This is an automated email from the ASF dual-hosted git repository.

kevinjqliu pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/iceberg-rust.git


The following commit(s) were added to refs/heads/main by this push:
     new 0e7cc4f19 chore(ci): Add check to Python release to verify workflow is 
running on expected tag (#2912)
0e7cc4f19 is described below

commit 0e7cc4f19ef3b8d29a5f81e3f666a76a6130a9d5
Author: Daniel Carl Jones <[email protected]>
AuthorDate: Fri Jul 31 18:26:42 2026 +0200

    chore(ci): Add check to Python release to verify workflow is running on 
expected tag (#2912)
    
    ## Which issue does this PR close?
    
    Addresses issue where pyiceberg-core was released from `main` rather
    than the release branch.
    The change should prevent this scenario from recurring.
    
    ## What changes are included in this PR?
    
    The code will checkout the ref it was executed with, and this change
    asserts that we're on a tagged commit.
    
    It may be worth removing the input version argument and simply using the
    tag that the workflow was invoked with - this is enough information.
    However, I wanted to keep changes simple for now.
    
    ## Are these changes tested?
    
    Yes, manually:
    
    - Invoked from a branch rather than a tag:
    
https://github.com/dannycjones/iceberg-rust/actions/runs/30254503263/job/89939838125
    - Invoked correctly (but the actually packages are wrong so fails
    anyway):
    
https://github.com/dannycjones/iceberg-rust/actions/runs/30254526325/job/89939906112
---
 .github/workflows/release_python.yml | 13 +++++++++++--
 1 file changed, 11 insertions(+), 2 deletions(-)

diff --git a/.github/workflows/release_python.yml 
b/.github/workflows/release_python.yml
index 53a481451..4183c1869 100644
--- a/.github/workflows/release_python.yml
+++ b/.github/workflows/release_python.yml
@@ -61,11 +61,20 @@ jobs:
             exit 1
           fi
           echo "✅ Release tag format is valid: $RELEASE_TAG"
-          
+
+          # Verify that the workflow is being run on the same version as the 
release tag
+          DESIRED_REF="refs/tags/${RELEASE_TAG}"
+          if [[ "${GITHUB_REF}" != "${DESIRED_REF}" ]]; then
+            echo "❌ Error: expected workflow execution on ref ${DESIRED_REF}, 
got ref: ${GITHUB_REF}"
+            echo "Workflow must be dispatched against the tag ref for the 
desired release."
+            echo "Dispatching workflow from main or another branch is not 
supported."
+            exit 1
+          fi
+
           # Strip 'v' prefix for cargo version
           CARGO_VERSION="${RELEASE_TAG#v}"
           echo "Cargo version (without v prefix): $CARGO_VERSION"
-          
+
           # For manual triggers, validate that the tag matches the version in 
Cargo.toml
           if [ "${{ github.event_name }}" == "workflow_dispatch" ]; then
             # Extract base version (without -rc.X suffix) for comparison with 
Cargo.toml

Reply via email to