fangorn/ex_git_objectstore
public
ref:4fb06f82042940ee7204eaa1e42ddac84f13e46a
fix(ci): stop a released tag from triggering another release
`release` ends by pushing a tag. That push starts a CI run, and that run's
HEAD is still the main commit — so the "am I on main?" SHA gate passes, and
it releases again, tags again, and starts another run.
It is not hypothetical. 2026.7.6, 2026.7.7 and 2026.7.8 are three releases of
the identical commit a7e0745, each minted by the run the previous one's tag
push started. The chain stopped only because an unrelated 403 broke it, not
because anything noticed.
The SHA gate cannot catch this by construction: a tag pointing at the main
commit is indistinguishable from main by SHA. Only the ref distinguishes them,
so both `release` and `bump-anvil-pin` now refuse a run whose ANVIL_BRANCH is
under refs/tags/. Without the guard on `bump-anvil-pin` too, every tag would
also open a second identical pin-bump PR.
ANVIL_BRANCH carries the full ref — the runner injects `pipeline_run.branch`,
which PushConsumer sets to `event.ref` verbatim.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
SHA:
4fb06f82042940ee7204eaa1e42ddac84f13e46a
Author:
Cole Christensen <cole.christensen@gmail.com>
Date:
2026-08-05 02:47
Parents:
aa652cb
1 files changed
+27
-0
| Type | ||
|---|---|---|
|
|
.anvil.yml | +27 −0 |
|
||