Skip to content

Restore registry-sync so the catalog is rebuilt and signed again - #235

Merged
HereLiesAz merged 2 commits into
mainfrom
claude/amazing-fermi-3o92qn-stale-catalog
Sep 27, 2026
Merged

HereLiesAz merged 2 commits into
mainfrom
claude/amazing-fermi-3o92qn-stale-catalog

Conversation

@HereLiesAz

@HereLiesAz HereLiesAz commented Sep 27, 2026 •

Copy link
Copy Markdown
Owner

Why

build-catalog --check fails for com.azphalt.example.hello-lut, com.hereliesaz.guillotine.cool-noir and com.hereliesaz.guillotine.teal-orange.

  • Cause: Fix glee-audit findings: billing, fee-math drift, dead search, stale versions, doc rot #214 removed their capabilities (asset packages declare none) but nothing rebuilt them, because .github/workflows/registry-sync.yml left the repo on 2026-09-22. The workflows sync then marked its executor obsolete.
  • Why not rebuild locally: the committed copies are signed. Rebuilding them here without the signing key would strip the publisher signature, and hosts that pinned that key would reject the update. So the fix is to bring back the workflow that holds the key, not to commit an unsigned rebuild.

What

  • .github/workflows/registry-sync.yml is restored from the registered source (registry/1296954472/registry-sync-9340fed1.source.yml in HereLiesAz/workflows). Only two things changed:
    • pnpm/action-setup no longer pins 9.15.0. It reads packageManager (pnpm 12), and naming both makes the action refuse to run.
    • The actions now use the majors the rest of the repo uses: checkout v7, setup-node v7, pnpm/action-setup v6.
  • docs/OPERATIONS.md gets a new section, "Rebuilding and signing the catalog": what triggers the workflow, where it runs, the signing secret it needs, and a rule never to commit an unsigned rebuild of a signed package.

After merging (user-side)

  1. Run Sync repository in HereLiesAz/workflows for azphalt. The path is still in azphalt's manifest, so the sync admits it, recompiles the repository-scoped executor (azphalt-registry-sync.yml, which is still grandfathered), and replaces this file with a tracker.
  2. In HereLiesAz/workflows → Settings → Environments → azphalt, set AZPHALT_PACKAGE_SIGNING_KEY (and optionally AZPHALT_PACKAGE_SIGNING_KEY_ID).
  3. Run the workflow in pinned mode. It rebuilds the three stale packages signed and opens the catalog PR.

Verification

  • The YAML parses, and the restored file differs from the registered source only in the lines above.
  • I confirmed the three packages' only content change is the removed capabilities, plus the dropped signature.json a local unsigned rebuild would produce. I left the committed bytes untouched.

🤖 Generated with Claude Code

https://claude.ai/code/session_01QwYWVPse8spRrfMMcuTJPv


Generated by Claude Code

Summary by Sourcery

Restore automated, signed catalog synchronization and document the operational requirements for safely publishing rebuilt packages.

New Features:

  • Restore the registry synchronization workflow to rebuild the committed catalog, regenerate previews, and open a reviewable PR for catalog changes.

Bug Fixes:

  • Restore automated rebuilding and signing of stale packages so publisher signatures and catalog consistency are preserved.

Enhancements:

  • Support pinned and latest synchronization modes across manual, scheduled, dispatch, and repository-change triggers.
  • Document catalog rebuild triggers, signing requirements, and the prohibition against committing unsigned replacements for signed packages.

CI:

  • Align the workflow's GitHub Actions and pnpm setup with the repository's current toolchain.

Documentation:

  • Add operational guidance for rebuilding and signing the catalog.

The file left the repo on 2026-09-22 and the sync marked its executor
obsolete, so nothing has rebuilt or signed the catalog since. Three
submissions changed after that and are stale in the committed catalog.
Restored as it was, except pnpm now comes from packageManager and the
actions use the majors the rest of the repo uses. Documents the signing
secret it needs.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QwYWVPse8spRrfMMcuTJPv
@vercel

vercel Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
azphalt Building Building Preview Sep 27, 2026 10:20pm UTC

@sourcery-ai

sourcery-ai Bot commented Sep 27, 2026

Copy link
Copy Markdown

Reviewer's Guide

Restores the registry-sync automation with current action versions and signing-secret support, allowing stale catalog packages to be rebuilt and reviewed without committing unsigned artifacts; adds operational guidance for running and securing the process.

Sequence diagram for signed registry catalog synchronization

sequenceDiagram
    participant Trigger
    participant Workflow as registry-sync.yml
    participant Build as build-catalog
    participant Signing as SigningSecret
    participant GitHub as GitHubPR
    participant Deploy as deploy-storefront

    Trigger->>Workflow: Trigger sync
    Workflow->>Workflow: Decide pinned or latest mode
    Workflow->>Build: build-catalog --update [--latest]
    Signing-->>Build: AZPHALT_PACKAGE_SIGNING_KEY
    Build-->>Workflow: Rebuild signed packages and catalog
    Workflow->>Workflow: build-previews
    Workflow->>GitHub: Open draft catalog PR
    GitHub-->>Deploy: Merge catalog PR
    Deploy->>Deploy: Rebuild and redeploy storefront
Loading

Flow diagram for registry sync modes and triggers

flowchart TD
    A[Sync trigger] --> B{Trigger type}
    B -->|sources.json or submissions push| C[pinned mode]
    B -->|schedule or extension-updated dispatch| D[latest mode]
    B -->|manual workflow run| E{Selected mode}
    E -->|pinned| C
    E -->|latest| D
    C --> F[Rebuild catalog with pinned refs]
    D --> G[Re-pin sources, then rebuild catalog]
    F --> H[Regenerate previews]
    G --> H
    H --> I{Registry changed?}
    I -->|yes| J[Commit branch and open catalog PR]
    I -->|no| K[Exit without PR]
Loading

File-Level Changes

Change Details Files
Restore the registry synchronization workflow so catalog packages can be rebuilt from pinned or latest sources, signed, and published through a reviewed PR.
  • Add repository-dispatch, scheduled, source-change, submission-change, and manual triggers with pinned/latest mode selection.
  • Install and build required workspace dependencies before running catalog and preview generation.
  • Inject package-signing secrets into catalog builds and regenerate previews from rebuilt packages.
  • Create a branch and draft PR only when the registry changes, with summaries of package and lockfile changes; tolerate PR-creation permission failures.
.github/workflows/registry-sync.yml
Document the operational process and signing requirements for catalog rebuilds.
  • Describe workflow triggers, execution environment, signing secrets, and manual modes.
  • Warn against committing unsigned replacements for packages with publisher signatures.
docs/OPERATIONS.md

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

🚀 Deploying Preview to Cloudflare 🚀

Preview Deployments by commit

Status Deployment URL Commit Updated (UTC) See this deployment's details
  • Build: Failed ❌

View logs ↗
4b45690 2026-09-27T21:34:02.460Z View logs ↗

@HereLiesAz

Copy link
Copy Markdown
Owner Author

OpenCode security review

⚠️ Review unavailable. Neither model answered; see the shared workflow run. This is not a finding about the pull request.

@HereLiesAz
HereLiesAz marked this pull request as ready for review September 27, 2026 22:20

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @HereLiesAz, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 23 hours and 6 minutes by commenting @sourcery-ai review. Upgrade to get a review now.

@HereLiesAz
HereLiesAz merged commit a2a81f6 into main Sep 27, 2026
5 of 7 checks passed
@HereLiesAz
HereLiesAz deleted the claude/amazing-fermi-3o92qn-stale-catalog branch September 27, 2026 22:20

This branch had an error being deployed

1 failed deployment
Preview — 3484586a Deployed Sep 27, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants