Verify release assets before upload - #24
Conversation
|
Combined compatibility validation across #24, #25, #26, #27, and #28 is complete. Recommended integration order: #24 checksums, #25 attestations, #26 immutable-action audit, #27 checkout/time/concurrency hardening, #28 version audit. The combined check found only additive prose conflicts in the shared Unreleased changelog and SECURITY text; |
|
Refreshed combined validation after the #26, #27, and #29 fixes includes YAML-semantic action scanning, YAML-semantic workflow policy tests, and exact integer KDF validation. Full stacked |
|
The release-documentation blocker is fixed at the new head. README now states that v0.2.3 predates the checksum workflow and has no |
…' into codex/release-checksums # Conflicts: # .github/workflows/release-assets.yml # CHANGELOG.md # SECURITY.md
…ecksums # Conflicts: # .github/workflows/release-assets.yml # SECURITY.md # docs/release-process.md
|
Superseded by #36, which preserves the checksum contract on a clean linear history with the protected release controls. |
Summary
SHA256SUMSfrom the protected version tagSHA256SUMSValidation
make release-gate: 109 passed, 1 optional skip, 91.83% coverageIntegration order is #35, then this PR, then #25. This PR still requires an eligible reviewer approval. No release or tag was created.