# \[ANN\] TagBot: Creates tags and releases for your Julia packages when they're registered

**URL:** <https://discourse.julialang.org/t/ann-tagbot-creates-tags-and-releases-for-your-julia-packages-when-theyre-registered/23084>\
**Category:** Package Announcements\
**Tags:** tagbot\
**Created:** [April 12, 2019, 4:00pm UTC](https://discourse.julialang.org/t/ann-tagbot-creates-tags-and-releases-for-your-julia-packages-when-theyre-registered/23084 "2019-04-12T16:00:00Z")\
**Posts on this page:** 14\
**Page:** 3

<div class="post-metadata">

**Author:** ![chakravala](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/chakravala/32/6832_2.png) [@chakravala](https://discourse.julialang.org/u/chakravala)\
**Post date:** [April 22, 2019, 1:43pm UTC](https://discourse.julialang.org/t/ann-tagbot-creates-tags-and-releases-for-your-julia-packages-when-theyre-registered/23084/41 "2019-04-22T13:43:06Z")

</div>

This is my attempt at improving the instructions (using some of the info from this discussion)

[https://github.com/JuliaComputing/Registrator.jl/pull/99](https://github.com/JuliaComputing/Registrator.jl/pull/99)

---

<div class="post-metadata">

**Author:** ![christopher-dG](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/christopher-dg/32/7387_2.png) [@christopher-dG](https://discourse.julialang.org/u/christopher-dG)\
**Post date:** [April 22, 2019, 2:50pm UTC](https://discourse.julialang.org/t/ann-tagbot-creates-tags-and-releases-for-your-julia-packages-when-theyre-registered/23084/42 "2019-04-22T14:50:05Z")

</div>

> [@felipenoris](#):
>
> Why is this new setup (Registrator + TagBot) better than the old one

In terms of UI I woudn’t say it’s better IMO, but it helps avoid having to delete Git tags which is essentially like rewriting history on your master branch, so that’s one nice thing.

> [@oxinabox](#):
>
> I would disagree, bots are magic.

I agree. I’m not really a big fan of the process myself, but it does work at least. And the nice thing is that it’s just a PR to be made, therefore you can wrap it in a variety of frontends.

> [@oxinabox](#):
>
> Rather than selecting a commit/branch via a webinterface.

Don’t worry, you’ll get that soon 😉

---

<div class="post-metadata">

**Author:** ![christopher-dG](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/christopher-dg/32/7387_2.png) [@christopher-dG](https://discourse.julialang.org/u/christopher-dG)\
**Post date:** [April 25, 2019, 4:39am UTC](https://discourse.julialang.org/t/ann-tagbot-creates-tags-and-releases-for-your-julia-packages-when-theyre-registered/23084/43 "2019-04-25T04:39:17Z")

</div>

FYI: I have added a trigger comment to manually tell TagBot to create your release, for when you didn’t install the app until after your registry PR was merged, or something else went wrong. See [this readme section](https://github.com/christopher-dG/tag-bot/tree/cdg/comments#manually-triggering-a-release) for more details.

---

<div class="post-metadata">

**Author:** ![StefanKarpinski](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/stefankarpinski/32/24_2.png) [@StefanKarpinski](https://discourse.julialang.org/u/StefanKarpinski)\
**Post date:** [April 25, 2019, 4:05pm UTC](https://discourse.julialang.org/t/ann-tagbot-creates-tags-and-releases-for-your-julia-packages-when-theyre-registered/23084/44 "2019-04-25T16:05:12Z")

</div>

> [@felipenoris](#):
>
> Why is this new setup (Registrator + TagBot) better than the old one (attobot) which required just a new tag to do the whole process?

> [@felipenoris](#):
>
> I’m just provoking you to think about the whole process and not lose focus. I’ll remember to tag releases just to trigger the Documenter. But I’m an experienced Julia user. I’m afraid others won’t see this. Or maybe I’m just wrong.

Believe it or not, we didn’t change the release process on a whim or just to annoy you. A lot of [time](https://github.com/JuliaLang/Pkg.jl/issues/849) and [energy](https://github.com/JuliaComputing/Registrator.jl/issues/1) was spent thinking about and designing the new process and it was designed specifically to fix shortcomings in the old process. The key problem with triggering registration via git tags and GitHub releases is that they are supposed to be immutable—once they are made, they should never be deleted or changed. With the old process, at the time you tagged something, you couldn’t possibly yet know if it was going to be an acceptable release or not. Maybe you made some mistake and the release was going to get rejected by CIBot. If the registration process rejected your proposed release triggered by creating a git tag or GitHub release, then you only have two bad options:

1. Delete and replace the tag / release that you already created in order to retrigger the release review process.

2. Just abandon the tag / release that you already created and skip on to a new one, leaving holes in the registered sequence of releases.

Almost no one did the former since it is appropriately annoying to replace tags or releases—_because you aren’t supposed to do it_. So in practice, people just would tag five different versions in a row until they got it right and as a result, Julia packages would regularly “release” five versions at at time, four of which are broken, uninstallable and never used by anyone. This problem was only going to get worse because we want to start doing more automated checks on packages, including making sure that they:

1. Have correct, sane package structure and layout.
2. Pass their own tests.
3. Don’t break the tests of reverse dependencies, with which they are supposed to be compatible.
4. Have correct compatibility bounds on their dependencies.

Since we’re planning on making the verification process stricter, it’s going to be more likely that the first attempt to register a new version won’t work, so the old process was simply not going to cut it. The new process separates proposing a new version from approving it, allowing all kinds of verification and testing in the middle, and only when a package is vetted and approved, does the new version get tagged after the fact.

Any issues with triggering doc builds can be solved with automation just as simply as tagging and creating releases has been.

---

<div class="post-metadata">

**Author:** ![StefanKarpinski](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/stefankarpinski/32/24_2.png) [@StefanKarpinski](https://discourse.julialang.org/u/StefanKarpinski)\
**Post date:** [April 25, 2019, 5:12pm UTC](https://discourse.julialang.org/t/ann-tagbot-creates-tags-and-releases-for-your-julia-packages-when-theyre-registered/23084/45 "2019-04-25T17:12:04Z")

</div>

Oh, and as to why there are two bots—there’s also a good reason for that! We already tried it the other way: originally Registrator made and tagged releases for you. But when we asked people to alpha test this, some people complained that it required write access to your repos—which it needs so that it can tag releases for you. Now GitHub does not allow choosing which permissions you grant a bot, it’s all or nothing. So we had to remove that feature entirely and make Registrator only require read access. But of course then the first complaint is “How come I have to create releases myself? Attobot did that for me, why can’t Registrator?” You can see where this is going… So the only option is to have a separate bot that has write access and does automatic tagging. People that don’t want to grant bots write access can make their own tags, everyone else can add TagBot to their repos and get tags automatically.

---

<div class="post-metadata">

**Author:** ![Tamas\_Papp](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/tamas_papp/32/25949_2.png) [@Tamas\_Papp](https://discourse.julialang.org/u/Tamas_Papp)\
**Post date:** [April 26, 2019, 6:01am UTC](https://discourse.julialang.org/t/ann-tagbot-creates-tags-and-releases-for-your-julia-packages-when-theyre-registered/23084/46 "2019-04-26T06:01:06Z")

</div>

> [@felipenoris](#):
>
> I’m just provoking you to think about the whole process and not lose focus.

People working on designing the new registry workflow have spent a significant part of the last few months thinking about the whole process, eg in [#849](https://github.com/JuliaLang/Pkg.jl/issues/849), and other discussions preceding that, without “losing focus”.

As always, things can be improved (and they are being improved on a daily basis). But after months of hard work which resulted in a functional and conceptually coherent solution, I don’t think it is nice to imagine that you can, or need to, “provoke” anyone to do better. They already did an excellent job.

---

<div class="post-metadata">

**Author:** ![felipenoris](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/felipenoris/32/553_2.png) [@felipenoris](https://discourse.julialang.org/u/felipenoris)\
**Post date:** [April 26, 2019, 12:51pm UTC](https://discourse.julialang.org/t/ann-tagbot-creates-tags-and-releases-for-your-julia-packages-when-theyre-registered/23084/47 "2019-04-26T12:51:12Z")

</div>

@fredrikekre, @StefanKarpinski, @Tamas_Papp, I guess I was just unreasonable and harsh on my words on this one. I’m very sorry about that. I respect all the effort you put in this work.

I think this is the 2nd time I put a negative feedback on anything in this community. The first time was on the [pkg.julialang.org](http://pkg.julialang.org) situation. Both these cases have something in common: if they’re wrong, they will hurt the community. So my intent here was to antecipate problems that outsiders of this forum will face. But, as I said, maybe I’m just wrong and trying to help the wrong way.

I once was a music producer and sometimes I could spend 48 hours in a row listening to the same 5 minute audio. In the end, the client gets by and catches something wrong in the result. It was really a pain, specially when I liked the song. But the thing is that it is very easy to lose perspective when you spend a lot of time on a single task. It hurts everytime, but the result was always better. I hope you understand.

---

<div class="post-metadata">

**Author:** ![Tamas\_Papp](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/tamas_papp/32/25949_2.png) [@Tamas\_Papp](https://discourse.julialang.org/u/Tamas_Papp)\
**Post date:** [April 26, 2019, 1:46pm UTC](https://discourse.julialang.org/t/ann-tagbot-creates-tags-and-releases-for-your-julia-packages-when-theyre-registered/23084/48 "2019-04-26T13:46:25Z")

</div>

FWIW, I am not one of the contributors on this. I am just concerned that if working on tooling leads to a lot of complaints no matter what you do (because [every change breaks someone’s workflow](https://xkcd.com/1172/)), then contributors will eventually burn out.

Instead, we should reward such work with a positive attitude (at minimum) and take occasional glitches gracefully. Especially since they get fixed really, really quickly.

---

<div class="post-metadata">

**Author:** ![StefanKarpinski](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/stefankarpinski/32/24_2.png) [@StefanKarpinski](https://discourse.julialang.org/u/StefanKarpinski)\
**Post date:** [May 7, 2019, 8:21pm UTC](https://discourse.julialang.org/t/ann-tagbot-creates-tags-and-releases-for-your-julia-packages-when-theyre-registered/23084/49 "2019-05-07T20:21:55Z")

</div>

I appreciate the sentiment—thank you for the kind reply. Bug reports, suggestions, constructive criticisms, etc. are always very much welcomed. To give feedback on your feedback, “I liked it better the old way” and “please think about the overall process” are just not very helpful comments. It’s obvious that one should think about the whole process. To suggest that’s not what we’ve been doing is, well, kind of insulting. If we had something like attobot that people liked and we’ve changed it, perhaps there was a reason. And indeed, the reason to deviate from the previous way is precisely because of thinking about improving the overall process.

---

<div class="post-metadata">

**Author:** ![JeffFessler](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/jefffessler/32/6650_2.png) [@JeffFessler](https://discourse.julialang.org/u/JeffFessler)\
**Post date:** [May 21, 2019, 2:10am UTC](https://discourse.julialang.org/t/ann-tagbot-creates-tags-and-releases-for-your-julia-packages-when-theyre-registered/23084/50 "2019-05-21T02:10:41Z")

</div>

I just got an email saying  
" Julia TagBot, installed on your account is requesting updated permissions."  
with a link to an unfamiliar url on github like this:  
[[https://github.com/settings/installations/955](https://github.com/settings/installations/955)…]  
and it asks for a password. I can’t tell if this is legit or phishing.

---

<div class="post-metadata">

**Author:** ![dawbarton](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/dawbarton/32/215461_2.png) [@dawbarton](https://discourse.julialang.org/u/dawbarton)\
**Post date:** [May 21, 2019, 2:52am UTC](https://discourse.julialang.org/t/ann-tagbot-creates-tags-and-releases-for-your-julia-packages-when-theyre-registered/23084/51 "2019-05-21T02:52:01Z")

</div>

This came up on slack - apparently it’s legit and due to [https://github.com/JuliaRegistries/TagBot/pull/22](https://github.com/JuliaRegistries/TagBot/pull/22)

---

<div class="post-metadata">

**Author:** ![christopher-dG](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/christopher-dg/32/7387_2.png) [@christopher-dG](https://discourse.julialang.org/u/christopher-dG)\
**Post date:** [May 21, 2019, 7:54pm UTC](https://discourse.julialang.org/t/ann-tagbot-creates-tags-and-releases-for-your-julia-packages-when-theyre-registered/23084/52 "2019-05-21T19:54:38Z")

</div>

Yes this was me. I generally wouldn’t consider [https://github.com/](https://github.com/)\*\*\* to be phishy 🙃

---

<div class="post-metadata">

**Author:** ![StefanKarpinski](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/stefankarpinski/32/24_2.png) [@StefanKarpinski](https://discourse.julialang.org/u/StefanKarpinski)\
**Post date:** [May 21, 2019, 10:15pm UTC](https://discourse.julialang.org/t/ann-tagbot-creates-tags-and-releases-for-your-julia-packages-when-theyre-registered/23084/53 "2019-05-21T22:15:58Z")

</div>

Also, adding read access to issues isn’t too alarming either—that’s already public info.

---

<div class="post-metadata">

**Author:** ![vlandau](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/vlandau/32/8986_2.png) [@vlandau](https://discourse.julialang.org/u/vlandau)\
**Post date:** [January 6, 2020, 8:20pm UTC](https://discourse.julialang.org/t/ann-tagbot-creates-tags-and-releases-for-your-julia-packages-when-theyre-registered/23084/54 "2020-01-06T20:20:53Z")

</div>

Hi @christopher-dG, I’m pretty late to the convo here, but does the TagBot still support manually triggering a tag? I had an issue with Docs not being deployed, so I had to delete the original tag and recreate it one commit ahead to trigger a new travis CI pipeline with a diferent yml config. I’ve since deleted that new tag, and I’m trying to go back and recreate the original tag so it’s in sync with the package registry. I’d like tagbot to do it since it creates nice release notes for me.

I tried TagBot tag and @TagBot tag in the commit comments, but I haven’t been able to retrigger it.

Thanks,  
Vincent

# **EDIT**

I was trying to comment TagBot tag on the commit instead of the PR… 🤦‍♂️. I put the comment on the PR in the registry and it worked like a charm.

[Previous page](https://discourse.julialang.org/t/ann-tagbot-creates-tags-and-releases-for-your-julia-packages-when-theyre-registered/23084.md?page=2)
