From ddbc5d88ed74f88b7ab0df51769765ec8f47be36 Mon Sep 17 00:00:00 2001 From: Claude Date: Wed, 30 Sep 2026 18:28:12 +0000 Subject: [PATCH 1/3] fix(ci): allow manual re-publish of a release to GitHub Packages The 0.1.9 publish run failed at checkout (it fetched tag v0.1.9, but release-please tags are lombokcss-v0.1.9), and 0.1.8 predates the workflow_call wiring, so NuGet, npm (GPR), Maven, RubyGems and the container image are still at 0.1.7. - Add workflow_dispatch with a version input so an existing release can be re-published from the Actions tab - Check out lombokcss-v in the build and container jobs so a manual run builds the released code, not the tip of main Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_011pv5NUFsXGzyv4F9TcK7Rz --- .github/workflows/publish-packages.yml | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/.github/workflows/publish-packages.yml b/.github/workflows/publish-packages.yml index e955be5..c89f438 100644 --- a/.github/workflows/publish-packages.yml +++ b/.github/workflows/publish-packages.yml @@ -22,6 +22,14 @@ on: description: 'Semver version WITHOUT leading v (e.g. 0.1.8)' required: true type: string + # Manual re-publish of an existing release (e.g. one whose publish run + # failed). Builds from that release's tag, not from the tip of main. + workflow_dispatch: + inputs: + version: + description: 'Released version WITHOUT leading v (tag lombokcss-v must exist)' + required: true + type: string # Default deny — each job declares only what it needs. permissions: {} @@ -38,6 +46,9 @@ jobs: version: ${{ inputs.version }} steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + with: + # Release tags are component-prefixed by release-please. + ref: lombokcss-v${{ inputs.version }} - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7 with: node-version: '24.x' @@ -107,6 +118,9 @@ jobs: IMAGE: ghcr.io/${{ github.repository_owner }}/lombokcss steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + with: + # Release tags are component-prefixed by release-please. + ref: lombokcss-v${{ inputs.version }} - name: Generate Dockerfile run: | From cf17c86e5ce7c65c87212244d7e862912335a007 Mon Sep 17 00:00:00 2001 From: Claude Date: Wed, 30 Sep 2026 18:30:04 +0000 Subject: [PATCH 2/3] fix(ci): let the GPR npm job publish a version package.json already has Publishing from the release tag means package.json already holds the target version, and 'npm version ' exits 1 without --allow-same-version, which would fail the npm (GPR) job. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_011pv5NUFsXGzyv4F9TcK7Rz --- .github/workflows/publish-packages.yml | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/.github/workflows/publish-packages.yml b/.github/workflows/publish-packages.yml index c89f438..150f366 100644 --- a/.github/workflows/publish-packages.yml +++ b/.github/workflows/publish-packages.yml @@ -99,7 +99,9 @@ jobs: fs.writeFileSync('package.json', JSON.stringify(pkg, null, 2)); " - name: Sync version from tag - run: npm version "${{ inputs.version }}" --no-git-tag-version + # The release tag already carries this version; without + # --allow-same-version npm exits 1 ("Version not changed"). + run: npm version "${{ inputs.version }}" --no-git-tag-version --allow-same-version - run: npm publish --ignore-scripts env: From 82b450b046e43de3bd317812afa6dc1d2ab171dd Mon Sep 17 00:00:00 2001 From: Claude Date: Wed, 30 Sep 2026 18:34:36 +0000 Subject: [PATCH 3/3] ci: document and skip checkov CKV_GHA_7 for the re-publish input CKV_GHA_7 (SLSA: workflow_dispatch inputs must be empty) failed on the new manual trigger. The version input only picks which existing release tag to re-publish; the build runs from that tag, so user input cannot change the build output. Skip the rule inline with that justification. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_011pv5NUFsXGzyv4F9TcK7Rz --- .github/workflows/publish-packages.yml | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/.github/workflows/publish-packages.yml b/.github/workflows/publish-packages.yml index 150f366..7090fa6 100644 --- a/.github/workflows/publish-packages.yml +++ b/.github/workflows/publish-packages.yml @@ -24,6 +24,10 @@ on: type: string # Manual re-publish of an existing release (e.g. one whose publish run # failed). Builds from that release's tag, not from the tip of main. + # The version input only selects WHICH existing release tag to publish; + # the build itself comes from that tag, so SLSA's "no dispatch inputs" + # rule does not apply here. + # checkov:skip=CKV_GHA_7:Input only selects an existing release tag to re-publish workflow_dispatch: inputs: version: