Repository navigation
docs(spec): restore nested-group Maven publication - #37857
Conversation
|
Claude finished @wezell's task in 35s —— View job ReviewTask list
This PR adds a single Spec-Kit document ( New IssuesNo issues found. The spec reads cleanly and is internally consistent:
A couple of observations, neither blocking:
The companion implementation lives in #37855; its actual Bash publisher changes and the offline regression tests are where the correctness review matters and should be done against that PR's diff. |
|
dotbot code review:
Spec-only addition with no executable code; no flag-worthy defect introduced by this patch. Deferred fail-closed scan handling is explicitly documented scope with compensating control. Tip: comment with "/dotbot address comments" to attempt automated fixes for unresolved review threads. reviewed by dotbot · meta/muse-spark-1.3 · medium |
|
dotbot code review:
The PR adds only a documentation spec file describing the Maven nested-group publishing hotfix contract; it contains no executable code, build config, or credentials. The spec is internally consistent and explicitly documents deferred fail-closed scan handling with compensating controls, so there is no flag-worthy defect. Tip: comment with "/dotbot address comments" to attempt automated fixes for unresolved review threads. reviewed by dotbot · ~z-ai/glm-latest · medium |
dotCMS-Machine-User
left a comment
There was a problem hiding this comment.
✅ dotbot review: all reviewer models (meta/muse-spark-1.3, ~z-ai/glm-latest) agree — patch is correct.
approved automatically by dotbot
Defect specification
Refs #37854. Implementation: #37855.
This spec-only PR records the intended repair contract for the customer-blocking Maven publishing regression. The developer explicitly approved the documented hotfix route: implementation first, followed by the defect spec as its own PR.
The contract covers recursive nested-group discovery, preserved Maven paths, actual metadata group IDs, checksums, module filtering, and regression coverage. Live recovery is separately authorized to copy exact original GitHub release-run build artifacts; no JAR regeneration or relabeling older releases.
Directory-scan error hardening is explicitly deferred from this narrow hotfix. No implementation, plans, tasks, credentials, or binary artifacts are included in this PR.
The original release files have been copied for all seven affected published releases. Public CDN SHA-256/sidecar/metadata verification passed, and a cold consumer resolution against core
26.09.28-02throughrepo.dotcms.compassed with checksum policyfail. Detailed provenance and operational evidence are being recorded on #37854.This PR fixes: #37854