Skip to content

fix: release-please never triggered the actual PyPI publish - #64

Merged
petercorke merged 2 commits into
mainfrom
fix/release-please-trigger-publish
Aug 11, 2026
Merged

petercorke merged 2 commits into
mainfrom
fix/release-please-trigger-publish

Conversation

@petercorke

Copy link
Copy Markdown
Owner

Summary

release.yml's on: release: types: [created] trigger has never fired, for any release — confirmed zero runs in its history, while PyPI was still sitting on 2.0.1 even though GitHub had already tagged 2.1.0 weeks ago and, as of this session, 2.2.0.

Root cause: release-please-action authenticates with GITHUB_TOKEN, and GitHub Actions has a built-in anti-recursion rule where events triggered by GITHUB_TOKEN don't start other workflows — workflow_dispatch/repository_dispatch are the only exceptions. So the release event it creates silently never reached release.yml.

Fix: release-please.yml now explicitly dispatches release.yml (gh workflow run) against the new release's tag once release-please-action reports releases_created. Must target the tag specifically, not main — confirmed by testing that the pypi deploy environment's protection rules only allow deploys from refs matching v*; a branch-ref dispatch gets rejected at the publish step even though build/smoke-test pass.

2.1.0 and 2.2.0 were both manually backfilled to PyPI via workflow_dispatch while diagnosing this — both are live now.

Test plan

  • Manually dispatched release.yml against v2.1.0 and v2.2.0 tags — both built, smoke-tested, and published successfully (confirmed live via pip index versions)
  • Manually dispatched against main (branch ref) to confirm the failure mode this fix avoids — rejected by the pypi environment's tag-only deploy policy, as expected
  • YAML validated
  • Real end-to-end validation of the new auto-dispatch step itself will happen the next time a release-please PR merges (can't rehearse on: push: branches: [main] + the actual release-please release-creation flow in isolation)

release.yml's `on: release: types: [created]` trigger has never fired
for any release -- confirmed by zero runs in its history and PyPI
sitting on 2.0.1 while GitHub had already tagged 2.1.0 weeks ago.
Root cause: release-please-action authenticates with GITHUB_TOKEN, and
GitHub Actions doesn't let GITHUB_TOKEN-triggered events start other
workflows (anti-recursion rule); only workflow_dispatch and
repository_dispatch are exempt.

Fix: explicitly dispatch release.yml against the new release's tag
once release-please-action reports a release was created, rather than
relying on the release event to do it. Must target the tag specifically,
not the main branch -- the pypi deploy environment's protection rules
only allow deploys from refs matching v*.

Manually backfilled 2.1.0 and 2.2.0 to PyPI via workflow_dispatch while
diagnosing this; both are live now.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@codacy-production

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@petercorke
petercorke merged commit 1458971 into main Aug 11, 2026
17 checks passed
@petercorke
petercorke deleted the fix/release-please-trigger-publish branch October 3, 2026 14:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant