Skip to content

ci : make release workflows use a deploy key - #27229

Merged
ggerganov merged 2 commits into
masterfrom
gg/ci-release-use-deploy-keys
Aug 17, 2026
Merged

ci : make release workflows use a deploy key#27229
ggerganov merged 2 commits into
masterfrom
gg/ci-release-use-deploy-keys

Conversation

@ggerganov

Copy link
Copy Markdown
Member

Overview

Tag creation in the llama.cpp repo is now restricted with a ruleset. The ruleset allows creating v* and b* tags only with a deploy key.

This PR updates the release workflows to use a deploy key when pushing release tags.

Requirements

@ggerganov
ggerganov requested a review from a team as a code owner August 17, 2026 07:00
@ggerganov ggerganov changed the title ci : make release workflows use a deply key ci : make release workflows use a deploy key Aug 17, 2026
@github-actions github-actions Bot added the devops improvements to build systems and github actions label Aug 17, 2026
@CISC

CISC commented Aug 17, 2026

Copy link
Copy Markdown
Member

This PR updates the release workflows to use a deploy key when pushing release tags.

This is required for docker.yml as well.

@ggerganov
ggerganov requested a review from CISC August 17, 2026 08:27
@ggerganov
ggerganov merged commit f9779dd into master Aug 17, 2026
3 checks passed
@ggerganov
ggerganov deleted the gg/ci-release-use-deploy-keys branch August 17, 2026 08:31
@CISC

CISC commented Aug 17, 2026

Copy link
Copy Markdown
Member

Who/how can create gguf-py release tags btw?

@ggerganov

Copy link
Copy Markdown
Member Author

Atm, we don't have a restriction for that - anyone with a write permission can push a gguf-py tag.

Let's see if this method of using a deploy key + ruleset works as expected. And if yes, we'll have to make the same restriction and workflow for the gguf-py. In short, the idea is not to have push the tags manually like we do now. They need to be created by an authorized workflow that performs some required checks before creating the tag.

@CISC

CISC commented Aug 17, 2026

Copy link
Copy Markdown
Member

@ggerganov

Copy link
Copy Markdown
Member Author

It's fixed now - I haven't had set the secret when the workflow started.

gabe-l-hart added a commit to gabe-l-hart/llama.cpp that referenced this pull request Aug 17, 2026
* origin/master: (86 commits)
ui: enforce alphabetical enum member ordering (ggml-org#27272)
ui: Refactor Built-In Tools naming (Server/Browser) (ggml-org#27271)
ci: more optimizations (ggml-org#26983)
doc: document MCP stdio servers and CORS defaults in the server README [no release] [no ci] (ggml-org#26847)
server: save processed mtmd chunks as placeholder (ggml-org#27278)
mtmd: use sha256 for input hashing (ggml-org#27274)
vocab : support integer tokenizer scores (ggml-org#27260)
mtmd : skip thumbnail for non-tiled LFM2 images (ggml-org#27246)
cuda : skip UMA override for HIP builds (ggml-org#27083)
vendor: move hash to vendor (ggml-org#27262)
ci : push release tag explicitly in release.yml (ggml-org#27261)
ui: move get_datetime tool to frontend (ggml-org#27255)
ci : reduce builds in build-xcframework.sh (ggml-org#27252)
model: support speculators-format checkpoints for DSpark (ggml-org#26275)
ui: add browser get_info tool (ggml-org#27251)
ci : restore release.yml check during make-release.yml (ggml-org#27247)
mtmd: harden preprocessor_granite (ggml-org#27235)
ci : allow make-release to target a specific commit (ggml-org#27234)
ci : make release workflows use a deploy key (ggml-org#27229)
convert: add @ModelBase.example (ggml-org#27208)
...
brittlewis12 pushed a commit to brittlewis12/llama.cpp that referenced this pull request Aug 17, 2026
* ci : make release workflows use a deply key

* cont : update docker.yml
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

devops improvements to build systems and github actions

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants