Skip to content

fix(release): push the version bump without rewriting the origin remote - #26

Merged
tokio-on-jupiter merged 2 commits into
mainfrom
PLATENG-1214/release-push-explicit-url
Sep 23, 2026
Merged

tokio-on-jupiter merged 2 commits into
mainfrom
PLATENG-1214/release-push-explicit-url

Conversation

@tokio-on-jupiter

Copy link
Copy Markdown
Contributor

Why

Run 35279850618 (the first release after #25) got further than any run before it: Chart.yaml bumped to 1.1.1 and committed, v1.1.1 tagged, application-1.1.1 published with .tgz and .prov. It then failed inside chart-releaser at the gh-pages index push:

fatal: unable to access '***github.com/JupiterOne/apps-helm-charts/': URL rejected: Port number was not a decimal number between 0 and 65535

Cause: the bump step ran git remote set-url origin https://x-access-token:<token>@github.com/... so it could push, and since #23 moved that step ahead of publishing, chart-releaser now sees the rewritten remote. chart-releaser v1.6.1 builds its push URL from origin (pkg/git/git.go GetPushURL: git remote get-url --push origin, split after https://, prefix https://x-access-token:<CR_TOKEN>@). With a token already in origin the result is

https://x-access-token:CRTOKEN@x-access-token:TOKEN@github.com/JupiterOne/apps-helm-charts

and curl parses TOKEN@github.com as a port number. Before #23 chart-releaser ran first and never saw the rewritten remote, which is why this never surfaced.

What

The bump step pushes through an explicit URL (git push "https://x-access-token:${TOKEN}@github.com/${GITHUB_REPOSITORY}.git" HEAD:main) and leaves origin untouched. Nothing else changes.

Verification

  • curl 'https://x-access-token:abc@x-access-token:abc@github.com/' returns curl: (3) URL rejected: Port number was not a decimal number between 0 and 65535, the same message as the run.
  • Replaying chart-releaser's construction on both origin shapes: a clean origin yields a valid single-credential URL; the rewritten origin yields the doubled one above.
  • On the runner image (catthehacker/ubuntu:act-latest, Ubuntu 24.04) via act: an explicit-URL git push --dry-run against this repository succeeds with origin left at https://github.com/JupiterOne/apps-helm-charts, and cr index (without --push) generates the index normally against that origin.

After merge

GitVersion resolves 1.1.2 from the v1.1.1 tag, the bump and tag land, chart-releaser publishes application-1.1.2 and rebuilds gh-pages/index.yaml from all releases, which also adds the missing 1.1.0 and 1.1.1 entries. No manual repair needed.

chart-releaser derives its gh-pages push URL from origin (pkg/git/git.go
GetPushURL: git remote get-url --push, then prefixes
https://x-access-token:<token>@). Since #23 moved the bump commit ahead of
publishing, the bump step's remote set-url left a token inside origin, so
chart-releaser produced token@token@github.com and git failed with
"URL rejected: Port number was not a decimal number" (run 35279850618,
after application-1.1.1 and its tag were already published). The bump is
now pushed through an explicit URL and origin is never modified.

Co-authored-by: Claude <noreply@anthropic.com>
@tokio-on-jupiter
tokio-on-jupiter requested a review from a team as a code owner September 18, 2026 02:07
@github-actions

github-actions Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

@ryanmcafee Validation Successful

@tokio-on-jupiter
tokio-on-jupiter merged commit aaf8787 into main Sep 23, 2026
3 checks passed
@tokio-on-jupiter
tokio-on-jupiter deleted the PLATENG-1214/release-push-explicit-url branch September 23, 2026 19:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants