chore: rolling promotion dev -> main (upload-artifact pin + orphan alarm) - #2659
Conversation
The workflow header's re-enable condition — verified against a fresh sample of tags — is now met. Manual dispatch 30178531358 ran against the debris of the 2026-07-20..25 release outage and detected exactly the 8 genuine orphans (v5.260725.1-.8: tags pushed, no Release), filing issues #2651-#2658 with zero false positives from the 1000+ historical v1.0.x tags excluded by the 24h upper bound. That outage is the scenario this alarm exists for: five days of releases died between tag-push and release-publish and nothing surfaced it automatically — every discovery was manual.
release-publish.yml pinned actions/upload-artifact to b7c4aadc2c921a8ff42c1c6b0e8950fc060e7c7e, which resolves to no commit in actions/upload-artifact. Every job using it failed immediately with 'Unable to resolve action', taking down Build canonical delivery descriptors, Independent candidate security gate, and Require complete Codex native dogfood matrix on v5.260725.10 — the first release to reach those jobs at all. Replaced with ea165f8d65b6e75b540449e92b4886f43607fa02, the real v4 tag, matching the existing '# v4' comment and the download-artifact v4 pin already used in the same file. Audited every pinned action across all workflows and composite actions against the GitHub API: 10 unique pins, this was the only unresolvable one.
|
Caution The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Plus Run ID: 📒 Files selected for processing (8)
📝 WalkthroughWalkthroughThe Genie version was synchronized to ChangesRelease maintenance
Estimated code review effort: 2 (Simple) | ~10 minutes Possibly related PRs
Suggested reviewers: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ee0f02cad4
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
Promotes two dev commits to
main. Required for effect —release-publish.ymlexecutes frommain, so the pin fix is inert until this merges.What it carries
fix(release):actions/upload-artifactwas pinned to a SHA that does not exist.b7c4aadc…resolves to no commit inactions/upload-artifact, so all 8 usages failed instantly withUnable to resolve action, taking down Build canonical delivery descriptors, Independent candidate security gate, and Require complete Codex native dogfood matrix. Replaced withea165f8d…— the real v4 tag, matching the file's own# v4comment and thedownload-artifact@…# v4pin already beside it.Audited every pinned action across all workflows and composite actions against the GitHub API: 10 unique pins, this was the only unresolvable one.
chore(release): tag-orphan alarm re-enabled. Its header required verification against a fresh sample; manual dispatch30178531358detected exactly the 8 genuine orphans (v5.260725.1–.8) and filed #2651–#2658, zero false positives. That alarm is the reason this outage went five days without automatic detection.Progress on v5.260725.10
The
TRIGGER_SHAfix worked — sign-attest passed for the first time and the chain advanced past the wall it hit four times. It then died in the publish-side jobs that PR #2624 added and that had never executed. This is that shakeout, exactly as flagged.Also verified statically for this pass: artifact upload/download pairing and every referenced script path resolve.
Summary by CodeRabbit
Release
Reliability
Maintenance