Skip to content

fix(release): verify branch checks with workflow read access - #125

Merged
roodboi merged 2 commits into
nextfrom
codex/prerelease-check-policy-read
Oct 3, 2026
Merged

roodboi merged 2 commits into
nextfrom
codex/prerelease-check-policy-read

Conversation

@roodboi

@roodboi roodboi commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

The first publication attempt stopped before any tag or release because GITHUB_TOKEN cannot read the administration-only classic branch-protection endpoint. The verifier now reads classic check requirements from the existing content-readable branch protection summary and combines them with effective ruleset requirements.

Missing or malformed policy still refuses publication. Required check application identity, exact source/CI, human environment review and immutable tag/asset checks are preserved. The verifier also reads every effective rule page, so a check on a later page cannot be omitted. No token scope or repository protection changes are required.

Validation: 15 prerelease regression controls pass, including combined and classic-only policy, wrong app/commit, failed checks, missing metadata and absent requirements. The API fixture rejects any administration-endpoint call. Full typecheck, quality/privacy and changed-script/test lint pass. Hosted publication remains to be verified after merge; no tag or release was created by the failed run.

@roodboi
roodboi merged commit 3bb8ec1 into next Oct 3, 2026
10 checks passed
@roodboi
roodboi deleted the codex/prerelease-check-policy-read branch October 3, 2026 04:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant