Repository navigation
A release requires main's checks on its commit, runs its image, reads PyPI back - #848
Merged
Merged
Conversation
…eads PyPI back - validate refused a tag on a commit that is not on main, then ran a typecheck, the unit suite and a build; it never asked whether main's CI had passed on that commit (the proofs, the claims checks, end to end, the image, the real clients). It now requires every required check that runs on main to have succeeded on the tagged commit, waiting up to 45 minutes for runs still going (scripts/ci/require-checks-passed.mjs). - verify-release checked that the pushed digest is what the tags point to, not that the image starts (0.5.0's exited on its default command, and the checklist asked by hand). It now pulls the digest and runs its self-test. - The Python publish now reads the version back from PyPI. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub. |
Iris gate — 1 of 2 tripped
|
| Trace | Verdict | Basis | Rules, classes or missing inputs | Evidence |
|---|---|---|---|---|
1b7a7045f13eb5843ad4b94e59425ed6 |
failed | detector_veto + risk_over_loss |
no_pii, pii_leak, credential_leak | no_pii: AWS Access Key (output 45–65) |
| Verdict basis | Traces |
|---|---|
detector_veto |
2 |
clean |
1 |
Unjudged questions: task_completed (3), tool_use_correct (3) — a trace that did not carry what a rule needs.
tests/fixtures/ci-gate/traces.ndjson · 3 evaluated · dataset release-gate: 2 in the gate · exit 1 · what the bases mean
Iris gate — 1 stored, nothing tripped
|
| Verdict basis | Traces |
|---|---|
clean |
1 |
Unjudged questions: task_completed (1), tool_use_correct (1) — a trace that did not carry what a rule needs.
tests/fixtures/ci-gate/clean.ndjson · 1 evaluated · exit 0 · what the bases mean
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changes
validaterefused a tag on a commit that is not on main, then ran a typecheck, the unit suite and a build itself. It never asked whether main's own CI had passed on that commit: the proofs, the claims checks, end to end, the image, the real clientsvalidaterequires every required check that runs on main (all of.github/required-checks.jsonexcept the two that run only on pull requests) to have succeeded on the tagged commit. A tag pushed while those runs are going waits up to 45 minutes; a failed or cancelled one refuses the release before anything publishes. A re-run that passed countsverify-releasechecked that the version tag and:latestpoint to the pushed digest. Whether the image starts was a manual checklist item, added after 0.5.0's image exited on its default commandverify-releasepulls the digest and runs its--self-testThe checklist's manual Docker item now points at the job that does it.
Tests
tests/unit/scripts/require-checks-passed.test.ts: passes when every context main runs succeeded; waits while one is running or has not started; refuses a failed or cancelled one; counts a re-run that passed; never waits for the two pull-request-only contexts.OK — every required check that runs on main passed on 7a6936af.release.ymlandpublish-python.yml; the tests that read the release files pass.npm run preflightpassed on this commit.🤖 Generated with Claude Code