From 13ccfda06e294cbe8f583e4660126116709c593c Mon Sep 17 00:00:00 2001 From: mescon <5875228+mescon@users.noreply.github.com> Date: Mon, 14 Sep 2026 23:18:48 +0200 Subject: [PATCH] ci(release): run the provenance job whenever the hashes exist The first provenance-only dispatch hashed the assets and then skipped the generator: with the channel jobs skipped upstream, GitHub skips every dependant that does not say otherwise, whatever its direct dependency did. The job now runs whenever the hash job succeeded. --- .github/workflows/publish-release.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/publish-release.yml b/.github/workflows/publish-release.yml index adaf4cd..db15316 100644 --- a/.github/workflows/publish-release.yml +++ b/.github/workflows/publish-release.yml @@ -699,6 +699,9 @@ jobs: provenance: name: Sign the provenance needs: hashes + # Without this a skipped channel job upstream makes GitHub skip this + # one too, however hashes fared (seen on the first provenance-only run). + if: ${{ !cancelled() && needs.hashes.result == 'success' }} permissions: actions: read # the generator reads this run's metadata id-token: write # keyless signing through Sigstore