ci: refresh release tools and restore Crabbox capacity - #61
Conversation
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: needs maintainer review before merge. Reviewed September 22, 2026, 8:20 AM ET / 12:20 UTC (Revision 2). ClawSweeper reviewWhat this changesThe PR increases Crabbox’s root disk to 400 GB and updates release and documentation tools alongside their validation fixtures. Merge readiness✅ Ready for maintainer review The PR remains useful: main still has the older pins and disk size. No actionable defect was found, and the exact-head macOS audit—including release contracts and snapshot reproducibility—passed. Priority: P2 Review scores
Verification
How this fits togetherCrabbox provides remote validation capacity, while CI and the local release producer turn repository source into checked release artifacts. These changes update their capacity and tool requirements without changing the CLI. flowchart LR
A[Repository source] --> B[Crabbox validation]
C[400 GB root disk] --> B
A --> D[CI checks]
E[Pinned release tools] --> D
E --> F[Local release producer]
A --> F
D --> G[Validated build artifacts]
F --> G
Before mergeNone. Agent review detailsSecurityNone. Review metrics
Technical reviewBest possible solution: Keep the coordinated tool pins and validation fixtures aligned while retaining the existing credential-free CI and local release safeguards. Do we have a high-confidence way to reproduce the issue? Not applicable to the tool refresh; the reported Crabbox capacity failure was not independently reproduced during this read-only review. Is this the best way to solve the issue? Yes. Updating the existing pins and fixtures is a focused solution, and the exact-head audit verifies their integration without introducing a parallel release path. AGENTS.md: not found in the target repository. Codex review notes: model internal, reasoning medium; reviewed against 415ff611d515. LabelsLabel changes: No label changes. Label justifications:
EvidenceWhat I checked:
Likely related people:
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
HistoryReview history (1 earlier review cycle)
|
Crabbox warmup failed because the configured 160 GB root disk is smaller than the current image snapshot. Raise it to the required 400 GB so the remote validation environment can start again.
Refresh GoReleaser to 2.18.2 and the reviewed GitHub CLI release-producer pin to 2.101.0. Use Node 26.10.0 for documentation CI and Homebrew’s currently available 26.9.0 for the canonical release producer. Update the matching release contract fixtures and checks without changing application behavior or the Go floor.
Validation: AWS Crabbox passed the documented build, lint, tests, coverage (92.4%), race tests, vet, Node 26.10.0 documentation tests and generated metadata check, and govulncheck (no vulnerabilities). The lease used explicit checksum-verified toolchain setup because the local Actions interpreter does not support setup-go’s cache option. A fresh checkout of the exact PR head also passed actionlint, deadcode, gosec, GoReleaser configuration and six-target snapshot builds, all six binary vulnerability scans, and isolated byte-for-byte reproducibility checks on Crabbox. macOS release-contract validation remains gated by exact-head CI. Independent Codex autoreview found no actionable P0–P2 findings.