ci: every SDK publish workflow runs on every language's release tag (Python shows a misleading green)
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 76/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- github-actions, yaml
- Domain
- ci-cd
Research direction
Start in .github/workflows/publish-py.yml: its build job lacks the if: gate its publish job has, which is why non-Python tags show a green Python run. Read every publish-*.yml in .github/workflows/, add a workflow-level tag filter (or the if: condition) to every job, and standardize on github.event.release.tag_name where github.ref_name is used. Also delete release-py.yml as recommended. Done looks like: cutting a <lang>-sdk-v* tag starts only that language's workflow, with all others absent or skipped.
Written by the indexing model from the issue text.
Description
What we saw
Cutting js-sdk-v0.8.0 (and each other v0.8.0 tag) triggered every SDK publish workflow. They show up in the Actions list under that release's name with mixed results:
Publish Python SDK #68: Release js-sdk-v0.8.0shows success (19s).Publish PHP SDK #63: Release js-sdk-v0.8.0shows skipped.Publish JavaScript SDK #68: Release js-sdk-v0.8.0shows success. This is the only one that should run.
What actually happened (no bad publish)
publish-py.ymlhas no workflow-level filter. Itsbuildjob (tests + package build) runs on every release, and only thepublishjob is gated withif: startsWith(github.ref_name, 'py-sdk-v'). So on a JS/Go/Java/PHP/Ruby tag it runs the Python tests, skips publish, and the run reads green. Example: run 37562889995 onjs-sdk-v0.8.0shows build success and publish skipped.- The other workflows put the tag filter on their only job, so they show skipped.
- Net effect: 6 releases × 6 workflows = 36 runs per lockstep release, and a green "Publish Python SDK" on a non-Python tag looks like a Python publish happened.
Related
release-py.yml (a second Python release workflow, using PYPI_TOKEN) runs on every push touching packages/py-sdk/** and has failed with 403 on its last 6 runs. If its token were ever fixed, every py-sdk merge to main would publish to PyPI and race publish-py.yml (which uses OIDC trusted publishing). Recommend deleting it.
Suggested fix
- Gate each publish workflow at the workflow level so non-matching tags don't start a run. Either use
on: push: tags: ['py-sdk-v*']style triggers, or putif: startsWith(github.event.release.tag_name, '<lang>-sdk-v')on every job (includingbuild). - Use
github.event.release.tag_nameconsistently. py and go currently usegithub.ref_name; the others userelease.tag_name. - Delete
release-py.yml. publish-ruby.yml: RubyGems publish failed "Access Denied" (run 37562896184). The gem has never been published and needs aRUBYGEMS_API_KEY. Scheduled separately.
Low priority: nothing was published wrongly in v0.8.0. Found during the v1.132.0 post-deploy SDK release.
- Dominant language
- PHP
- Stars
- 1
- Forks
- 0
- Avg merge
- 3d 16h
- Merged PRs (30d)
- 10
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from TurboDocx/SDK
-
bug
Difficulty 1/5 Under an hour Newbie friendliness 86/100
Maintainers usually reply within 1 day
-
embed: handleTurboSignMessage header comment says the signing page posts to '*' (it never does)Opendocumentation
Difficulty 2/5 Under an hour Newbie friendliness 82/100
Maintainers usually reply within 1 day
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
Maintainers usually reply within 1 day
-
bug
Difficulty 1/5 Under an hour Newbie friendliness 88/100
Maintainers usually reply within 1 day
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
-
extension/Commercial needs-triage
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 2 days
-
Difficulty 1/5 Under an hour Newbie friendliness 90/100
crazy-goat/rabbit-stream#753 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
opensourcepos/opensourcepos#4743 ·
Maintainers usually reply within 2 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
OpenConext/OpenConext-engineblock#2129 ·
Maintainers usually reply within 3 days