Skip to content

A release requires main's checks on its commit, runs its image, reads PyPI back - #848

Merged
irparent merged 1 commit into
mainfrom
ci/release-safety
Oct 5, 2026
Merged

irparent merged 1 commit into
mainfrom
ci/release-safety

Conversation

@irparent

@irparent irparent commented Oct 5, 2026

Copy link
Copy Markdown
Member

What changes

Gap Before Now
Main's CI on the tagged commit validate refused a tag on a commit that is not on main, then ran a typecheck, the unit suite and a build itself. It never asked whether main's own CI had passed on that commit: the proofs, the claims checks, end to end, the image, the real clients validate requires every required check that runs on main (all of .github/required-checks.json except the two that run only on pull requests) to have succeeded on the tagged commit. A tag pushed while those runs are going waits up to 45 minutes; a failed or cancelled one refuses the release before anything publishes. A re-run that passed counts
The published image starts verify-release checked that the version tag and :latest point to the pushed digest. Whether the image starts was a manual checklist item, added after 0.5.0's image exited on its default command verify-release pulls the digest and runs its --self-test
PyPI the publish step's success was taken as the release the job reads the version back from PyPI, as the npm release reads npm

The checklist's manual Docker item now points at the job that does it.

Tests

  • tests/unit/scripts/require-checks-passed.test.ts: passes when every context main runs succeeded; waits while one is running or has not started; refuses a failed or cancelled one; counts a re-run that passed; never waits for the two pull-request-only contexts.
  • The gate run against main's commit for A fast local preflight by default; test totals counted at a release #841: OK — every required check that runs on main passed on 7a6936af.
  • actionlint (the pinned image CI uses) passes on release.yml and publish-python.yml; the tests that read the release files pass.
  • npm run preflight passed on this commit.

🤖 Generated with Claude Code

…eads PyPI back

- validate refused a tag on a commit that is not on main, then ran a
  typecheck, the unit suite and a build; it never asked whether main's CI
  had passed on that commit (the proofs, the claims checks, end to end,
  the image, the real clients). It now requires every required check
  that runs on main to have succeeded on the tagged commit, waiting up to
  45 minutes for runs still going (scripts/ci/require-checks-passed.mjs).
- verify-release checked that the pushed digest is what the tags point
  to, not that the image starts (0.5.0's exited on its default command,
  and the checklist asked by hand). It now pulls the digest and runs its
  self-test.
- The Python publish now reads the version back from PyPI.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@vercel

vercel Bot commented Oct 5, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
website Ignored Ignored Oct 5, 2026 10:34pm UTC

@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Iris gate — 1 of 2 tripped --fail-on detector_veto

iris-eval ingest: 3 stored, 1 tripped --fail-on detector_veto (2 of 3 evaluated in dataset "release-gate")

Trace Verdict Basis Rules, classes or missing inputs Evidence
1b7a7045f13eb5843ad4b94e59425ed6 failed detector_veto + risk_over_loss no_pii, pii_leak, credential_leak no_pii: AWS Access Key (output 45–65)
Verdict basis Traces
detector_veto 2
clean 1

Unjudged questions: task_completed (3), tool_use_correct (3) — a trace that did not carry what a rule needs.

tests/fixtures/ci-gate/traces.ndjson · 3 evaluated · dataset release-gate: 2 in the gate · exit 1 · what the bases mean

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

Iris gate — 1 stored, nothing tripped --fail-on any

iris-eval ingest: 1 stored, 0 tripped --fail-on any

Verdict basis Traces
clean 1

Unjudged questions: task_completed (1), tool_use_correct (1) — a trace that did not carry what a rule needs.

tests/fixtures/ci-gate/clean.ndjson · 1 evaluated · exit 0 · what the bases mean

@irparent
irparent merged commit 8d4b601 into main Oct 5, 2026
135 of 137 checks passed
@irparent
irparent deleted the ci/release-safety branch October 5, 2026 23:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant