The Release run for v1.27.0 (run 36049315801) failed at the "Sign Windows build" step. No release was published, because release.yml creates the release only after signing succeeds.
What failed
| Attempts |
Time (UTC) |
Error from SignPath |
| 1 to 3 |
2026-09-24 19:42 to 20:33 |
Failed to retrieve GitHub App token. Ensure that the GitHub App 'https://github.com/apps/signpath' is installed and not suspended |
| 4 to 7 |
2026-09-24 20:53 to 2026-09-25 01:27 |
Too many workflow reruns. The maximum number of supported reruns is: 3 |
Cause
Dependabot PR #538 (merged 2026-09-21) moved signpath/github-action-submit-signing-request from v2 to v3. The only functional change in v3 is the default connector-url. It now points to SignPath's new Pipeline Connector, the service that receives signing requests. Before, it pointed to githubactions.connectors.signpath.io.
The Pipeline Connector gets a token from the SignPath GitHub App. The app was not installed on this repository. The v2 connector did not need the app, and it signed v1.26.0 on 2026-09-16. Signing runs only in a release, so v1.27.0 was the first run that used v3.
SignPath signs only the first 3 attempts of a run. It refused attempts 4 to 7 for that reason, and run 36049315801 cannot sign now.
GitHub had no outage at the time. The last GitHub incident for API requests ended at 04:55 UTC on 2026-09-24, before the first failure.
Steps to finish
The Release run for v1.27.0 (run 36049315801) failed at the "Sign Windows build" step. No release was published, because
release.ymlcreates the release only after signing succeeds.What failed
Failed to retrieve GitHub App token. Ensure that the GitHub App 'https://github.com/apps/signpath' is installed and not suspendedToo many workflow reruns. The maximum number of supported reruns is: 3Cause
Dependabot PR #538 (merged 2026-09-21) moved
signpath/github-action-submit-signing-requestfrom v2 to v3. The only functional change in v3 is the defaultconnector-url. It now points to SignPath's new Pipeline Connector, the service that receives signing requests. Before, it pointed togithubactions.connectors.signpath.io.The Pipeline Connector gets a token from the SignPath GitHub App. The app was not installed on this repository. The v2 connector did not need the app, and it signed v1.26.0 on 2026-09-16. Signing runs only in a release, so v1.27.0 was the first run that used v3.
SignPath signs only the first 3 attempts of a run. It refused attempts 4 to 7 for that reason, and run 36049315801 cannot sign now.
GitHub had no outage at the time. The last GitHub incident for API requests ended at 04:55 UTC on 2026-09-24, before the first failure.
Steps to finish
Install the SignPath GitHub App on PerformanceStudio and PerformanceMonitor (done on 2026-09-24).
Correct the out-of-date comments in
release.ymland.signpath/policies/PerformanceStudio/release-signing.yml(Correct the SignPath comments for action v3 #570, merged into dev).Start a fresh Release run with a new dev to main merge. Done with Release v1.27.0 #571 (admin merge past
check-version). Run 36087840589 signed the Windows build with v3 and published v1.27.0 on 2026-09-25.Check for a pipeline policy on the
release-signingsigning policy in SignPath. On 2026-09-25 it had none, and the organization cannot add one. The organization is on SignPath's OSS subscription, and its dashboard shows no pipeline policy setting. Pipeline Connector 0.8.0 (2026-09-09) reads.signpath/policies/*files only when a pipeline policy references them. For that reason, SignPath does not enforce the rule that requires GitHub-hosted runners. If the setting becomes available, SignPath documents this format for the rule:Set Allowed branch names on the
release-signingsigning policy todev(it was**). Done on 2026-09-25. SignPath records each release request under branchdev, the head branch of the release PR. If the value is onlymain, SignPath rejects every release.Change the comment in
.signpath/policies/PerformanceStudio/release-signing.ymlto say that SignPath does not enforce the file (Say the SignPath policy file is not enforced #572, merged into dev).Track the move of PerformanceMonitor's
build.ymlfrom v2 to v3 in Low priority pre-release checklist item (not for immediate action): move the SignPath action to v3 PerformanceMonitor#4218. It is a low priority step for the checklist before a PerformanceMonitor release.