Skip to content

Verify release metadata without reserved runner variables - #8

Merged
edilec merged 1 commit into
edilec:mainfrom
KRISHNAMMurarka:fix/release-workflow-input
Aug 24, 2026
Merged

edilec merged 1 commit into
edilec:mainfrom
KRISHNAMMurarka:fix/release-workflow-input

Conversation

@KRISHNAMMurarka

Copy link
Copy Markdown
Owner

Summary

  • verify the requested immutable tag against package metadata directly in the release workflow
  • verify the exact checked-out tag and dated changelog section
  • avoid GitHub reserved environment-variable behavior

Evidence

The protected release again stopped before publication because GitHub does not allow GITHUB-prefixed runtime values to be changed reliably. This implementation has no dependency on that namespace and leaves v0.1.1 untouched.

Verification

  • npm run check
  • workflow YAML parse
  • shell metadata checks for v0.1.1
  • git diff check

@edilec edilec left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Direct metadata verification avoids reserved runner variables, preserves the immutable tag, and all required CI, dependency-review, and CodeQL checks pass.

@edilec
edilec merged commit e340a79 into edilec:main Aug 24, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants