Skip to content

chore(ci): run release-please and the release merge with the PAT - #63

Merged
ericviana merged 1 commit into
mainfrom
eric/release-chain-pat
Aug 4, 2026
Merged

ericviana merged 1 commit into
mainfrom
eric/release-chain-pat

Conversation

@ericviana

Copy link
Copy Markdown
Member

Third and final link in the release chain, found the same way as the first two: by watching it fail.

#62 made the release PR merge itself, and it worked: run 00:18:40 logged "Merging release PR #61" and #61 is merged. But 3.1.1 never published. PyPI is still on 3.1.0, there is no v3.1.1 tag, and no publish run exists after the merge.

The reason is a GitHub rule we have now hit in three different places: a push made with GITHUB_TOKEN does not start any workflow. Our own merge lands the release commit on main and then nothing reacts to it, so the run that would create the release and upload to PyPI never happens. 3.1.0 only published because a human (me) merged its release PR, which is a real user push.

Fix: run release-please and the merge step with secrets.SDK_SYNC_PAT, which already exists in this repo and is already what the api-sync workflow uses to open and auto-merge the sync PR. Two benefits: the merge push starts the publish run, and the release PR now gets CI (a GITHUB_TOKEN-opened PR never does).

The chain terminates: sync PR merged, publish runs, release-please opens the release PR, the merge step merges it, that push starts publish again, release-please creates the release, the publish job uploads to PyPI, and the merge step finds nothing pending and no-ops.

Merging this also unsticks 3.1.1, since the release commit is already on main and the next run will cut its release.

I will confirm on PyPI rather than assert it here. Every previous claim about this pipeline that I made from reading rather than watching turned out to be wrong.

https://claude.ai/code/session_01F1stiNzuNtJXoXtiW9ZCbs

A push made with GITHUB_TOKEN starts no workflow, so 3.1.1's release PR merged
onto main and then nothing published: the run that creates the release and
uploads to PyPI never started. The PAT the sync flow already uses keeps the
chain alive, and it also lets CI run on the release PR.

Claude-Session: https://claude.ai/code/session_01F1stiNzuNtJXoXtiW9ZCbs
@BernardoSM

Copy link
Copy Markdown
Collaborator

✅ Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
✅ Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@ericviana
ericviana merged commit 4a02c25 into main Aug 4, 2026
8 checks passed
@ericviana
ericviana deleted the eric/release-chain-pat branch August 4, 2026 00:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants