chore: rolling promotion dev -> main - #2660
Conversation
|
Caution The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased. |
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
📝 WalkthroughWalkthroughRelease versions are synchronized across package and plugin manifests. Release artifact handling now includes hidden manifests, action pins are validated against GitHub, and dogfood provenance verification supports legacy and delivery-era identity formats. ChangesRelease and validation updates
Estimated code review effort: 3 (Moderate) | ~25 minutes Sequence Diagram(s)sequenceDiagram
participant CI as CI workflow
participant Script as check-action-pins.sh
participant GitHub as GitHub API
CI->>Script: Run action pin checks
Script->>GitHub: Resolve repository commit SHA
GitHub-->>Script: Return commit status
Script-->>CI: Report success or failure
Possibly related PRs
Suggested reviewers: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: de9c5f6244
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@scripts/check-action-pins.sh`:
- Line 20: Update the scanning logic around the `uses:` regex in
`check-action-pins.sh` to inspect all workflow and action manifest files,
recognize both quoted and unquoted valid YAML scalar values, and require the
entire scalar to match the action reference ending in exactly a 40-hex SHA.
Preserve the existing GitHub query behavior only for complete valid matches,
rejecting trailing invalid suffixes.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 688e9bfb-ae62-47cc-97e2-8798bbe9424b
📒 Files selected for processing (7)
.claude-plugin/marketplace.jsonpackage.jsonplugins/genie/.claude-plugin/plugin.jsonplugins/genie/.codex-plugin/plugin.jsonplugins/genie/package.jsonplugins/hermes-genie/plugin.yamlscripts/check-action-pins.sh
All five publish-side first-run fixes are live on main. This fires the dev chain to exercise them end to end.
Bun's BoringSSL-backed crypto.verify throws NO_DEFAULT_DIGEST when called without an algorithm on EC/RSA keys, where Node/OpenSSL infers SHA-256. @sigstore/core wraps that call in a try/catch that converts the throw into a failed verification, so every EC signature check in @sigstore/verify (tlog SET, checkpoint, DSSE envelope) silently fails under Bun with TLOG_INCLUSION_PROMISE_ERROR — the delivery-evidence-compatibility job could never pass, and the compiled binary's own update/activation verifier carried the same defect. Patch @sigstore/core (latest 4.0.1; upstream has no fixed release) via bun patchedDependencies to make the OpenSSL default digest explicit for EC/RSA keys, leaving Ed25519/Ed448 untouched. Verified against the four real endorsement bundles from run 30212680700: all verify; tampered SET and DSSE signatures are rejected. Add a real-crypto regression test: the production verifier CLI must verify a real run-30212680700 evidence pack (descriptor + bundle + manifest committed as byte-exact fixtures, exempted from Biome formatting because their digests are signed) with no cryptographic seam, and must reject tampered bundles. The test fails against unpatched @sigstore/core, reproducing the release outage.
…digest fix(release): give Bun the ECDSA digest sigstore verification relies on
automagik-genie
left a comment
There was a problem hiding this comment.
Promotion reviewed and approved as the batch carrying the release-chain fix to main.
What this promotes (main..dev): the @sigstore/core Bun patch (patches/ + patchedDependencies + real-crypto regression fixtures), the action-pin CI gate, and auto-version bumps.
Why main needs it now: run 30214153213 (v5.260726.4, dev) proved the fix in production — Verify production delivery evidence compatibility and Independent candidate security gate passed for the first time ever from the patched source_sha. The four Codex native dogfood jobs then failed with the same root cause (inclusion promise could not be verified) because the dogfood harness checks out github.sha = main, whose node_modules is unpatched. Promoting applies the patch to the harness; the candidate binary side is already fixed via source_sha.
Both review threads addressed: pin-checker CI wiring is included in this PR (ci.yml action-pins job); scanner regex hardening deferred to #2669 with rationale.
The merge-base changed after approval.
automagik-genie
left a comment
There was a problem hiding this comment.
Re-approving after branch update (previous approval was auto-dismissed by the update). Promotion carries the sigstore-under-Bun fix to main so the dogfood harness (checkout github.sha) gets the patched verifier — run 30214153213 proved the fix at delivery-evidence-compatibility and the security gate; the four dogfood failures are the same root cause from main's unpatched checkout.
automagik-genie
left a comment
There was a problem hiding this comment.
Re-approving after the auto-version bump to 5.260726.5 dismissed the previous approval (bump pushed by the Version workflow). No content change beyond the bump; promotion rationale unchanged — carries the sigstore-under-Bun harness fix to main.
Rolling Promotion PR
Auto-maintained rolling promotion PR from
devtomain.Process:
ready-to-mergeadded when all checks passSummary by CodeRabbit
.well-knowncontents.VERSIONfile next to the installed binary.uses:references are pinned to resolvable commit SHAs.