Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .github/workflows/main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -29,6 +29,9 @@ jobs:
with:
version: v2.5.0

- name: Test release tag push script
run: ./scripts/release/push-to-origin_test.sh

- name: Run tests with gotestsum
run: |
mkdir -p ${{ github.workspace }}/artifacts
Expand Down
23 changes: 20 additions & 3 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,10 @@ jobs:
aws_assume_role: ${{ vars.AWS_ROLE_ARN }}
ssm_parameter_pairs: '/global/services/docker/public/username = DOCKER_USERNAME, /global/services/docker/public/token = DOCKER_TOKEN'
- name: set release token
run: echo "GITHUB_TOKEN=$GITHUB_RELEASE_TOKEN" >> $GITHUB_ENV
run: |
if [[ -n "${GITHUB_RELEASE_TOKEN:-}" ]]; then
echo "GITHUB_TOKEN=$GITHUB_RELEASE_TOKEN" >> "$GITHUB_ENV"
fi

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Publish aborts on unset GITHUB_TOKEN

High Severity

When GITHUB_RELEASE_TOKEN is empty, GITHUB_TOKEN is no longer exported to GITHUB_ENV. stage-artifacts.sh later expands $GITHUB_TOKEN under set -u, so the publish step dies before Docker Hub, Homebrew, or the GitHub release run.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit eb2eda7. Configure here.

- name: setup access for find-code-references
uses: launchdarkly/gh-actions/actions/ssh-key-by-repo@main
with:
Expand All @@ -55,7 +58,9 @@ jobs:

make build
- name: prepare release
run: ./scripts/release/prepare-release.sh
run: |
./scripts/release/prepare-release.sh
echo "RELEASE_COMMIT=$(git rev-parse HEAD)" >> "$GITHUB_ENV"
- name: publish
run: |
if [[ "$DRY_RUN" = true ]]; then
Expand All @@ -67,12 +72,24 @@ jobs:
run: |
git show -p
ls -1a "$ARTIFACT_DIRECTORY"
- name: push to origin
- name: push tag to origin
continue-on-error: true
run: ./scripts/release/push-to-origin.sh
- name: create Github release
uses: ncipollo/release-action@v1.14.0
if: ${{ !inputs.dryRun }}
with:
token: ${{ github.token }}
tag: v${{ inputs.releaseVersion }}
commit: ${{ env.RELEASE_COMMIT }}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Failed tag push cannot create release

Medium Severity

If the tag push fails, the bump commit never reaches GitHub. ncipollo/release-action cannot create a tag at RELEASE_COMMIT because the GitHub API only tags SHAs that already exist on the remote, so continue-on-error does not still produce a release.

Additional Locations (1)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit eb2eda7. Configure here.

body: ${{ inputs.changeLog }}
artifacts: ${{ env.ARTIFACT_DIRECTORY }}/*
draft: true
allowUpdates: true
updateOnlyUnreleased: true
artifactErrorsFailBuild: true
- name: publish Github release
if: ${{ !inputs.dryRun }}
env:
GH_TOKEN: ${{ github.token }}
run: gh release edit "v${LD_RELEASE_VERSION}" --draft=false
10 changes: 4 additions & 6 deletions scripts/release/push-to-origin.sh
Original file line number Diff line number Diff line change
Expand Up @@ -5,16 +5,15 @@ set -euo pipefail
release_tag="v$LD_RELEASE_VERSION"

tag_exists() (
git ls-remote --tags git@github.com:launchdarkly/ld-find-code-refs.git "refs/tags/$release_tag" | grep -q "$release_tag"
git ls-remote --tags origin "refs/tags/${release_tag}" | grep -q "refs/tags/${release_tag}$"
)

push_to_origin() (
push_tag() (
if tag_exists; then
echo "Tag $release_tag already exists. Aborting."
echo "Tag $release_tag already exists on origin. Skipping tag push."
return 0
fi

git push origin HEAD
git push origin "$release_tag"
)

Expand All @@ -23,6 +22,5 @@ if [[ "$DRY_RUN" == "true" ]]; then
git reset --hard HEAD^ # defensive
echo "Dry run mode: skipping push"
else
push_to_origin
push_tag
fi

47 changes: 47 additions & 0 deletions scripts/release/push-to-origin_test.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,47 @@
#!/bin/bash

set -euo pipefail

SCRIPT="$(cd "$(dirname "$0")" && pwd)/push-to-origin.sh"
root="$(cd "$(dirname "$0")/../.." && pwd)"
workdir=$(mktemp -d "$root/.push-to-origin-test.XXXXXX")
trap 'rm -rf "$workdir"' EXIT

git init --bare --initial-branch=main "$workdir/remote.git" >/dev/null
git clone "$workdir/remote.git" "$workdir/local" >/dev/null 2>&1
cd "$workdir/local"

git config user.email "test@example.com"
git config user.name "test"

echo init > file
git add file
git commit --no-verify -m init >/dev/null
git push -u origin main >/dev/null
main_sha=$(git rev-parse origin/main)

echo bump > file
git add file
git commit --no-verify -m bump >/dev/null
git tag v2.99.0
bump_sha=$(git rev-parse HEAD)

export LD_RELEASE_VERSION=2.99.0
export DRY_RUN=false
"$SCRIPT"

remote_tag=$(git ls-remote --tags origin "refs/tags/v2.99.0" | awk '{print $1}')
if [[ "$remote_tag" != "$bump_sha" ]]; then
echo "expected origin tag v2.99.0 -> $bump_sha, got ${remote_tag:-empty}" >&2
exit 1
fi

remote_main=$(git rev-parse origin/main)
if [[ "$remote_main" != "$main_sha" ]]; then
echo "origin/main moved; expected $main_sha, got $remote_main" >&2
exit 1
fi

"$SCRIPT"

echo "push-to-origin_test.sh ok"
Loading