Skip to content

chore: rolling promotion dev -> main (upload-artifact pin + orphan alarm) - #2659

Merged
namastex888 merged 4 commits into
mainfrom
promote/action-pin-fix
Jul 25, 2026
Merged

namastex888 merged 4 commits into
mainfrom
promote/action-pin-fix

Conversation

@automagik-genie

@automagik-genie automagik-genie commented Jul 25, 2026 •

Copy link
Copy Markdown
Contributor

Promotes two dev commits to main. Required for effect — release-publish.yml executes from main, so the pin fix is inert until this merges.

What it carries

fix(release): actions/upload-artifact was pinned to a SHA that does not exist. b7c4aadc… resolves to no commit in actions/upload-artifact, so all 8 usages failed instantly with Unable to resolve action, taking down Build canonical delivery descriptors, Independent candidate security gate, and Require complete Codex native dogfood matrix. Replaced with ea165f8d… — the real v4 tag, matching the file's own # v4 comment and the download-artifact@…# v4 pin already beside it.

Audited every pinned action across all workflows and composite actions against the GitHub API: 10 unique pins, this was the only unresolvable one.

chore(release): tag-orphan alarm re-enabled. Its header required verification against a fresh sample; manual dispatch 30178531358 detected exactly the 8 genuine orphans (v5.260725.1–.8) and filed #2651–#2658, zero false positives. That alarm is the reason this outage went five days without automatic detection.

Progress on v5.260725.10

The TRIGGER_SHA fix worked — sign-attest passed for the first time and the chain advanced past the wall it hit four times. It then died in the publish-side jobs that PR #2624 added and that had never executed. This is that shakeout, exactly as flagged.

Also verified statically for this pass: artifact upload/download pairing and every referenced script path resolve.

Summary by CodeRabbit

  • Release

    • Updated the Genie plugin version to 5.260725.10 across all published metadata.
  • Reliability

    • Re-enabled automated release monitoring every 30 minutes to detect orphaned release tags.
  • Maintenance

    • Updated the artifact-upload tooling used during release evidence collection.

automagik-genie and others added 3 commits July 25, 2026 19:58
The workflow header's re-enable condition — verified against a fresh
sample of tags — is now met. Manual dispatch 30178531358 ran against the
debris of the 2026-07-20..25 release outage and detected exactly the 8
genuine orphans (v5.260725.1-.8: tags pushed, no Release), filing issues
#2651-#2658 with zero false positives from the 1000+ historical v1.0.x
tags excluded by the 24h upper bound.

That outage is the scenario this alarm exists for: five days of releases
died between tag-push and release-publish and nothing surfaced it
automatically — every discovery was manual.
release-publish.yml pinned actions/upload-artifact to
b7c4aadc2c921a8ff42c1c6b0e8950fc060e7c7e, which resolves to no commit in
actions/upload-artifact. Every job using it failed immediately with
'Unable to resolve action', taking down Build canonical delivery
descriptors, Independent candidate security gate, and Require complete
Codex native dogfood matrix on v5.260725.10 — the first release to reach
those jobs at all.

Replaced with ea165f8d65b6e75b540449e92b4886f43607fa02, the real v4 tag,
matching the existing '# v4' comment and the download-artifact v4 pin
already used in the same file.

Audited every pinned action across all workflows and composite actions
against the GitHub API: 10 unique pins, this was the only unresolvable
one.
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

@coderabbitai

coderabbitai Bot commented Jul 25, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 876bd895-97c9-4cae-a479-bfc0de9c6b62

📥 Commits

Reviewing files that changed from the base of the PR and between 8ee5540 and ee0f02c.

📒 Files selected for processing (8)
  • .claude-plugin/marketplace.json
  • .github/workflows/release-orphan-alert.yml
  • .github/workflows/release-publish.yml
  • package.json
  • plugins/genie/.claude-plugin/plugin.json
  • plugins/genie/.codex-plugin/plugin.json
  • plugins/genie/package.json
  • plugins/hermes-genie/plugin.yaml

📝 Walkthrough

Walkthrough

The Genie version was synchronized to 5.260725.10. The orphan alert workflow regained its 30-minute schedule, and release evidence uploads were updated to a new pinned actions/upload-artifact revision.

Changes

Release maintenance

Layer / File(s) Summary
Coordinated Genie version metadata
.claude-plugin/marketplace.json, package.json, plugins/genie/*, plugins/hermes-genie/plugin.yaml
Genie version declarations were updated from 5.260725.8 to 5.260725.10.
Re-enable orphan alert schedule
.github/workflows/release-orphan-alert.yml
The orphan alert workflow now runs every 30 minutes through its cron trigger.
Update release artifact action pins
.github/workflows/release-publish.yml
Release evidence upload steps now use the updated pinned actions/upload-artifact revision without changing artifact configuration.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

Suggested reviewers: namastex888

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the main workflow fix and re-enabled orphan alarm promotion from dev to main.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch promote/action-pin-fix

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: ee0f02cad4

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread .github/workflows/release-orphan-alert.yml
@namastex888
namastex888 merged commit 8e97e82 into main Jul 25, 2026
16 checks passed
@automagik-genie
automagik-genie deleted the promote/action-pin-fix branch September 25, 2026 04:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants