Goal
Preserve the annotated release tag when the tag-triggered release workflow checks out its source, so base-demo-release-provenance can verify the tag and the governed release can publish its assets.
Reproduction
The annotated remote v0.2.0 tag points to the tag object for commit c5709ed8dfa623539e9c326554712490e14f1774, but the Release Demo verify job's checkout refspec force-maps GITHUB_SHA to refs/tags/v0.2.0. The local tag becomes lightweight and provenance fails before asset finalization.
Scope
- Restore/fetch the annotated
refs/tags/${GITHUB_REF_NAME} after checkout, or otherwise prevent checkout from replacing the tag object with the peeled commit.
- Keep provenance bound to the annotated tag target and exact reviewed commit.
- Add a workflow or shell-level regression check that distinguishes an annotated tag from a lightweight tag.
- Rerun the governed release verification against a disposable tag or controlled workflow fixture; do not retag or replace an existing published tag.
Acceptance Criteria
Project Fields
- Status: Ready
- Priority: P1
- Area: Packaging
- Initiative: Contract Hardening
- Size: S
- Milestone: v0.2.0
Agent Assignment
Goal
Preserve the annotated release tag when the tag-triggered release workflow checks out its source, so
base-demo-release-provenancecan verify the tag and the governed release can publish its assets.Reproduction
The annotated remote
v0.2.0tag points to the tag object for commitc5709ed8dfa623539e9c326554712490e14f1774, but theRelease Demoverify job's checkout refspec force-mapsGITHUB_SHAtorefs/tags/v0.2.0. The local tag becomes lightweight and provenance fails before asset finalization.Scope
refs/tags/${GITHUB_REF_NAME}after checkout, or otherwise prevent checkout from replacing the tag object with the peeled commit.Acceptance Criteria
base-demo-release-provenancepasses for an annotated tag and still rejects a lightweight tag.Project Fields
Agent Assignment