Skip to content

ci(release): preserve annotated tag identity during release checkout #320

Description

@codeforester

Goal

Preserve the annotated release tag when the tag-triggered release workflow checks out its source, so base-demo-release-provenance can verify the tag and the governed release can publish its assets.

Reproduction

The annotated remote v0.2.0 tag points to the tag object for commit c5709ed8dfa623539e9c326554712490e14f1774, but the Release Demo verify job's checkout refspec force-maps GITHUB_SHA to refs/tags/v0.2.0. The local tag becomes lightweight and provenance fails before asset finalization.

Scope

  • Restore/fetch the annotated refs/tags/${GITHUB_REF_NAME} after checkout, or otherwise prevent checkout from replacing the tag object with the peeled commit.
  • Keep provenance bound to the annotated tag target and exact reviewed commit.
  • Add a workflow or shell-level regression check that distinguishes an annotated tag from a lightweight tag.
  • Rerun the governed release verification against a disposable tag or controlled workflow fixture; do not retag or replace an existing published tag.

Acceptance Criteria

  • The release workflow sees the annotated tag object after checkout.
  • base-demo-release-provenance passes for an annotated tag and still rejects a lightweight tag.
  • Finalized BOM and installer assets remain bound to the annotated tag target and exact successful compatibility run.
  • Existing tag/release immutability rules remain unchanged.

Project Fields

  • Status: Ready
  • Priority: P1
  • Area: Packaging
  • Initiative: Contract Hardening
  • Size: S
  • Milestone: v0.2.0

Agent Assignment

  • Assignee: codeforester

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

ciContinuous integration, tests, automation, or release workflows

Type

No type

Projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions