Repository navigation
Restore release-publication authority modes and release v0.18.87 - #571
Merged
Merged
Conversation
The promotion-lattice retirement removed the publication-prewrite and publication-postwrite modes from release-ref-authority.ts while github-release-publish.ts still invokes them, so the immutable Release step fails at the authority check. Restore both modes as bindings over verifyReleaseRefAuthority that additionally pin the expected release commit and authenticated current main before emitting the receipt, and cover the argument grammar with CLI regressions. v0.18.86 was tagged but never published; this release carries its changes forward.
The publish job checks out the bare verified SHA, so its local ref inventory is empty and the helper runs before every write. Binding publication modes over verifyReleaseRefAuthority was wrong: it demands a pre-existing tag ref and leaves origin/main behind, so every call after the first fails preflight. Restore the publication verifier that imports governed refs under temporary ghostget-release names, proves them, and removes them, with the ported happy-path, advertisement drift, higher-tag and release-control drift regressions.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
publication-prewrite/publication-postwriteinscripts/release-ref-authority.ts, whichgithub-release-publish.tsstill invokes before and after every Release write. The promotion-lattice retirement removed the modes, so the v0.18.85 and v0.18.86 Release runs both failed at the immutable-Release authority step.refs/ghostget-release/publication-*names, proves the advertised tag/main commits, release ancestry, and unchanged release controls, then removes them so re-entry stays clean across per-write checks.753ffbeb…).Test plan
bun test scripts/release-ref-authority.test.ts— ported v0.18.84 publication tests plus new CLI grammar regressions: happy-path binding with temp-ref cleanup and re-entry, annotated-tag rejection, terminal-advertisement drift, higher-tag tolerance in both phases, release-control drift per phase.bun test scripts/github-release-publish-model.test.ts scripts/npm-release-workflow.test.ts— model and contract suites green.bun run checkgreen: static, package smoke, 5,321 unit + 18 omni tests, Quint/Apalache/Lean/oracle verification.Generated with Devin