Skip to content

chore: rolling promotion dev -> main - #2660

Merged
namastex888 merged 8 commits into
mainfrom
dev
Jul 26, 2026
Merged

namastex888 merged 8 commits into
mainfrom
dev

Conversation

@namastex888

@namastex888 namastex888 commented Jul 26, 2026 •

Copy link
Copy Markdown
Contributor

Rolling Promotion PR

Auto-maintained rolling promotion PR from dev to main.

Process:

  • This PR is automatically created and kept open
  • Human reviews and merges when ready
  • Label ready-to-merge added when all checks pass

IMPORTANT: Merge with "Create a merge commit" — NEVER squash.
Squash merging breaks history sync between dev and main,
causing the next rolling PR to show all commits again.

Human approval required for merge to production.

Summary by CodeRabbit

  • Release
    • Updated package and plugin versions to 5.260726.3.
  • Chores
    • Improved release artifact uploading to correctly include hidden .well-known contents.
    • Enhanced live dogfood evidence validation for legacy vs non-legacy provenance and stable-channel branching rules.
    • Updated the dogfood test harness for legacy/delivery differences and to write the VERSION file next to the installed binary.
    • Added CI validation to ensure GitHub Actions uses: references are pinned to resolvable commit SHAs.

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

@coderabbitai

coderabbitai Bot commented Jul 26, 2026 •

Copy link
Copy Markdown

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

Release versions are synchronized across package and plugin manifests. Release artifact handling now includes hidden manifests, action pins are validated against GitHub, and dogfood provenance verification supports legacy and delivery-era identity formats.

Changes

Release and validation updates

Layer / File(s) Summary
Synchronized release metadata
.claude-plugin/marketplace.json, package.json, plugins/genie/..., plugins/hermes-genie/plugin.yaml
Updates release versions from 5.260725.10 to 5.260726.3.
Release artifact and action-pin validation
.github/workflows/release-publish.yml, .github/workflows/ci.yml, scripts/check-action-pins.sh
Includes hidden .well-known manifests in release uploads and adds CI checks that resolve pinned GitHub Actions SHAs.
Provenance verification paths
scripts/validate-live-dogfood-evidence.ts, tests/support/codex-dogfood-harness.ts
Adjusts branch validation, legacy provenance extraction, capability probing, and installed binary VERSION placement.

Estimated code review effort: 3 (Moderate) | ~25 minutes

Sequence Diagram(s)

sequenceDiagram
  participant CI as CI workflow
  participant Script as check-action-pins.sh
  participant GitHub as GitHub API
  CI->>Script: Run action pin checks
  Script->>GitHub: Resolve repository commit SHA
  GitHub-->>Script: Return commit status
  Script-->>CI: Report success or failure
Loading

Possibly related PRs

Suggested reviewers: automagik-genie

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly matches the PR’s rolling promotion from dev to main.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dev

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: de9c5f6244

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread scripts/check-action-pins.sh

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@scripts/check-action-pins.sh`:
- Line 20: Update the scanning logic around the `uses:` regex in
`check-action-pins.sh` to inspect all workflow and action manifest files,
recognize both quoted and unquoted valid YAML scalar values, and require the
entire scalar to match the action reference ending in exactly a 40-hex SHA.
Preserve the existing GitHub query behavior only for complete valid matches,
rejecting trailing invalid suffixes.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 688e9bfb-ae62-47cc-97e2-8798bbe9424b

📥 Commits

Reviewing files that changed from the base of the PR and between 8e97e82 and de9c5f6.

📒 Files selected for processing (7)
  • .claude-plugin/marketplace.json
  • package.json
  • plugins/genie/.claude-plugin/plugin.json
  • plugins/genie/.codex-plugin/plugin.json
  • plugins/genie/package.json
  • plugins/hermes-genie/plugin.yaml
  • scripts/check-action-pins.sh

Comment thread scripts/check-action-pins.sh
github-actions Bot and others added 6 commits July 26, 2026 17:26
All five publish-side first-run fixes are live on main. This fires the
dev chain to exercise them end to end.
Bun's BoringSSL-backed crypto.verify throws NO_DEFAULT_DIGEST when called
without an algorithm on EC/RSA keys, where Node/OpenSSL infers SHA-256.
@sigstore/core wraps that call in a try/catch that converts the throw into
a failed verification, so every EC signature check in @sigstore/verify
(tlog SET, checkpoint, DSSE envelope) silently fails under Bun with
TLOG_INCLUSION_PROMISE_ERROR — the delivery-evidence-compatibility job
could never pass, and the compiled binary's own update/activation
verifier carried the same defect.

Patch @sigstore/core (latest 4.0.1; upstream has no fixed release) via
bun patchedDependencies to make the OpenSSL default digest explicit for
EC/RSA keys, leaving Ed25519/Ed448 untouched. Verified against the four
real endorsement bundles from run 30212680700: all verify; tampered SET
and DSSE signatures are rejected.

Add a real-crypto regression test: the production verifier CLI must
verify a real run-30212680700 evidence pack (descriptor + bundle +
manifest committed as byte-exact fixtures, exempted from Biome
formatting because their digests are signed) with no cryptographic seam,
and must reject tampered bundles. The test fails against unpatched
@sigstore/core, reproducing the release outage.
…digest

fix(release): give Bun the ECDSA digest sigstore verification relies on

@automagik-genie automagik-genie left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Promotion reviewed and approved as the batch carrying the release-chain fix to main.

What this promotes (main..dev): the @sigstore/core Bun patch (patches/ + patchedDependencies + real-crypto regression fixtures), the action-pin CI gate, and auto-version bumps.

Why main needs it now: run 30214153213 (v5.260726.4, dev) proved the fix in production — Verify production delivery evidence compatibility and Independent candidate security gate passed for the first time ever from the patched source_sha. The four Codex native dogfood jobs then failed with the same root cause (inclusion promise could not be verified) because the dogfood harness checks out github.sha = main, whose node_modules is unpatched. Promoting applies the patch to the harness; the candidate binary side is already fixed via source_sha.

Both review threads addressed: pin-checker CI wiring is included in this PR (ci.yml action-pins job); scanner regex hardening deferred to #2669 with rationale.

@namastex888
namastex888 dismissed automagik-genie’s stale review July 26, 2026 18:20

The merge-base changed after approval.

@automagik-genie automagik-genie left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-approving after branch update (previous approval was auto-dismissed by the update). Promotion carries the sigstore-under-Bun fix to main so the dogfood harness (checkout github.sha) gets the patched verifier — run 30214153213 proved the fix at delivery-evidence-compatibility and the security gate; the four dogfood failures are the same root cause from main's unpatched checkout.

@automagik-genie automagik-genie left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-approving after the auto-version bump to 5.260726.5 dismissed the previous approval (bump pushed by the Version workflow). No content change beyond the bump; promotion rationale unchanged — carries the sigstore-under-Bun harness fix to main.

@namastex888
namastex888 merged commit 9b39704 into main Jul 26, 2026
23 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants