Skip to content

chore: release v0.6.44 — ship pipeline auto-commit - #629

Merged
githubrobbi merged 2 commits into
mainfrom
release/v0.6.44
Oct 3, 2026
Merged

githubrobbi merged 2 commits into
mainfrom
release/v0.6.44

Conversation

@githubrobbi

Copy link
Copy Markdown
Collaborator

Summary

just ship Phase 2 auto-commit for v0.6.44 — the [workspace.package].version bump in Cargo.toml. This PR routes that commit through branch-protection rules. Once it merges to main, run just release-tag to cut the signed v0.6.44 tag, which fires release.yml and builds the cross-platform binaries + GitHub Release v0.6.44. (No auto-tag on merge — the tag step is manual on-demand, Path B.)

Auto-merge

--auto --squash is queued — GitHub will merge as soon as the required status checks pass. Squash is required because main-protection mandates signed commits, and GitHub's rebase-auto-merge cannot sign the rebased commit; the squash-merge commit is signed by GitHub's own key, which satisfies required_signatures: true. The original author's signed commit remains verifiable in the PR branch history.

After merge

The auto-commit lived only on release/v0.6.44, so local main never drifted — sync it with a plain git pull --ff-only origin main (no reset --hard needed).

… scope

Field failure 2026-10-03 (v0.6.43): microsoft/winget-pkgs had merged a
.github/workflows change since the last release, and GitHub refuses to
fast-forward a fork over such commits for a PAT without the `workflow`
scope.  The sync step was `continue-on-error` with a `||` warning, so
the refusal scrolled past, the fork stayed 81 commits behind, and komac
failed with the same misleading `CreateRef` permissions error as the
August stale-fork incident — the submission looked like a credential
problem again.

The sync step now fails hard, naming the real cause: the workflow-scope
refusal gets its own message with the in-place PAT fix and the manual
sync command, any other sync failure says so, and a fork that is still
behind upstream after the sync stops the job before komac runs.  The
weekly readiness probe reads the token's scopes directly (the refusal
only reproduces while upstream has pending workflow changes, so the
sync-then-branch probe alone can pass one week and fail the next) and
treats a failed or incomplete sync as not ready.  Docs and the rotation
issue state the required scopes: `public_repo` + `workflow`.
@githubrobbi
githubrobbi enabled auto-merge October 3, 2026 06:29
@githubrobbi
githubrobbi added this pull request to the merge queue Oct 3, 2026
Merged via the queue into main with commit c8c74a8 Oct 3, 2026
23 checks passed
@githubrobbi
githubrobbi deleted the release/v0.6.44 branch October 3, 2026 06:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant