Skip to content

fix(ci): require release-revision tests and scope publishing OIDC - #467

Merged
imran-siddique merged 1 commit into
agentrust-io:mainfrom
dinakarjs:fix/release-test-gates
Oct 5, 2026
Merged

imran-siddique merged 1 commit into
agentrust-io:mainfrom
dinakarjs:fix/release-test-gates

Conversation

@dinakarjs

@dinakarjs dinakarjs commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Require release-revision tests before TRACE package publication

Both publishers currently build and inspect installed artifacts without depending on the full test matrix. The root publisher also grants OIDC token access at workflow scope.

Make the existing root and conformance CI workflows reusable. Each publisher invokes the relevant matrix and makes its build depend on successful tests. Keep the existing release tag/version and artifact checks. Restrict root id-token: write permission to the publishing job.

Validation: the patch applies to aa5c350 and all four workflow files parse. Dependency-model checks cover successful, failed, cancelled and skipped tests. Removing either new build dependency lets the model reach publishing despite failed tests, demonstrating the intended gate. Static permission checks confirm the root build has no OIDC grant. These checks do not execute Actions or the full suites; actionlint and release-ref execution remain required. Upstream CI, Conformance CI, CodeQL and Workflow lint are awaiting maintainer approval to run; GitHub reports four workflows awaiting approval. The contributor reputation check passed. The separate governance gate requires one independent maintainer approval of head 7acaa5269e673e6150a8b239381a6dc16c570531 and found zero.

Scoped follow-up to agentrust-io/.github#54. Environment restrictions, publisher bindings and operator availability remain unverified. No publishing dispatch or settings change occurred.

Pre-submission independent reading: completed by a fresh agent session with no previous work context. The reader checked the diff, description, validator, baseline and updated workflows, and independently fetched the unchanged conformance package workflow. No blocking bug was found. The reader identified stale pending-review statements; those were updated. This reading does not establish live Actions execution or environment/operator safeguards.

Signed-off-by: Srinivasa Dinakar Jainti <dinakarjs@gmail.com>
@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

🟡 Contributor Check: MEDIUM

Check Result
Profile MEDIUM
Credential LOW
Overall MEDIUM

Automated check by AgenTrust Contributor Check.

@github-actions github-actions Bot added the needs-review:MEDIUM Contributor check flagged MEDIUM risk label Oct 3, 2026
@imran-siddique
imran-siddique marked this pull request as ready for review October 5, 2026 04:30
@imran-siddique
imran-siddique requested review from a team, lywinged and rajnisht7 as code owners October 5, 2026 04:30

@imran-siddique imran-siddique left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Publishing now waits on the full matrix in both publishers, and id-token: write is scoped to the publish job. Both called workflows request only contents: read, so the call does not widen anything. Marking ready and merging.

@imran-siddique
imran-siddique merged commit 03ea1ef into agentrust-io:main Oct 5, 2026
10 of 11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-review:MEDIUM Contributor check flagged MEDIUM risk

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants