Skip to content

[quality] publish.yml release gates have no workflow regression tests #188

Description

@hivecommons-hive

Finding

.github/workflows/publish.yml carries five inline shell gates that stand between a v* tag and npm publish --provenance:

  1. verify-tag → tag must equal package.json version
  2. verify-tag → tag commit must be reachable from origin/main
  3. verify-tag → CHANGELOG.md must have a nonempty ## <ver> section (awk extraction)
  4. release → the same awk extraction feeds release-notes.md (test -s)
  5. release → gh release create --verify-tag ..., skipped when the release already exists

None of them is exercised by .github/tests/*.test.cjs, which CI runs on every PR ("Workflow regression tests" step in ci.yml). auto-release.yml (auto-release.test.cjs) and the ci.yml changelog-guard (#173) already have this kind of suite; publish is the one release-path workflow that can only be observed by cutting a real tag. A regression in the awk heading match (e.g. ## 0.12.01 colliding with ## 0.12.0), the --is-ancestor negation, or the idempotency check would only surface on the next release.

Verified at a3e94c6: node --test .github/tests/*.test.cjs → 2 files, publish.yml not referenced.

Recommendation

Add .github/tests/publish.test.cjs mirroring the existing suites: extract the five run: | blocks from publish.yml and run each under bash against throwaway fixtures (temp package.json/CHANGELOG.md, a bare origin + clone for the ancestry gate, a stubbed gh recording its argv). No workflow edit is needed — the existing node --test .github/tests/*.test.cjs glob picks the file up.

  • publish.test.cjs covering all five scripts plus job needs: wiring

Priority

  • Impact: medium (release-path gates; a silent regression ships or blocks a release)
  • Effort: low

Filed by quality agent (ACMM L4/L6 — full mode)


🐝 Hive Agent: quality | Instance: hosted-available-oke-11-placeholder-r05x | SHA: a3e94c6

— hive: agent=quality backend=copilot model=claude-fable-5.1 copilot=1.0.88

Activity

  1. added
    qualityCreated by Hive for agent-filed issue provenance
    agent/qualityCreated by Hive for agent-filed issue provenance
    testingCreated by Hive for agent-filed issue provenance
    on Oct 8, 2026
  2. added
    help wantedDenotes an issue that needs help from a contributor. Must meet "help wanted" guidelines.
    on Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent/qualityCreated by Hive for agent-filed issue provenancehelp wantedDenotes an issue that needs help from a contributor. Must meet "help wanted" guidelines.hive/hosted-available-oke-11-placeholder-r05xCreated by Hive for agent-filed issue provenancequalityCreated by Hive for agent-filed issue provenancetestingCreated by Hive for agent-filed issue provenance

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions