Skip to content

fix(release): bump BOTH gated skill manifests; give every full-suite job the differential baseline - #238

Merged
Rome-1 merged 1 commit into
mainfrom
fix/release-version-and-differential-baseline
Sep 9, 2026
Merged

Rome-1 merged 1 commit into
mainfrom
fix/release-version-and-differential-baseline

Conversation

@Rome-1

@Rome-1 Rome-1 commented Sep 9, 2026

Copy link
Copy Markdown
Collaborator

Unblocks #237. Larger than the one-line bump it looked like — please read the second half before merging.

1. The version gate named one file because it exits at the first

validate-versions loops over two manifests and exit 1s on the first mismatch, so it only reported the node one. python/rafter_cli/resources/rafter-security-skill.md was equally stale at 0.10.0 and would have failed the very next run. Both are now 0.10.1; I simulated the gate over both files.

Four other manifests carry a version: and are not in the loop — rafter/SKILL.md and rafter-code-review at 0.7.0, rafter-secure-design and rafter-skill-review at 0.1.0, each duplicated node/python. Left alone deliberately (they aren't release-versioned), but noted: prod history already contains fix(release): bump ClawHub skill resource versions to 0.8.9, so this desync recurs. Bead to follow.

2. Five other checks were failing, all of them mine

test-build and all four cross-platform legs failed on tests/rf6pqx-differential.test.ts:

Command failed: git show origin/main:node/src/core/risk-rules.ts
fatal: invalid object name 'origin/main'.

The differential fails rather than skips when the baseline is missing, which is correct — but that makes the baseline a precondition of every job running the suite, and I'd added the fetch to only the two jobs whose failure I happened to be looking at.

So I swept all four workflows rather than patching instances again:

workflow job
test-comprehensive test-node already had it
test-comprehensive test-python already had it
test-comprehensive cross-platform added
validate-release test-build added
publish test-node added
publish test-python added

The last two are why this matters. publish.yaml runs the full node and python suites, and publish-node/publish-python are gated on them — so without this, the release would have passed every check on #237 and then failed at the moment Rome merged it.

e2e-node, secret-detection-accuracy and backend-api run single targeted files, never collect the differential, and need nothing. Checked rather than assumed.

Verification

Gate simulated over both manifests; differential and battery suites pass in both runtimes locally; full-suite sweep re-run and clean.

…ite job the differential baseline

Two separate things blocking #237, both larger than they first looked.

1. THE VERSION GATE NAMED ONE FILE BECAUSE IT EXITS AT THE FIRST.
   validate-versions loops over TWO manifests and `exit 1`s on the first
   mismatch, so it reported only node/resources/rafter-security-skill.md.
   python/rafter_cli/resources/rafter-security-skill.md was equally stale
   at 0.10.0 and would have failed the very next run. Both bumped to
   0.10.1; gate simulated over both files, OK on each.

   Four more manifests carry a version and are NOT in the loop
   (rafter/SKILL.md and rafter-code-review at 0.7.0, rafter-secure-design
   and rafter-skill-review at 0.1.0, each duplicated node/python). Left
   alone deliberately — they are not release-versioned — but a gate that
   checks two of six is a gate with a blind spot, and prod history
   already contains "fix(release): bump ClawHub skill resource versions
   to 0.8.9". Recurrence is the finding; bead to follow.

2. FIVE OTHER CHECKS WERE FAILING, ALL OF THEM MINE.
   test-build and all four cross-platform legs failed on
   tests/rf6pqx-differential.test.ts:

       Command failed: git show origin/main:node/src/core/risk-rules.ts
       fatal: invalid object name 'origin/main'.

   The differential FAILS rather than skips when the baseline is missing,
   which is right — but that makes the baseline a precondition of every
   job that runs the suite, and I had added the fetch to exactly the two
   jobs whose failure I happened to be looking at.

   So I swept all four workflows for jobs running a FULL suite instead of
   patching the instances again:

       test-comprehensive  test-node       already had it
       test-comprehensive  test-python     already had it
       test-comprehensive  cross-platform  ADDED
       validate-release    test-build      ADDED
       publish             test-node       ADDED
       publish             test-python     ADDED

   The last two are the ones that matter most: publish.yaml runs the full
   node and python suites, and publish-node/publish-python are gated on
   them. Without this the release would have passed every check on #237
   and then FAILED AT THE MOMENT ROME MERGED — the worst place to find it.

   e2e-node, secret-detection-accuracy and backend-api run single targeted
   files, so they never collect the differential and need nothing. Checked
   rather than assumed.

Local: the differential and battery suites pass in both runtimes.
@Rome-1
Rome-1 merged commit 31f9c11 into main Sep 9, 2026
9 checks passed
Rome-1 added a commit that referenced this pull request Sep 13, 2026
Unblocks rf-f5is. #250 merged to a PUBLIC main on 2026-09-11 and the registries
have served 0.10.3 ever since — a fix disclosed and not shipped, for an
EXTERNALLY reported finding. Cutting the disclosure line from the PR body did
not undo the disclosure: merging to a public repo publishes a diff naming
exactly which key shapes were undetected and at what lengths.

CONTENTS
  6839663  #250  rf-f5is   OpenAI + Supabase rules in the regex engine
  14eb1c6  #246  rf-3n1i   command_policy.allowed_patterns in python, under the
                           policy floor, plus two allowlist bypasses closed

SCOPE OF THE BUMP — four files, found by searching for the current version
rather than by trusting the validator's list, because #238 exists precisely
because a partial bump PASSED validation once:

    node/package.json
    python/pyproject.toml
    node/resources/rafter-security-skill.md                 (gated ClawHub manifest)
    python/rafter_cli/resources/rafter-security-skill.md    (gated ClawHub manifest)

DELIBERATELY NOT BUMPED. The repo carries six other SKILL.md files with their
own frontmatter versions — rafter-code-review at 0.7.0, rafter-secure-design,
rafter-skill-review and rafter at 0.1.0/0.7.0. Those are independently
versioned skill resources, not package-version mirrors; moving them to 0.10.4
would be wrong, and "every manifest" does not mean every file with a version.
The two that ARE package mirrors are the two validate-release gates.

VERIFIED by running validate-release's own checks locally rather than trusting
the edit: node and python versions match at 0.10.4, and both gated skill
manifests match the package version. Plus the check validate-release does NOT
do and which is the one that actually bites — 0.10.4 is not already on the
registry. main's version equalling the published version is what made the last
two gaps unpublishable: validation passes and the publish job fails later, at
the registry, with an error that does not say "you forgot the bump".

Does not push prod. PR #251 (main -> prod) is open and is Rome's to merge.

Co-authored-by: secbolt/crew/goldwasser <hello@rafter.so>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant