Repository navigation
fix: release workflow — use github.token and handle first release - #515
Conversation
…release - Replace secrets.RELEASE_PLEASE_TOKEN with github.token (built-in, already has contents:write permission) - Skip git-cliff when no previous release tag exists (avoids traversing entire v2 merge history) - Fall back to simple "Initial release" note for first v3 release - Write notes to file to avoid argument length limits
|
Note Gemini is unable to generate a summary for this pull request due to the file types involved not being currently supported. |
📝 WalkthroughWalkthroughGitHub Actions release workflow updated to use GitHub's built-in token instead of a custom secret, refines conditional execution for changelog generation, changes git-cliff range formatting logic, and updates release notes handling with fallback messaging. Changes
Estimated code review effort🎯 2 (Simple) | ⏱️ ~12 minutes 🚥 Pre-merge checks | ✅ 3✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c52c24c66b
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| run: | | ||
| TAG="v${{ steps.pkg.outputs.version }}" | ||
| printf '%s' "$RELEASE_NOTES" > /tmp/release-notes.md | ||
| NOTES="${{ steps.cliff.outputs.content }}" |
There was a problem hiding this comment.
Avoid interpolating release notes directly into shell code
The Create release step now inlines steps.cliff.outputs.content into NOTES="...", which means GitHub expression expansion happens before Bash parsing; if the changelog contains characters like ", backticks, or $() (common in commit subjects/body text), the script can break or perform command substitution, causing release jobs to fail unpredictably. This regression is introduced by moving from an env var to direct inline assignment, so release notes should be passed in a way that bypasses shell parsing.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In @.github/workflows/release.yml:
- Around line 71-73: The fallback NOTES assignment currently sets "Initial
release of genie v3 CLI." which can be incorrect when git-cliff ran but produced
no output; update the logic in the release workflow to use a neutral fallback
(e.g., set NOTES="No notable changes.") or add a check that distinguishes the
git-cliff step being skipped vs run-but-empty (inspect the git-cliff output
variable or file before assigning NOTES) so the fallback no longer claims an
initial release; update the block that assigns the NOTES variable accordingly.
- Around line 70-74: Replace the inline interpolation of `${{
steps.cliff.outputs.content }}` with an environment variable to avoid shell
injection: set an env entry (e.g. env: NOTES: ${{ steps.cliff.outputs.content
}}) on the workflow step that writes the file, then use the already-present
printf '%s' "$NOTES" > /tmp/release-notes.md (ensure the printf uses the quoted
"$NOTES"). This keeps the multi-line/unsafe content out of the command string
while preserving the original behavior.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: b79cb308-1f43-4b30-8742-2c708a8932e3
📒 Files selected for processing (1)
.github/workflows/release.yml
| NOTES="${{ steps.cliff.outputs.content }}" | ||
| if [ -z "$NOTES" ]; then | ||
| NOTES="Initial release of genie v3 CLI." | ||
| fi | ||
| printf '%s' "$NOTES" > /tmp/release-notes.md |
There was a problem hiding this comment.
Shell injection risk: avoid direct interpolation of multi-line content.
${{ steps.cliff.outputs.content }} is interpolated into the shell string before execution. If the changelog contains quotes, backticks, $, or newlines, this can break parsing or cause unexpected behavior. Pass via environment variable instead.
Proposed fix
- name: Create release
if: steps.exists.outputs.skip != 'true'
env:
GH_TOKEN: ${{ github.token }}
+ CLIFF_NOTES: ${{ steps.cliff.outputs.content }}
run: |
TAG="v${{ steps.pkg.outputs.version }}"
- NOTES="${{ steps.cliff.outputs.content }}"
+ NOTES="${CLIFF_NOTES}"
if [ -z "$NOTES" ]; then
NOTES="Initial release of genie v3 CLI."
fi
printf '%s' "$NOTES" > /tmp/release-notes.md📝 Committable suggestion
‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.
| NOTES="${{ steps.cliff.outputs.content }}" | |
| if [ -z "$NOTES" ]; then | |
| NOTES="Initial release of genie v3 CLI." | |
| fi | |
| printf '%s' "$NOTES" > /tmp/release-notes.md | |
| - name: Create release | |
| if: steps.exists.outputs.skip != 'true' | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| CLIFF_NOTES: ${{ steps.cliff.outputs.content }} | |
| run: | | |
| TAG="v${{ steps.pkg.outputs.version }}" | |
| NOTES="${CLIFF_NOTES}" | |
| if [ -z "$NOTES" ]; then | |
| NOTES="Initial release of genie v3 CLI." | |
| fi | |
| printf '%s' "$NOTES" > /tmp/release-notes.md |
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In @.github/workflows/release.yml around lines 70 - 74, Replace the inline
interpolation of `${{ steps.cliff.outputs.content }}` with an environment
variable to avoid shell injection: set an env entry (e.g. env: NOTES: ${{
steps.cliff.outputs.content }}) on the workflow step that writes the file, then
use the already-present printf '%s' "$NOTES" > /tmp/release-notes.md (ensure the
printf uses the quoted "$NOTES"). This keeps the multi-line/unsafe content out
of the command string while preserving the original behavior.
| if [ -z "$NOTES" ]; then | ||
| NOTES="Initial release of genie v3 CLI." | ||
| fi |
There was a problem hiding this comment.
Fallback message may be misleading on subsequent releases.
If git-cliff runs (previous tag exists) but produces empty output—e.g., only merge commits or non-conventional messages—the fallback claims "Initial release of genie v3 CLI." which would be incorrect for a non-initial release.
Consider a more generic fallback like "No notable changes." or check whether the cliff step was skipped vs ran-but-empty.
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In @.github/workflows/release.yml around lines 71 - 73, The fallback NOTES
assignment currently sets "Initial release of genie v3 CLI." which can be
incorrect when git-cliff ran but produced no output; update the logic in the
release workflow to use a neutral fallback (e.g., set NOTES="No notable
changes.") or add a check that distinguishes the git-cliff step being skipped vs
run-but-empty (inspect the git-cliff output variable or file before assigning
NOTES) so the fallback no longer claims an initial release; update the block
that assigns the NOTES variable accordingly.
Summary
Fixes the release workflow that's been failing on every push to main since v3 promotion.
Root causes:
secrets.RELEASE_PLEASE_TOKENwas never set —ghCLI exits with code 4 (auth error)Fixes:
github.token(built-in, already hascontents: writepermission) instead of a custom secret--notes-file) to avoid argument length limitsTest plan
v3.260302.2npm info @automagik/genieshows the published versionSummary by CodeRabbit