Fix: authenticate release fetches through checkout - #137
Conversation
|
Bugbot is not enabled for your account, so this pull request was not reviewed. Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs. |
There was a problem hiding this comment.
馃挕 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 414e27a65e
鈩癸笍 About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 馃憤.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| ref: ${{ github.event_name == 'workflow_dispatch' && github.event.repository.default_branch || needs.provenance.outputs.commit }} | ||
| fetch-depth: 0 | ||
| persist-credentials: false | ||
| persist-credentials: true |
There was a problem hiding this comment.
Remove the second Authorization header from the release job
Persisting the checkout credential here leaves an http.https://github.com/.extraheader Authorization value in the repository, but the unchanged post-publication step at lines 264-267 adds another value with git -c; Git treats http.extraHeader as multivalued (git config --get-all exposes both), so that fetch sends duplicate Authorization headers and can fail the Release workflow after assets are uploaded. Because .github/workflows/post-release-formula.yml only updates the formula when this workflow concludes successfully, affected releases will not reach Homebrew. Use the persisted credential for that final fetch as well instead of constructing another header.
AGENTS.md reference: AGENTS.md:L125-L126
Useful? React with 馃憤聽/ 馃憥.
| grep -Fq 'test "$RELEASE_TAG" = "v$(cat VERSION)"' "$workflow" | ||
| grep -Fq 'test "$("$BIN_DIR/aps" --version)" = "${RELEASE_TAG#v}"' "$workflow" | ||
| test "$(grep -c 'persist-credentials: true' "$workflow")" -eq 2 | ||
| ! grep -Fq 'authorization="$(printf' "$workflow" |
There was a problem hiding this comment.
Make the negative grep assertion fail the test
When the workflow contains the forbidden text, grep succeeds and ! changes its status to failure, but Bash disables set -e handling for commands whose status is inverted with !; execution therefore continues and this assertion never rejects anything. The current workflow still contains authorization="$(printf in its final fetch, yet this test reports success, so use an explicit conditional that exits nonzero when the pattern is found.
AGENTS.md reference: AGENTS.md:L125-L126
Useful? React with 馃憤聽/ 馃憥.
Summary
Test Plan
This repairs v1.1.0 publication without moving or replacing the signed tag.