fix(github): create the release over the REST API; drop GitHub-only annotations #51
No reviewers
Labels
No labels
pull-request
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
webgrip/workflows!51
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "chore/forgejo-native-diagnostics"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Two changes to the Forgejo tree, both from chasing the ploeg GitHub track to green.
1.
fix(github): create the release over the REST API, not theghCLIThe Forgejo ci-runner image does not ship
gh. ploeg run 181 mirrored every branch and tag to github.com successfully and then died on the next line:leaving the repo mirrored but with no GitHub Release — the one part of the GitHub track that had never actually run.
Installing
ghwould have been the wrong fix: another github.com download on the release path, which is exactly the dependency that keeps flaking here (the syft installer took the signing job down in runs 172 and 175, then recovered on its own in 177).curlandjqare already present, and this step already used both for the Forgejo API.gh release view→GET /releases/tags/{tag}.gh release create→POST /releaseswith a jq-built payload.--verify-tagis preserved explicitly, becausePOST /releaseswill otherwise create the tag as a side effect, and a release pointing at a tag the mirror never pushed would be a silent lie.GH_HOSTis dropped — it only ever configured the CLI.Verified against a stubbed curl across all five branches: release already exists, tag not mirrored, create with Forgejo notes, create with generated notes, and a 422.
2.
chore(forgejo): drop GitHub-only annotation commands from.forgejo/::error::/::warning::/::notice::create annotations on GitHub. On Forgejo they create nothing —act_runnerre-emits the line with a❗marker but keeps the raw::error::text, and the job API has no field to put an annotation in.$GITHUB_STEP_SUMMARYis not an alternative either; Forgejo dumps it into the log as one line with literal\n.All 34 cosmetic sites in
.forgejo/become plainERROR:/WARN:/NOTE:, with operator-actionable remediation on the last lines beforeexit 1.::add-mask::untouched at all 5 sites — that one IS functional on act_runner and is what producesAUTHORIZATION: basic ***in checkout logs..github/untouched, per ADR 002 — the commands do real work there.The Forgejo ci-runner image does not ship `gh`. ploeg run 181 mirrored every branch and tag to github.com successfully and then died on the next line with line 18: gh: command not found leaving the repo mirrored but with no GitHub Release — the one part of the GitHub track that had never actually run. Installing gh was the wrong fix: it would put another github.com download on the release path, which is precisely the dependency that keeps flaking here (the syft installer took the signing job down in runs 172 and 175, and recovered on its own in 177). curl and jq are already present and this step already used both for the Forgejo API. `gh release view` becomes GET /releases/tags/{tag}, and `gh release create` becomes POST /releases with a jq-built payload. `--verify-tag` is preserved explicitly, because POST /releases will otherwise CREATE the tag as a side effect and a release pointing at a tag the mirror never pushed would be a silent lie. GH_HOST is dropped; it only ever configured the gh CLI. Verified by running the step body against a stubbed curl across all five branches: release already exists, tag not mirrored, create with Forgejo notes, create with generated notes, and a 422 from the API. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>chore(forgejo): drop GitHub-only annotation commands from the .forgejo treeto fix(github): create the release over the REST API; drop GitHub-only annotations