Skip to content

ci: bump publish-platforms pin to the multipart-JSON fix - #455

Merged
tastybento merged 2 commits into
developfrom
ci/publish-platforms-pin
Jul 30, 2026
Merged

ci: bump publish-platforms pin to the multipart-JSON fix#455
tastybento merged 2 commits into
developfrom
ci/publish-platforms-pin

Conversation

@tastybento

Copy link
Copy Markdown
Member

What

Bumps the pinned SHA of the shared publish-platforms.yml reusable workflow to 1f91a0e (master HEAD of BentoBoxWorld/.github).

Why

The pinned version passes the CurseForge metadata and Hangar versionUpload multipart JSON as an inline curl value:

-F "metadata=${META};type=application/json"

curl reads a ; inside an inline -F value as the start of a type=/filename= attribute, so the JSON is silently truncated at the first semicolon in the release body. Both platforms then reject the upload:

  • CurseForge — {"errorCode":1002,"errorMessage":"Error in field \metadata`: Invalid JSON."}`
  • Hangar — {"status":400,"detail":"Failed to read request"}

This is latent, not theoretical: it took down the AOneBlock 1.26.3 publish (run) because those release notes happened to contain one semicolon. Any release body with a semicolon in it trips this.

BentoBoxWorld/.github#13 fixed it on 2026-07-20 by writing the JSON to a file and using curl's <file form (-F "metadata=<cf_meta.json;type=application/json"). This repo was still pinned to the commit before that fix.

Modrinth publishing is unaffected — it does not go through this workflow.

No behaviour change beyond the fix; the pin is the only line touched.

🤖 Generated with Claude Code

https://claude.ai/code/session_01SAQ3YQkcfRoCZEwa6SPJcp

tastybentoand others added 2 commits July 29, 2026 09:07
The pinned SHA predates BentoBoxWorld/.github#13, which moved the CurseForge
metadata and Hangar versionUpload JSON out of inline curl -F values and into
files. curl treats a ';' in an inline -F value as the start of a type=
attribute, so a release body containing a semicolon truncates the JSON and
both platforms reject the upload.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQ3YQkcfRoCZEwa6SPJcp
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQ3YQkcfRoCZEwa6SPJcp
@sonarqubecloud

Copy link
Copy Markdown

@tastybento
tastybento merged commit 2d9915c into developJul 30, 2026
3 checks passed
@tastybento
tastybento deleted the ci/publish-platforms-pin branch July 30, 2026 00:04
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@tastybento
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
ci: bump publish-platforms pin to the multipart-JSON fix by tastybento · Pull Request #455 · BentoBoxWorld/Level · GitHub
Skip to content

ci: bump publish-platforms pin to the multipart-JSON fix - #455

Merged
tastybento merged 2 commits into
developfrom
ci/publish-platforms-pin
Jul 30, 2026
Merged

ci: bump publish-platforms pin to the multipart-JSON fix#455
tastybento merged 2 commits into
developfrom
ci/publish-platforms-pin

Conversation

@tastybento

Copy link
Copy Markdown
Member

What

Bumps the pinned SHA of the shared publish-platforms.yml reusable workflow to 1f91a0e (master HEAD of BentoBoxWorld/.github).

Why

The pinned version passes the CurseForge metadata and Hangar versionUpload multipart JSON as an inline curl value:

-F "metadata=${META};type=application/json"

curl reads a ; inside an inline -F value as the start of a type=/filename= attribute, so the JSON is silently truncated at the first semicolon in the release body. Both platforms then reject the upload:

  • CurseForge — {"errorCode":1002,"errorMessage":"Error in field \metadata`: Invalid JSON."}`
  • Hangar — {"status":400,"detail":"Failed to read request"}

This is latent, not theoretical: it took down the AOneBlock 1.26.3 publish (run) because those release notes happened to contain one semicolon. Any release body with a semicolon in it trips this.

BentoBoxWorld/.github#13 fixed it on 2026-07-20 by writing the JSON to a file and using curl's <file form (-F "metadata=<cf_meta.json;type=application/json"). This repo was still pinned to the commit before that fix.

Modrinth publishing is unaffected — it does not go through this workflow.

No behaviour change beyond the fix; the pin is the only line touched.

🤖 Generated with Claude Code

https://claude.ai/code/session_01SAQ3YQkcfRoCZEwa6SPJcp

tastybentoand others added 2 commits July 29, 2026 09:07
The pinned SHA predates BentoBoxWorld/.github#13, which moved the CurseForge
metadata and Hangar versionUpload JSON out of inline curl -F values and into
files. curl treats a ';' in an inline -F value as the start of a type=
attribute, so a release body containing a semicolon truncates the JSON and
both platforms reject the upload.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQ3YQkcfRoCZEwa6SPJcp
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQ3YQkcfRoCZEwa6SPJcp
@sonarqubecloud

Copy link
Copy Markdown

@tastybento
tastybento merged commit 2d9915c into developJul 30, 2026
3 checks passed
@tastybento
tastybento deleted the ci/publish-platforms-pin branch July 30, 2026 00:04
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@tastybento
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' ci: bump publish-platforms pin to the multipart-JSON fix by tastybento · Pull Request #455 · BentoBoxWorld/Level · GitHub
Skip to content

ci: bump publish-platforms pin to the multipart-JSON fix - #455

Merged
tastybento merged 2 commits into
developfrom
ci/publish-platforms-pin
Jul 30, 2026
Merged

ci: bump publish-platforms pin to the multipart-JSON fix#455
tastybento merged 2 commits into
developfrom
ci/publish-platforms-pin

Conversation

@tastybento

Copy link
Copy Markdown
Member

What

Bumps the pinned SHA of the shared publish-platforms.yml reusable workflow to 1f91a0e (master HEAD of BentoBoxWorld/.github).

Why

The pinned version passes the CurseForge metadata and Hangar versionUpload multipart JSON as an inline curl value:

-F "metadata=${META};type=application/json"

curl reads a ; inside an inline -F value as the start of a type=/filename= attribute, so the JSON is silently truncated at the first semicolon in the release body. Both platforms then reject the upload:

  • CurseForge — {"errorCode":1002,"errorMessage":"Error in field \metadata`: Invalid JSON."}`
  • Hangar — {"status":400,"detail":"Failed to read request"}

This is latent, not theoretical: it took down the AOneBlock 1.26.3 publish (run) because those release notes happened to contain one semicolon. Any release body with a semicolon in it trips this.

BentoBoxWorld/.github#13 fixed it on 2026-07-20 by writing the JSON to a file and using curl's <file form (-F "metadata=<cf_meta.json;type=application/json"). This repo was still pinned to the commit before that fix.

Modrinth publishing is unaffected — it does not go through this workflow.

No behaviour change beyond the fix; the pin is the only line touched.

🤖 Generated with Claude Code

https://claude.ai/code/session_01SAQ3YQkcfRoCZEwa6SPJcp

tastybentoand others added 2 commits July 29, 2026 09:07
The pinned SHA predates BentoBoxWorld/.github#13, which moved the CurseForge
metadata and Hangar versionUpload JSON out of inline curl -F values and into
files. curl treats a ';' in an inline -F value as the start of a type=
attribute, so a release body containing a semicolon truncates the JSON and
both platforms reject the upload.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQ3YQkcfRoCZEwa6SPJcp
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQ3YQkcfRoCZEwa6SPJcp
@sonarqubecloud

Copy link
Copy Markdown

@tastybento
tastybento merged commit 2d9915c into developJul 30, 2026
3 checks passed
@tastybento
tastybento deleted the ci/publish-platforms-pin branch July 30, 2026 00:04
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@tastybento
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' ci: bump publish-platforms pin to the multipart-JSON fix by tastybento · Pull Request #455 · BentoBoxWorld/Level · GitHub
Skip to content

ci: bump publish-platforms pin to the multipart-JSON fix - #455

Merged
tastybento merged 2 commits into
developfrom
ci/publish-platforms-pin
Jul 30, 2026
Merged

ci: bump publish-platforms pin to the multipart-JSON fix#455
tastybento merged 2 commits into
developfrom
ci/publish-platforms-pin

Conversation

@tastybento

Copy link
Copy Markdown
Member

What

Bumps the pinned SHA of the shared publish-platforms.yml reusable workflow to 1f91a0e (master HEAD of BentoBoxWorld/.github).

Why

The pinned version passes the CurseForge metadata and Hangar versionUpload multipart JSON as an inline curl value:

-F "metadata=${META};type=application/json"

curl reads a ; inside an inline -F value as the start of a type=/filename= attribute, so the JSON is silently truncated at the first semicolon in the release body. Both platforms then reject the upload:

  • CurseForge — {"errorCode":1002,"errorMessage":"Error in field \metadata`: Invalid JSON."}`
  • Hangar — {"status":400,"detail":"Failed to read request"}

This is latent, not theoretical: it took down the AOneBlock 1.26.3 publish (run) because those release notes happened to contain one semicolon. Any release body with a semicolon in it trips this.

BentoBoxWorld/.github#13 fixed it on 2026-07-20 by writing the JSON to a file and using curl's <file form (-F "metadata=<cf_meta.json;type=application/json"). This repo was still pinned to the commit before that fix.

Modrinth publishing is unaffected — it does not go through this workflow.

No behaviour change beyond the fix; the pin is the only line touched.

🤖 Generated with Claude Code

https://claude.ai/code/session_01SAQ3YQkcfRoCZEwa6SPJcp

tastybentoand others added 2 commits July 29, 2026 09:07
The pinned SHA predates BentoBoxWorld/.github#13, which moved the CurseForge
metadata and Hangar versionUpload JSON out of inline curl -F values and into
files. curl treats a ';' in an inline -F value as the start of a type=
attribute, so a release body containing a semicolon truncates the JSON and
both platforms reject the upload.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQ3YQkcfRoCZEwa6SPJcp
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQ3YQkcfRoCZEwa6SPJcp
@sonarqubecloud

Copy link
Copy Markdown

@tastybento
tastybento merged commit 2d9915c into developJul 30, 2026
3 checks passed
@tastybento
tastybento deleted the ci/publish-platforms-pin branch July 30, 2026 00:04
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@tastybento
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' ci: bump publish-platforms pin to the multipart-JSON fix by tastybento · Pull Request #455 · BentoBoxWorld/Level · GitHub
Skip to content

ci: bump publish-platforms pin to the multipart-JSON fix - #455

Merged
tastybento merged 2 commits into
developfrom
ci/publish-platforms-pin
Jul 30, 2026
Merged

ci: bump publish-platforms pin to the multipart-JSON fix#455
tastybento merged 2 commits into
developfrom
ci/publish-platforms-pin

Conversation

@tastybento

Copy link
Copy Markdown
Member

What

Bumps the pinned SHA of the shared publish-platforms.yml reusable workflow to 1f91a0e (master HEAD of BentoBoxWorld/.github).

Why

The pinned version passes the CurseForge metadata and Hangar versionUpload multipart JSON as an inline curl value:

-F "metadata=${META};type=application/json"

curl reads a ; inside an inline -F value as the start of a type=/filename= attribute, so the JSON is silently truncated at the first semicolon in the release body. Both platforms then reject the upload:

  • CurseForge — {"errorCode":1002,"errorMessage":"Error in field \metadata`: Invalid JSON."}`
  • Hangar — {"status":400,"detail":"Failed to read request"}

This is latent, not theoretical: it took down the AOneBlock 1.26.3 publish (run) because those release notes happened to contain one semicolon. Any release body with a semicolon in it trips this.

BentoBoxWorld/.github#13 fixed it on 2026-07-20 by writing the JSON to a file and using curl's <file form (-F "metadata=<cf_meta.json;type=application/json"). This repo was still pinned to the commit before that fix.

Modrinth publishing is unaffected — it does not go through this workflow.

No behaviour change beyond the fix; the pin is the only line touched.

🤖 Generated with Claude Code

https://claude.ai/code/session_01SAQ3YQkcfRoCZEwa6SPJcp

tastybentoand others added 2 commits July 29, 2026 09:07
The pinned SHA predates BentoBoxWorld/.github#13, which moved the CurseForge
metadata and Hangar versionUpload JSON out of inline curl -F values and into
files. curl treats a ';' in an inline -F value as the start of a type=
attribute, so a release body containing a semicolon truncates the JSON and
both platforms reject the upload.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQ3YQkcfRoCZEwa6SPJcp
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQ3YQkcfRoCZEwa6SPJcp
@sonarqubecloud

Copy link
Copy Markdown

@tastybento
tastybento merged commit 2d9915c into developJul 30, 2026
3 checks passed
@tastybento
tastybento deleted the ci/publish-platforms-pin branch July 30, 2026 00:04
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@tastybento
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' ci: bump publish-platforms pin to the multipart-JSON fix by tastybento · Pull Request #455 · BentoBoxWorld/Level · GitHub
Skip to content

ci: bump publish-platforms pin to the multipart-JSON fix - #455

Merged
tastybento merged 2 commits into
developfrom
ci/publish-platforms-pin
Jul 30, 2026
Merged

ci: bump publish-platforms pin to the multipart-JSON fix#455
tastybento merged 2 commits into
developfrom
ci/publish-platforms-pin

Conversation

@tastybento

Copy link
Copy Markdown
Member

What

Bumps the pinned SHA of the shared publish-platforms.yml reusable workflow to 1f91a0e (master HEAD of BentoBoxWorld/.github).

Why

The pinned version passes the CurseForge metadata and Hangar versionUpload multipart JSON as an inline curl value:

-F "metadata=${META};type=application/json"

curl reads a ; inside an inline -F value as the start of a type=/filename= attribute, so the JSON is silently truncated at the first semicolon in the release body. Both platforms then reject the upload:

  • CurseForge — {"errorCode":1002,"errorMessage":"Error in field \metadata`: Invalid JSON."}`
  • Hangar — {"status":400,"detail":"Failed to read request"}

This is latent, not theoretical: it took down the AOneBlock 1.26.3 publish (run) because those release notes happened to contain one semicolon. Any release body with a semicolon in it trips this.

BentoBoxWorld/.github#13 fixed it on 2026-07-20 by writing the JSON to a file and using curl's <file form (-F "metadata=<cf_meta.json;type=application/json"). This repo was still pinned to the commit before that fix.

Modrinth publishing is unaffected — it does not go through this workflow.

No behaviour change beyond the fix; the pin is the only line touched.

🤖 Generated with Claude Code

https://claude.ai/code/session_01SAQ3YQkcfRoCZEwa6SPJcp

tastybentoand others added 2 commits July 29, 2026 09:07
The pinned SHA predates BentoBoxWorld/.github#13, which moved the CurseForge
metadata and Hangar versionUpload JSON out of inline curl -F values and into
files. curl treats a ';' in an inline -F value as the start of a type=
attribute, so a release body containing a semicolon truncates the JSON and
both platforms reject the upload.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQ3YQkcfRoCZEwa6SPJcp
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQ3YQkcfRoCZEwa6SPJcp
@sonarqubecloud

Copy link
Copy Markdown

@tastybento
tastybento merged commit 2d9915c into developJul 30, 2026
3 checks passed
@tastybento
tastybento deleted the ci/publish-platforms-pin branch July 30, 2026 00:04
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@tastybento
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); })(); ci: bump publish-platforms pin to the multipart-JSON fix by tastybento · Pull Request #455 · BentoBoxWorld/Level · GitHub
Skip to content

ci: bump publish-platforms pin to the multipart-JSON fix - #455

Merged
tastybento merged 2 commits into
developfrom
ci/publish-platforms-pin
Jul 30, 2026
Merged

ci: bump publish-platforms pin to the multipart-JSON fix#455
tastybento merged 2 commits into
developfrom
ci/publish-platforms-pin

Conversation

@tastybento

Copy link
Copy Markdown
Member

What

Bumps the pinned SHA of the shared publish-platforms.yml reusable workflow to 1f91a0e (master HEAD of BentoBoxWorld/.github).

Why

The pinned version passes the CurseForge metadata and Hangar versionUpload multipart JSON as an inline curl value:

-F "metadata=${META};type=application/json"

curl reads a ; inside an inline -F value as the start of a type=/filename= attribute, so the JSON is silently truncated at the first semicolon in the release body. Both platforms then reject the upload:

  • CurseForge — {"errorCode":1002,"errorMessage":"Error in field \metadata`: Invalid JSON."}`
  • Hangar — {"status":400,"detail":"Failed to read request"}

This is latent, not theoretical: it took down the AOneBlock 1.26.3 publish (run) because those release notes happened to contain one semicolon. Any release body with a semicolon in it trips this.

BentoBoxWorld/.github#13 fixed it on 2026-07-20 by writing the JSON to a file and using curl's <file form (-F "metadata=<cf_meta.json;type=application/json"). This repo was still pinned to the commit before that fix.

Modrinth publishing is unaffected — it does not go through this workflow.

No behaviour change beyond the fix; the pin is the only line touched.

🤖 Generated with Claude Code

https://claude.ai/code/session_01SAQ3YQkcfRoCZEwa6SPJcp

tastybentoand others added 2 commits July 29, 2026 09:07
The pinned SHA predates BentoBoxWorld/.github#13, which moved the CurseForge
metadata and Hangar versionUpload JSON out of inline curl -F values and into
files. curl treats a ';' in an inline -F value as the start of a type=
attribute, so a release body containing a semicolon truncates the JSON and
both platforms reject the upload.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQ3YQkcfRoCZEwa6SPJcp
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQ3YQkcfRoCZEwa6SPJcp
@sonarqubecloud

Copy link
Copy Markdown

@tastybento
tastybento merged commit 2d9915c into developJul 30, 2026
3 checks passed
@tastybento
tastybento deleted the ci/publish-platforms-pin branch July 30, 2026 00:04
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@tastybento