Skip to content

ci(release): PAT-mode release PRs are not exempt from the authoring gates (ADR-1151) #1608

Description

@lusoris

Release PRs fail the Doc-Substance Gate because release-please runs with the RELEASE_BOT_TOKEN fallback, and the ADR-1151 exemption only recognises bot authors.

  • .github/workflows/release-please.yml accepts two identities: the release-bot App (RELEASE_BOT_APP_ID plus RELEASE_BOT_PRIVATE_KEY) or, as a fallback, RELEASE_BOT_TOKEN. The App secrets are not set, so it runs in PAT mode and the release PR is authored by lusoris.
  • scripts/ci/release-pr-exempt.sh exempts a release PR from the four authoring gates only if its author is a bot (user.type == Bot or a [bot] login). A PAT-authored release PR is therefore not exempt.
  • The release PR bumps mcp-server/vmaf-mcp/pyproject.toml's version, which the Doc-Substance path map ties to docs/mcp/, so the gate fails. This hit the rc.2 release PR chore(master): release 1.0.0-rc.2 #1575. The rc.1 release PR fix(release): clear the 1.0.0-rc.1 merge and publication path #1570 was authored by lusoris the same way.

Workaround used for #1575: a no docs needed: comment appended after the release-please footer. release-please parses release notes only between the --- delimiters, so the footer text is ignored. The comment is lost whenever release-please rewrites the body on the next master push.

Two ways to fix it:

  1. Create the release-bot GitHub App and set RELEASE_BOT_APP_ID / RELEASE_BOT_PRIVATE_KEY, as docs/development/release.md ("Release-bot identity") describes. App registration is browser-only. This is the intended ADR-1151 identity, and it also gives short-lived tokens.
  2. Teach release-pr-exempt.sh the PAT identity. It must not let a human-pushed release-please--* branch disarm the gates, which is the threat the author check guards against. For example, it could also require the diff to touch only release-please's version markers and CHANGELOG.md.

Option 1 matches the ADR and needs no code change.

Activity

  1. added 5 commits that reference this issue on Sep 30, 2026
    eb43857
    cdd78c9
    60ac1cf
    b712536
    4b1a4f3
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions