Skip to content

Fix the release job when Syft's installer treats a GitHub 302 as failure - #4

Open
dimondevceo wants to merge 1 commit into
mainfrom
cursor/fix-release-syft-install-7dcc
Open

dimondevceo wants to merge 1 commit into
mainfrom
cursor/fix-release-syft-install-7dcc

Conversation

@dimondevceo

Copy link
Copy Markdown
Collaborator

Fixes the release job failure on main at 6694afb (run 36654794921). The job deleted tag v0.9.12 before GoReleaser ran. The next push published v0.9.12 on run 36655166444. This change stops the same hop from dropping the next tag.

Root cause

anchore/sbom-action/download-syft@v0 runs Anchore install.sh for Syft v1.42.3. That script downloads https://github.com/anchore/syft/releases/download/v1.42.3/syft_1.42.3_checksums.txt with curl -sL and accepts only HTTP 200.

GitHub answers that URL with 302 to release-assets.githubusercontent.com. When the second hop fails, curl exits 7, reports status 302, and writes no file. install.sh has no retry, so the step fails. GoReleaser is skipped. The job deletes the tag it just pushed.

Reproduced locally with the runner's curl (8.5.0-2ubuntu10.13) pointed at a closed redirect target: captured code 302, output file absent, exit 7. The same curl follows the live redirect and installs Syft 1.42.3. Twelve repeats of that download all returned 200. The failed runner image was ubuntu24/20260920.314. The next release used ubuntu24/20260927.320 and the same download-syft@v0 step succeeded.

What changed

.github/workflows/release.yml only. The Syft step downloads the pinned v1.42.3 linux archive with curl -fsSL --retry 5 --retry-all-errors, checks sha256sum, and puts syft on PATH. Tag creation, tag deletion on a failed publish, GHCR login, cosign, and .goreleaser.yaml are unchanged.

How verified

  • Failed-hop shape: curl reports 302, exit 7, no file. --retry-all-errors retries that exit.
  • Live install of the workflow script: checksum OK, syft 1.42.3 on PATH.
  • bash -n on the step script. Workflow YAML parses.

Residual risk

A retry of download-syft@v0 alone would have published this release. Run 36655166444 did that and shipped v0.9.12. The installer can still fail the same way on the next blip, which is why the step now retries.

Merging this to main cuts the next patch tag and publishes it. Do not merge from this card. CoS QC, then CEO.

Open in Web Open in Cursor 

…release tag.

anchore install.sh treats a failed follow of the release-asset 302 as a hard error and does not retry. The release job then deletes the tag before GoReleaser runs.

Co-authored-by: DimonDev <dimondevceo@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants