Skip to content

feat(tags): create missing tags automatically; push tags with a scoped App token, no unsigned fallback - #369

Merged
Shinrai merged 1 commit into
nextfrom
fix/sync-release-notes-auto-tags
Oct 4, 2026
Merged

Shinrai merged 1 commit into
nextfrom
fix/sync-release-notes-auto-tags

Conversation

@cldmv-bot

@cldmv-bot cldmv-bot Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

🚀 What's Changed

💥 Breaking Changes

No breaking changes

✨ Features

  • feat(tags): create missing tags automatically; push tags with a scoped App token, no unsigned fallback (214ae49)

🐛 Bug Fixes

No bug fixes

📦 Dependencies

No dependency updates

🔧 Other Changes

No other changes

👥 Contributors

…d App token, no unsigned fallback

The "refusing to allow a GitHub App to create or update workflow ...
without workflows permission" error that blocked tags on older commits
was a credential problem, not a platform limit: every tag-writing job
checked out with the default GITHUB_TOKEN, actions/checkout persisted it,
and git pushed with it. That token can never hold the workflows scope;
the App token was only used for REST calls.

- tag-health (orphaned releases, major/minor, bot signatures, unsigned,
  misaligned, orphaned tags): create the App token first, scoped to
  permission_contents + permission_workflows, and check out with it so
  pushes carry it.
- publishing (create-release, update-version-tags, publish-extras) and
  sync-release-notes: same two scopes; checkout-code gains a token input
  and create-release / update-major-version-tags persist the App token.
- tag/create: no REST fallback. A refused push throws, naming the tag and
  git's error; an unsigned tag is never created. Git calls use argv.
  fix-orphaned-releases drops its unsigned REST fallback too, and
  fix-unsigned-tags fails the job when a re-sign push is refused.
- sync-release-notes: automatic runs create missing version tags at their
  release commits, bot-signed, with the changelog file as the verbatim
  message, capped by max_new_tags (default 20) per run; the rest are
  reported for the next run. Creating missing releases stays a dispatch
  switch (each new release fires release:published).
- Tests: signed tag creation pushes a verified, heading-preserving tag; a
  refused push throws and makes no REST call and no tag.

Refs #362
@cldmv-bot cldmv-bot Bot added ! fix → next v4 flow: fix contributor PR targeting the next integration branch type: feature Implements new functionality — a PR or issue that adds a feature area: core Touches core library / runtime source code type: ci Changes to CI workflows, actions, or build pipelines type: config Changes to repository or project configuration files type: documentation Relates to docs, README updates, guides, or inline code comments labels Oct 4, 2026
@Shinrai
Shinrai merged commit 884ee39 into next Oct 4, 2026
17 checks passed
@cldmv-bot
cldmv-bot Bot deleted the fix/sync-release-notes-auto-tags branch October 4, 2026 23:04
cldmv-bot Bot added a commit that referenced this pull request Oct 5, 2026
## 🚀 What's Changed

### 💥 Breaking Changes
_No breaking changes_

### ✨ Features
- #369
  - feat(tags): create missing tags automatically; push tags with a scoped App token, no unsigned fallback (214ae49)

- #365
  - feat(sync-release-notes): run automatically as part of the standard v4 set (006752d)

### 🐛 Bug Fixes
- #365
  - fix(tags): keep Markdown headings in tag messages (--cleanup=verbatim) (84227b7)

### 📦 Dependencies
- #367
  - deps: bump brace-expansion from 5.0.9 to 5.0.12 (85aaaec)

### 🔧 Other Changes
- #366
  - docs: add v4.30.7 release notes and a What's New block to the README (dc49336)
  - docs(changelogs): backfill every shipped v4 release without a changelog file (abcb453)



<details>
<summary>👥 Contributors</summary>

- @Shinrai

</details>

<!-- co-authors -->

Co-authored-by: Shinrai <Shinrai@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: core Touches core library / runtime source code ! fix → next v4 flow: fix contributor PR targeting the next integration branch type: ci Changes to CI workflows, actions, or build pipelines type: config Changes to repository or project configuration files type: documentation Relates to docs, README updates, guides, or inline code comments type: feature Implements new functionality — a PR or issue that adds a feature

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant