Skip to content

ci: harden publish.yaml concurrency, release environment, recovery SHA pin #449

Description

@DecisionNerd

Summary

publish.yaml lacks a concurrency group, registry jobs are not gated by a release environment, release_tag defaults to stale v0.5.2, and recovery overlays scripts from floating origin/main tip rather than an explicit reviewed SHA.

Acceptance criteria

  • concurrency: { group: publish-<tag>, cancel-in-progress: false }
  • Registry-writing jobs use environment: release
  • Remove stale release_tag default v0.5.2
  • Pin recovery overlay to explicit reviewed SHA input
  • Update release runbooks accordingly

Non-goals

  • Binding RC Bazel natives (PR11)
  • npm OIDC (already landed)

BDD

  • Given two publish runs for the same tag, When both are active, Then they do not cancel each other
  • Given recovery dispatch, When overlay scripts are fetched, Then they come from the explicit SHA input, not floating main tip
  • Given a registry write job, When it starts, Then it requires the release environment

Source

Devinfra Audit Fix-It Plan Wave D / PR10

Activity

  1. coderabbitai commented on Aug 7, 2026

    @coderabbitai
    🔗 Related PRs

    #282 - fix(release): resume immutable v0.5.0 publication [merged]
    #305 - feat(release): orchestrate resumable publication [merged]
    #326 - fix(release): refresh crate observation before authorize [merged]
    #332 - fix(release): clobber attempt/receipt uploads on recovery [merged]
    #377 - test(release): isolate npm publication dry-run policy [merged]


    📝 Issue Planner

    Check the box below or use the @coderabbitai plan command to generate an implementation plan and prompts that you can use with your favorite coding assistant.

    • Create Plan

    🧪 Issue enrichment is currently in open beta.

    You can configure auto-planning by selecting labels in the issue_enrichment configuration.

    To disable automatic issue enrichment, add the following to your .coderabbit.yaml:

    issue_enrichment:
      auto_enrich:
        enabled: false

    💬 Have feedback or questions? Drop into our discord!

  2. added 3 commits that reference this issue on Aug 7, 2026
    b5ebfe7
    65b8c38
    15c2ba6
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions