The has_tag helper at line 79 uses grep -qx "$1" rather than fixed-string matching. VERSION comes from PyPI and normally contains dots, which are regex wildcards in grep.
For example, with VERSION=0.35.1 and registry tags containing 0x35x1 but not 0.35.1, the helper returns success. The workflow then sets present=yes for a tag that is not the PyPI version and can report the registry as matching when the literal version tag is absent.
Use grep -qxF -- "$1" so the tag is compared literally, and add a test covering a tag that differs only at the dot positions.
Code at the merge commit:
|
has_tag() { printf '%s\n' "${tags}" | grep -qx "$1"; } |
Merged change:
#3412
The has_tag helper at line 79 uses grep -qx "$1" rather than fixed-string matching. VERSION comes from PyPI and normally contains dots, which are regex wildcards in grep.
For example, with VERSION=0.35.1 and registry tags containing 0x35x1 but not 0.35.1, the helper returns success. The workflow then sets present=yes for a tag that is not the PyPI version and can report the registry as matching when the literal version tag is absent.
Use grep -qxF -- "$1" so the tag is compared literally, and add a test covering a tag that differs only at the dot positions.
Code at the merge commit:
lionagi/.github/workflows/image-matches-pypi.yml
Line 79 in d2192e2
Merged change: #3412