Skip to content

fix: release workflow — use github.token and handle first release - #515

Merged
automagik-genie merged 1 commit into
mainfrom
fix/release-auth
Mar 9, 2026
Merged

automagik-genie merged 1 commit into
mainfrom
fix/release-auth

Conversation

@automagik-genie

@automagik-genie automagik-genie commented Mar 7, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Fixes the release workflow that's been failing on every push to main since v3 promotion.

Root causes:

  1. secrets.RELEASE_PLEASE_TOKEN was never set — gh CLI exits with code 4 (auth error)
  2. No previous release tag exists, so git-cliff traverses the entire v2 merge history, generating a changelog too large for shell arguments

Fixes:

  • Use github.token (built-in, already has contents: write permission) instead of a custom secret
  • Skip git-cliff entirely when no previous release tag exists
  • Fall back to "Initial release of genie v3 CLI." as release notes
  • Write notes to a temp file (--notes-file) to avoid argument length limits

Test plan

  • After merge: release workflow triggers and creates GitHub release v3.260302.2
  • npm publish step runs successfully
  • npm info @automagik/genie shows the published version

Summary by CodeRabbit

  • Chores
    • Updated release workflow automation to enhance authentication handling and release notes generation processes.

…release

- Replace secrets.RELEASE_PLEASE_TOKEN with github.token (built-in,
  already has contents:write permission)
- Skip git-cliff when no previous release tag exists (avoids
  traversing entire v2 merge history)
- Fall back to simple "Initial release" note for first v3 release
- Write notes to file to avoid argument length limits
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Note

Gemini is unable to generate a summary for this pull request due to the file types involved not being currently supported.

@coderabbitai

coderabbitai Bot commented Mar 7, 2026 •

Copy link
Copy Markdown
📝 Walkthrough

Walkthrough

GitHub Actions release workflow updated to use GitHub's built-in token instead of a custom secret, refines conditional execution for changelog generation, changes git-cliff range formatting logic, and updates release notes handling with fallback messaging.

Changes

Cohort / File(s) Summary
Release Workflow Authentication & Logic
.github/workflows/release.yml
Replaced secrets.RELEASE_PLEASE_TOKEN with github.token for gh and API authentication. Refined changelog generation to only run when a previous tag exists (checking prev.tag != ''). Updated git-cliff range argument from conditional fallback to always formatting as {prevTag}..HEAD. Modified release creation to use inline NOTES variable from cliff output with fallback to default message ("Initial release of genie v3 CLI."), writing to file for --notes-file argument.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately describes the main changes: switching from a custom secret to github.token and handling the first v3 release scenario.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch fix/release-auth

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c52c24c66b

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

run: |
TAG="v${{ steps.pkg.outputs.version }}"
printf '%s' "$RELEASE_NOTES" > /tmp/release-notes.md
NOTES="${{ steps.cliff.outputs.content }}"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Avoid interpolating release notes directly into shell code

The Create release step now inlines steps.cliff.outputs.content into NOTES="...", which means GitHub expression expansion happens before Bash parsing; if the changelog contains characters like ", backticks, or $() (common in commit subjects/body text), the script can break or perform command substitution, causing release jobs to fail unpredictably. This regression is introduced by moving from an env var to direct inline assignment, so release notes should be passed in a way that bypasses shell parsing.

Useful? React with 👍 / 👎.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In @.github/workflows/release.yml:
- Around line 71-73: The fallback NOTES assignment currently sets "Initial
release of genie v3 CLI." which can be incorrect when git-cliff ran but produced
no output; update the logic in the release workflow to use a neutral fallback
(e.g., set NOTES="No notable changes.") or add a check that distinguishes the
git-cliff step being skipped vs run-but-empty (inspect the git-cliff output
variable or file before assigning NOTES) so the fallback no longer claims an
initial release; update the block that assigns the NOTES variable accordingly.
- Around line 70-74: Replace the inline interpolation of `${{
steps.cliff.outputs.content }}` with an environment variable to avoid shell
injection: set an env entry (e.g. env: NOTES: ${{ steps.cliff.outputs.content
}}) on the workflow step that writes the file, then use the already-present
printf '%s' "$NOTES" > /tmp/release-notes.md (ensure the printf uses the quoted
"$NOTES"). This keeps the multi-line/unsafe content out of the command string
while preserving the original behavior.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: b79cb308-1f43-4b30-8742-2c708a8932e3

📥 Commits

Reviewing files that changed from the base of the PR and between 2d33429 and c52c24c.

📒 Files selected for processing (1)
  • .github/workflows/release.yml

Comment on lines +70 to +74
NOTES="${{ steps.cliff.outputs.content }}"
if [ -z "$NOTES" ]; then
NOTES="Initial release of genie v3 CLI."
fi
printf '%s' "$NOTES" > /tmp/release-notes.md

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major

Shell injection risk: avoid direct interpolation of multi-line content.

${{ steps.cliff.outputs.content }} is interpolated into the shell string before execution. If the changelog contains quotes, backticks, $, or newlines, this can break parsing or cause unexpected behavior. Pass via environment variable instead.

Proposed fix
       - name: Create release
         if: steps.exists.outputs.skip != 'true'
         env:
           GH_TOKEN: ${{ github.token }}
+          CLIFF_NOTES: ${{ steps.cliff.outputs.content }}
         run: |
           TAG="v${{ steps.pkg.outputs.version }}"
-          NOTES="${{ steps.cliff.outputs.content }}"
+          NOTES="${CLIFF_NOTES}"
           if [ -z "$NOTES" ]; then
             NOTES="Initial release of genie v3 CLI."
           fi
           printf '%s' "$NOTES" > /tmp/release-notes.md
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
NOTES="${{ steps.cliff.outputs.content }}"
if [ -z "$NOTES" ]; then
NOTES="Initial release of genie v3 CLI."
fi
printf '%s' "$NOTES" > /tmp/release-notes.md
- name: Create release
if: steps.exists.outputs.skip != 'true'
env:
GH_TOKEN: ${{ github.token }}
CLIFF_NOTES: ${{ steps.cliff.outputs.content }}
run: |
TAG="v${{ steps.pkg.outputs.version }}"
NOTES="${CLIFF_NOTES}"
if [ -z "$NOTES" ]; then
NOTES="Initial release of genie v3 CLI."
fi
printf '%s' "$NOTES" > /tmp/release-notes.md
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In @.github/workflows/release.yml around lines 70 - 74, Replace the inline
interpolation of `${{ steps.cliff.outputs.content }}` with an environment
variable to avoid shell injection: set an env entry (e.g. env: NOTES: ${{
steps.cliff.outputs.content }}) on the workflow step that writes the file, then
use the already-present printf '%s' "$NOTES" > /tmp/release-notes.md (ensure the
printf uses the quoted "$NOTES"). This keeps the multi-line/unsafe content out
of the command string while preserving the original behavior.

Comment on lines +71 to +73
if [ -z "$NOTES" ]; then
NOTES="Initial release of genie v3 CLI."
fi

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟡 Minor

Fallback message may be misleading on subsequent releases.

If git-cliff runs (previous tag exists) but produces empty output—e.g., only merge commits or non-conventional messages—the fallback claims "Initial release of genie v3 CLI." which would be incorrect for a non-initial release.

Consider a more generic fallback like "No notable changes." or check whether the cliff step was skipped vs ran-but-empty.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In @.github/workflows/release.yml around lines 71 - 73, The fallback NOTES
assignment currently sets "Initial release of genie v3 CLI." which can be
incorrect when git-cliff ran but produced no output; update the logic in the
release workflow to use a neutral fallback (e.g., set NOTES="No notable
changes.") or add a check that distinguishes the git-cliff step being skipped vs
run-but-empty (inspect the git-cliff output variable or file before assigning
NOTES) so the fallback no longer claims an initial release; update the block
that assigns the NOTES variable accordingly.

@automagik-genie
automagik-genie merged commit 7c5f9c3 into main Mar 9, 2026
4 checks passed
@coderabbitai coderabbitai Bot mentioned this pull request Apr 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant