Part of the CI overhaul execution plan (#59, map #53). Order: 5 of 9 — must land before 6/9 removes the fast workflows' push-to-main triggers, or the poll starts failing every release.
Decision: #58.
Scope
The release workflow trusts branch protection and verifies nothing at runtime. Delete the "Require ordinary push gates for the same commit" step in release.yml (the gh run list poll over ci.yml/docs.yml) with no substitute — no wait loop, no recheck, no commit-to-PR mapping. The main ruleset (PRs required, strict up-to-date checks, zero bypass actors) is the authorization that every main SHA passed the fast set. Everything else in the trust chain is already in place: workflow_run trigger gated to event == push && head_branch == main, artifact download pinned to the triggering run id, and publish-verified-candidate.mjs re-asserting sha256/byte-length/sourceCommit.
Files
.github/workflows/release.yml — delete the poll step (currently ~lines 35–49 in the mode job).
docs/adr/0010-release-documentation-and-contribution-lifecycle.md — append a short amendment: fast-check authorization moved from runtime re-verification to the main ruleset; the sha256-pinned tarball chain is the only runtime verification.
Ruleset / required-check changes
None in this task (the ruleset already enforces what the poll re-checked). The required-check list itself changes in 6/9.
Acceptance criteria
release.yml contains no gh run list invocation; the mode job goes straight from setup to select-release-mode.mjs.
- ADR 0010 amendment appended.
- The next candidate success on main triggers a release run whose
mode job completes.
Part of the CI overhaul execution plan (#59, map #53). Order: 5 of 9 — must land before 6/9 removes the fast workflows' push-to-main triggers, or the poll starts failing every release.
Decision: #58.
Scope
The release workflow trusts branch protection and verifies nothing at runtime. Delete the "Require ordinary push gates for the same commit" step in
release.yml(thegh run listpoll over ci.yml/docs.yml) with no substitute — no wait loop, no recheck, no commit-to-PR mapping. Themainruleset (PRs required, strict up-to-date checks, zero bypass actors) is the authorization that every main SHA passed the fast set. Everything else in the trust chain is already in place:workflow_runtrigger gated toevent == push && head_branch == main, artifact download pinned to the triggering run id, andpublish-verified-candidate.mjsre-asserting sha256/byte-length/sourceCommit.Files
.github/workflows/release.yml— delete the poll step (currently ~lines 35–49 in themodejob).docs/adr/0010-release-documentation-and-contribution-lifecycle.md— append a short amendment: fast-check authorization moved from runtime re-verification to the main ruleset; the sha256-pinned tarball chain is the only runtime verification.Ruleset / required-check changes
None in this task (the ruleset already enforces what the poll re-checked). The required-check list itself changes in 6/9.
Acceptance criteria
release.ymlcontains nogh run listinvocation; themodejob goes straight from setup toselect-release-mode.mjs.modejob completes.