Skip to content

fix(ci): gate registry releases on validation and installed artifacts - #123

Merged
imran-siddique merged 1 commit into
agentrust-io:mainfrom
dinakarjs:fix/release-validation-artifact-gates
Oct 6, 2026
Merged

imran-siddique merged 1 commit into
agentrust-io:mainfrom
dinakarjs:fix/release-validation-artifact-gates

Conversation

@dinakarjs

Copy link
Copy Markdown
Contributor

The publisher previously had no release-revision CI dependency or installed-artifact verification, and its build-only job held the PyPI environment and OIDC grant. This change makes the existing CI validation job a reusable prerequisite, installs and verifies both final distributions outside the checkout, and transfers those checked files to a separate publishing job.

Scope follows Imran's ruling in .github #54. The existing ci.yml job is named validate; all its validation is reused. Its two named append-only/base-SHA steps are explicitly skipped for release/manual events, preserving push/PR behavior. Build and publication require successful validation; failed, cancelled or skipped dependencies block them. Manual dispatch remains build-only by default, and the existing exact ref/tag/package/runtime-version guard is retained. Only the publishing job has environment: pypi and id-token: write.

The artifact check confirms installed metadata/runtime/CLI versions, import origin in the clean environment, valid signed inclusion, and rejection of a changed Merkle root with a still-valid signature. Wheel and sdist are installed separately. Build backends use existing hash-locked CI dependencies with build isolation disabled for these artifact builds; new transfer actions are commit-pinned. The publishing job downloads the same named artifact and does not rebuild it.

Validation at base a1466d280f30df31b2b359d6cd54592da7b6b967, Python 3.12.14:

  • 395 unittest tests passed; after the final version-generic test cleanup, the 11 safeguard tests passed again.
  • Ruff, actionlint 1.7.12 and git diff --check passed.
  • Wheel/sdist build and Twine checks passed; the actual installed-artifact workflow shell block passed for both artifacts in separate clean environments outside the checkout.
  • All seven remaining non-install CI validation shell blocks passed, including CLI/witness smoke checks, schema/producer validation, whole checkpoint chain, staged-record dry run, sample anchor round trip and required files.
  • Executed weakening checks are caught: removing validation dependency, allowing build-only publication, and removing runtime/package version agreement. Always-accept and always-reject CLI checks also fail on the appropriate paired case.

Local dependency installation used the repository's hash-locked CI/witness/runtime/publish files. No publishing workflow was dispatched, settings changed or package uploaded. Remote CI and independent maintainer review remain pending. Environment protections, trusted-publisher bindings and primary/backup operators remain separate #54 work; this PR does not close the organization-wide audit.

Review owner: Imran Siddique, as confirmed in the ruling. DCO sign-off is included.

Implement the trace-registry scope approved in agentrust-io/.github#54.

Signed-off-by: Srinivasa Dinakar <dinakarjs@gmail.com>
@dinakarjs
dinakarjs requested a review from a team as a code owner October 6, 2026 08:05

@imran-siddique imran-siddique left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed bd88d7a against the approved scope in agentrust-io/.github#54. Release/manual builds depend on the existing CI validation job; only the named append-only comparison steps are skipped without a push/PR base. Publication requires successful validation and artifact checks, retains the exact tag/package/runtime guard, and downloads the checked distributions without rebuilding. Build-only execution has neither the PyPI environment nor OIDC write permission.

Validation: all 11 release-safeguard tests passed locally against this checkout, including the real CLI accepting the signed control and refusing a changed anchor while preserving signature validity. Inspected CI job 112170695500: 395 tests passed; workflow lint and CodeQL are green. The Linux clean-environment wheel/sdist workflow was inspected but not executed locally on Windows. No publishing workflow or environment settings were changed.

@imran-siddique
imran-siddique merged commit ba566ed into agentrust-io:main Oct 6, 2026
7 of 8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants