From 098a5f3303c0da1279d872b4327ef89a496546ca Mon Sep 17 00:00:00 2001 From: Roland Rabien Date: Thu, 30 Apr 2026 09:25:23 -0700 Subject: [PATCH] release: harden upload pipeline (TAG/VER split, --fail-with-body, GITHUB_TOKEN, contents:write) Aligns with the chip-plugin repos: - Use TAG (with v prefix) for gh release create, VER (stripped) for Changelist lookup and upload.php's version field. - curl --fail-with-body so server-side errors fail the workflow instead of passing silently. - Switch GH_TOKEN to the auto-provided GITHUB_TOKEN with explicit contents:write permission, dropping the dependency on a per-repo ACCESS_TOKEN PAT. --- .github/workflows/release.yaml | 4 +++- release.sh | 9 ++++++--- tag.sh | 4 ++-- 3 files changed, 11 insertions(+), 6 deletions(-) diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index 491a0ef..42df63a 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -67,6 +67,8 @@ jobs: needs: build runs-on: ubuntu-latest timeout-minutes: 30 + permissions: + contents: write steps: - uses: actions/checkout@v4 - name: Download Artifacts @@ -75,5 +77,5 @@ jobs: run: ./release.sh shell: bash env: - GH_TOKEN: ${{ secrets.ACCESS_TOKEN }} + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} APIKEY: ${{ secrets.APIKEY }} diff --git a/release.sh b/release.sh index 50fefed..f39f24a 100755 --- a/release.sh +++ b/release.sh @@ -4,7 +4,10 @@ set -x cd "$(dirname "$0")" ROOT=$(pwd) -VER="$GITHUB_REF_NAME" +TAG="$GITHUB_REF_NAME" +# Tags are pushed with a leading "v" (see tag.sh); strip for the changelog +# lookup and the upload.php version field, but use TAG for gh release create. +VER="${TAG#v}" # Extract the changelog section for the current version # Matches version with optional colon, captures until the next version line or EOF @@ -32,13 +35,13 @@ if [ -f "./Binaries macOS/Symbols_Mac.zip" ]; then ASSETS+=("./Binaries macOS/Symbols_Mac.zip") fi -gh release create "$VER" --title "$VER" -F /tmp/release_notes.txt "${ASSETS[@]}" +gh release create "$TAG" --title "$TAG" -F /tmp/release_notes.txt "${ASSETS[@]}" PLUGIN=wavetable for f in "./Binaries Linux"/*.deb \ "./Binaries Windows"/*.exe \ "./Binaries macOS"/*.pkg; do - curl -sS -F "files=@${f}" \ + curl -sS --fail-with-body -F "files=@${f}" \ -F "plugin=${PLUGIN}" \ -F "version=${VER}" \ -F "changelog=${NOTES}" \ diff --git a/tag.sh b/tag.sh index eb1bdb5..b903424 100755 --- a/tag.sh +++ b/tag.sh @@ -13,5 +13,5 @@ if ! grep -q "^${VER}:*$" Changelist.txt; then exit 1 fi -echo "Tagging [$VER]" -git tag "$VER" && git push origin "$VER" +echo "Tagging [v$VER]" +git tag "v$VER" && git push origin "v$VER"