ci: gate release assets on version and package verification - #181
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Implements B2–B4 of the 1.0.0 release readiness plan:
scripts/smoke-installed-cli.mjs— installs a real tarball into a temp prefix (--ignore-scripts) and exercises both binaries (vault-inspector,vinspect) end to end: help, JSON scan schema/toolVersion, duplicate hash confirmation, baseline profile comparison (persisting/new/resolved), old-comparisonVersionbaseline → exit 2semantics-changed,--fail-on any→ exit 1, B1 invalid config → exit 2, and vault read-only verification. Wired asnpm run smoke:package.verifyjob now uploads the packed tarball; a newinstalled-climatrix job re-verifies that exact artifact on Node 18 and 24 (no build on 18). Branch ruleset now requiresverify,installed-cli (18), andinstalled-cli (24).scripts/check-release-version.mjskeeps package.json, lockfile root, manifest, versions.json mapping, andcli/version.tsconsistent (tag argument must match on release). The release workflow now checks out with full history, verifies tag/main ancestry, and reruns lint/build/coverage/pack plus the installed-package smoke on Node 24 and Node 18 before creating the release — tag releases no longer rely on a historical passing run.Validation
69db84bfailed at the invalid-config assertion (exit 1 instead of 2); GREEN on the current tree:Installed CLI smoke passed on v24.16.0(tarball integrity sha512-ZUDJfrOoJfh8…).node scripts/check-release-version.mjs 999.0.0exits nonzero; GREEN exits 0.