chore: release v0.6.44 — ship pipeline auto-commit - #629
Merged
Merged
Conversation
… scope Field failure 2026-10-03 (v0.6.43): microsoft/winget-pkgs had merged a .github/workflows change since the last release, and GitHub refuses to fast-forward a fork over such commits for a PAT without the `workflow` scope. The sync step was `continue-on-error` with a `||` warning, so the refusal scrolled past, the fork stayed 81 commits behind, and komac failed with the same misleading `CreateRef` permissions error as the August stale-fork incident — the submission looked like a credential problem again. The sync step now fails hard, naming the real cause: the workflow-scope refusal gets its own message with the in-place PAT fix and the manual sync command, any other sync failure says so, and a fork that is still behind upstream after the sync stops the job before komac runs. The weekly readiness probe reads the token's scopes directly (the refusal only reproduces while upstream has pending workflow changes, so the sync-then-branch probe alone can pass one week and fail the next) and treats a failed or incomplete sync as not ready. Docs and the rotation issue state the required scopes: `public_repo` + `workflow`.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
just shipPhase 2 auto-commit for v0.6.44 — the[workspace.package].versionbump inCargo.toml. This PR routes that commit through branch-protection rules. Once it merges tomain, runjust release-tagto cut the signedv0.6.44tag, which firesrelease.ymland builds the cross-platform binaries + GitHub Release v0.6.44. (No auto-tag on merge — the tag step is manual on-demand, Path B.)Auto-merge
--auto --squashis queued — GitHub will merge as soon as the required status checks pass. Squash is required becausemain-protectionmandates signed commits, and GitHub's rebase-auto-merge cannot sign the rebased commit; the squash-merge commit is signed by GitHub's own key, which satisfiesrequired_signatures: true. The original author's signed commit remains verifiable in the PR branch history.After merge
The auto-commit lived only on
release/v0.6.44, so localmainnever drifted — sync it with a plaingit pull --ff-only origin main(noreset --hardneeded).