Skip to content

chore(main): release hve-core 3.2.1#1166

Merged
WilliamBerryiii merged 1 commit intomainfrom
release-please--branches--main--components--hve-core
Mar 23, 2026
Merged

chore(main): release hve-core 3.2.1#1166
WilliamBerryiii merged 1 commit intomainfrom
release-please--branches--main--components--hve-core

Conversation

@hve-core-release-please
Copy link
Copy Markdown
Contributor

@hve-core-release-please hve-core-release-please bot commented Mar 21, 2026

🤖 I have created a release beep boop

3.2.1 (2026-03-23)

🐛 Bug Fixes

  • workflows: expand dependency-review license allow-list and add docusaurus build step (#1168) (5458cab)
  • workflows: prevent zero-diff force-push, fix SBOM attestation, and consolidate security collection (#1159) (0fbd111)

This PR was generated with Release Please. See documentation.

@hve-core-release-please hve-core-release-please bot requested a review from a team as a code owner March 21, 2026 00:30
@hve-core-release-please hve-core-release-please bot added the autorelease: pending Release-please: PR awaiting merge label Mar 21, 2026
@codecov-commenter
Copy link
Copy Markdown

codecov-commenter commented Mar 21, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 86.89%. Comparing base (5458cab) to head (ab8e8a3).

Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff             @@
##             main    #1166      +/-   ##
==========================================
- Coverage   86.90%   86.89%   -0.02%     
==========================================
  Files          59       59              
  Lines        8774     8774              
==========================================
- Hits         7625     7624       -1     
- Misses       1149     1150       +1     
Flag Coverage Δ
pester 85.32% <ø> (-0.02%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.
see 1 file with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@github-actions
Copy link
Copy Markdown
Contributor

github-actions bot commented Mar 21, 2026

Dependency Review Summary

The full dependency review summary was too large to display here (3099KB, limit is 1024KB).

Please download the artifact named "dependency-review-summary" to view the complete report.

View full job summary

@hve-core-release-please hve-core-release-please bot force-pushed the release-please--branches--main--components--hve-core branch from 63bc286 to ab8e8a3 Compare March 23, 2026 17:00
@WilliamBerryiii WilliamBerryiii merged commit 671f798 into main Mar 23, 2026
33 checks passed
@hve-core-release-please
Copy link
Copy Markdown
Contributor Author

🤖 Created releases:

🌻

@hve-core-release-please hve-core-release-please bot added autorelease: tagged Release-please: Release created and tagged and removed autorelease: pending Release-please: PR awaiting merge labels Mar 23, 2026
WilliamBerryiii added a commit that referenced this pull request Mar 23, 2026
…1178)

## Description

Fixes the SBOM Dependency Diff failure in the stable and prerelease
release pipelines.

`anchore/sbom-action` uses `artifact-name` as both the GitHub Actions
artifact name **and** the filename inside the artifact. With
`artifact-name: sbom-dependencies`, the file stored inside the artifact
was named `sbom-dependencies` (no extension) instead of
`dependencies.spdx.json`. Downstream jobs (`sbom-diff`,
`attest-and-upload`) download the artifact and look for
`dependencies.spdx.json` — file not found.

**Fix**: Disable `sbom-action`'s built-in upload (`upload-artifact:
false`), add an explicit `actions/upload-artifact` step that uploads the
correctly-named local file `dependencies.spdx.json` as artifact
`sbom-dependencies`. Applied identically to both `release-stable.yml`
and `release-prerelease.yml`.

## Related Issue(s)

Fixes the v3.2.1 release failure in PR #1166, run #85.

## Type of Change

- [x] Bug fix (non-breaking change which fixes an issue)
- [ ] New feature (non-breaking change which adds functionality)
- [ ] Breaking change (fix or feature with breaking side effects)
- [ ] Documentation update
- [x] GitHub Actions workflow
- [ ] Linting or code quality tooling
- [ ] Security hardening
- [ ] DevContainer or environment configuration
- [ ] Dependency update
- [ ] Instructions (`.instructions.md`)
- [ ] Prompt (`.prompt.md`)
- [ ] Agent (`.agent.md`)
- [ ] Skill (`SKILL.md`)

## Testing

- Verified with `actionlint` — no errors in either workflow file.
- Verified with `npm run lint:yaml` — no YAML lint errors.
- Confirmed the fix covers all 11 downstream jobs (10
`attest-and-upload` matrix entries + `sbom-diff`).

## Checklist

### Required Checks

- [x] Documentation is updated (if applicable)
- [x] Naming conventions followed per instructions
- [x] Backwards compatibility considered
- [x] Tests added/updated (if applicable)

### Required Automated Checks

- [x] `npm run lint:md`
- [x] `npm run spell-check`
- [x] `npm run lint:frontmatter`
- [x] `npm run validate:skills`
- [x] `npm run lint:md-links`
- [x] `npm run lint:ps`
- [x] `npm run plugin:generate`

## Security Considerations

- [x] No sensitive data (API keys, tokens, passwords) included
- [x] Dependencies have been reviewed for security vulnerabilities
- [x] Principle of least privilege followed for any permission changes

No new dependencies introduced. Workflow permissions unchanged. The
explicit `upload-artifact` step uses the same SHA-pinned action already
present elsewhere in the pipeline.

## Additional Notes

The per-VSIX SBOM uploads (e.g., `sbom-ado`, `sbom-hve-core-all`) are
unaffected because no downstream job downloads those artifacts by
filename.

Co-authored-by: Bill Berry <wbery@microsoft.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

autorelease: tagged Release-please: Release created and tagged

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants