Skip to content

ci: a release goes public only once every artifact is up - #104

Merged
sepehr-safari merged 1 commit into
mainfrom
a-release-goes-public-only-once-every-artifact-is-up
Sep 25, 2026
Merged

sepehr-safari merged 1 commit into
mainfrom
a-release-goes-public-only-once-every-artifact-is-up

Conversation

@sepehr-safari

Copy link
Copy Markdown
Contributor

Closes zig-nostr/plaza#362, together with zig-nostr/plaza#387, which makes the same change to Plaza's copy of this workflow.

  • publish runs scripts/check-release-assets.sh before lifting the draft: each expected file (Notary-vX.Y.Z-macos.zip, and each Linux tarball with its .sha256) must be listed, have state == uploaded and a non-zero size. Otherwise the release stays a draft and the step names what is missing. It fails closed if gh errors.
  • The macOS job's existing-release branch re-drafts the release before uploading.
  • The lift uses gh api with draft=false and make_latest=legacy, so re-running an older tag cannot move /releases/latest, which both installers read, back a version.

Verified: the self-test passes (each negative case asserts which file was reported) and is shellcheck clean; against v0.10.12 the check passes with all five files. The check and the lift against a real draft run for the first time on the next release, and both fail closed.

The publish job lifted the draft as soon as the macOS and Linux jobs exited 0 and claimed that meant every artifact was up. It now runs scripts/check-release-assets.sh first: every file a release of that tag should carry has to be listed by name, finished uploading and not empty, or the release stays a draft and the job names what is missing.

The macOS job's branch for a release that already exists uploaded into it while it was public. It now turns it back into a draft first, and the lift goes through the API with make_latest=legacy, so a re-run of an older tag cannot take Latest from a newer one.

The same change as Plaza's release workflow, which this one mirrors. Against v0.10.12 the check passes with all five files; CI runs its self-test.
@sepehr-safari
sepehr-safari merged commit 9c0d22d into main Sep 25, 2026
6 checks passed
@sepehr-safari
sepehr-safari deleted the a-release-goes-public-only-once-every-artifact-is-up branch September 25, 2026 07:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

The publish job says it checks the artifacts and does not

1 participant