semantic-release creates the tag via the GitHub Releases API (@semantic-release/github). API-created tags don't emit the refs/tags/* push event that 'on: push: tags' listens for, so the artifact build never auto-ran — every release so far was built by manual workflow_dispatch. The PAT-published release does fire 'release: published', so trigger on that. workflow_dispatch stays as a manual fallback.