Skip to content

fix(ci): allow manual re-publish of a release to GitHub Packages - #44

Merged
codinglombok merged 3 commits into
mainfrom
claude/affectionate-sagan-o4rxmx
Sep 30, 2026
Merged

codinglombok merged 3 commits into
mainfrom
claude/affectionate-sagan-o4rxmx

Conversation

@codinglombok

@codinglombok codinglombok commented Sep 30, 2026 •

Copy link
Copy Markdown
Owner

Summary

publish-packages.yml:

  • Add workflow_dispatch with a version input to re-publish an existing release to GitHub Packages (npm, container, Maven, NuGet, RubyGems). Checkov CKV_GHA_7 is skipped inline: the input only selects an existing release tag.
  • Check out lombokcss-v<version> in the build and container jobs so packages are built from the release tag.
  • npm (GPR) job: npm version --allow-same-version, since the tag already carries the version.

Type

  • Bug fix
  • Chore / tooling

Checklist

  • yamllint and checkov pass
  • No source changes; bundles unchanged

The 0.1.9 publish run failed at checkout (it fetched tag v0.1.9, but
release-please tags are lombokcss-v0.1.9), and 0.1.8 predates the
workflow_call wiring, so NuGet, npm (GPR), Maven, RubyGems and the
container image are still at 0.1.7.

- Add workflow_dispatch with a version input so an existing release can
  be re-published from the Actions tab
- Check out lombokcss-v<version> in the build and container jobs so a
  manual run builds the released code, not the tip of main

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011pv5NUFsXGzyv4F9TcK7Rz
@github-actions

Copy link
Copy Markdown
Contributor

Message that will be displayed on users' first pull request

@github-actions github-actions Bot added the ci label Sep 30, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

Publishing from the release tag means package.json already holds the
target version, and 'npm version <same>' exits 1 without
--allow-same-version, which would fail the npm (GPR) job.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011pv5NUFsXGzyv4F9TcK7Rz
CKV_GHA_7 (SLSA: workflow_dispatch inputs must be empty) failed on the
new manual trigger. The version input only picks which existing release
tag to re-publish; the build runs from that tag, so user input cannot
change the build output. Skip the rule inline with that justification.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011pv5NUFsXGzyv4F9TcK7Rz
@codinglombok
codinglombok merged commit 7c42592 into main Sep 30, 2026
28 checks passed
@codinglombok
codinglombok deleted the claude/affectionate-sagan-o4rxmx branch September 30, 2026 18:38
codinglombok added a commit that referenced this pull request Oct 1, 2026
…rxmx

fix(ci): allow manual re-publish of a release to GitHub Packages
codinglombok added a commit that referenced this pull request Oct 3, 2026
…rxmx

fix(ci): allow manual re-publish of a release to GitHub Packages
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants