From d976038dc835bdc5d0edc26c67081a76bfc37dd3 Mon Sep 17 00:00:00 2001 From: Copilot <198982749+Copilot@users.noreply.github.com> Date: Sun, 19 Apr 2026 09:41:30 +0100 Subject: [PATCH] fix: guard RC docker job against empty vtag and add early validation in docker.yml (#983) * Initial plan * fix: guard docker job and add tag validation in docker.yml - Add `&& needs.publish.outputs.vtag != ''` to the `docker` job's `if:` in release-candidate.yml so it is skipped when publish produces no vtag, preventing an opaque buildx "tag is needed" error. - Add an early "Validate tag input" step in docker.yml that fails fast with a clear ::error:: message when inputs.tag is empty, covering direct workflow_call invocations that bypass the release-candidate guard. Agent-Logs-Url: https://github.com/abhigyanpatwari/GitNexus/sessions/b9afe2df-85ea-4a87-bf30-77f0e945a64d Co-authored-by: magyargergo <11230420+magyargergo@users.noreply.github.com> * fix: scope docker.yml tag validation to workflow_call only Direct tag-push triggers (on: push, tags: v*) populate the tag from GITHUB_REF and have inputs.tag empty, so the unconditional validation step would fail every direct tag-push run. Restrict the new step to workflow_call invocations, which is the only path where an empty tag is actually a problem. Agent-Logs-Url: https://github.com/abhigyanpatwari/GitNexus/sessions/4b7e3bfa-15c0-4186-affa-95cd71e50153 Co-authored-by: magyargergo <11230420+magyargergo@users.noreply.github.com> --------- Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: magyargergo <11230420+magyargergo@users.noreply.github.com> --- .github/workflows/docker.yml | 11 +++++++++++ .github/workflows/release-candidate.yml | 2 +- 2 files changed, 12 insertions(+), 1 deletion(-) diff --git a/.github/workflows/docker.yml b/.github/workflows/docker.yml index ce583e537..1b83a1e4b 100644 --- a/.github/workflows/docker.yml +++ b/.github/workflows/docker.yml @@ -60,6 +60,17 @@ jobs: slug: gitnexus steps: + - name: Validate tag input + if: github.event_name == 'workflow_call' + shell: bash + env: + TAG_INPUT: ${{ inputs.tag }} + run: | + if [ -z "${TAG_INPUT}" ]; then + echo "::error::No tag provided to docker.yml — refusing to build/push." + exit 1 + fi + # When triggered by workflow_call the caller passes the RC tag as an input; # we check out that tag so the Dockerfile and package.json match the built image. # For tag-push events github.ref is already the tag ref — no override needed. diff --git a/.github/workflows/release-candidate.yml b/.github/workflows/release-candidate.yml index 3e35a58ee..61782da1c 100644 --- a/.github/workflows/release-candidate.yml +++ b/.github/workflows/release-candidate.yml @@ -377,7 +377,7 @@ jobs: docker: name: Build & Push RC Docker images needs: [guard, publish] - if: needs.guard.outputs.should_run == 'true' + if: needs.guard.outputs.should_run == 'true' && needs.publish.outputs.vtag != '' uses: ./.github/workflows/docker.yml permissions: contents: read