Fix the release job when Syft's installer treats a GitHub 302 as failure - #4
Open
dimondevceo wants to merge 1 commit into
Open
dimondevceo wants to merge 1 commit into
dimondevceo wants to merge 1 commit into
Conversation
…release tag. anchore install.sh treats a failed follow of the release-asset 302 as a hard error and does not retry. The release job then deletes the tag before GoReleaser runs. Co-authored-by: DimonDev <dimondevceo@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes the release job failure on main at
6694afb(run 36654794921). The job deleted tagv0.9.12before GoReleaser ran. The next push publishedv0.9.12on run 36655166444. This change stops the same hop from dropping the next tag.Root cause
anchore/sbom-action/download-syft@v0runs Anchoreinstall.shfor Syft v1.42.3. That script downloadshttps://github.com/anchore/syft/releases/download/v1.42.3/syft_1.42.3_checksums.txtwithcurl -sLand accepts only HTTP 200.GitHub answers that URL with 302 to
release-assets.githubusercontent.com. When the second hop fails, curl exits 7, reports status 302, and writes no file.install.shhas no retry, so the step fails. GoReleaser is skipped. The job deletes the tag it just pushed.Reproduced locally with the runner's curl (8.5.0-2ubuntu10.13) pointed at a closed redirect target: captured code
302, output file absent, exit 7. The same curl follows the live redirect and installs Syft 1.42.3. Twelve repeats of that download all returned 200. The failed runner image wasubuntu24/20260920.314. The next release usedubuntu24/20260927.320and the samedownload-syft@v0step succeeded.What changed
.github/workflows/release.ymlonly. The Syft step downloads the pinned v1.42.3 linux archive withcurl -fsSL --retry 5 --retry-all-errors, checkssha256sum, and putssyftonPATH. Tag creation, tag deletion on a failed publish, GHCR login, cosign, and.goreleaser.yamlare unchanged.How verified
302, exit 7, no file.--retry-all-errorsretries that exit.OK,syft1.42.3 onPATH.bash -non the step script. Workflow YAML parses.Residual risk
A retry of
download-syft@v0alone would have published this release. Run 36655166444 did that and shipped v0.9.12. The installer can still fail the same way on the next blip, which is why the step now retries.Merging this to main cuts the next patch tag and publishes it. Do not merge from this card. CoS QC, then CEO.