Skip to content

fix(release): dispatch publish/homebrew instead of workflow_call (main mirror of #81)#82

Merged
I4cTime merged 1 commit into
mainfrom
fix/release-dispatch-main
Jul 11, 2026
Merged

fix(release): dispatch publish/homebrew instead of workflow_call (main mirror of #81)#82
I4cTime merged 1 commit into
mainfrom
fix/release-dispatch-main

Conversation

@I4cTime

@I4cTime I4cTime commented Jul 11, 2026

Copy link
Copy Markdown
Owner

Cherry-pick of the #81 squash commit onto main so the release workflows are identical on both branches before re-tagging v0.13.0. See #81 for the npm OIDC explanation.

🤖 Generated with Claude Code

… OIDC) (#81)

The first v0.13.0 run created the GitHub Release but npm rejected the
publish with its misleading E404: npm trusted publishing validates the
OIDC token's top-level workflow file, which is release.yml when
publish.yml runs via workflow_call — but the trusted publisher on
npmjs.com is registered for publish.yml.

release.yml now dispatches publish.yml and update-homebrew.yml on the
tag ref via the workflow_dispatch API (allowed with GITHUB_TOKEN; the
recursion block only suppresses event-triggered runs). Dispatched runs
have publish.yml as their top-level workflow, so the OIDC claim matches
the existing npm configuration and the manual re-run path keeps working
unchanged.

- release.yml: permissions actions:write (id-token no longer needed
  here), dispatch step after release creation
- publish.yml: drop the now-unused workflow_call trigger
- update-homebrew.yml: workflow_call -> workflow_dispatch (it already
  polls npm for up to 5 min, so dispatch order doesn't matter)
- docs/releasing.md: document the dispatch architecture and both
  failure modes hit on the first tag run

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
@I4cTime
I4cTime merged commit 435568c into main Jul 11, 2026
9 checks passed
@I4cTime
I4cTime deleted the fix/release-dispatch-main branch July 11, 2026 07:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant