Repository navigation
fix(release): require CI validation before artifact build - #235
Conversation
Signed-off-by: Srinivasa Dinakar <dinakarjs@gmail.com>
|
🟡 Contributor Check: MEDIUM
Automated check by AgenTrust Contributor Check. |
|
@imran-siddique The approved #54/#234 release-CI dependency patch is now submitted at 46633d9 after your vouch. Please review the current head and, after inspecting the diff, approve the pending first-time fork CI, CodeQL and Workflow lint runs. Fresh Linux/Python 3.12 validation: 814 passed, 2 skipped; removing the dependency is caught; lint/format/types/security audit passed. governance-release remains after publish. I could not add a formal reviewer request because the repository permission rejected it; existing code-owner requests remain intact. |
|
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
imran-siddique
left a comment
There was a problem hiding this comment.
@dinakarjs the dependency is right and the parametrized test pins the skip behaviour well. One change: validate now grants id-token: write to the reused CI inside the release workflow, so the test code and the codecov action can mint an OIDC token in a release run. Whether PyPI would accept that token depends on the trusted publisher requiring the pypi environment, a live setting this repo cannot show. Skip the coverage upload when github.event_name == 'release' and drop id-token from validate, so publish stays the only job that can mint a publishing token; the test asserting id-token == "write" flips with it.
Signed-off-by: Srinivasa Dinakar <dinakarjs@gmail.com>
imran-siddique
left a comment
There was a problem hiding this comment.
The credential-free mirror is a better answer than the one I suggested: no token exists in the release run at all, and the drift test compares the whole job set rather than spot checks.
Release builds need the complete CI checks before artifacts can be built or published. Validation now calls a credential-free CI mirror with the same Python 3.11/3.12/3.13 Linux/Windows matrix, lint, formatting, type checks, security scan and governance steps. It omits coverage upload and OIDC permission; a parity test prevents all other jobs/steps from drifting. Normal CI retains its coverage reporting and skips upload on release events. Only the separate publish job can mint a release OIDC token.
This addresses Imran's requested OIDC change, including the grant inside the called workflow, while preserving failure/cancellation/skip blocking and the existing wheel/sdist smoke checks. governance-release remains post-publication as ruled.
Implements the ca2a scope approved in agentrust-io/.github#54: agentrust-io/.github#54 (comment). Closes #234. Maintainer vouching was confirmed before submission.
Validation, Linux/Python 3.12: 816 passed, 2 skipped; 90.20% coverage. All 12 focused release tests pass; Ruff lint and format across src/tests and mypy across the runtime/verifier pass. The new permission checks reject the previous validation grant. Remote OS/Python matrix, security tooling and actual release artifact execution on this revision remain pending.
Environment protections, registry bindings and operator coverage remain separate maintainer work. No publishing workflow was dispatched.