Conversation
Passing a commit SHA to `gh release create --target` sets the release's
targetCommitish to the SHA rather than the source branch name. Consumers
that use the GH releases API to derive "which branch was this nightly
built for" then get back a 40-hex string instead of "3008.x" / "master"
and can end up mis-routing downstream artifacts.
Concretely, this is what caused the recent Broadcom nightly-publish
watcher to fanout to Artifactory paths like
nightly/rpm/191a6df6d9cec9f16ddcde15b6a6a28a7426d2c7/
instead of
nightly/rpm/3008.x/
before the watcher was patched to derive branch from the release body
instead of targetCommitish. Switching --target to the branch name here
is the belt-and-suspenders fix; anyone else reading targetCommitish will
now see a branch name.
The release body still records the exact commit
"Nightly build from branch `${BRANCH}` at commit `${HEAD_SHA}`."
so per-commit traceability is preserved.
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Passing a commit SHA to
gh release create --targetsets the release's targetCommitish to the SHA rather than the source branch name. Consumers that use the GH releases API to derive "which branch was this nightly built for" then get back a 40-hex string instead of "3008.x" / "master" and can end up mis-routing downstream artifacts.Concretely, this is what caused the recent Broadcom nightly-publish watcher to fanout to Artifactory paths like
nightly/rpm/191a6df6d9cec9f16ddcde15b6a6a28a7426d2c7/
instead of
nightly/rpm/3008.x/
before the watcher was patched to derive branch from the release body instead of targetCommitish. Switching --target to the branch name here is the belt-and-suspenders fix; anyone else reading targetCommitish will now see a branch name.
The release body still records the exact commit
"Nightly build from branch
${BRANCH}at commit${HEAD_SHA}."so per-commit traceability is preserved.