Repository navigation
Keep release tag names out of shell source - #473
Merged
Merged
Conversation
The major-tag step declared GITHUB_TOKEN: secrets.WORKFLOW_TOKEN, but git never reads that variable. The push authenticates with the http.extraheader credential actions/checkout persists, which is the default GITHUB_TOKEN, and `refs/tags/v4` having no release proves it: a PAT-authored push would have re-triggered create-release on the v4 tag. Record why the inertness is load-bearing rather than leaving a line that reads like an oversight. Also bound the guard test's step slice at the next step. Reading to end-of-file only holds while the major-tag step is last in the file. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015EmepbnR2nSdk8q8DBsrsD
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Security invariant
A matching tag name is data, never shell source. Existing major-version extraction remains compatible with the repository's current tag formats.
Verification
npm test— 29/29npm run lintnpm run format-checkactionlint .github/workflows/release.yml