Skip to content

[codex] Harden sbom-diff-and-risk release asset automation#12

Merged
stacknil merged 1 commit intomainfrom
codex/sbom-diff-risk-v040x-release-automation
Apr 22, 2026
Merged

[codex] Harden sbom-diff-and-risk release asset automation#12
stacknil merged 1 commit intomainfrom
codex/sbom-diff-risk-v040x-release-automation

Conversation

@stacknil
Copy link
Copy Markdown
Owner

Summary

  • keep this follow-up strictly within sbom-diff-and-risk release asset automation
  • make publish-release-assets use explicit repo context for all gh release operations
  • fetch full tag/history context before using gh release create --verify-tag

Notes

  • no CLI behavior changes
  • current remote main already has checkout@v5 and setup-python@v6 in the sbom-diff-and-risk workflows, so this PR does not churn those versions further
  • workflow_dispatch sanity check passed on this branch: run 24742814836
  • the publish-release-assets job is still tag-gated, so the exact release-asset path will be fully exercised on the next v0.4.x or later tag

@stacknil stacknil merged commit fdfbd50 into main Apr 22, 2026
6 checks passed
@stacknil stacknil deleted the codex/sbom-diff-risk-v040x-release-automation branch April 22, 2026 01:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant