Repository navigation
fix(ci): gate releases on native artifact checks - #138
Merged
Merged
Conversation
5 of 16 tasks
sadiksaifi
commented
Sep 20, 2026
sadiksaifi
left a comment
Owner
Author
There was a problem hiding this comment.
Findings
P1: npm bypasses the verified workflow artifacts
- Location:
.github/workflows/release.yml:450 - Failure: The native jobs verify and assemble
release-artifacts, butpublish-npmignores that immutable in-run artifact and downloads from the GitHub Release instead. This repository currently has immutable releases disabled, andsoftprops/action-gh-releasedefaults to overwriting same-named assets. A release-asset replacement or full rerun can therefore make npm consume bytes that are different from the artifact that passed this workflow's native gates. - Impact: npm can publish binaries that were not the exact verified inputs used for the GitHub/Homebrew release, and retry paths can leave channels serving different bytes under one version.
- Fix: Download
release-artifactsdirectly withactions/download-artifactinpublish-npmand verifychecksums.txtbefore packaging. Separately enable GitHub immutable releases or otherwise fail closed instead of overwriting existing release assets.
Owner
Author
FIXED
Verified:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Prevent corrupt, incorrectly targeted, invalidly signed, or non-launching binaries from reaching GitHub releases, Homebrew, or npm. The tag-only release workflow now validates the exact archives on native runners before any publication step can start.
These jobs run only for version tags in
.github/workflows/release.yml; normal pull-request and branch CI remains unchanged.What is the purpose of this pull request?
Changes
ai-git --versionchecks for every platform.Testing
actionlint .github/workflows/release.ymlsuccessfully.git diff --check.v3.0.2macOS ARM64 archive locally.Screenshots
Not applicable.
Checklist