Repository navigation
feat(NO-TASK): Add the release post action - #1
Merged
Merged
Conversation
Composite action that reports a published GitHub release to the linchpin/v1/release-post endpoint on builditbelieveit.com, which writes the draft post. Nothing is generated here. Everything reaches the script through the environment — release notes are built from commit messages, including bot ones, so interpolating them into a run block would be a shell injection. The payload is assembled with jq for the same reason string quoting cannot survive multi-line markdown. The response is read as text before anything parses it as JSON. This request crosses Cloudflare Access and a WAF before it reaches WordPress and all three answer with HTML when unhappy, so a non-JSON body reports status, content-type, cf-ray and a snippet rather than a parse error. Failures annotate and exit 0 by default. A release must not be held up because the blog was unreachable. CI lints action.yml as well as the workflows, which the shared actions repo does not do for its own composite actions, and runs the action against itself in dry-run mode so the wiring is covered without credentials. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The initial contents of this repo. Paired with
linchpin/linchpin.com#1023, which adds
the endpoint this calls.
mainis an empty root commit — the repo had no commits, so there was no base to open a PRagainst. Everything real is in this one.
What it does
Reports a published GitHub release to
linchpin/v1/release-poston builditbelieveit.com,which writes the draft post. Nothing is generated here; this only rings the bell and reports
where the draft landed.
A caller usually passes
productand the credentials — the rest defaults off the releaseevent.
Choices worth reviewing
env:. Release notes are built from commitmessages, including bot ones, so a
${{ }}inside arun:block would be a shellinjection. The payload is assembled with
jqfor the same reason string quoting cannotsurvive multi-line markdown intact.
Cloudflare Access and a WAF before reaching WordPress and all three answer with HTML when
unhappy, so a non-JSON body reports status,
content-type,cf-rayand the first 300bytes rather than a parse error.
blog was unreachable.
fail-on-error: trueflips it.000,429,5xx. A 4xx is our own bad requestand would fail identically three times.
action.yml, which the sharedlinchpin/actionsCI does not do for its owncomposite actions, and runs this action against itself in dry-run mode so the wiring is
covered without credentials.
Verification
Exercised against a stub endpoint across nine cases: created, ungenerated-overview warning,
human_edited,already_published, two 503s then success, a Cloudflare HTML challenge pagewith and without
fail-on-error, a 401, and dry-run. Payload and headers were confirmedbyte-for-byte on the wire, including that the credential is masked before it can reach a log
line. YAML parses and is within the 125-column limit;
bash -nclean.Before the first caller can use this
Settings → Actions → General → Access → Accessible from repositories in the linchpin
organization, or every caller fails with "repository not found".
Setup in the README.
release-as: "1.0.0"is pinned inrelease-please-config.jsonso the first tag matchesthe
@v1contract callers use. Remove it once v1.0.0 has shipped, or every subsequentrelease will try to be 1.0.0 again.
Scope
Committed as
NO-TASK. Happy to amend with a ClickUp key.