Skip to content

feat: add tagged release automation with fail-closed release gate (Phase 19) - #11

Open
mattpartida wants to merge 1 commit into
mainfrom
feat/20260907-tagged-release-automation
Open

mattpartida wants to merge 1 commit into
mainfrom
feat/20260907-tagged-release-automation

Conversation

@mattpartida

Copy link
Copy Markdown
Owner

Summary

Implements roadmap Phase 19: Tagged release automation and attestations — the next unclaimed planned phase (Phases 1–18 shipped; open PRs #7–#10 cover different areas; #10 covers Phase 20).

  • scripts/verify_release_gate.py — dependency-light, fail-closed pre-release gate. Verifies: stable vX.Y.Z tag shape; tag→commit binding with annotated-tag peeling (workflow GITHUB_SHA may be a tag object); a ## X.Y.Z section in CHANGELOG.md ordered above older releases; exact dist/ inventory (agent-security.skill, healthcheck.skill, MANIFEST.json); manifest structure; per-archive SHA-256 vs manifest; secret-shaped content scan over archive bytes (GitHub/AWS/Slack/private-key/Google-API-key patterns, label-only reporting, never echoes matches); and the Phase 18 deterministic rebuild (package_skills.py --check). Exits 0/1/2 (pass/gate-failure/usage). Never mutates repo, dist, or remote state.
  • .github/workflows/release.yml — triggers only on v*.*.* tag pushes. Job-scoped permissions: contents: write, attestations: write, id-token: write; workflow-level default permissions: {}; persist-credentials: false; node24 majors (checkout@v7, setup-python@v7) consistent with PR chore: upgrade first-party actions to node24 majors #9. Runs the full CI quality gate (ruff/compileall/pytest), rebuilds archives deterministically, runs the release gate with GITHUB_REF_NAME/GITHUB_SHA, attests build provenance via actions/attest-build-provenance@v4 (current major, v4.2.2), then publishes with gh release create --verify-tag (first-party CLI, no third-party release action) uploading both .skill archives and MANIFEST.json. Any step failure → no release created. Pull requests never receive release permissions from this workflow.
  • Docs — new docs/release-automation.md (workflow steps, gate semantics, maintainer release flow, retry path via delete/re-tag); links from docs/installation-and-release.md; roadmap Phase 19 → Shipped with scope/acceptance criteria; CHANGELOG entries.
  • Tests — tests/test_phase19_release_gate.py, 13 tests: tag shape, changelog section detection + ordering, inventory/manifest/digest failure modes, secret-scan reporting without echoing, annotated vs lightweight tag binding (temp git repos), packager-check drift detection, end-to-end gate pass (rc 0) and blocked runs (rc 1), workflow least-privilege shape assertions.

No scanner behavior, JSON fields, or skill behavior changes — CLI additions only. Fully backwards compatible.

Test Plan

Local (Python 3.11.13, matching CI):

  • python -m compileall -q skills tests scripts — OK
  • python -m pytest -q — 142 passed (129 pre-existing + 13 new)
  • ruff check . — All checks passed
  • ./package-skills.sh + python scripts/package_skills.py --check — reproducible, no drift
  • git diff --check — clean
  • CLI smoke: no-args → usage exit 2; unknown tag/missing changelog → gate failures, exit 1
  • No real secrets committed; secret-pattern scan over repo content clean

CI will run the same gates on this PR.

Notes

…ase 19)

- scripts/verify_release_gate.py: verifies tag shape, tag/commit binding
  (annotated-tag peeling), changelog version section, exact dist inventory,
  manifest structure, archive digests, secret-shaped content, and the
  Phase 18 deterministic rebuild before any tagged release publishes.
- .github/workflows/release.yml: tag-push-only workflow (v*.*.*), job-scoped
  contents/attestations/id-token permissions, persist-credentials: false,
  full quality gate, deterministic rebuild, release gate,
  actions/attest-build-provenance@v4 attestations, gh release --verify-tag
  publication with skill archives and MANIFEST.json attached.
- docs/release-automation.md: workflow steps, gate checks, maintainer flow,
  retry path, and pull-request permission non-goals.
- tests/test_phase19_release_gate.py: 13 regression tests across gate checks,
  annotated-tag binding, drift/tamper/secret failure modes, and workflow
  least-privilege shape.
- roadmap Phase 19 -> Shipped; changelog + installation guide links.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant