Repository navigation
fix: release-please never triggered the actual PyPI publish - #64
Merged
Merged
Conversation
release.yml's `on: release: types: [created]` trigger has never fired for any release -- confirmed by zero runs in its history and PyPI sitting on 2.0.1 while GitHub had already tagged 2.1.0 weeks ago. Root cause: release-please-action authenticates with GITHUB_TOKEN, and GitHub Actions doesn't let GITHUB_TOKEN-triggered events start other workflows (anti-recursion rule); only workflow_dispatch and repository_dispatch are exempt. Fix: explicitly dispatch release.yml against the new release's tag once release-please-action reports a release was created, rather than relying on the release event to do it. Must target the tag specifically, not the main branch -- the pypi deploy environment's protection rules only allow deploys from refs matching v*. Manually backfilled 2.1.0 and 2.2.0 to PyPI via workflow_dispatch while diagnosing this; both are live now. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Up to standards ✅🟢 Issues
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
release.yml'son: release: types: [created]trigger has never fired, for any release — confirmed zero runs in its history, while PyPI was still sitting on2.0.1even though GitHub had already tagged2.1.0weeks ago and, as of this session,2.2.0.Root cause:
release-please-actionauthenticates withGITHUB_TOKEN, and GitHub Actions has a built-in anti-recursion rule where events triggered byGITHUB_TOKENdon't start other workflows —workflow_dispatch/repository_dispatchare the only exceptions. So thereleaseevent it creates silently never reachedrelease.yml.Fix:
release-please.ymlnow explicitly dispatchesrelease.yml(gh workflow run) against the new release's tag oncerelease-please-actionreportsreleases_created. Must target the tag specifically, notmain— confirmed by testing that thepypideploy environment's protection rules only allow deploys from refs matchingv*; a branch-ref dispatch gets rejected at the publish step even though build/smoke-test pass.2.1.0and2.2.0were both manually backfilled to PyPI viaworkflow_dispatchwhile diagnosing this — both are live now.Test plan
release.ymlagainstv2.1.0andv2.2.0tags — both built, smoke-tested, and published successfully (confirmed live viapip index versions)main(branch ref) to confirm the failure mode this fix avoids — rejected by thepypienvironment's tag-only deploy policy, as expectedon: push: branches: [main]+ the actual release-please release-creation flow in isolation)