The README tells consumers to pin the v1 tag, and no workflow tests main #58

Open
opened 2026-10-06 05:35:54 +00:00 by jercik · 0 comments
Owner

The README describes a release process the repository does not follow, and the checks run on pull request heads only, so the merge result that consumers pin is never tested by a workflow.

The README names a tag nobody pins

The Release section says to move the v1 tag to the new bundle commit and that "consumers pin the action at v1" (README.md:165-167). This repository's own review workflow pins a full commit SHA (.forgejo/workflows/review.yml:81), and the pin updates land as commits such as "chore: update review wrapper pin". The repository has no tags, so the v1 tag the section moves and tells consumers to pin does not exist.

The section should describe what happens: merge to main, then pin the merge commit's full SHA. A moving tag is the weaker pin, and the wrapper's security notes assume the pinned bundle is the reviewed one.

No workflow runs on main

checks.yml triggers on pull_request and workflow_call only (.forgejo/workflows/checks.yml:5). commit-msg.yml runs on pull requests. dedupe-check.yml runs on pushes to main, but only when pnpm-lock.yaml changes. The test suite, including the test that rebuilds the bundle and compares it with the committed dist/index.mjs, never runs on a merge result.

Consumers run dist/index.mjs at a commit on main. A squash merge produces a tree that no check saw whenever main moved after the pull request's last run, and nothing would show it.

Add push: branches: [main] to the Checks workflow. The file's header says a standalone repository renders it, so it may be generated by j4k-align. If so, the trigger belongs in the template that renders it.

🤖 Generated with Claude Code

The README describes a release process the repository does not follow, and the checks run on pull request heads only, so the merge result that consumers pin is never tested by a workflow. ## The README names a tag nobody pins The Release section says to move the `v1` tag to the new bundle commit and that "consumers pin the action at `v1`" ([`README.md:165-167`](https://code.j4k.dev/j4k-oss/review-wrapper/src/commit/9f272a522e8ed6f748533761de45ee3e94fd7481/README.md#L165-L167)). This repository's own review workflow pins a full commit SHA ([`.forgejo/workflows/review.yml:81`](https://code.j4k.dev/j4k-oss/review-wrapper/src/commit/9f272a522e8ed6f748533761de45ee3e94fd7481/.forgejo/workflows/review.yml#L81)), and the pin updates land as commits such as "chore: update review wrapper pin". The repository has no tags, so the `v1` tag the section moves and tells consumers to pin does not exist. The section should describe what happens: merge to `main`, then pin the merge commit's full SHA. A moving tag is the weaker pin, and the wrapper's security notes assume the pinned bundle is the reviewed one. ## No workflow runs on `main` `checks.yml` triggers on `pull_request` and `workflow_call` only ([`.forgejo/workflows/checks.yml:5`](https://code.j4k.dev/j4k-oss/review-wrapper/src/commit/9f272a522e8ed6f748533761de45ee3e94fd7481/.forgejo/workflows/checks.yml#L5)). `commit-msg.yml` runs on pull requests. `dedupe-check.yml` runs on pushes to `main`, but only when `pnpm-lock.yaml` changes. The test suite, including the test that rebuilds the bundle and compares it with the committed `dist/index.mjs`, never runs on a merge result. Consumers run `dist/index.mjs` at a commit on `main`. A squash merge produces a tree that no check saw whenever `main` moved after the pull request's last run, and nothing would show it. Add `push: branches: [main]` to the Checks workflow. The file's header says a standalone repository renders it, so it may be generated by `j4k-align`. If so, the trigger belongs in the template that renders it. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
Sign in to join this conversation.
No labels
No milestone
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
j4k-oss/review-wrapper#58
No description provided.