.just/prerelease_tag.py duplicates two values that release/publish-artifacts.toml already owns, and one of the copies is already wrong.
Found by two independent reviewers plus schema-reviewer during the qa-scpublish-r3 pass on #1367 (report: #1367 (comment)). Filed as ARCH-001 and RBQA-A003 there; they are the same defect class in the same file, so one manifest-driven fix closes both. Pre-existing — the file was last touched at an unrelated commit — and out of scope for #1367, which is why it is an issue rather than a finding on that PR.
1. Hardcoded tag prefix
prerelease_tag.py builds the tag as a Python literal rather than reading [prerelease].tag_prefix from release/publish-artifacts.toml. PR #1367 removed exactly this duplication from .claude/skills/daemon-switch/scripts/release_resolution.py (finding PRERELEASE-DUP-1), so after that PR merges the repository has one manifest-bound reader and one literal copy of the same value.
2. Hardcoded protected branches, already diverged
prerelease_tag.py carries its own protected-branch set of {"develop", "main"}. The manifest declares three: develop, main, master. So the script's copy is already missing master, and the gap is reachable: just prerelease-tag invokes this script directly and does not go through prerelease.py's gate, which is the reader that was made manifest-declared by RBQA-A002 in the same PR.
The practical consequence is that a prerelease-tag run on a master branch is refused by one path and permitted by the other.
Fix
Make prerelease_tag.py read both tag_prefix and the protected-branch list from release/publish-artifacts.toml, matching what release_resolution.py and prerelease.py do after #1367. Add a test that feeds a divergent manifest and asserts the script's behaviour follows the manifest, the way arch-qa verified the release_resolution.py binding — deleting the constants without a live-binding test would leave the same class of defect undetectable.
Neither gap gates any current work: prerelease/v1.5.12, prerelease/v1.5.13 and the upcoming prerelease/v1.5.14 are all cut from non-protected release branches with the standard prefix.
.just/prerelease_tag.pyduplicates two values thatrelease/publish-artifacts.tomlalready owns, and one of the copies is already wrong.Found by two independent reviewers plus
schema-reviewerduring theqa-scpublish-r3pass on #1367 (report: #1367 (comment)). Filed as ARCH-001 and RBQA-A003 there; they are the same defect class in the same file, so one manifest-driven fix closes both. Pre-existing — the file was last touched at an unrelated commit — and out of scope for #1367, which is why it is an issue rather than a finding on that PR.1. Hardcoded tag prefix
prerelease_tag.pybuilds the tag as a Python literal rather than reading[prerelease].tag_prefixfromrelease/publish-artifacts.toml. PR #1367 removed exactly this duplication from.claude/skills/daemon-switch/scripts/release_resolution.py(finding PRERELEASE-DUP-1), so after that PR merges the repository has one manifest-bound reader and one literal copy of the same value.2. Hardcoded protected branches, already diverged
prerelease_tag.pycarries its own protected-branch set of{"develop", "main"}. The manifest declares three:develop,main,master. So the script's copy is already missingmaster, and the gap is reachable:just prerelease-taginvokes this script directly and does not go throughprerelease.py's gate, which is the reader that was made manifest-declared by RBQA-A002 in the same PR.The practical consequence is that a
prerelease-tagrun on amasterbranch is refused by one path and permitted by the other.Fix
Make
prerelease_tag.pyread bothtag_prefixand the protected-branch list fromrelease/publish-artifacts.toml, matching whatrelease_resolution.pyandprerelease.pydo after #1367. Add a test that feeds a divergent manifest and asserts the script's behaviour follows the manifest, the wayarch-qaverified therelease_resolution.pybinding — deleting the constants without a live-binding test would leave the same class of defect undetectable.Neither gap gates any current work:
prerelease/v1.5.12,prerelease/v1.5.13and the upcomingprerelease/v1.5.14are all cut from non-protected release branches with the standard prefix.