fix(ci): don't let the clean no-credentials scan result abort the release - #13
Merged
Merged
Conversation
…abort the release verify-bundle-secrets.sh exits 2 when no credentials are configured, which is the expected state in CI. The release step documented 2 as acceptable, but Actions runs steps under `bash -e`, so the bare call aborted the step before `rc=$?` was reached and the `case` never ran. The v1.5.1 release failed here before the canary check and the upload. Capture the exit code with `|| rc=$?` and emit an error annotation when the scan reports a real failure. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
|
4 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Why
The
v1.5.1Release run (36826457541) failed at Verify no Rokid credential reached the staged artifacts. Build, 16 KB alignment and signature checks all passed; the canary check and the upload were skipped, so no GitHub Release was created.scripts/verify-bundle-secrets.shprinted "no Rokid credentials configured locally; nothing to look for" and exited 2, which is the expected clean state in CI. The step already treats 2 as acceptable, but Actions runs it underbash -e(shell: /usr/bin/bash -e {0}in the log). The bare call aborts the step right there, sorc=$?and thecasewere never reached.This check was added in #8, and this is the first tag push since then, so it had never run.
Change
.github/workflows/release.yml, that one step only: capture the exit code with|| rc=$?, and emit an::error::annotation when the scan reports a real failure.The next step ("Verify release builds ignore configured credentials") is unchanged. There the canaries are configured, so the script returns 0 or 1, and under
-eany non-zero (including 2) fails the step, which is the strict behaviour we want.Verification
I ran the step's actual
run:block, extracted from the workflow, underbash -ewith a stub scan script:The workflow YAML still parses. The real fix can only be proven by a tag push.
Not in this PR
workflow_dispatchis also broken, so it can't be used to re-run a release:TAG="${GITHUB_REF_NAME:-${{ github.event.inputs.tag }}}"never falls back, becauseGITHUB_REF_NAMEis always set (to the branch name on a dispatch), and the checkout doesn't use thetaginput. Left for a separate change.🤖 Generated with Claude Code