77a5befd53
Two issues caught in review on #2597: 1. `gh release list` in GitHub Actions requires GH_TOKEN. The release notes step in `.github/workflows/ci.yml` had no env block, so gh would exit non-zero and the script's silent fallback would re-strand the silent-tag entries this change is meant to recover. Pass `GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}` to the step. 2. Silently degrading to legacy single-version output on gh failure is itself the regression vector — a future token misconfig or gh outage would lose data with no signal. `resolvePublishedFloorTag` now throws on gh failure with an actionable hint ("pass GH_TOKEN in Actions; set OMP_RELEASE_NOTES_FLOOR= locally to opt into legacy mode"). The thrown error propagates out of `main` and exits non-zero, failing the CI step loudly so the release is rebuilt with the fix. The legitimate null path is preserved: `OMP_RELEASE_NOTES_FLOOR=` (empty) still forces single-version mode, and a successful gh call with no candidate < target still returns null (first-ever publish case). Verified locally: hiding gh from PATH now exits 1 with the hint; `OMP_RELEASE_NOTES_FLOOR=` with hidden gh still produces the legacy 84-bullet single-version output. Refs #2596