Skip to content

Fix: authenticate release fetches through checkout - #137

Merged
0xLeif merged 1 commit into
mainfrom
leif/fix-release-fetch-auth
Jul 29, 2026
Merged

0xLeif merged 1 commit into
mainfrom
leif/fix-release-fetch-auth

Conversation

@0xLeif

@0xLeif 0xLeif commented Jul 29, 2026

Copy link
Copy Markdown
Owner

Summary

  • use checkout-managed job credentials for release tag and attest-note fetches
  • remove duplicate manual Authorization headers that failed on the macOS runner
  • retain disabled credentials for jobs without authenticated fetches
  • add distribution and provenance regression contracts

Test Plan

  • fledge verify build, serial tests, parallel tests, smoke, and release contracts
  • release provenance gate rerun
  • release distribution contract

This repairs v1.1.0 publication without moving or replacing the signed tag.

@cursor

cursor Bot commented Jul 29, 2026

Copy link
Copy Markdown

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

@0xLeif
0xLeif merged commit 9148bfa into main Jul 29, 2026
5 checks passed
@0xLeif
0xLeif deleted the leif/fix-release-fetch-auth branch July 29, 2026 05:46

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

馃挕 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 414e27a65e

鈩癸笍 About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 馃憤.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

ref: ${{ github.event_name == 'workflow_dispatch' && github.event.repository.default_branch || needs.provenance.outputs.commit }}
fetch-depth: 0
persist-credentials: false
persist-credentials: true

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Remove the second Authorization header from the release job

Persisting the checkout credential here leaves an http.https://github.com/.extraheader Authorization value in the repository, but the unchanged post-publication step at lines 264-267 adds another value with git -c; Git treats http.extraHeader as multivalued (git config --get-all exposes both), so that fetch sends duplicate Authorization headers and can fail the Release workflow after assets are uploaded. Because .github/workflows/post-release-formula.yml only updates the formula when this workflow concludes successfully, affected releases will not reach Homebrew. Use the persisted credential for that final fetch as well instead of constructing another header.

AGENTS.md reference: AGENTS.md:L125-L126

Useful? React with 馃憤聽/ 馃憥.

grep -Fq 'test "$RELEASE_TAG" = "v$(cat VERSION)"' "$workflow"
grep -Fq 'test "$("$BIN_DIR/aps" --version)" = "${RELEASE_TAG#v}"' "$workflow"
test "$(grep -c 'persist-credentials: true' "$workflow")" -eq 2
! grep -Fq 'authorization="$(printf' "$workflow"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Make the negative grep assertion fail the test

When the workflow contains the forbidden text, grep succeeds and ! changes its status to failure, but Bash disables set -e handling for commands whose status is inverted with !; execution therefore continues and this assertion never rejects anything. The current workflow still contains authorization="$(printf in its final fetch, yet this test reports success, so use an explicit conditional that exits nonzero when the pattern is found.

AGENTS.md reference: AGENTS.md:L125-L126

Useful? React with 馃憤聽/ 馃憥.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant