Skip to content

ci: publish GitHub release as a draft until post-release steps succeed - #3348

Closed
javirln wants to merge 2 commits into
chainloop-dev:mainfrom
javirln:javier/pfm-6883-release-workflow-use-goreleaser-draft-release-and-publish
Closed

javirln wants to merge 2 commits into
chainloop-dev:mainfrom
javirln:javier/pfm-6883-release-workflow-use-goreleaser-draft-release-and-publish

Conversation

@javirln

@javirln javirln commented Aug 13, 2026 •

Copy link
Copy Markdown
Member

Summary

The release workflow used to publish the GitHub release immediately via GoReleaser and then keep adding post-release artifacts (SBOMs, vulnerability reports, Chainloop attestation link, source-code attestation, release-note edits). When one of those post-release steps failed, the release was already public but incomplete.

This makes the release atomic from a user's perspective:

  • .goreleaser.yml: the release: block now sets draft: true, so GoReleaser creates the release as a draft.
  • .github/workflows/release.yaml: all existing post-release steps run against the draft (they reference it by tag). A final success()-gated Publish release step flips the draft to published only after every post-release step has succeeded.

If any post-release step fails, the release stays a draft for a human to inspect or retry, rather than a broken release going public.

Refs PFM-6883.

Assisted-by: Claude Code

Review in cubic

GoReleaser now creates the release as a draft. The workflow runs all
post-release steps (SBOM upload, Grype scans, source-code attestation,
version bumps, attestation push, release-note edits) against the draft
and adds a final success()-gated step that flips the draft to published.
A failure in any post-release step leaves the release as a draft rather
than publishing a public but incomplete release.

Assisted-by: Claude Code
Signed-off-by: Javier Rodriguez <javier@chainloop.dev>

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 2 files

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread .github/workflows/release.yaml
The source-code attestation step ran before the release is published (it is
now created as a draft) and relied on `gh release download -A tar.gz`, which
depends on GitHub's auto-generated source asset that is only exposed once a
release is published. Fetch the archive directly by git tag instead so the
step succeeds against a draft; otherwise it would fail, keep success() false,
and leave every release stuck as a draft.

Assisted-by: Claude Code
Signed-off-by: Javier Rodriguez <javier@chainloop.dev>
@javirln

javirln commented Aug 13, 2026

Copy link
Copy Markdown
Member Author

Good catch — fixed in 69eb523. The Include source code on attestation step ran during the draft window and relied on gh release download -A tar.gz, whose auto-generated source asset isn't reliably available for a draft. Switched it to fetch the tarball directly from the tag archive URL (https://github.com/${GITHUB_REPOSITORY}/archive/refs/tags/${RELEASE_TAG}.tar.gz), which depends only on the git tag and yields the same auto-generated archive, so it works before publish.

@migmartri

Copy link
Copy Markdown
Member

Do we want this? it's in draft

@javirln javirln closed this Sep 30, 2026
@chainloop-platform

Copy link
Copy Markdown
Contributor

AI Session Checks — ⚠️ no AI session found

Missing AI Coding Sessions

This organization requires every PR to be backed by a Chainloop Trace AI coding session, and none was found for this one.

Please make sure the AI coding session evidence has been sent by the Chainloop CLI, or add the skip-ai-session label to this PR to bypass this check.

Learn more about Chainloop Trace.


Powered by Chainloop and Chainloop Trace

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants