fix(release): verify branch checks with workflow read access - #125
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The first publication attempt stopped before any tag or release because
GITHUB_TOKENcannot read the administration-only classic branch-protection endpoint. The verifier now reads classic check requirements from the existing content-readable branch protection summary and combines them with effective ruleset requirements.Missing or malformed policy still refuses publication. Required check application identity, exact source/CI, human environment review and immutable tag/asset checks are preserved. The verifier also reads every effective rule page, so a check on a later page cannot be omitted. No token scope or repository protection changes are required.
Validation: 15 prerelease regression controls pass, including combined and classic-only policy, wrong app/commit, failed checks, missing metadata and absent requirements. The API fixture rejects any administration-endpoint call. Full typecheck, quality/privacy and changed-script/test lint pass. Hosted publication remains to be verified after merge; no tag or release was created by the failed run.