From 04fceb3c2b6048ad04cfd91395eafea02d145f46 Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Tue, 22 Sep 2026 16:58:38 -0300 Subject: [PATCH 1/2] chore: publish github-workflows v0.6.18 --- .github/workflows/publish-v0.6.18.yml | 50 +++++++++++++++++++++++++++ 1 file changed, 50 insertions(+) create mode 100644 .github/workflows/publish-v0.6.18.yml diff --git a/.github/workflows/publish-v0.6.18.yml b/.github/workflows/publish-v0.6.18.yml new file mode 100644 index 0000000..eb67bc6 --- /dev/null +++ b/.github/workflows/publish-v0.6.18.yml @@ -0,0 +1,50 @@ +# SPDX-FileCopyrightText: 2026 LibreCode coop and contributors +# SPDX-License-Identifier: AGPL-3.0-or-later + +name: Publish github-workflows v0.6.18 +on: + push: + branches: + - main + paths: + - '.github/workflows/publish-v0.6.18.yml' + +permissions: + contents: write + +jobs: + publish: + runs-on: ubuntu-latest + timeout-minutes: 10 + env: + TAG: v0.6.18 + GH_TOKEN: ${{ github.token }} + steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + fetch-depth: 0 + persist-credentials: true + + - name: Create release tag + shell: bash + run: | + set -euo pipefail + remote_sha="$(git ls-remote --tags origin "refs/tags/${TAG}" | awk '{print $1}')" + if [[ -n "${remote_sha}" ]]; then + if [[ "${remote_sha}" != "${GITHUB_SHA}" ]]; then + echo "::error::${TAG} already exists at ${remote_sha}, expected ${GITHUB_SHA}" + exit 1 + fi + git tag "${TAG}" "${GITHUB_SHA}" 2>/dev/null || true + else + git tag "${TAG}" "${GITHUB_SHA}" + git push origin "refs/tags/${TAG}" + fi + + - name: Publish GitHub release + run: | + if gh release view "${TAG}" >/dev/null 2>&1; then + echo "Release ${TAG} already exists." + exit 0 + fi + gh release create "${TAG}" --verify-tag --title "${TAG}" --generate-notes From d38de6c274620263e35610d3b8c21df1518f2fe4 Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Tue, 22 Sep 2026 16:59:09 -0300 Subject: [PATCH 2/2] fix: publish tag without persisted checkout credentials --- .github/workflows/publish-v0.6.18.yml | 14 ++++++-------- 1 file changed, 6 insertions(+), 8 deletions(-) diff --git a/.github/workflows/publish-v0.6.18.yml b/.github/workflows/publish-v0.6.18.yml index eb67bc6..9839b10 100644 --- a/.github/workflows/publish-v0.6.18.yml +++ b/.github/workflows/publish-v0.6.18.yml @@ -23,22 +23,20 @@ jobs: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 - persist-credentials: true + persist-credentials: false - name: Create release tag shell: bash run: | set -euo pipefail - remote_sha="$(git ls-remote --tags origin "refs/tags/${TAG}" | awk '{print $1}')" - if [[ -n "${remote_sha}" ]]; then - if [[ "${remote_sha}" != "${GITHUB_SHA}" ]]; then - echo "::error::${TAG} already exists at ${remote_sha}, expected ${GITHUB_SHA}" + existing_sha="$(gh api "repos/${GITHUB_REPOSITORY}/git/ref/tags/${TAG}" --jq '.object.sha' 2>/dev/null || true)" + if [[ -n "${existing_sha}" ]]; then + if [[ "${existing_sha}" != "${GITHUB_SHA}" ]]; then + echo "::error::${TAG} already exists at ${existing_sha}, expected ${GITHUB_SHA}" exit 1 fi - git tag "${TAG}" "${GITHUB_SHA}" 2>/dev/null || true else - git tag "${TAG}" "${GITHUB_SHA}" - git push origin "refs/tags/${TAG}" + gh api --method POST "repos/${GITHUB_REPOSITORY}/git/refs" -f ref="refs/tags/${TAG}" -f sha="${GITHUB_SHA}" >/dev/null fi - name: Publish GitHub release