Skip to content

fix(release): require CI validation before artifact build - #235

Merged
imran-siddique merged 2 commits into
agentrust-io:mainfrom
dinakarjs:fix/release-ci-validation
Oct 8, 2026
Merged

imran-siddique merged 2 commits into
agentrust-io:mainfrom
dinakarjs:fix/release-ci-validation

Conversation

@dinakarjs

@dinakarjs dinakarjs commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Release builds need the complete CI checks before artifacts can be built or published. Validation now calls a credential-free CI mirror with the same Python 3.11/3.12/3.13 Linux/Windows matrix, lint, formatting, type checks, security scan and governance steps. It omits coverage upload and OIDC permission; a parity test prevents all other jobs/steps from drifting. Normal CI retains its coverage reporting and skips upload on release events. Only the separate publish job can mint a release OIDC token.

This addresses Imran's requested OIDC change, including the grant inside the called workflow, while preserving failure/cancellation/skip blocking and the existing wheel/sdist smoke checks. governance-release remains post-publication as ruled.

Implements the ca2a scope approved in agentrust-io/.github#54: agentrust-io/.github#54 (comment). Closes #234. Maintainer vouching was confirmed before submission.

Validation, Linux/Python 3.12: 816 passed, 2 skipped; 90.20% coverage. All 12 focused release tests pass; Ruff lint and format across src/tests and mypy across the runtime/verifier pass. The new permission checks reject the previous validation grant. Remote OS/Python matrix, security tooling and actual release artifact execution on this revision remain pending.

Environment protections, registry bindings and operator coverage remain separate maintainer work. No publishing workflow was dispatched.

Signed-off-by: Srinivasa Dinakar <dinakarjs@gmail.com>
@dinakarjs
dinakarjs requested review from a team, carloshvp and zohebk8s as code owners October 8, 2026 06:30
@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

🟡 Contributor Check: MEDIUM

Check Result
Profile MEDIUM
Credential LOW
Overall MEDIUM

Automated check by AgenTrust Contributor Check.

@github-actions github-actions Bot added the needs-review:MEDIUM Contributor check flagged MEDIUM risk label Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

@imran-siddique The approved #54/#234 release-CI dependency patch is now submitted at 46633d9 after your vouch. Please review the current head and, after inspecting the diff, approve the pending first-time fork CI, CodeQL and Workflow lint runs. Fresh Linux/Python 3.12 validation: 814 passed, 2 skipped; removing the dependency is caught; lint/format/types/security audit passed. governance-release remains after publish. I could not add a formal reviewer request because the repository permission rejected it; existing code-owner requests remain intact.

@codecov-commenter

Copy link
Copy Markdown

⚠️ Please install the 'codecov app svg image' to ensure uploads and comments are reliably processed by Codecov.

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@imran-siddique imran-siddique left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@dinakarjs the dependency is right and the parametrized test pins the skip behaviour well. One change: validate now grants id-token: write to the reused CI inside the release workflow, so the test code and the codecov action can mint an OIDC token in a release run. Whether PyPI would accept that token depends on the trusted publisher requiring the pypi environment, a live setting this repo cannot show. Skip the coverage upload when github.event_name == 'release' and drop id-token from validate, so publish stays the only job that can mint a publishing token; the test asserting id-token == "write" flips with it.

Signed-off-by: Srinivasa Dinakar <dinakarjs@gmail.com>

@imran-siddique imran-siddique left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The credential-free mirror is a better answer than the one I suggested: no token exists in the release run at all, and the drift test compares the whole job set rather than spot checks.

@imran-siddique
imran-siddique merged commit 407f78e into agentrust-io:main Oct 8, 2026
12 of 13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-review:MEDIUM Contributor check flagged MEDIUM risk

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Release safeguards from .github#54

3 participants