fix: harden v2.0.8 release preflight gate - #24
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c2af604334
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| if git rev-parse --verify --quiet "refs/tags/$RELEASE_TAG" >/dev/null; then | ||
| echo "Release tag already exists at the validated candidate: $RELEASE_TAG" |
There was a problem hiding this comment.
Recheck the tag target before accepting it
If RELEASE_TAG is created after the earlier Validate versioned tag state step but before this fetch (for example, by a concurrently dispatched run on a different ref or a manual tag push), this branch accepts it without comparing its peeled commit to HEAD_SHA. The following v2 update then resolves and promotes that foreign tag, and the release is published, even though the current preflight validated different source; repeat the SHA check here (or make validation and creation atomic) before proceeding.
Useful? React with 👍 / 👎.
Objective
Harden the automatic release path before the next production release.
Changes
Verification
The release workflow itself will provide the authoritative live preflight and release evidence after merge.