Skip to content

chore(ci): refresh build pins and strengthen portable checks - #52

Merged
steipete merged 1 commit into
mainfrom
chore/phase-five-ci
Sep 13, 2026
Merged

steipete merged 1 commit into
mainfrom
chore/phase-five-ci

Conversation

@steipete

@steipete steipete commented Sep 13, 2026 •

Copy link
Copy Markdown
Collaborator

Refresh the existing Go 1.26 release line to 1.26.8 for upstream compiler/runtime fixes, with matching producer, verifier, archive hashes, and rejection fixtures. Update GoReleaser to 2.18.1, Node to 26.8.2, deadcode to 0.50.0, and govulncheck to 1.8.0, including its reviewed module checksum. Kong 1.16.1 and golangci-lint 2.13.2 are already current. The application version stays unchanged.

Pin every external Action to its stable release commit. Keep full CI for PRs and main while avoiding duplicate branch-push audits. CI now uses the installed linter, checks formatting without rewriting files, runs Node metadata tests and checks generated docs, and exercises macOS race tests plus Windows race tests on Go 1.27.1. Staticcheck remains enabled through golangci-lint; the duplicate standalone invocation is removed. The coverage threshold, all release/security contract tests, source/binary vulnerability scans, and six-platform reproducibility gates are retained.

Release-age evidence: Go 1.26.8 (September 1), GoReleaser 2.18.1 (September 5), Node 26.8.2 (September 9), and x/tools 0.50.0 / x/vuln 1.8.0 (September 8, official Go module proxy metadata) all exceed 48 hours. Action tags were resolved through the official repositories; existing create-github-app-token was already current and pinned. Setup-node is added to run the existing metadata tests on the reviewed Node version.

Validation: isolated Codex autoreview is scoped-clean at P0–P2 after correcting stale negative fixtures. Go 1.26.8 race tests, 91.5% coverage, lint, actionlint, deadcode, source govulncheck, Node metadata tests, and all four release/security contract suites pass. A deliberately unformatted temporary source produces exit 1 from the new formatting check without changing the file.

Built-binary proof: the Go 1.26.8 CLI passes the same 21 synthetic HTTP cases as the baseline (all eight commands, human/JSON output, help/version and validation); captured requests/output/exit-code records remain byte-identical, SHA-256 043a9aa35c7e9a159a75b42afed4e4d56bf606646ee1352e3a22e8af3185eefe. GoReleaser builds all six platform binaries locally. Clean-checkout provenance, binary vulnerability scans and reproducibility are also required in exact-head CI before merge. No release, tag, signing or publication is performed.

Clean-checkout proof at a2acf7f also passes locally: SNAPSHOT_REQUIRE_CLEAN=1 ./scripts/verify-snapshot-security.sh accepts the exact six-binary inventory, Git revision and clean-source metadata; govulncheck reports no vulnerabilities for all six. ./scripts/test-reproducible-builds.sh dist reports “exact six-target byte comparison passed” after independent rebuilds. A standalone checkout is used because this Go toolchain omits VCS metadata for linked worktrees.

@steipete
steipete requested a review from a team as a code owner September 13, 2026 02:51
@clawsweeper

clawsweeper Bot commented Sep 13, 2026 •

Copy link
Copy Markdown
Contributor

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@clawsweeper clawsweeper Bot added P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. merge-risk: 🚨 compatibility 🚨 Merging this PR could break existing users, config, migrations, defaults, or upgrades. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. labels Sep 13, 2026
@clawsweeper

clawsweeper Bot commented Sep 13, 2026

Copy link
Copy Markdown
Contributor

Codex review: blocked before merge. Reviewed September 12, 2026, 10:57 PM ET / September 13, 2026, 02:57 UTC.

ClawSweeper review

What this changes

Updates build and release toolchain pins, pins GitHub Actions to commits, and adds non-mutating formatting, documentation metadata, and cross-platform race checks.

Merge readiness

⛔ Blocked before merge - 1 item remains

This remains useful work: main and v0.4.9 still require Go 1.26.7, and no replacement PR owns this refresh. No actionable introduced defect was found. The collaborator-authored PR should remain open for normal merge handling.

Priority: P3
Reviewed head: a2acf7fb415a47d8017ad0c19fcf51cf2456c8dd

Review scores

Measure Result What it means
Overall readiness 🐚 platinum hermit (4/6) A coherent toolchain refresh with consistent fixtures, useful reported binary validation, and no actionable correctness finding.
Proof confidence 🐚 platinum hermit (4/6) Not applicable: The ordinary contributor proof gate is exempt for this collaborator-authored PR. The captured body nevertheless reports built-CLI compatibility and six-target snapshot/reproducibility results; inspected workflow steps corroborate the build and verification path.
Patch quality 🐚 platinum hermit (4/6) No actionable review findings were identified.

Verification

Check Result Evidence
Real behavior Not applicable Not applicable: The ordinary contributor proof gate is exempt for this collaborator-authored PR. The captured body nevertheless reports built-CLI compatibility and six-target snapshot/reproducibility results; inspected workflow steps corroborate the build and verification path.
Evidence reviewed 11 items Policy and patch scope: The verified origin is openclaw/goplaces. No root or nested AGENTS.md or maintainer-notes files were found. The complete introduced delta was inspected locally; it changes 21 files without changing application Go source.
Current main still needs the refresh: The fetched main revision declares Go 1.26.7. Its CI lacks the newly introduced Windows job and documentation metadata checks.
Release and competing work: The v0.4.9 go.mod also declares Go 1.26.7. The live open-PR listing returned only this PR, so no open replacement was identified.
Findings None None.
Security None None.

How this fits together

goplaces provides a Go library and CLI for Google Places and Routes. Its build automation turns source into tested, vulnerability-scanned binaries, while separate release tooling verifies provenance before publication.

flowchart TD
  A[Source changes] --> B[Linux and Windows checks]
  A --> C[macOS audit]
  D[Pinned build tools] --> B
  D --> C
  C --> E[Six platform binaries]
  E --> F[Vulnerability and reproducibility checks]
  F --> G[Separate gated release process]
Loading

Before merge

  • Resolve merge risk (P1) - Source builders using Go 1.26.7 and release workstations using the previous Go, Node, or GoReleaser versions must upgrade; the refreshed release gates intentionally reject those older tools.
Agent review details

Security

None.

Review metrics

Metric Value Why it matters
CI coverage 3 platform jobs; 6 binary targets retained Windows race coverage is added while existing cross-platform artifact verification remains active.

Merge-risk options

Maintainer options:

  1. Adopt the refreshed release toolchain (recommended)
    Accept the author-stated toolchain upgrade while retaining exact-version rejection and the existing release validation gates.

Technical review

Best possible solution:

Keep the coordinated producer/verifier refresh and its existing fail-closed release policy, with operators adopting the explicitly documented tool versions.

Do we have a high-confidence way to reproduce the issue?

Not applicable: this is a build-maintenance PR, and inspection identified no concrete introduced failure to reproduce.

Is this the best way to solve the issue?

Yes: updating producer and verifier pins together preserves the established release contract, and the new formatting check uses supported non-mutating behavior.

AGENTS.md: not found in the target repository.

Codex review notes: model internal, reasoning medium; reviewed against 7f230595529a.

Labels

Label changes:

  • add P3: This is build and CI maintenance without an established urgent user-facing regression.
  • add merge-risk: 🚨 compatibility: The minimum Go version and exact release-tool allowlist advance, requiring existing development and release environments to upgrade.
  • add rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🐚 platinum hermit and patch quality is 🐚 platinum hermit.
  • add status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Not applicable: The ordinary contributor proof gate is exempt for this collaborator-authored PR. The captured body nevertheless reports built-CLI compatibility and six-target snapshot/reproducibility results; inspected workflow steps corroborate the build and verification path.

Label justifications:

  • P3: This is build and CI maintenance without an established urgent user-facing regression.
  • merge-risk: 🚨 compatibility: The minimum Go version and exact release-tool allowlist advance, requiring existing development and release environments to upgrade.
  • rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🐚 platinum hermit and patch quality is 🐚 platinum hermit.
  • status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Not applicable: The ordinary contributor proof gate is exempt for this collaborator-authored PR. The captured body nevertheless reports built-CLI compatibility and six-target snapshot/reproducibility results; inspected workflow steps corroborate the build and verification path.

Evidence

What I checked:

  • Policy and patch scope: The verified origin is openclaw/goplaces. No root or nested AGENTS.md or maintainer-notes files were found. The complete introduced delta was inspected locally; it changes 21 files without changing application Go source. (a2acf7fb415a)
  • Current main still needs the refresh: The fetched main revision declares Go 1.26.7. Its CI lacks the newly introduced Windows job and documentation metadata checks. (go.mod:3, 7f230595529a)
  • Release and competing work: The v0.4.9 go.mod also declares Go 1.26.7. The live open-PR listing returned only this PR, so no open replacement was identified. (go.mod:3, 424df65ba142)
  • Preserved release protections: Producer, bootstrap, rebuild, source-recheck, snapshot verification, and release verification consistently require Go 1.26.8. Exact executable identity, source identity, credential isolation, and non-publishing snapshot checks remain in place. Rejection fixtures were updated, including a guard ensuring hostile scanner metadata actually differs from valid metadata. (scripts/release-local:1854, a2acf7fb415a)
  • Formatting dependency contract: Makefile's new lint-check target directly invokes golangci-lint v2.13.2. Its formatter sets exit code 1 when differences exist and returns before writing files; the command propagates that exit code. This supports the claimed non-mutating formatting gate. (pkg/goformat/runner.go, 27774aaf853a)
  • New Action identity: The newly added Node setup Action pin resolves exactly to the upstream v7.0.0 release tag. (820762786026)

Likely related people:

  • unknown: The claimed source-line change could not be verified from bounded local history. (role: source history unknown; confidence: low)
  • openclaw/openclaw-secops: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

@steipete
steipete merged commit d7a8361 into main Sep 13, 2026
13 checks passed
@vincentkoc
vincentkoc deleted the chore/phase-five-ci branch September 25, 2026 11:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

merge-risk: 🚨 compatibility 🚨 Merging this PR could break existing users, config, migrations, defaults, or upgrades. P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant