Skip to content

v1.27.0 release did not sign after the SignPath action moved to v3 #569

Description

@erikdarlingdata

The Release run for v1.27.0 (run 36049315801) failed at the "Sign Windows build" step. No release was published, because release.yml creates the release only after signing succeeds.

What failed

Attempts Time (UTC) Error from SignPath
1 to 3 2026-09-24 19:42 to 20:33 Failed to retrieve GitHub App token. Ensure that the GitHub App 'https://github.com/apps/signpath' is installed and not suspended
4 to 7 2026-09-24 20:53 to 2026-09-25 01:27 Too many workflow reruns. The maximum number of supported reruns is: 3

Cause

Dependabot PR #538 (merged 2026-09-21) moved signpath/github-action-submit-signing-request from v2 to v3. The only functional change in v3 is the default connector-url. It now points to SignPath's new Pipeline Connector, the service that receives signing requests. Before, it pointed to githubactions.connectors.signpath.io.

The Pipeline Connector gets a token from the SignPath GitHub App. The app was not installed on this repository. The v2 connector did not need the app, and it signed v1.26.0 on 2026-09-16. Signing runs only in a release, so v1.27.0 was the first run that used v3.

SignPath signs only the first 3 attempts of a run. It refused attempts 4 to 7 for that reason, and run 36049315801 cannot sign now.

GitHub had no outage at the time. The last GitHub incident for API requests ended at 04:55 UTC on 2026-09-24, before the first failure.

Steps to finish

  • Install the SignPath GitHub App on PerformanceStudio and PerformanceMonitor (done on 2026-09-24).

  • Correct the out-of-date comments in release.yml and .signpath/policies/PerformanceStudio/release-signing.yml (Correct the SignPath comments for action v3 #570, merged into dev).

  • Start a fresh Release run with a new dev to main merge. Done with Release v1.27.0 #571 (admin merge past check-version). Run 36087840589 signed the Windows build with v3 and published v1.27.0 on 2026-09-25.

  • Check for a pipeline policy on the release-signing signing policy in SignPath. On 2026-09-25 it had none, and the organization cannot add one. The organization is on SignPath's OSS subscription, and its dashboard shows no pipeline policy setting. Pipeline Connector 0.8.0 (2026-09-09) reads .signpath/policies/* files only when a pipeline policy references them. For that reason, SignPath does not enforce the rule that requires GitHub-hosted runners. If the setting becomes available, SignPath documents this format for the rule:

    github-build-policies:
      version: '1.0'
      runners:
        require_github_hosted: true
  • Set Allowed branch names on the release-signing signing policy to dev (it was **). Done on 2026-09-25. SignPath records each release request under branch dev, the head branch of the release PR. If the value is only main, SignPath rejects every release.

  • Change the comment in .signpath/policies/PerformanceStudio/release-signing.yml to say that SignPath does not enforce the file (Say the SignPath policy file is not enforced #572, merged into dev).

  • Track the move of PerformanceMonitor's build.yml from v2 to v3 in Low priority pre-release checklist item (not for immediate action): move the SignPath action to v3 PerformanceMonitor#4218. It is a low priority step for the checklist before a PerformanceMonitor release.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions