fix(ci): allow manual re-publish of a release to GitHub Packages - #44
Merged
Merged
Conversation
The 0.1.9 publish run failed at checkout (it fetched tag v0.1.9, but release-please tags are lombokcss-v0.1.9), and 0.1.8 predates the workflow_call wiring, so NuGet, npm (GPR), Maven, RubyGems and the container image are still at 0.1.7. - Add workflow_dispatch with a version input so an existing release can be re-published from the Actions tab - Check out lombokcss-v<version> in the build and container jobs so a manual run builds the released code, not the tip of main Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011pv5NUFsXGzyv4F9TcK7Rz
Contributor
|
Message that will be displayed on users' first pull request |
Contributor
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned FilesNone |
Publishing from the release tag means package.json already holds the target version, and 'npm version <same>' exits 1 without --allow-same-version, which would fail the npm (GPR) job. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011pv5NUFsXGzyv4F9TcK7Rz
CKV_GHA_7 (SLSA: workflow_dispatch inputs must be empty) failed on the new manual trigger. The version input only picks which existing release tag to re-publish; the build runs from that tag, so user input cannot change the build output. Skip the rule inline with that justification. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011pv5NUFsXGzyv4F9TcK7Rz
This was referenced Sep 30, 2026
codinglombok
added a commit
that referenced
this pull request
Oct 1, 2026
…rxmx fix(ci): allow manual re-publish of a release to GitHub Packages
codinglombok
added a commit
that referenced
this pull request
Oct 3, 2026
…rxmx fix(ci): allow manual re-publish of a release to GitHub Packages
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
publish-packages.yml:workflow_dispatchwith aversioninput to re-publish an existing release to GitHub Packages (npm, container, Maven, NuGet, RubyGems). CheckovCKV_GHA_7is skipped inline: the input only selects an existing release tag.lombokcss-v<version>in the build and container jobs so packages are built from the release tag.npm version --allow-same-version, since the tag already carries the version.Type
Checklist