Skip to content

docs: release skill never re-creates a tag and only tags a verified commit - #43

Open
alejoamiras wants to merge 2 commits into
mainfrom
worktree-release-skill-tag-guard
Open

alejoamiras wants to merge 2 commits into
mainfrom
worktree-release-skill-tag-guard

Conversation

@alejoamiras

@alejoamiras alejoamiras commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

Two fixes to the release skill's tagging step.

  • Never re-create a tag. Step 4 used to delete the remote tag before every push, so re-running it after a publish would move the tag off the commit npm's provenance names. Now it stops if the version is already on npm, if npm can't be reached, or if the tag already exists on origin (or origin can't be reached). The one legit re-tag (tag on the wrong commit, run never got to publish) is in the gotchas, with the checks to run and the user's explicit OK.
  • Only tag a verified commit. v6.0.0-rc.1 shows as Unverified: release tags are lightweight, so GitHub shows the commit's signature, and chore!: bump Aztec to 6.0.0-rc.1 #41 was rebase-merged, which strips it. Step 3 now records the SHA and stops unless GitHub reports it verified, and Step 4 tags that exact SHA. Tags stay lightweight (--no-sign).

Repo settings changed alongside this: squash-only merges, and signed commits required on main.

Tested both guards under bash -e against real cases: rc.1 already on npm, an existing tag, a new version, npm or origin down, and the unsigned rc.1 commit vs signed ones.

🤖 Generated with Claude Code

alejoamiras and others added 2 commits September 29, 2026 21:41
Step 4 deleted the remote tag before every push, so re-running it after a
publish would move a published version's tag off the commit its provenance
names. It now stops if the version is already on npm, if npm can't be
reached, or if the tag already exists on origin or origin can't be
reached. The tag is created with --no-sign so a machine with
tag.gpgSign=true still makes a lightweight tag instead of opening an
editor for a signed annotated one.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
v6.0.0-rc.1 shows as Unverified on GitHub. Its tag is lightweight, so
GitHub shows the tagged commit's signature, and that commit is unsigned:
#41 was rebase-merged, and GitHub re-creates rebase-merged commits
without a signature.

Step 3 now records the commit to release as SHA and aborts unless GitHub
reports a verified signature on it; Step 4 tags that exact SHA, so a
later checkout can't swap in an unchecked commit. The rc flow signs its
rehearse commit and pushes the branch so GitHub can verify it before the
tag exists. A new gotcha says to squash-merge into main.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@alejoamiras alejoamiras changed the title docs: stop the release skill from deleting and re-creating release tags docs: release skill never re-creates a tag and only tags a verified commit Sep 30, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant