Repository navigation
Conversation
GoReleaser now creates the release as a draft. The workflow runs all post-release steps (SBOM upload, Grype scans, source-code attestation, version bumps, attestation push, release-note edits) against the draft and adds a final success()-gated step that flips the draft to published. A failure in any post-release step leaves the release as a draft rather than publishing a public but incomplete release. Assisted-by: Claude Code Signed-off-by: Javier Rodriguez <javier@chainloop.dev>
There was a problem hiding this comment.
All reported issues were addressed across 2 files
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
The source-code attestation step ran before the release is published (it is now created as a draft) and relied on `gh release download -A tar.gz`, which depends on GitHub's auto-generated source asset that is only exposed once a release is published. Fetch the archive directly by git tag instead so the step succeeds against a draft; otherwise it would fail, keep success() false, and leave every release stuck as a draft. Assisted-by: Claude Code Signed-off-by: Javier Rodriguez <javier@chainloop.dev>
|
Good catch — fixed in 69eb523. The |
|
Do we want this? it's in draft |
AI Session Checks —
|
Summary
The release workflow used to publish the GitHub release immediately via GoReleaser and then keep adding post-release artifacts (SBOMs, vulnerability reports, Chainloop attestation link, source-code attestation, release-note edits). When one of those post-release steps failed, the release was already public but incomplete.
This makes the release atomic from a user's perspective:
.goreleaser.yml: therelease:block now setsdraft: true, so GoReleaser creates the release as a draft..github/workflows/release.yaml: all existing post-release steps run against the draft (they reference it by tag). A finalsuccess()-gated Publish release step flips the draft to published only after every post-release step has succeeded.If any post-release step fails, the release stays a draft for a human to inspect or retry, rather than a broken release going public.
Refs PFM-6883.
Assisted-by: Claude Code