Community catalog workflows: make tag-pinned download_url a MUST and reject `releases/latest/`

Abierto
#4,185 2 comentarios 0 reacciones 1 asignado Ver en GitHub

@Shaurya2k06 ya está trabajando en esto.

Desde el 19/8/2026.

Evaluación

Este issue todavía no se ha evaluado.

Descripción

bug-assess severity-high

Problem

The community-catalog agentic workflows only softly require a version-pinned download_url. Step 2d currently says the URL "should follow the pattern" — advisory language an autonomous run can rationalize around.

This surfaced in PR #4183 (update speckit-superpowers-bridge to v1.2.0), where the run switched the URL to a floating "latest" alias and validation passed it:

- .../releases/download/v1.1.0/speckit-superpowers-bridge-v1.1.0.zip   (tag-pinned)
+ .../releases/latest/download/speckit-superpowers-bridge.zip          (floating "latest")

…/releases/latest/download/… is neither of the two accepted tag-pinned patterns. It resolves to whatever the newest release happens to be, not to the <tag> (v1.2.0) recorded in the entry — so the catalog would keep serving the author's future releases under the pinned "version": "1.2.0" record. That's an integrity/reproducibility hole and breaks the convention (all existing catalog download_urls are tag-pinned; none use releases/latest).

The run passed validation because the checks only confirmed the URL returns HTTP 200 and that a v1.2.0 release exists — neither verifies the URL is pinned to the v1.2.0 tag.

Affected workflows

Same soft wording appears in all three community-catalog workflows:

  • .github/workflows/add-community-extension.md:110
  • .github/workflows/add-community-bundle.md:123
  • .github/workflows/add-community-preset.md:164

Proposed changes

  1. Change "should follow the pattern" → MUST for the tag-pinned download_url requirement in all three workflows.
  2. Add an explicit rejection rule: a download_url whose path contains releases/latest/ fails validation, even if it returns HTTP 200.
  3. Strengthen the release check to verify the URL's <tag> segment matches the submitted v<version> (not just that a release exists and a URL 200s).

Accepted URL patterns (unchanged)

  • https://github.com/<owner>/<repo>/archive/refs/tags/v<version>.zip
  • https://github.com/<owner>/<repo>/releases/download/<tag>/<asset>.zip

Context

  • PR #4183
Lenguaje dominante
Python
Estrellas
138k
Forks
12.4k
Merge medio
3 d 6 h
PR fusionados (30 d)
136

Guía de contribución

Abrir la guía de contribución

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de github/spec-kit

Todos los issues de github/spec-kit

Issues similares

Más issues de Python

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.