Skip to content

feat(release): prepare reviewed Rust crate artifacts - #44

Merged
zoeyrose merged 4 commits into
mainfrom
feat/crate-trusted-publishing
Oct 4, 2026
Merged

zoeyrose merged 4 commits into
mainfrom
feat/crate-trusted-publishing

Conversation

@zoeyrose

@zoeyrose zoeyrose commented Oct 4, 2026 •

Copy link
Copy Markdown
Member

Summary

Prepare the unpublished Rust 0.2.0 crate for a separately reviewed registry activation, and fix the release download layout exposed by v2.6.0.

The published v2.6.0 assets remain unchanged. Its 33 downloaded assets match their GitHub digests and all 32 flat checksum entries pass, but its checksum manifest also names 30 nested fixtures absent from the GitHub asset list. Those fixtures are present in the source archive.

Implementation / behavior

  • Produce a deterministic contract bundle containing the full contract layout, nested fixtures and internal checksums. Keep the outer release directory flat, with every downloadable asset covered by the outer checksum manifest.
  • Prepare Cargo source for crates.io while keeping the candidate explicitly unpublished. Preserve the immutable published 0.1.0 release coordinates and checksum.
  • Add a manual preparation-only workflow. It has no OIDC permission, registry credentials or upload job. The pending artifact policy contains no predicted source revision or digest.
  • Validate an actual published tag and exact source revision against local/public Git identity and release provenance; package twice with Rust 1.97.1; check identical bytes, package inventory, clean VCS metadata and registry-only dependencies.
  • Emit the actual crate and artifact pins for the next review. The verifier also provides credential-free checks for later pinned release assets and public API/sparse-index checksums; it never uploads.

Validation

At fec06675d996c41e2802a3c8e71d6239733773b2:

  • Full tools/validate.sh passed in the pinned Atrinik Linux build image sha256:7904a1802054662b0ede5b55de72e4c92b0112a3c211125f994ed6c62e9ec9d8, with Go 1.26.6 and Rust 1.97.1.
  • Workflow actionlint, shell lint and full-base whitespace checks passed. The full aggregate also passed with the pull-request CI environment variables set.
  • Tests cover flat publish-glob discovery, complete outer/internal checksum inventories, omitted/tampered files, redirected fixture roots, disabled activation, malformed artifact pins, source-tag drift, crate provenance/dependency boundaries and registry checksum conflicts.
  • Independent review approved the implementation and the final test-only CI-environment correction. Required GitHub checks Protocol validation and Conventional PR title passed on this exact head and accepted base.

Limitations / follow-up

This is the preparation source change, not registry activation. v2.6.0 still has Cargo publication disabled and cannot supply publishable bytes without changing them. Actual released-tag preparation therefore follows a separately approved source merge/release and manual preparation dispatch.

The next activation PR must use the real prepared source release, revision, asset and checksum, and add the reviewed Trusted Publishing upload job. Exact release-asset attachment, environment/Trusted Publisher setup and publication dispatch each retain their authorization boundary. Governance preparation is tracked in atrinik/github-settings#86; access-token consumer coordination remains in #43.

No release asset, environment, registry configuration or package was changed. No merge, dispatch or publication is authorized by this PR. Consumers still need the actual registry release and normal dependency-lock validation.

@zoeyrose
zoeyrose marked this pull request as ready for review October 4, 2026 17:21
@zoeyrose

zoeyrose commented Oct 4, 2026

Copy link
Copy Markdown
Member Author

@codex review

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-04T17:29:09.853077Z fec0667 Manual request
🔒 Security Review ✅ Completed 2026-10-04T17:29:46.265200Z fec0667 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. 👍

Reviewed commit: fec06675d9

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review · Automatically triggered

Security review completed. No security issues were found in this pull request.

Reviewed commit: fec06675d9

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@zoeyrose
zoeyrose merged commit 5a1c441 into main Oct 4, 2026
9 checks passed
@zoeyrose
zoeyrose deleted the feat/crate-trusted-publishing branch October 4, 2026 17:40
@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown

🎉 This PR is included in version 2.7.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant