build(release): automate official and nightly releases - #110
Conversation
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
|
Security review completed for the Socket warning.
The @SocketSecurity ignore npm/yargs@17.7.3 |
Add the generated same-repository proof collector and metadata attestation path, validate official metadata again before attestation, and reconcile all target evidence into the exact non-publishable eleven-file candidate.\n\nAccept cargo-dist's real GNU checksum marker format while continuing to reject extra or mismatched checksum entries.\n\nValidated with bash scripts/ci-preflight.sh and a retained four-platform artifact assembly from workflow run 33344301744.
|
Progress checkpoint: pushed the current release-automation work through commit e036bef. Known issues still requiring remediation before merge:
This PR intentionally remains a draft and is not merge-ready until these three issues are fixed and the resulting head is fully validated and reviewed. The pushed checkpoint passed the repository pre-push suite, including 932 Rust tests, Clippy, build and docs checks, release and nightly harnesses, generated workflow validation, 2 of 2 mutants caught, cargo-deny, and cargo-audit. |
Historical official and nightly archive checks now require trusted signer workflows, and nightly branch fast-forward uses the plural GitHub refs API.
Nightly archive verification looks up Actions runs, so repair and post-mutation checks must use the job token rather than the App token.
Include the packaging digest script in the canonical input list so an algorithm or selection change updates packagingContractSha256.
Temporarily select cargo-dist PR upload mode so this same-repository draft can build and retain the eleven-file proof. Restore plan mode after the artifacts are inspected.
Retain four-platform upload proof from Actions run 33428168802. The eleven-file candidate validated locally; official mutation jobs stayed skipped. cargo-dist is back to pr-run-mode = "plan".
GitHub leaves matrix join expressions unevaluated when the job is skipped, so plan-mode checks showed the raw template. Use a fixed label for that job instead.
There was a problem hiding this comment.
Sorry @jatmn, your pull request is larger than the review limit of 300,000 diff characters
Summary
Contribution checklist
Validation
bash scripts/ci-preflight.shbash scripts/install-git-hooks.shpr-run-mode = "plan".Maintainer checklist
Release-As: 0.1.0