feat: add tagged release automation with fail-closed release gate (Phase 19) - #11
Open
mattpartida wants to merge 1 commit into
Open
mattpartida wants to merge 1 commit into
mattpartida wants to merge 1 commit into
Conversation
…ase 19) - scripts/verify_release_gate.py: verifies tag shape, tag/commit binding (annotated-tag peeling), changelog version section, exact dist inventory, manifest structure, archive digests, secret-shaped content, and the Phase 18 deterministic rebuild before any tagged release publishes. - .github/workflows/release.yml: tag-push-only workflow (v*.*.*), job-scoped contents/attestations/id-token permissions, persist-credentials: false, full quality gate, deterministic rebuild, release gate, actions/attest-build-provenance@v4 attestations, gh release --verify-tag publication with skill archives and MANIFEST.json attached. - docs/release-automation.md: workflow steps, gate checks, maintainer flow, retry path, and pull-request permission non-goals. - tests/test_phase19_release_gate.py: 13 regression tests across gate checks, annotated-tag binding, drift/tamper/secret failure modes, and workflow least-privilege shape. - roadmap Phase 19 -> Shipped; changelog + installation guide links.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Implements roadmap Phase 19: Tagged release automation and attestations — the next unclaimed planned phase (Phases 1–18 shipped; open PRs #7–#10 cover different areas; #10 covers Phase 20).
scripts/verify_release_gate.py— dependency-light, fail-closed pre-release gate. Verifies: stablevX.Y.Ztag shape; tag→commit binding with annotated-tag peeling (workflowGITHUB_SHAmay be a tag object); a## X.Y.Zsection inCHANGELOG.mdordered above older releases; exactdist/inventory (agent-security.skill,healthcheck.skill,MANIFEST.json); manifest structure; per-archive SHA-256 vs manifest; secret-shaped content scan over archive bytes (GitHub/AWS/Slack/private-key/Google-API-key patterns, label-only reporting, never echoes matches); and the Phase 18 deterministic rebuild (package_skills.py --check). Exits 0/1/2 (pass/gate-failure/usage). Never mutates repo, dist, or remote state..github/workflows/release.yml— triggers only onv*.*.*tag pushes. Job-scoped permissions:contents: write,attestations: write,id-token: write; workflow-level defaultpermissions: {};persist-credentials: false; node24 majors (checkout@v7,setup-python@v7) consistent with PR chore: upgrade first-party actions to node24 majors #9. Runs the full CI quality gate (ruff/compileall/pytest), rebuilds archives deterministically, runs the release gate withGITHUB_REF_NAME/GITHUB_SHA, attests build provenance viaactions/attest-build-provenance@v4(current major, v4.2.2), then publishes withgh release create --verify-tag(first-party CLI, no third-party release action) uploading both.skillarchives andMANIFEST.json. Any step failure → no release created. Pull requests never receive release permissions from this workflow.docs/release-automation.md(workflow steps, gate semantics, maintainer release flow, retry path via delete/re-tag); links fromdocs/installation-and-release.md; roadmap Phase 19 → Shipped with scope/acceptance criteria; CHANGELOG entries.tests/test_phase19_release_gate.py, 13 tests: tag shape, changelog section detection + ordering, inventory/manifest/digest failure modes, secret-scan reporting without echoing, annotated vs lightweight tag binding (temp git repos), packager-check drift detection, end-to-end gate pass (rc 0) and blocked runs (rc 1), workflow least-privilege shape assertions.No scanner behavior, JSON fields, or skill behavior changes — CLI additions only. Fully backwards compatible.
Test Plan
Local (Python 3.11.13, matching CI):
python -m compileall -q skills tests scripts— OKpython -m pytest -q— 142 passed (129 pre-existing + 13 new)ruff check .— All checks passed./package-skills.sh+python scripts/package_skills.py --check— reproducible, no driftgit diff --check— cleanCI will run the same gates on this PR.
Notes
v0.1.0(annotated, no GitHub release attached) predates this workflow; it will not trigger it. First use: moveUnreleasedchangelog entries into a## 0.2.0section, tag, push — the workflow verifies and publishes.gh release createavoids addingsoftprops/action-gh-releaseas a third-party dependency; PR chore: upgrade first-party actions to node24 majors #9's action allowlist (which only guardsci.yml+examples/) is unaffected, and versions stay consistent with it.