From 6da7c385e0c664a5f5c7050913ece601631bd768 Mon Sep 17 00:00:00 2001 From: Josh Vaughen Date: Wed, 30 Sep 2026 21:28:06 -0700 Subject: [PATCH] ci(release): publish the GitHub release after moving the major tag The release workflow built the images and moved v2 but never published a GitHub release, so the repository page still showed v2.0.1, the last one written by hand. The tag job now publishes vX.Y.Z last, with notes generated from the pull requests merged since the previous release, and leaves an existing release alone on a re-run. --- .github/workflows/release.yml | 11 +++++++++-- README.md | 6 ++++-- 2 files changed, 13 insertions(+), 4 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index be31daa..0883d25 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -1,6 +1,7 @@ # On a semver tag: build each image for amd64 and arm64, push both tags, move the -# floating major tag. Mirrors pin v in the include URL and the image name, so -# moving it is the rollout. +# floating major tag, then publish the GitHub release. Mirrors pin v in the +# include URL and the image name, so moving it is the rollout; the release comes last, +# so a published one names a version that is live. name: release on: push: @@ -51,3 +52,9 @@ jobs: major="${GITHUB_REF_NAME%%.*}" git tag -f "$major" "$GITHUB_SHA" git push -f origin "refs/tags/$major" + # Notes list the pull requests merged since the last release. A re-run finds the + # release already published and leaves it. + - name: Publish the release + env: + GH_TOKEN: ${{ github.token }} + run: gh release view "$GITHUB_REF_NAME" > /dev/null 2>&1 || gh release create "$GITHUB_REF_NAME" --verify-tag --generate-notes diff --git a/README.md b/README.md index 2021cbe..5b47b9f 100644 --- a/README.md +++ b/README.md @@ -650,6 +650,7 @@ flowchart LR df --> rel["release.yml, on a tag vX.Y.Z"] rel --> ghcr["ghcr.io/katoptra/toolbox:variant-vX.Y.Z
and :variant-vX, amd64 and arm64"] rel --> tag["the git tag vX, moved"] + tag --> gr["the GitHub release vX.Y.Z"] tag --> inc["mirrors include toolbox.yml and an engine at v2"] ghcr --> img["mirrors name IMAGE at -v2"] ``` @@ -942,8 +943,9 @@ Proton mirror. ### Releasing Tag a commit `vX.Y.Z` and push the tag. The release workflow builds both images for -amd64 and arm64, pushes `-vX.Y.Z` and `-vX`, and moves the `vX` git -tag. Every mirror pinned to `vX` picks the change up on its next run; the workflow +amd64 and arm64, pushes `-vX.Y.Z` and `-vX`, moves the `vX` git +tag, and last publishes the GitHub release `vX.Y.Z`, its notes the pull requests merged +since the one before. Every mirror pinned to `vX` picks the change up on its next run; the workflow callers follow through Dependabot. A breaking change to a verb's name or contract is a new major, and every mirror moves its two `v2` strings by hand.