Skip to content

ci(release): resolve the next version without push credentials - #243

Merged
dborgards merged 1 commit into
mainfrom
claude/nifty-albattani-e4b9fe
Sep 30, 2026
Merged

dborgards merged 1 commit into
mainfrom
claude/nifty-albattani-e4b9fe

Conversation

@dborgards

Copy link
Copy Markdown
Owner

What does this change?

The first manual dry run of the Release workflow (run 36667479053) failed in the verify job at Resolve next version:

SemanticReleaseError: Cannot push to the Git repository.   code: 'EGITNOPERMISSION'
    at .../eng/next-release-version.mjs:19:16

semantic-release runs git push --dry-run against the repository URL before any plugin, dry run or not (verifyAuth in index.js), and aborts if that fails. The verify job deliberately has no credentials (persist-credentials: false, contents: read), so the check could never pass against the GitHub URL. The script's own comment said "no token"; that held for the plugins but not for this check.

eng/next-release-version.mjs now passes the local checkout as repositoryUrl. Pushing HEAD to the branch it already is needs no network and no token and changes nothing, and the commit analyser still sees the full history and tags that the checkout fetched. The credential-free design of the verify job is unchanged; nothing is added to its permissions or environment.

This is the ordering problem ADR 0001 predicted for the release pipeline ("the first real test of the release pipeline is this release"). It predates the actor change and is not caused by any recent PR.

Type of change

  • feat — new behaviour (minor release)
  • fix / perf — bug or performance fix (patch release)
  • docs / test / refactor / chore / ci — no release
  • Breaking change (! in the title, plus a BREAKING CHANGE: footer explaining the migration)

Checklist

  • dotnet build CanKit.Pro.sln -c Release succeeds (run without -p:CI=true this time; the change is a Node script outside the solution)
  • dotnet test CanKit.Pro.sln -c Release passes — not run; no .cs file changed
  • Public API changes are documented with XML comments (none)
  • New behaviour is covered by a test — none; the workflow cannot be exercised before merge, see below
  • The requirement or ADR this relates to is referenced (ADR 0001)

How this was checked

Against a fresh clone of main (780e512), with the container's authenticating proxy removed from the environment so that no credentials were available:

  • unmodified script: fatal: Authentication failed → EGITNOPERMISSION, exit 1, the same failure as in CI
  • modified script: prints 1.3.0, exit 0. With credentials the unmodified script resolves the same 1.3.0
  • node eng/verify-release-config.mjs 1.3.0 passes (breaking -> minor, releasing 1.3.0)

What is not verified

  • The workflow itself. The verify job refuses to run off main, so no pull-request check reaches it. Whether the dry run goes green is only known after merge, by dispatching Release with dry_run checked.
  • Everything after this step. The run stopped at step 7 of 13. Restore, build, test, pack, the artifact handover and the whole release job (RELEASE_TOKEN, OIDC) have never run in this shape, so this may not be the last failure. The test step runs the full suite as its gate, so a flaky test such as Sdo_BlockUpload_Server_Deadline_Measures_Peer_Idle_Time_Not_The_Whole_Transfer failed once on ubuntu-latest #240 could also stop it.

🤖 Generated with Claude Code

https://claude.ai/code/session_01UWRpkQzKkNDYz3WiNgWvWU


Generated by Claude Code

The release workflow's verify job failed at "Resolve next version" with
EGITNOPERMISSION on its first manual dry run. semantic-release runs
`git push --dry-run` against the repository URL before any plugin, dry run or
not, and aborts if that fails. The verify job deliberately has no credentials
(persist-credentials: false, contents: read), so the check could never pass
against the GitHub URL; the script's own comment claimed "no token" and that
was true of the plugins but not of this check.

eng/next-release-version.mjs now hands semantic-release the local checkout as
the repository URL. Pushing HEAD to the branch it already is needs no network
and no token and changes nothing, and the commit analyser still sees the full
history and tags that the checkout fetched.

Reproduced against a fresh clone of main with the network's credentials
removed: the unmodified script fails with "Authentication failed" and
EGITNOPERMISSION, the modified one prints 1.3.0, the same version the
unmodified script resolves with credentials.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UWRpkQzKkNDYz3WiNgWvWU
@cursor

cursor Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

PR Summary

Low Risk
CI-only change to a release helper script; no runtime app or permission expansion.

Overview
Fixes the credential-free Release workflow verify job failing with EGITNOPERMISSION when resolving the next version.

eng/next-release-version.mjs now passes the local checkout path as repositoryUrl (via fileURLToPath) so semantic-release’s pre-plugin git push --dry-run auth check succeeds without GitHub credentials. Comments document why that check runs even in dry-run mode. Commit-analyzer behavior and the verify job’s no-token design are unchanged.

Reviewed by Cursor Bugbot for commit fbba9ff. Bugbot is set up for automated code reviews on this repo. Configure here.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-30T04:14:47.650414Z fbba9ff PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@codecov

codecov Bot commented Sep 30, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@dborgards
dborgards merged commit 92bed55 into main Sep 30, 2026
14 checks passed
@dborgards
dborgards deleted the claude/nifty-albattani-e4b9fe branch September 30, 2026 04:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants