Skip to content

release: add fail-closed coordinated draft packaging - #18

Merged
ruizkinio merged 1 commit into
mainfrom
release/package-v3-20260813
Aug 13, 2026
Merged

release: add fail-closed coordinated draft packaging#18
ruizkinio merged 1 commit into
mainfrom
release/package-v3-20260813

Conversation

@ruizkinio

Copy link
Copy Markdown
Owner

Summary

  • lock the exact seven-asset Kodi draft inventory and verify hashes, metadata, SBOMs, and provenance before packaging
  • add a manual split-authority workflow that runs full readiness, creates an exact annotated tag, re-audits public history, and creates only a private root draft
  • reject stale commits, unfinished notes, mutable UAT references, foreign tags/releases/assets, altered draft bodies, and ambiguous retries

Safety boundary

  • no automatic publication, deletion, overwrite, cleanup, or release replacement
  • read-only Kodi source token never reaches root write jobs
  • root write jobs never receive cross-repository source authority
  • current draft notes and missing physical UAT intentionally make check-inputs refuse

Verification

  • npm test (38/38)
  • node --check release/package-release.mjs
  • actionlint 1.7.7 on both workflows
  • real read-only prepare against Kodi draft 369936173, including all seven SHA-256 values and six-subject provenance
  • staged secret-shape scan: no findings

@ruizkinio
ruizkinio merged commit e2cf840 into main Aug 13, 2026
4 checks passed
@ruizkinio
ruizkinio deleted the release/package-v3-20260813 branch August 13, 2026 14:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant