Repository navigation
fix(ci): require release-revision tests and scope publishing OIDC - #467
Merged
imran-siddique merged 1 commit intoOct 5, 2026
Merged
Conversation
Signed-off-by: Srinivasa Dinakar Jainti <dinakarjs@gmail.com>
Contributor
|
🟡 Contributor Check: MEDIUM
Automated check by AgenTrust Contributor Check. |
imran-siddique
marked this pull request as ready for review
October 5, 2026 04:30
imran-siddique
requested review from
a team,
lywinged and
rajnisht7
as code owners
October 5, 2026 04:30
imran-siddique
approved these changes
Oct 5, 2026
imran-siddique
left a comment
Member
There was a problem hiding this comment.
Publishing now waits on the full matrix in both publishers, and id-token: write is scoped to the publish job. Both called workflows request only contents: read, so the call does not widen anything. Marking ready and merging.
2 of 7 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Require release-revision tests before TRACE package publication
Both publishers currently build and inspect installed artifacts without depending on the full test matrix. The root publisher also grants OIDC token access at workflow scope.
Make the existing root and conformance CI workflows reusable. Each publisher invokes the relevant matrix and makes its build depend on successful tests. Keep the existing release tag/version and artifact checks. Restrict root id-token: write permission to the publishing job.
Validation: the patch applies to aa5c350 and all four workflow files parse. Dependency-model checks cover successful, failed, cancelled and skipped tests. Removing either new build dependency lets the model reach publishing despite failed tests, demonstrating the intended gate. Static permission checks confirm the root build has no OIDC grant. These checks do not execute Actions or the full suites; actionlint and release-ref execution remain required. Upstream CI, Conformance CI, CodeQL and Workflow lint are awaiting maintainer approval to run; GitHub reports four workflows awaiting approval. The contributor reputation check passed. The separate governance gate requires one independent maintainer approval of head
7acaa5269e673e6150a8b239381a6dc16c570531and found zero.Scoped follow-up to agentrust-io/.github#54. Environment restrictions, publisher bindings and operator availability remain unverified. No publishing dispatch or settings change occurred.
Pre-submission independent reading: completed by a fresh agent session with no previous work context. The reader checked the diff, description, validator, baseline and updated workflows, and independently fetched the unchanged conformance package workflow. No blocking bug was found. The reader identified stale pending-review statements; those were updated. This reading does not establish live Actions execution or environment/operator safeguards.