# \[ANN\] Required updates to TagBot.yml

**URL:** <https://discourse.julialang.org/t/ann-required-updates-to-tagbot-yml/49249>\
**Category:** Tooling\
**Tags:** tagbot\
**Created:** [October 29, 2020, 5:00pm UTC](https://discourse.julialang.org/t/ann-required-updates-to-tagbot-yml/49249 "2020-10-29T17:00:49Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![christopher-dG](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/christopher-dg/32/7387_2.png) [@christopher-dG](https://discourse.julialang.org/u/christopher-dG)\
**Post date:** [October 29, 2020, 5:00pm UTC](https://discourse.julialang.org/t/ann-required-updates-to-tagbot-yml/49249/1 "2020-10-29T17:00:49Z")

</div>

Hi all, [remember when I said that you’d never have to do any maintenance on your `TagBot.yml` files](https://discourse.julialang.org/t/ann-the-tagbot-github-app-is-deprecated-in-favour-of-the-tagbot-github-action/34344/6)?  
I lied, I’m sorry.

GitHub has started automatically disabling Actions workflows that run on a schedule for repositories that have not seen any activity for 60 days.

To quote [the docs](https://docs.github.com/en/free-pro-team@latest/actions/managing-workflow-runs/disabling-and-enabling-a-workflow):

> **Warning:** To prevent unnecessary workflow runs, scheduled workflows may be disabled automatically. When a public repository is forked, scheduled workflows are disabled by default. In a public repository, scheduled workflows are automatically disabled when no repository activity has occurred in 60 days.

That means that if you don’t touch a repo for 2 months, the scheduled workflows such as TagBot or CompatHelper will no longer run even after you come back to it, unless you re-enable them manually.  
To avoid this problem for TagBot, we are switching to a new method that does not rely on scheduled workflows, and instead triggers TagBot on demand. This means that TagBot remain enabled on inactive repos, and also that your tags will come much sooner after registration!

# What Do I Need To Do?

Probably within the next few days, merged pull requests in the General registry will start to be accompanied by issue comments made on package repositories that have a TagBot workflow file in `.github/workflows`. The idea is that TagBot will react to these issue comments, so you need to update your workflow file accordingly.

Your `TagBot.yml` probably looks something like this:

```yml
name: TagBot
on:
  schedule:
    - cron: 0 0 * * *
  workflow_dispatch:
jobs:
  TagBot:
    runs-on: ubuntu-latest
    steps:
      - uses: JuliaRegistries/TagBot@v1
        with:
          token: ${{ secrets.GITHUB_TOKEN }}
          ssh: ${{ secrets.DOCUMENTER_KEY }}

```

There are two changes to make: one is the `on` block, and the second is an `if` condition in the `TagBot` job. Here are the new contents that will work:

```yml
name: TagBot
on:
  issue_comment: # THIS BIT IS NEW
    types:
      - created
  workflow_dispatch:
jobs:
  TagBot:
    # THIS 'if' LINE IS NEW
    if: github.event_name == 'workflow_dispatch' || github.actor == 'JuliaTagBot'
    # NOTHING BELOW HAS CHANGED
    runs-on: ubuntu-latest
    steps:
      - uses: JuliaRegistries/TagBot@v1
        with:
          token: ${{ secrets.GITHUB_TOKEN }}
          ssh: ${{ secrets.DOCUMENTER_KEY }}

```

As you can see, the `schedule` trigger has been replaced with the `issue_comment` trigger, and the `TagBot` job now only runs when triggered under certain conditions.

TagBot will open an issue and instantly close it, and will add a new comment on that issue for each new version. You can safely unsubscribe from and ignore that issue.

### This looks tedious… and for what benefit?

I won’t be rolling out any automated PRs this time around, since that annoyed a lot of people last time (for good reason), and this change is also not strictly necessary. If your repository stays active, the scheduled workflow will never be disabled. But there are two advantages to adopting the new trigger: your tags will be created almost instantly after your registry PRs are merged, and you’ll no longer have hourly/daily TagBot runs that don’t do anything.  
If you want to apply this change to a bunch of repos at once, [MassInstallAction.jl](https://github.com/bcbi/MassInstallAction.jl) can help you out.

### For custom registry maintainers

If you run a custom registry, you’ll need to add a new Actions workflow to the registry: see [here](https://github.com/JuliaRegistries/RegistryCI.jl/blob/master/example_github_workflow_files/TagBotTriggers.yml) for an example. This workflow is responsible for notifying package repositories about new versions. You’ll need to create a `TAGBOT_TOKEN` secret on your registry, and it must contain a user’s personal access token, so that it can create issues and comments on repositories other than your registry. Feel free to contact me if you need a hand getting things set up. I also don’t think it works on self-hosted GitHub currently, so definitely let me know if you maintain one of those so I can figure out what’s necessary.

### For custom registry users

If you have packages registered in a registry other than General, you’ll need to change one small detail in the `if` condition. `JuliaTagBot` will not be the user creating issue comments, so you need to change that username to whatever your registry is using. Your registry maintainers will know what username to use.

### What about CompatHelper?

CompatHelper is another scheduled workflow that will soon be disabled on many inactive repos. There’s not really a good fix for that one, so I’ll soon be implementing [Dependabot](https://docs.github.com/en/free-pro-team@latest/github/administering-a-repository/about-github-dependabot-version-updates) support for Julia. More on that later!

* * *

That is all. If you have questions about this whole thing, or if you just want to tell me that I’ve ruined your week, don’t hesitate!

---

<div class="post-metadata">

**Author:** ![Tamas\_Papp](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/tamas_papp/32/25949_2.png) [@Tamas\_Papp](https://discourse.julialang.org/u/Tamas_Papp)\
**Post date:** [October 30, 2020, 3:41pm UTC](https://discourse.julialang.org/t/ann-required-updates-to-tagbot-yml/49249/2 "2020-10-30T15:41:18Z")

</div>

> [@christopher-dG](#):
>
> if you just want to tell me that I’ve ruined your week, don’t hesitate!

I just want to say thank you — for all your work on TagBot and CompatHelper, and the user-friendly upgrade paths.

I recognize that these services constantly have to adapt to changes outside the control of the Julia community to keep going, and how difficult this is.

---

<div class="post-metadata">

**Author:** ![christopher-dG](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/christopher-dg/32/7387_2.png) [@christopher-dG](https://discourse.julialang.org/u/christopher-dG)\
**Post date:** [October 30, 2020, 3:45pm UTC](https://discourse.julialang.org/t/ann-required-updates-to-tagbot-yml/49249/3 "2020-10-30T15:45:03Z")

</div>

> [@Tamas\_Papp](#):
>
> CompatHelper

One must thank @dilumaluthge for CompatHelper!

---

<div class="post-metadata">

**Author:** ![Tamas\_Papp](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/tamas_papp/32/25949_2.png) [@Tamas\_Papp](https://discourse.julialang.org/u/Tamas_Papp)\
**Post date:** [October 30, 2020, 3:47pm UTC](https://discourse.julialang.org/t/ann-required-updates-to-tagbot-yml/49249/4 "2020-10-30T15:47:18Z")

</div>

Thanks! I will take the opportunity to thank @dilumaluthge too.

---

<div class="post-metadata">

**Author:** ![roflmaostc](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/roflmaostc/32/30123_2.png) [@roflmaostc](https://discourse.julialang.org/u/roflmaostc)\
**Post date:** [November 5, 2020, 8:22pm UTC](https://discourse.julialang.org/t/ann-required-updates-to-tagbot-yml/49249/5 "2020-11-05T20:22:32Z")

</div>

> [@christopher-dG](#):
>
> ### For custom registry maintainers
> 
> If you run a custom registry, you’ll need to add a new Actions workflow to the registry: see [here](https://github.com/JuliaRegistries/RegistryCI.jl/blob/cdg/tagbot/example_github_workflow_files/TagBot.yml) for an

This link might be broken. I discovered it only because I struggle to get TagBot creating new GitHub tags…

Thanks,  
Felix

---

<div class="post-metadata">

**Author:** ![juliohm](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/juliohm/32/215266_2.png) [@juliohm](https://discourse.julialang.org/u/juliohm)\
**Post date:** [November 8, 2020, 12:18pm UTC](https://discourse.julialang.org/t/ann-required-updates-to-tagbot-yml/49249/6 "2020-11-08T12:18:00Z")

</div>

Thank you all! These bots are really amazing and of great value to the Julia community! ❤

---

<div class="post-metadata">

**Author:** ![christopher-dG](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/christopher-dg/32/7387_2.png) [@christopher-dG](https://discourse.julialang.org/u/christopher-dG)\
**Post date:** [November 13, 2020, 1:32am UTC](https://discourse.julialang.org/t/ann-required-updates-to-tagbot-yml/49249/7 "2020-11-13T01:32:30Z")

</div>

Sorry, I meant to update that link but forgot. What problems are you having?

---

<div class="post-metadata">

**Author:** ![roflmaostc](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/roflmaostc/32/30123_2.png) [@roflmaostc](https://discourse.julialang.org/u/roflmaostc)\
**Post date:** [November 18, 2020, 8:58am UTC](https://discourse.julialang.org/t/ann-required-updates-to-tagbot-yml/49249/8 "2020-11-18T08:58:03Z")

</div>

No problems anymore. Works now!

---

<div class="post-metadata">

**Author:** ![nicoleepp](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/nicoleepp/32/5840_2.png) [@nicoleepp](https://discourse.julialang.org/u/nicoleepp)\
**Post date:** [December 2, 2020, 4:31pm UTC](https://discourse.julialang.org/t/ann-required-updates-to-tagbot-yml/49249/9 "2020-12-02T16:31:36Z")

</div>

> GitHub has started automatically disabling Actions workflows that run on a schedule for repositories that have not seen any activity for 60 days.

Will it re-enable them if there is activity? For something like Tagbot, wouldn’t it start working again if a new tag was made?

---

<div class="post-metadata">

**Author:** ![giordano](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/giordano/32/2166_2.png) [@giordano](https://discourse.julialang.org/u/giordano)\
**Post date:** [December 2, 2020, 5:33pm UTC](https://discourse.julialang.org/t/ann-required-updates-to-tagbot-yml/49249/10 "2020-12-02T17:33:03Z")

</div>

I think you need to manually re-enable them from the Actions tab of the repository

---

<div class="post-metadata">

**Author:** ![fonsp](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/fonsp/32/222349_2.png) [@fonsp](https://discourse.julialang.org/u/fonsp)\
**Post date:** [December 27, 2020, 11:28am UTC](https://discourse.julialang.org/t/ann-required-updates-to-tagbot-yml/49249/12 "2020-12-27T11:28:52Z")

</div>

GitHub is giving me this linter warning:

 ![image](https://global.discourse-cdn.com/julialang/original/3X/e/9/e9bbfb83c0258d60ab265e0b64f4261ab42c2f0a.png)

---

<div class="post-metadata">

**Author:** ![giordano](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/giordano/32/2166_2.png) [@giordano](https://discourse.julialang.org/u/giordano)\
**Post date:** [December 27, 2020, 2:05pm UTC](https://discourse.julialang.org/t/ann-required-updates-to-tagbot-yml/49249/13 "2020-12-27T14:05:47Z")

</div>

The if should be within the TagBot job, not outside of it. Just copy the yaml file in the first message 🙂

---

<div class="post-metadata">

**Author:** ![fonsp](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/fonsp/32/222349_2.png) [@fonsp](https://discourse.julialang.org/u/fonsp)\
**Post date:** [December 27, 2020, 4:15pm UTC](https://discourse.julialang.org/t/ann-required-updates-to-tagbot-yml/49249/14 "2020-12-27T16:15:40Z")

</div>

Aha! Programming inside config files 😢 why didn’t they make this a drag & drop situation like Scratch

---

<div class="post-metadata">

**Author:** ![e3c6](https://avatars.discourse-cdn.com/v4/letter/e/e79b87/32.png) [@e3c6](https://discourse.julialang.org/u/e3c6)\
**Post date:** [January 15, 2022, 5:41pm UTC](https://discourse.julialang.org/t/ann-required-updates-to-tagbot-yml/49249/15 "2022-01-15T17:41:13Z")

</div>

> [@christopher-dG](#):
>
> ```julia
> ssh: ${{ secrets.DOCUMENTER_KEY }}
> 
> ```

Do I need this line if I’m not using Documenter in my package?

---

<div class="post-metadata">

**Author:** ![giordano](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/giordano/32/2166_2.png) [@giordano](https://discourse.julialang.org/u/giordano)\
**Post date:** [January 15, 2022, 5:46pm UTC](https://discourse.julialang.org/t/ann-required-updates-to-tagbot-yml/49249/16 "2022-01-15T17:46:20Z")

</div>

That’s needed to trigger other actions when TagBot creates the tag, for example other CI jobs on tags (CI jobs which may or may not include building and deploying documentation). If you don’t care about triggering this other jobs on tags, then no, you don’t need to add that line (or any other SSH key, not necessarily the documenter key).

---

<div class="post-metadata">

**Author:** ![e3c6](https://avatars.discourse-cdn.com/v4/letter/e/e79b87/32.png) [@e3c6](https://discourse.julialang.org/u/e3c6)\
**Post date:** [January 15, 2022, 5:47pm UTC](https://discourse.julialang.org/t/ann-required-updates-to-tagbot-yml/49249/17 "2022-01-15T17:47:29Z")

</div>

Ok, but then I should define a `DOCUMENTER_KEY` ssh key in my repo and give it write permissions?

---

<div class="post-metadata">

**Author:** ![giordano](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/giordano/32/2166_2.png) [@giordano](https://discourse.julialang.org/u/giordano)\
**Post date:** [January 15, 2022, 5:55pm UTC](https://discourse.julialang.org/t/ann-required-updates-to-tagbot-yml/49249/18 "2022-01-15T17:55:42Z")

</div>

It doesn’t have to be called `DOCUMENTER_KEY`, but it must be an ssh key (not sure whether it needs write permissions in order to trigger other jobs) and your TagBot configuration must match that name. The usual recommendation is to reuse the Documenter key because most users have it already anyway. You don’t build documentation for your package?

---

<div class="post-metadata">

**Author:** ![e3c6](https://avatars.discourse-cdn.com/v4/letter/e/e79b87/32.png) [@e3c6](https://discourse.julialang.org/u/e3c6)\
**Post date:** [January 15, 2022, 7:08pm UTC](https://discourse.julialang.org/t/ann-required-updates-to-tagbot-yml/49249/19 "2022-01-15T19:08:06Z")

</div>

> [@giordano](#):
>
> You don’t build documentation for your package?

No, for this particular one I don’t.

---

<div class="post-metadata">

**Author:** ![e3c6](https://avatars.discourse-cdn.com/v4/letter/e/e79b87/32.png) [@e3c6](https://discourse.julialang.org/u/e3c6)\
**Post date:** [February 9, 2022, 5:16pm UTC](https://discourse.julialang.org/t/ann-required-updates-to-tagbot-yml/49249/20 "2022-02-09T17:16:06Z")

</div>

What happens when I accidentally modify a commit that was supposed to be a tagged registered release?

I have this issue here:

[https://github.com/cossio/RestrictedBoltzmannMachines.jl/issues/1](https://github.com/cossio/RestrictedBoltzmannMachines.jl/issues/1)

I registered v0.14.0, but then accidentally modified git commit history and lost the commit corresponding to this version, and this happened right before the registration PR got merged into General and before TagBot got a chance to create the tag. Since then, TagBot has been failing to create tags for new versions.

Anything I can do to fix this situation?

**Update:** There is a `lookback` setting ([https://github.com/JuliaRegistries/TagBot#lookback-period](https://github.com/JuliaRegistries/TagBot#lookback-period)). So TagBot checks for previous releases within a `lookback` time window and tries to tag them, and complains if there is a commit that doesn’t match. So the issue will auto-resolve itself after `lookback` days have passed. Otherwise, one can just temporarily set `lookback` to a small amount like 1 day to exclude the offending commit, and later on reset `lookback`.

---

<div class="post-metadata">

**Author:** ![sylvaticus](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/sylvaticus/32/203883_2.png) [@sylvaticus](https://discourse.julialang.org/u/sylvaticus)\
**Post date:** [May 30, 2022, 3:45pm UTC](https://discourse.julialang.org/t/ann-required-updates-to-tagbot-yml/49249/21 "2022-05-30T15:45:33Z")

</div>

> [@christopher-dG](#):
>
> ### What about CompatHelper?
> 
> CompatHelper is another scheduled workflow that will soon be disabled on many inactive repos. There’s not really a good fix for that one, so I’ll soon be implementing [Dependabot](https://docs.github.com/en/free-pro-team@latest/github/administering-a-repository/about-github-dependabot-version-updates) support for Julia. More on that later!

Hello, what about it ? Which is now the solution (if any) for CompatHelper ?
