You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
ci(release): PAT-mode release PRs are not exempt from the authoring gates (ADR-1151) #1608
Release PRs fail the Doc-Substance Gate because release-please runs with the RELEASE_BOT_TOKEN fallback, and the ADR-1151 exemption only recognises bot authors.
.github/workflows/release-please.yml accepts two identities: the release-bot App (RELEASE_BOT_APP_ID plus RELEASE_BOT_PRIVATE_KEY) or, as a fallback, RELEASE_BOT_TOKEN. The App secrets are not set, so it runs in PAT mode and the release PR is authored by lusoris.
scripts/ci/release-pr-exempt.sh exempts a release PR from the four authoring gates only if its author is a bot (user.type == Bot or a [bot] login). A PAT-authored release PR is therefore not exempt.
Workaround used for #1575: a no docs needed: comment appended after the release-please footer. release-please parses release notes only between the --- delimiters, so the footer text is ignored. The comment is lost whenever release-please rewrites the body on the next master push.
Two ways to fix it:
Create the release-bot GitHub App and set RELEASE_BOT_APP_ID / RELEASE_BOT_PRIVATE_KEY, as docs/development/release.md ("Release-bot identity") describes. App registration is browser-only. This is the intended ADR-1151 identity, and it also gives short-lived tokens.
Teach release-pr-exempt.sh the PAT identity. It must not let a human-pushed release-please--* branch disarm the gates, which is the threat the author check guards against. For example, it could also require the diff to touch only release-please's version markers and CHANGELOG.md.
Option 1 matches the ADR and needs no code change.
Release PRs fail the Doc-Substance Gate because release-please runs with the
RELEASE_BOT_TOKENfallback, and the ADR-1151 exemption only recognises bot authors..github/workflows/release-please.ymlaccepts two identities: the release-bot App (RELEASE_BOT_APP_IDplusRELEASE_BOT_PRIVATE_KEY) or, as a fallback,RELEASE_BOT_TOKEN. The App secrets are not set, so it runs in PAT mode and the release PR is authored bylusoris.scripts/ci/release-pr-exempt.shexempts a release PR from the four authoring gates only if its author is a bot (user.type == Botor a[bot]login). A PAT-authored release PR is therefore not exempt.mcp-server/vmaf-mcp/pyproject.toml's version, which the Doc-Substance path map ties todocs/mcp/, so the gate fails. This hit the rc.2 release PR chore(master): release 1.0.0-rc.2 #1575. The rc.1 release PR fix(release): clear the 1.0.0-rc.1 merge and publication path #1570 was authored bylusoristhe same way.Workaround used for #1575: a
no docs needed:comment appended after the release-please footer. release-please parses release notes only between the---delimiters, so the footer text is ignored. The comment is lost whenever release-please rewrites the body on the next master push.Two ways to fix it:
RELEASE_BOT_APP_ID/RELEASE_BOT_PRIVATE_KEY, asdocs/development/release.md("Release-bot identity") describes. App registration is browser-only. This is the intended ADR-1151 identity, and it also gives short-lived tokens.release-pr-exempt.shthe PAT identity. It must not let a human-pushedrelease-please--*branch disarm the gates, which is the threat the author check guards against. For example, it could also require the diff to touch only release-please's version markers andCHANGELOG.md.Option 1 matches the ADR and needs no code change.