Skip to content

fix: hash draft release assets through the API endpoint - #12934

Merged
lawrencecchen merged 1 commit into
mainfrom
feat-ci-digest-api-fallback
Sep 18, 2026
Merged

lawrencecchen merged 1 commit into
mainfrom
feat-ci-digest-api-fallback

Conversation

@lawrencecchen

@lawrencecchen lawrencecchen commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Use the authenticated GitHub API asset URL when hashing an asset with a nullable digest.
  • Keep draft-release publisher verification working before a release is published.

Testing

  • 28 release publication tests pass, including draft API URL fallback.
  • python3 -m py_compile scripts/ci/publish-release-assets.py
  • git diff --check

This fixes the live publisher verification case found while testing an isolated draft release.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.


Summary by cubic

Fixes hashing of draft release assets by using the authenticated API asset URL instead of the browser download URL, which is unavailable for drafts.

  • Prefers the API URL over browser_download_url when hashing assets with a null digest.
  • Works for both draft and published assets.

Written for commit 59b2e4c. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Bug Fixes
    • Improved release asset verification for draft releases by using the authenticated asset URL when a public download URL is unavailable.
    • Preserved HTTPS safety checks and existing hashing behavior.

@github-actions

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@coderabbitai

coderabbitai Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: b663795d-f14b-486a-9b50-5d44553809e3

📥 Commits

Reviewing files that changed from the base of the PR and between 7f3c330 and 59b2e4c.

📒 Files selected for processing (2)
  • scripts/ci/publish-release-assets.py
  • tests/test_github_release_publication.py

Included review availability: Your plan provides up to 10 included reviews per hour; 7 remain after this review.


📝 Walkthrough

Walkthrough

Changes

Release asset digest retrieval

Layer / File(s) Summary
Authenticated asset URL selection and validation
scripts/ci/publish-release-assets.py, tests/test_github_release_publication.py
GitHub.asset_digest now prefers the authenticated API asset URL over browser_download_url. The test verifies streamed retrieval when the remote digest is missing.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 59b2e

The authenticated asset URL behavior is covered, with no unresolved production risk identified.

🚥 Pre-merge checks | ✅ 24 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 25.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 4 functions across 2 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (24 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes the main change: hashing draft release assets through the GitHub API endpoint.
Description check ✅ Passed The description includes the change rationale and detailed testing results. It omits the Demo Video and Checklist sections, but the core information is complete and relevant.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Cloud Persistent Session And Early Input ✅ Passed PASS: The pull request changes only GitHub release-asset hashing and its publication test. It does not change Cloud terminal creation, cmux-tui transport, manual renderer admission, PTY readiness, inp…
Cmux Swift Actor Isolation ✅ Passed PASS: The authoritative pull-request diff changes only scripts/ci/publish-release-assets.py and tests/test_github_release_publication.py. It adds no Swift files or Swift actor-isolation annotation…
Cmux Swift Blocking Runtime ✅ Passed PASS. The pull request changes only scripts/ci/publish-release-assets.py and tests/test_github_release_publication.py. It introduces no production Swift changes, so the Swift blocking-runtime chec…
Cmux Browser Automation Off-Main ✅ Passed PASS: The reviewed diff changes only scripts/ci/publish-release-assets.py and its Python tests. It changes GitHub release asset URL selection and adds a URL-selection test. It does not modify `Sourc…
Cmux Expensive Synchronous Load ✅ Passed PASS. The review range changes only scripts/ci/publish-release-assets.py and tests/test_github_release_publication.py. It adds Python URL selection and a Python test. It adds no production Swift c…
Cmux Cache Substitution Correctness ✅ Passed PASS: The pull request changes scripts/ci/publish-release-assets.py and a Python test only. The custom check applies to production Swift, TypeScript, and JavaScript changes, so it is not applicable.…
Cmux No Hacky Sleeps ✅ Passed The pull request does not introduce or expand a hacky sleep or wall-clock synchronization. The production change only reorders GitHub asset URL selection and adds a comment. The existing backoff() i…
Cmux Algorithmic Complexity ✅ Passed PASS. The production change only reverses URL fallback precedence in scripts/ci/publish-release-assets.py:185. It does not add collection scans, sorting, filtering, joins, rescans, or a slower algor…
Cmux Swift Concurrency ✅ Passed The pull request changes only scripts/ci/publish-release-assets.py and tests/test_github_release_publication.py. The diff contains no Swift files or Swift concurrency patterns. The custom check is…
Cmux Swift @Concurrent ✅ Passed PASS: The review-scoped diff changes only scripts/ci/publish-release-assets.py and tests/test_github_release_publication.py. It introduces no Swift code, nonisolated async work, @concurrent an…
Cmux Swift Package Boundaries ✅ Passed The reviewed range changes only scripts/ci/publish-release-assets.py and tests/test_github_release_publication.py. It contains no production Swift, SwiftPM package, Xcode project, or workspace cha…
Cmux Swiftpm Lockfiles ✅ Passed PASS. The authoritative pull-request diff changes only scripts/ci/publish-release-assets.py and tests/test_github_release_publication.py. The patch contains no Package.swift, Package.resolved,…
Cmux Swift Logging ✅ Passed The pull request changes only Python files and tests. The authoritative diff contains no Swift changes. The changed production code only changes release asset URL selection, and the added test verifie…
Cmux User-Facing Error Privacy ✅ Passed The pull request does not add or materially change user-facing error text. The production diff only changes asset URL selection and adds a developer-only comment. Existing errors and stderr output rem…
Cmux Full Internationalization ✅ Passed PASS. The pull request changes only a CI release-publisher Python script and its test. The production change reorders GitHub asset URLs and adds a developer comment; it adds no user-facing text, local…
Cmux Swiftui State Layout ✅ Passed PASS: The reviewed range changes only scripts/ci/publish-release-assets.py and tests/test_github_release_publication.py. Both files are Python files. The diff introduces no SwiftUI, Swift state, l…
Cmux Architecture Rethink ✅ Passed PASS. The pull request changes only scripts/ci/publish-release-assets.py and tests/test_github_release_publication.py; it contains no Swift files or Swift architecture changes. The code change is …
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed PASS: The pull request changes only scripts/ci/publish-release-assets.py and tests/test_github_release_publication.py. The diff contains no Swift code, standalone cmux-owned window code, or auxili…
Cmux Source Artifacts ✅ Passed The pull request changes only scripts/ci/publish-release-assets.py and tests/test_github_release_publication.py. These are hand-written source and test files. The diff adds API URL handling and a …
Cmux No Test Or Debug Seam In Production Source ✅ Passed The review-scoped diff changes only scripts/ci/publish-release-assets.py and tests/test_github_release_publication.py. It changes no Swift file under a production Sources/ path, so the stated pr…
  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@lawrencecchen
lawrencecchen merged commit bc6b422 into main Sep 18, 2026
24 of 27 checks passed
@lawrencecchen
lawrencecchen deleted the feat-ci-digest-api-fallback branch September 18, 2026 05:31
rustybret pushed a commit to rustybret/bmux that referenced this pull request Sep 18, 2026
bc6b422 fix: hash draft release assets through the API endpoint (manaflow-ai#12934)
cbe279d feat: move TUI tabs between workspaces with drag and context menus
7f3c330 fix: clear current Swift warning budget failures (manaflow-ai#12932)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant