Add an opt-in publish step at the tail of the build job:
- Bump job permissions to contents: write so the workflow token can
create releases.
- Read the HEAD commit message via `git log -1` and set an
is_release output when it contains the literal substring [Release].
- When set, `gh release create build-<sha>` and attach the staged
OpenZenLoader-<sha>.exe and OpenZen-<sha>.jar. Notes are piped
through a file (--notes-file) so brackets / newlines in the commit
message can't corrupt the CLI invocation.
Pushes without the marker keep producing only the existing per-build
artifacts.
Co-Authored-By: Claude Opus 4.7 <[email protected]>