jobs: release: name: Bump version and publish release runs-on: ubuntu-latest - if: "github.event.workflow_run.conclusion == 'success' && !startsWith(github.event.workflow_run.head_commit.message, 'chore: bump version')" + if: "!startsWith(github.event.head_commit.message, 'chore: bump version')" permissions: contents: write @@ -35,7 +33,7 @@ jobs: - name: Determine bump type id: bump run: | - MSG=$(echo "${{ github.event.workflow_run.head_commit.message }}" | head -1) + MSG=$(echo "${{ github.event.head_commit.message }}" | head -1) if echo "$MSG" | grep -qiE "(BREAKING CHANGE|^[a-z]+(\([^)]*\))?!:)"; then echo "type=major" >> "$GITHUB_OUTPUT" elif echo "$MSG" | grep -qE "^feat(\([^)]*\))?:"; then From ec9a6ab4d3e056cebfce6483ef99db41892e6589 Mon Sep 17 00:00:00 2001 From: 0x56696B Date: Mon, 4 May 2026 17:30:00 +0300 Subject: [PATCH 3/4] fix(ci): prevent shell injection via commit message in release workflow --- .github/workflows/release.yml | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 0b94fd0..1acfbd3 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -32,8 +32,10 @@ jobs: # ------------------------------------------------------------------ # - name: Determine bump type id: bump + env: + MSG_RAW: ${{ github.event.head_commit.message }} run: | - MSG=$(echo "${{ github.event.head_commit.message }}" | head -1) + MSG=$(echo "$MSG_RAW" | head -1) if echo "$MSG" | grep -qiE "(BREAKING CHANGE|^[a-z]+(\([^)]*\))?!:)"; then echo "type=major" >> "$GITHUB_OUTPUT" elif echo "$MSG" | grep -qE "^feat(\([^)]*\))?:"; then From 099df068f34bcdcb1735a065bff16d9de3e4221e Mon Sep 17 00:00:00 2001 From: 0x56696B Date: Mon, 4 May 2026 17:35:40 +0300 Subject: [PATCH 4/4] chore(ci): restore push trigger on CI, keep release sequential via workflow_run --- .github/workflows/ci.yaml | 2 ++ .github/workflows/release.yml | 8 +++++--- 2 files changed, 7 insertions(+), 3 deletions(-) diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index 04e3866..cd6dd30 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -1,6 +1,8 @@ name: CI on: + push: + branches: [main] pull_request: branches: [main] diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 1acfbd3..7d9d51c 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -1,7 +1,9 @@ name: Release on: - push: + workflow_run: + workflows: [CI] + types: [completed] branches: [main] concurrency: @@ -12,7 +14,7 @@ jobs: release: name: Bump version and publish release runs-on: ubuntu-latest - if: "!startsWith(github.event.head_commit.message, 'chore: bump version')" + if: "github.event.workflow_run.conclusion == 'success' && !startsWith(github.event.workflow_run.head_commit.message, 'chore: bump version')" permissions: contents: write @@ -33,7 +35,7 @@ jobs: - name: Determine bump type id: bump env: - MSG_RAW: ${{ github.event.head_commit.message }} + MSG_RAW: ${{ github.event.workflow_run.head_commit.message }} run: | MSG=$(echo "$MSG_RAW" | head -1) if echo "$MSG" | grep -qiE "(BREAKING CHANGE|^[a-z]+(\([^)]*\))?!:)"; then