Repository navigation
fix(ci): gate registry releases on validation and installed artifacts - #123
Conversation
Implement the trace-registry scope approved in agentrust-io/.github#54. Signed-off-by: Srinivasa Dinakar <dinakarjs@gmail.com>
imran-siddique
left a comment
There was a problem hiding this comment.
Reviewed bd88d7a against the approved scope in agentrust-io/.github#54. Release/manual builds depend on the existing CI validation job; only the named append-only comparison steps are skipped without a push/PR base. Publication requires successful validation and artifact checks, retains the exact tag/package/runtime guard, and downloads the checked distributions without rebuilding. Build-only execution has neither the PyPI environment nor OIDC write permission.
Validation: all 11 release-safeguard tests passed locally against this checkout, including the real CLI accepting the signed control and refusing a changed anchor while preserving signature validity. Inspected CI job 112170695500: 395 tests passed; workflow lint and CodeQL are green. The Linux clean-environment wheel/sdist workflow was inspected but not executed locally on Windows. No publishing workflow or environment settings were changed.
The publisher previously had no release-revision CI dependency or installed-artifact verification, and its build-only job held the PyPI environment and OIDC grant. This change makes the existing CI validation job a reusable prerequisite, installs and verifies both final distributions outside the checkout, and transfers those checked files to a separate publishing job.
Scope follows Imran's ruling in .github #54. The existing
ci.ymljob is namedvalidate; all its validation is reused. Its two named append-only/base-SHA steps are explicitly skipped for release/manual events, preserving push/PR behavior. Build and publication require successful validation; failed, cancelled or skipped dependencies block them. Manual dispatch remains build-only by default, and the existing exact ref/tag/package/runtime-version guard is retained. Only the publishing job hasenvironment: pypiandid-token: write.The artifact check confirms installed metadata/runtime/CLI versions, import origin in the clean environment, valid signed inclusion, and rejection of a changed Merkle root with a still-valid signature. Wheel and sdist are installed separately. Build backends use existing hash-locked CI dependencies with build isolation disabled for these artifact builds; new transfer actions are commit-pinned. The publishing job downloads the same named artifact and does not rebuild it.
Validation at base
a1466d280f30df31b2b359d6cd54592da7b6b967, Python 3.12.14:git diff --checkpassed.Local dependency installation used the repository's hash-locked CI/witness/runtime/publish files. No publishing workflow was dispatched, settings changed or package uploaded. Remote CI and independent maintainer review remain pending. Environment protections, trusted-publisher bindings and primary/backup operators remain separate #54 work; this PR does not close the organization-wide audit.
Review owner: Imran Siddique, as confirmed in the ruling. DCO sign-off is included.