Skip to content

ci(release): add release-tag-guard backstop for release-please auto-tag - #1523

Merged
LucasSantana-Dev merged 2 commits into
mainfrom
ci/release-tag-guard
Jun 22, 2026
Merged

LucasSantana-Dev merged 2 commits into
mainfrom
ci/release-tag-guard

Conversation

@LucasSantana-Dev

@LucasSantana-Dev LucasSantana-Dev commented Jun 22, 2026 •

Copy link
Copy Markdown
Owner

Why

The group-pull-request-title-pattern fix (PR #1521) got the version into the release PR title (chore: release 2.20.1 ✅) — but on merge, release-please still aborted (untagged, merged release PRs outstanding) and did not tag v2.20.1. With skip-github-release: false + the PAT, its release-creation step is still unreliable here (squash-merge association + accumulated manual-tag state). v2.20.1 was tagged via the manual workaround one last time.

So release-please's auto-tag can't be relied on. This adds a deterministic backstop.

What

.github/workflows/release-tag-guard.yml — on a .release-please-manifest.json bump (i.e. a release PR merged to main), ensure v<version> exists:

  • If the tag already exists (release-please did tag it) → no-op.
  • If missing → create the tag + GitHub Release via the PAT (so release: published fires deploy.yml).

Idempotent, paths-filtered to fire only on release merges. Pairs with the title fix (kept as a precondition).

Validation

  • The guard only acts when a manifest bump leaves v<version> untagged — exactly the 4× failure mode.
  • Next release is the live test: merge the release PR → guard ensures the tag with no manual step.

ADR: decisions/2026-06-22-release-please-group-title-pattern.md (updated with the validation outcome). decision-critic recommended shipping this alongside the config fix.


Summary by cubic

Add a CI guard that auto-creates the v<version> tag and GitHub Release after a manifest bump, as a backstop for unreliable release-please auto-tagging. It prevents silent deploy skips by ensuring the release is published via the PAT and is idempotent on the GitHub Release.

  • New Features
    • Added .github/workflows/release-tag-guard.yml triggered on .release-please-manifest.json changes to main.
    • If GitHub Release v<version> exists → no-op; if missing → create the tag (if absent) and the Release using RELEASE_PLEASE_TOKEN so release: published triggers deploy.yml.
    • Idempotent by checking the Release (covers partial runs where the tag exists but the Release does not); paths-filtered to run only on release merges.

Written for commit 62cf24d. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Chores
    • Improved automated release creation workflow for more reliable deployment consistency.
    • Updated internal release automation documentation.

release-please's group-pull-request-title-pattern fix got the version into the
release PR title, but it STILL aborted ('untagged, merged release PRs
outstanding') and did not tag v2.20.1 on merge — its release-creation step is
unreliable here (squash-merge association + accumulated manual-tag state).

Add a deterministic guard: on a .release-please-manifest.json bump (release PR
merge), ensure v<version> tag + GitHub Release exist; create them via the PAT
(so release: published fires deploy) if release-please did not. Idempotent —
no-op when the tag already exists. ADR updated with the validation outcome.
@vercel

vercel Bot commented Jun 22, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
lucky Ready Ready Preview, Comment Jun 22, 2026 5:18pm

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your free trial has ended. If you'd like to continue receiving code reviews, you can add a payment method here.

@coderabbitai

coderabbitai Bot commented Jun 22, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

A new GitHub Actions workflow release-tag-guard.yml is added to act as a backstop when release-please fails to create the v<version> git tag and GitHub Release. The accompanying decision document is updated to record that this guard is the primary durable fix, replacing the prior assumption that fixing the PR title pattern alone would suffice.

Changes

Release Tag Guard Workflow and Decision Record

Layer / File(s) Summary
Workflow trigger, permissions, and checkout
.github/workflows/release-tag-guard.yml
Defines the workflow triggered on main pushes that touch .release-please-manifest.json, grants contents: write, and runs an ensure-release-tag job that checks out the repo with RELEASE_PLEASE_TOKEN and full history.
Tag/release idempotency shell logic
.github/workflows/release-tag-guard.yml
Parses the version from .release-please-manifest.json, checks for an existing GitHub Release via gh release view (exits if present), conditionally creates and pushes the git tag using git ls-remote, then calls gh release create --verify-tag with the PAT to fire the release: published event.
Decision document update
decisions/2026-06-22-release-please-group-title-pattern.md
Records that release-please still aborted after the title fix (v2.20.1 required a manual workaround), promotes the CI guard to the primary durable mechanism, and revises consequences, plan steps, and revisit triggers accordingly.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

  • LucasSantana-Dev/Lucky#1490: Introduces the core release-please.yml workflow whose tag/release creation failures this guard is designed to backstop.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the main change: adding a release-tag-guard backstop workflow for release-please auto-tagging. It is concise, specific, and clearly conveys the primary purpose of the changeset.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch ci/release-tag-guard

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions

Copy link
Copy Markdown

Failed to generate code suggestions for PR

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

2 issues found across 2 files

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread .github/workflows/release-tag-guard.yml Outdated
Comment thread decisions/2026-06-22-release-please-group-title-pattern.md
cubic P1: key idempotency on the GitHub Release (gh release view), not just the
tag — a partial prior run (tag pushed, release-create failed) would otherwise
skip on rerun and leave deploy broken. Now skip only if the Release exists;
else create the tag if missing, then the Release.

cubic P2: reconcile adr alternatives/consequences/plan/revisit sections to
reflect the guard is shipped and primary, not future.

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your free trial has ended. If you'd like to continue receiving code reviews, you can add a payment method here.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
.github/workflows/release-tag-guard.yml (1)

32-32: 🧹 Nitpick | 🔵 Trivial

Consider pinning actions/checkout to a commit SHA for supply-chain security.

While pinning actions to commit SHAs is a security best practice, the repo does not consistently apply this pattern—most workflows use version tags (@v6, @v7, etc.) for standard GitHub actions. Only select third-party actions are pinned to SHAs.

Note: Credentials must persist here for the git push on line 59, so persist-credentials: false is correctly not used.

🔒 Suggested fix
-      - uses: actions/checkout@v4
+      - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/release-tag-guard.yml at line 32, The actions/checkout
action at line 32 should be pinned to a specific commit SHA instead of using the
version tag `@v4` for enhanced supply-chain security. Replace the version tag with
the appropriate commit SHA (you can find the current SHA for the v4 release on
the GitHub Actions checkout repository). Keep persist-credentials at its default
value (true) since the git push operation on line 59 requires valid credentials
to work.

Source: Linters/SAST tools

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Nitpick comments:
In @.github/workflows/release-tag-guard.yml:
- Line 32: The actions/checkout action at line 32 should be pinned to a specific
commit SHA instead of using the version tag `@v4` for enhanced supply-chain
security. Replace the version tag with the appropriate commit SHA (you can find
the current SHA for the v4 release on the GitHub Actions checkout repository).
Keep persist-credentials at its default value (true) since the git push
operation on line 59 requires valid credentials to work.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 562174d2-d4e2-4e75-a089-cecafe4edef8

📥 Commits

Reviewing files that changed from the base of the PR and between 4ceefac and 62cf24d.

📒 Files selected for processing (2)
  • .github/workflows/release-tag-guard.yml
  • decisions/2026-06-22-release-please-group-title-pattern.md
📜 Review details
⏰ Context from checks skipped due to timeout. (13)
  • GitHub Check: Test — shared
  • GitHub Check: Test — bot
  • GitHub Check: Test — backend
  • GitHub Check: Test — frontend
  • GitHub Check: Checks
  • GitHub Check: cubic · AI code reviewer
  • GitHub Check: danger / danger
  • GitHub Check: quality / Lint (lint)
  • GitHub Check: quality / Dead code (knip)
  • GitHub Check: quality / SAST (CodeQL) (javascript-typescript)
  • GitHub Check: Security
  • GitHub Check: Build — frontend
  • GitHub Check: Build — bot
🧰 Additional context used
🪛 LanguageTool
decisions/2026-06-22-release-please-group-title-pattern.md

[uncategorized] ~39-~39: The official name of this software platform is spelled with a capital “H”.
Context: ...durable fix is the CI auto-tag guard** (.github/workflows/release-tag-guard.yml), ship...

(GITHUB)


[uncategorized] ~44-~44: The official name of this software platform is spelled with a capital “H”.
Context: ...primary durable mechanism** (shipped in .github/workflows/release-tag-guard.yml), beca...

(GITHUB)

🪛 zizmor (1.26.1)
.github/workflows/release-tag-guard.yml

[warning] 32-35: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false

(artipacked)


[error] 32-32: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)

🔇 Additional comments (5)
decisions/2026-06-22-release-please-group-title-pattern.md (1)

33-75: LGTM! The updated decision document accurately documents the validation outcome, properly promotes the CI guard to primary mechanism, and comprehensively frames the decision and its revisit triggers.

Spot-checks confirm alignment with the workflow implementation:

  • Line 52's claim that "guard guarantees the v<version> tag + GitHub Release" matches the workflow's idempotent logic (checks Release existence via gh release view, creates tag+Release if missing).
  • Line 57's "Release-existence check makes this safe" correctly describes the workflow's idempotency strategy (keyed on Release, not tag).
  • Line 74's multi-package limitation accurately identifies the guard's single-${version} assumption, a real constraint in the current setup.
  • Line 73's revisit trigger for "neither release-please nor the guard tagging" is a sound regression detector.

The validation outcome section appropriately documents why the title fix alone was insufficient (release-please still aborted post-merge despite correct PR title), justifying the guard's promotion from companion to primary. The alternatives section clearly frames the tradeoff decisions.

.github/workflows/release-tag-guard.yml (4)

1-17: LGTM!


18-22: LGTM!


24-25: LGTM!


37-65: LGTM!

@sonarqubecloud

Copy link
Copy Markdown

@LucasSantana-Dev
LucasSantana-Dev merged commit 9564b9a into main Jun 22, 2026
45 checks passed
@LucasSantana-Dev
LucasSantana-Dev deleted the ci/release-tag-guard branch June 22, 2026 17:21

This branch was successfully deployed

1 active deployment
Preview — 62cf24dc Deployed Jun 22, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant