From 090d129283570eb06d8fa2d547356d5fc3ce2e9c Mon Sep 17 00:00:00 2001 From: cucadmuh <49571317+cucadmuh@users.noreply.github.com> Date: Fri, 1 May 2026 21:44:44 +0300 Subject: [PATCH] Fix/release create tag before verify (#403) * fix(release): create missing app-v tag before release verification Ensure reusable publish creates and pushes the expected app-v tag when absent, then validates it points to source_ref. This prevents release records with tag_name but no git refs/tags object, which previously broke Source code archives. * fix(release): pin tauri publish to tagged release metadata Pass tagName/releaseName/releaseDraft/prerelease to tauri-action in addition to releaseId, so asset upload fallback remains bound to the expected app-v release instead of creating untagged releases. * chore(ci): align workflow action versions for release flow Update github-script usage to v9 across release-related workflows and keep the current tauri-action release binding changes in the same branch for testing. --- .github/workflows/promote-main-to-next.yml | 2 +- .github/workflows/promote-next-to-release.yml | 2 +- .github/workflows/reusable-channel-publish.yml | 6 +++--- .github/workflows/validate-main-green-ci.yml | 2 +- 4 files changed, 6 insertions(+), 6 deletions(-) diff --git a/.github/workflows/promote-main-to-next.yml b/.github/workflows/promote-main-to-next.yml index e31b5566..8afb8dfe 100644 --- a/.github/workflows/promote-main-to-next.yml +++ b/.github/workflows/promote-main-to-next.yml @@ -72,7 +72,7 @@ jobs: - name: push next run: git push --force-with-lease origin HEAD:next - name: dispatch Next Channel workflow - uses: actions/github-script@v7 + uses: actions/github-script@v9 env: SOURCE_ONLY: ${{ inputs.source_only && 'true' || 'false' }} with: diff --git a/.github/workflows/promote-next-to-release.yml b/.github/workflows/promote-next-to-release.yml index 70bce82c..ca8bbb77 100644 --- a/.github/workflows/promote-next-to-release.yml +++ b/.github/workflows/promote-next-to-release.yml @@ -57,7 +57,7 @@ jobs: - name: push release run: git push --force-with-lease origin HEAD:release - name: dispatch Release Channel workflow - uses: actions/github-script@v7 + uses: actions/github-script@v9 env: SOURCE_ONLY: ${{ inputs.source_only && 'true' || 'false' }} with: diff --git a/.github/workflows/reusable-channel-publish.yml b/.github/workflows/reusable-channel-publish.yml index d3dfc503..df7f9a1e 100644 --- a/.github/workflows/reusable-channel-publish.yml +++ b/.github/workflows/reusable-channel-publish.yml @@ -148,7 +148,7 @@ jobs: echo "$EOF_MARKER" >> "$GITHUB_OUTPUT" - name: create or update release id: create_release - uses: actions/github-script@v7 + uses: actions/github-script@v9 env: PACKAGE_VERSION: ${{ steps.get-version.outputs.version }} RELEASE_TAG: ${{ steps.tag.outputs.value }} @@ -214,7 +214,7 @@ jobs: exit 1 fi - name: verify release-tag binding - uses: actions/github-script@v7 + uses: actions/github-script@v9 env: RELEASE_ID: ${{ steps.create_release.outputs.release_id }} EXPECTED_TAG: ${{ steps.tag.outputs.value }} @@ -324,7 +324,7 @@ jobs: mkdir -p ~/private_keys echo "${{ secrets.APPLE_API_KEY_B64 }}" | base64 --decode > ~/private_keys/AuthKey.p8 echo "APPLE_API_KEY_PATH=$HOME/private_keys/AuthKey.p8" >> "$GITHUB_ENV" - - uses: tauri-apps/tauri-action@v0 + - uses: tauri-apps/tauri-action@v1 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} VITE_LASTFM_API_KEY: ${{ secrets.VITE_LASTFM_API_KEY }} diff --git a/.github/workflows/validate-main-green-ci.yml b/.github/workflows/validate-main-green-ci.yml index 974d82a3..574bc1b9 100644 --- a/.github/workflows/validate-main-green-ci.yml +++ b/.github/workflows/validate-main-green-ci.yml @@ -32,7 +32,7 @@ jobs: checks: read steps: - name: validate required checks - uses: actions/github-script@v7 + uses: actions/github-script@v9 env: TARGET_BRANCH: ${{ inputs.branch || github.event.inputs.branch || 'main' }} REQUIRED_CONTEXTS: ${{ inputs.required_contexts || github.event.inputs.required_contexts || 'ci-ok|ci-main / ci-ok' }}