From cd23a8a52cde24a49bc39f709545055550c2c1cc Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=F0=9D=90=93=F0=9D=90=9E=F0=9D=90=9A=F0=9D=90=A4?= =?UTF-8?q?=F0=9D=90=A8=F0=9D=90=B0=F0=9D=90=9A?= <27560638+Teakowa@users.noreply.github.com> Date: Wed, 19 Aug 2026 00:38:28 +0800 Subject: [PATCH 1/7] fix(release): normalize GitHub Release to draft --- .github/workflows/release-please.yml | 13 +++++++------ 1 file changed, 7 insertions(+), 6 deletions(-) diff --git a/.github/workflows/release-please.yml b/.github/workflows/release-please.yml index 291d5666..3e5b6cd8 100644 --- a/.github/workflows/release-please.yml +++ b/.github/workflows/release-please.yml @@ -41,23 +41,24 @@ jobs: config-file: release-please-config.json manifest-file: .release-please-manifest.json - - name: Ensure draft GitHub Release exists + - name: Normalize GitHub Release to draft if: steps.release.outputs.release_created == 'true' env: GH_TOKEN: ${{ secrets.GH_TOKEN }} RELEASE_TAG: ${{ steps.release.outputs.tag_name }} run: | set -euo pipefail - if gh release view "${RELEASE_TAG}" --json isDraft,publishedAt >/dev/null 2>&1; then + if gh release view "${RELEASE_TAG}" --json isDraft >/dev/null 2>&1; then is_draft="$(gh release view "${RELEASE_TAG}" --json isDraft --jq .isDraft)" - published_at="$(gh release view "${RELEASE_TAG}" --json publishedAt --jq .publishedAt)" - if [[ "${is_draft}" == "true" && "${published_at}" == "null" ]]; then + if [[ "${is_draft}" == "true" ]]; then echo "draft GitHub Release ${RELEASE_TAG} already exists" exit 0 fi - echo "${RELEASE_TAG} exists but is not an unpublished draft." >&2 - exit 1 + echo "GitHub Release ${RELEASE_TAG} was published before distribution completed; returning it to draft" + gh release edit "${RELEASE_TAG}" --draft + exit 0 fi + echo "GitHub Release ${RELEASE_TAG} does not exist; creating draft" gh release create "${RELEASE_TAG}" \ --draft \ --verify-tag \ From c240066a6f8d7fa2e8f333f2a92f1c49891ae6ff Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=F0=9D=90=93=F0=9D=90=9E=F0=9D=90=9A=F0=9D=90=A4?= =?UTF-8?q?=F0=9D=90=A8=F0=9D=90=B0=F0=9D=90=9A?= <27560638+Teakowa@users.noreply.github.com> Date: Wed, 19 Aug 2026 00:58:07 +0800 Subject: [PATCH 2/7] test(release): diagnose draft release visibility --- .github/workflows/release-auth-diagnostic.yml | 40 +++++++++++++++++++ 1 file changed, 40 insertions(+) create mode 100644 .github/workflows/release-auth-diagnostic.yml diff --git a/.github/workflows/release-auth-diagnostic.yml b/.github/workflows/release-auth-diagnostic.yml new file mode 100644 index 00000000..845b5210 --- /dev/null +++ b/.github/workflows/release-auth-diagnostic.yml @@ -0,0 +1,40 @@ +name: Release auth diagnostic + +on: + pull_request: + branches: [main] + +permissions: + contents: write + +jobs: + diagnose: + if: github.head_ref == 'agent/fix-release-state-handling' + runs-on: ubuntu-latest + steps: + - name: Show GitHub CLI version + run: gh --version + + - name: Query v0.2.6 with workflow token + continue-on-error: true + env: + GH_TOKEN: ${{ github.token }} + run: | + set -uo pipefail + echo 'token=github.token' + gh release view v0.2.6 \ + --repo "$GITHUB_REPOSITORY" \ + --json tagName,isDraft,isImmutable,publishedAt,url + echo "exit=$?" + + - name: Query v0.2.6 with dedicated token + continue-on-error: true + env: + GH_TOKEN: ${{ secrets.GH_TOKEN }} + run: | + set -uo pipefail + echo 'token=secrets.GH_TOKEN' + gh release view v0.2.6 \ + --repo "$GITHUB_REPOSITORY" \ + --json tagName,isDraft,isImmutable,publishedAt,url + echo "exit=$?" From c261567db9d4c32f660773ca106c0d66a3bff1b2 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=F0=9D=90=93=F0=9D=90=9E=F0=9D=90=9A=F0=9D=90=A4?= =?UTF-8?q?=F0=9D=90=A8=F0=9D=90=B0=F0=9D=90=9A?= <27560638+Teakowa@users.noreply.github.com> Date: Wed, 19 Aug 2026 00:59:23 +0800 Subject: [PATCH 3/7] test(release): reproduce release guard expressions --- .github/workflows/release-auth-diagnostic.yml | 41 +++++++++++-------- 1 file changed, 25 insertions(+), 16 deletions(-) diff --git a/.github/workflows/release-auth-diagnostic.yml b/.github/workflows/release-auth-diagnostic.yml index 845b5210..40c6f0d4 100644 --- a/.github/workflows/release-auth-diagnostic.yml +++ b/.github/workflows/release-auth-diagnostic.yml @@ -15,26 +15,35 @@ jobs: - name: Show GitHub CLI version run: gh --version - - name: Query v0.2.6 with workflow token - continue-on-error: true + - name: Reproduce release lookups with workflow token env: GH_TOKEN: ${{ github.token }} run: | - set -uo pipefail - echo 'token=github.token' - gh release view v0.2.6 \ - --repo "$GITHUB_REPOSITORY" \ - --json tagName,isDraft,isImmutable,publishedAt,url - echo "exit=$?" + set -euo pipefail + for tag in v0.2.5 v0.2.6; do + echo "tag=${tag} token=github.token" + gh release view "${tag}" --repo "$GITHUB_REPOSITORY" \ + --json tagName,isDraft,isImmutable,publishedAt,url + printf 'isDraft=<%s>\n' "$(gh release view "${tag}" --repo "$GITHUB_REPOSITORY" --json isDraft --jq .isDraft)" + printf 'publishedAt=<%s>\n' "$(gh release view "${tag}" --repo "$GITHUB_REPOSITORY" --json publishedAt --jq .publishedAt)" + if gh release view "${tag}" --repo "$GITHUB_REPOSITORY" --json isDraft --jq '.isDraft' | grep -qx true; then + echo 'wait-expression=PASS' + else + echo 'wait-expression=FAIL' + fi + done - - name: Query v0.2.6 with dedicated token - continue-on-error: true + - name: Reproduce release guard with dedicated token env: GH_TOKEN: ${{ secrets.GH_TOKEN }} run: | - set -uo pipefail - echo 'token=secrets.GH_TOKEN' - gh release view v0.2.6 \ - --repo "$GITHUB_REPOSITORY" \ - --json tagName,isDraft,isImmutable,publishedAt,url - echo "exit=$?" + set -euo pipefail + tag=v0.2.6 + is_draft="$(gh release view "${tag}" --repo "$GITHUB_REPOSITORY" --json isDraft --jq .isDraft)" + published_at="$(gh release view "${tag}" --repo "$GITHUB_REPOSITORY" --json publishedAt --jq .publishedAt)" + printf 'isDraft=<%s> publishedAt=<%s>\n' "${is_draft}" "${published_at}" + if [[ "${is_draft}" == "true" && "${published_at}" == "null" ]]; then + echo 'guard-expression=PASS' + else + echo 'guard-expression=FAIL' + fi From 4c9383894e4ca16ed1da3788509972d265b5f3c8 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=F0=9D=90=93=F0=9D=90=9E=F0=9D=90=9A=F0=9D=90=A4?= =?UTF-8?q?=F0=9D=90=A8=F0=9D=90=B0=F0=9D=90=9A?= <27560638+Teakowa@users.noreply.github.com> Date: Wed, 19 Aug 2026 01:05:54 +0800 Subject: [PATCH 4/7] test(release): reproduce missing repository context --- .github/workflows/release-auth-diagnostic.yml | 38 +++++++------------ 1 file changed, 13 insertions(+), 25 deletions(-) diff --git a/.github/workflows/release-auth-diagnostic.yml b/.github/workflows/release-auth-diagnostic.yml index 40c6f0d4..fc151f98 100644 --- a/.github/workflows/release-auth-diagnostic.yml +++ b/.github/workflows/release-auth-diagnostic.yml @@ -15,35 +15,23 @@ jobs: - name: Show GitHub CLI version run: gh --version - - name: Reproduce release lookups with workflow token + - name: Reproduce original lookup without repository context + continue-on-error: true env: GH_TOKEN: ${{ github.token }} run: | - set -euo pipefail - for tag in v0.2.5 v0.2.6; do - echo "tag=${tag} token=github.token" - gh release view "${tag}" --repo "$GITHUB_REPOSITORY" \ - --json tagName,isDraft,isImmutable,publishedAt,url - printf 'isDraft=<%s>\n' "$(gh release view "${tag}" --repo "$GITHUB_REPOSITORY" --json isDraft --jq .isDraft)" - printf 'publishedAt=<%s>\n' "$(gh release view "${tag}" --repo "$GITHUB_REPOSITORY" --json publishedAt --jq .publishedAt)" - if gh release view "${tag}" --repo "$GITHUB_REPOSITORY" --json isDraft --jq '.isDraft' | grep -qx true; then - echo 'wait-expression=PASS' - else - echo 'wait-expression=FAIL' - fi - done + set -uo pipefail + echo 'original-command-without-checkout-or-repo:' + gh release view v0.2.6 --json isDraft --jq '.isDraft' + echo "exit=$?" - - name: Reproduce release guard with dedicated token + - name: Verify explicit repository lookup env: - GH_TOKEN: ${{ secrets.GH_TOKEN }} + GH_TOKEN: ${{ github.token }} run: | set -euo pipefail - tag=v0.2.6 - is_draft="$(gh release view "${tag}" --repo "$GITHUB_REPOSITORY" --json isDraft --jq .isDraft)" - published_at="$(gh release view "${tag}" --repo "$GITHUB_REPOSITORY" --json publishedAt --jq .publishedAt)" - printf 'isDraft=<%s> publishedAt=<%s>\n' "${is_draft}" "${published_at}" - if [[ "${is_draft}" == "true" && "${published_at}" == "null" ]]; then - echo 'guard-expression=PASS' - else - echo 'guard-expression=FAIL' - fi + echo 'explicit-repo-command:' + gh release view v0.2.6 \ + --repo "$GITHUB_REPOSITORY" \ + --json tagName,isDraft,isImmutable,publishedAt,url + test "$(gh release view v0.2.6 --repo "$GITHUB_REPOSITORY" --json isDraft --jq .isDraft)" = true From 6a3531dc7417dc8493ece9dc5fa79e48a845be46 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=F0=9D=90=93=F0=9D=90=9E=F0=9D=90=9A=F0=9D=90=A4?= =?UTF-8?q?=F0=9D=90=A8=F0=9D=90=B0=F0=9D=90=9A?= <27560638+Teakowa@users.noreply.github.com> Date: Wed, 19 Aug 2026 01:06:51 +0800 Subject: [PATCH 5/7] fix(release): keep draft ownership in release-please --- .github/workflows/release-please.yml | 24 ------------------------ 1 file changed, 24 deletions(-) diff --git a/.github/workflows/release-please.yml b/.github/workflows/release-please.yml index 3e5b6cd8..f126f84f 100644 --- a/.github/workflows/release-please.yml +++ b/.github/workflows/release-please.yml @@ -41,30 +41,6 @@ jobs: config-file: release-please-config.json manifest-file: .release-please-manifest.json - - name: Normalize GitHub Release to draft - if: steps.release.outputs.release_created == 'true' - env: - GH_TOKEN: ${{ secrets.GH_TOKEN }} - RELEASE_TAG: ${{ steps.release.outputs.tag_name }} - run: | - set -euo pipefail - if gh release view "${RELEASE_TAG}" --json isDraft >/dev/null 2>&1; then - is_draft="$(gh release view "${RELEASE_TAG}" --json isDraft --jq .isDraft)" - if [[ "${is_draft}" == "true" ]]; then - echo "draft GitHub Release ${RELEASE_TAG} already exists" - exit 0 - fi - echo "GitHub Release ${RELEASE_TAG} was published before distribution completed; returning it to draft" - gh release edit "${RELEASE_TAG}" --draft - exit 0 - fi - echo "GitHub Release ${RELEASE_TAG} does not exist; creating draft" - gh release create "${RELEASE_TAG}" \ - --draft \ - --verify-tag \ - --title "${RELEASE_TAG}" \ - --generate-notes - - name: Synchronize checked-in release metadata env: GITHUB_TOKEN: ${{ secrets.GH_TOKEN }} From 50cea23272262c03b291a16d9faecf3696fabfaa Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=F0=9D=90=93=F0=9D=90=9E=F0=9D=90=9A=F0=9D=90=A4?= =?UTF-8?q?=F0=9D=90=A8=F0=9D=90=B0=F0=9D=90=9A?= <27560638+Teakowa@users.noreply.github.com> Date: Wed, 19 Aug 2026 01:09:29 +0800 Subject: [PATCH 6/7] fix(release): use explicit repository context for GitHub releases --- .github/workflows/release.yml | 32 +++++++++++++++++++------------- 1 file changed, 19 insertions(+), 13 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index aa57f5c0..5fb87435 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -222,24 +222,24 @@ jobs: (cd release && sha256sum wright-*.tar.gz wright-*.zip > SHA256SUMS) ls -l release/ - - name: Wait for the release-please draft Release + - name: Verify the release-please draft Release env: GH_TOKEN: ${{ github.token }} run: | set -euo pipefail - for attempt in $(seq 1 30); do - if gh release view "${RELEASE_TAG}" --json isDraft --jq '.isDraft' 2>/dev/null | grep -qx true; then - exit 0 - fi - sleep 2 - done - echo "draft GitHub Release ${RELEASE_TAG} was not found" >&2 - exit 1 + release="$(gh release view "${RELEASE_TAG}" \ + --repo "${GITHUB_REPOSITORY}" \ + --json tagName,isDraft,isImmutable,url)" + echo "${release}" + test "$(jq -r .tagName <<<"${release}")" = "${RELEASE_TAG}" + test "$(jq -r .isDraft <<<"${release}")" = "true" - name: Attach native archives and checksums env: GH_TOKEN: ${{ github.token }} - run: gh release upload "${RELEASE_TAG}" release/* --clobber + run: >- + gh release upload "${RELEASE_TAG}" release/* --clobber + --repo "${GITHUB_REPOSITORY}" package-manifests: name: Generate package-manager manifests @@ -304,7 +304,9 @@ jobs: - name: Attach package-manager manifests to the draft Release env: GH_TOKEN: ${{ github.token }} - run: gh release upload "${RELEASE_TAG}" attach/* --clobber + run: >- + gh release upload "${RELEASE_TAG}" attach/* --clobber + --repo "${GITHUB_REPOSITORY}" publish-tap: name: Publish formula to homebrew-tap @@ -411,7 +413,9 @@ jobs: - name: Attach npm tarballs to the draft Release env: GH_TOKEN: ${{ github.token }} - run: gh release upload "${RELEASE_TAG}" npm-packages/*.tgz --clobber + run: >- + gh release upload "${RELEASE_TAG}" npm-packages/*.tgz --clobber + --repo "${GITHUB_REPOSITORY}" - name: Upload npm tarballs for registry publishing uses: actions/upload-artifact@v7 @@ -525,4 +529,6 @@ jobs: env: GH_TOKEN: ${{ github.token }} RELEASE_TAG: ${{ inputs.tag }} - run: gh release edit "${RELEASE_TAG}" --draft=false --latest + run: >- + gh release edit "${RELEASE_TAG}" --draft=false --latest + --repo "${GITHUB_REPOSITORY}" From 44c051a906cfa67b91a06b4e5a2cda3570a3bfc3 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=F0=9D=90=93=F0=9D=90=9E=F0=9D=90=9A=F0=9D=90=A4?= =?UTF-8?q?=F0=9D=90=A8=F0=9D=90=B0=F0=9D=90=9A?= <27560638+Teakowa@users.noreply.github.com> Date: Wed, 19 Aug 2026 01:09:46 +0800 Subject: [PATCH 7/7] test(release): remove temporary release diagnostic --- .github/workflows/release-auth-diagnostic.yml | 37 ------------------- 1 file changed, 37 deletions(-) delete mode 100644 .github/workflows/release-auth-diagnostic.yml diff --git a/.github/workflows/release-auth-diagnostic.yml b/.github/workflows/release-auth-diagnostic.yml deleted file mode 100644 index fc151f98..00000000 --- a/.github/workflows/release-auth-diagnostic.yml +++ /dev/null @@ -1,37 +0,0 @@ -name: Release auth diagnostic - -on: - pull_request: - branches: [main] - -permissions: - contents: write - -jobs: - diagnose: - if: github.head_ref == 'agent/fix-release-state-handling' - runs-on: ubuntu-latest - steps: - - name: Show GitHub CLI version - run: gh --version - - - name: Reproduce original lookup without repository context - continue-on-error: true - env: - GH_TOKEN: ${{ github.token }} - run: | - set -uo pipefail - echo 'original-command-without-checkout-or-repo:' - gh release view v0.2.6 --json isDraft --jq '.isDraft' - echo "exit=$?" - - - name: Verify explicit repository lookup - env: - GH_TOKEN: ${{ github.token }} - run: | - set -euo pipefail - echo 'explicit-repo-command:' - gh release view v0.2.6 \ - --repo "$GITHUB_REPOSITORY" \ - --json tagName,isDraft,isImmutable,publishedAt,url - test "$(gh release view v0.2.6 --repo "$GITHUB_REPOSITORY" --json isDraft --jq .isDraft)" = true