Dashboard › publish › Distillation
0c20c655-861f-4ae1-8cf0-aa5b0945eb95["lore_tm_v1_qQqJt--ge5b_JENVBnccH9z_kv5rv82bFxxUS7FnhXQ","lore_tm_v1_ftXMXMLrAP-uDx2d5fh9Kx5S6PwsHfhtF44pn33vZv0","lore_tm_v1_u0KRTa2K2PeGNahFs6d155LsXqKyQAxrpWZkPvOMBV0","lore_tm_v1_2qNyGE6Rnox8MWlR686FB7-yvThd8nB_tayCh0Xg80A","lore_tm_v1_PQn5pHbtTC4B6Gt055z6zOpAT_zqQVzgVKebMbcEnvU","lore_tm_v1_8u8FS_bPOHTxGQayHIh3aAfHfGjMAVNBAS0fQICf0hs","lore_tm_v1_5Ng1MCJA5fqJVP2G8vvBUnARURU6EAWT2k20NZATEiM","lore_tm_v1_XiqNK3U0fr69ST1pzHMfcgEjydhjp366NMkHqm1CIMM","lore_tm_v1_NahSDJlK9b8mAYqfy6IS1iimQRMKEcbZnS7k-qfGqUk","lore_tm_v1_setLGOjQOugTvBsLQKkMHIlhVcuTQBgXlBzPj6PlSlA","lore_tm_v1_kXO0blHk9YQmr-dafGPIePqTd97BOud3lXYkHb9U_s8","lore_tm_v1_9ZYj7rLXvutpBbtg8zokrAgqAW1fhbgxIl4RH_j8Ohw","lore_tm_v1_Nf5YYtznkdMyzEJ4bmyLR1jCPIB7WAx3WOPpHRtV3M0","lore_tm_v1_cwSCGtalmes-nGH3-_XDTXXXtTcbSZRGxQL486DeUjA","lore_tm_v1_NJe-qGq8xbm4slFaLSZrMGYb8s_JxAGdJaxhR30MHsk","lore_tm_v1_dKWe_eIDwgsq-gbUH_PUfO8M48AztLY-LMc4QkKqi74","lore_tm_v1_gIbSf1_uYwiwL8P49c8h9benrJaSy9uvIIQSUinF8E0","lore_tm_v1_7y7BceLlnI8jo_CrQDS2Ivn4glVKbrZhitAbvLRkI90","lore_tm_v1_X_PHjWtkoDezV9hj4mj65IQxgqFY02NnDGwunu4rRT8"]
Date: Sep 10, 2026
/home/byk/Code/getsentry/publish against base commit 7c60ddb7f43040fe8fbfea70efc833f689c04e75 (origin/main).ci-ready remove/revalidate/re-add; revision movement requiring reapproval; event-snapshot TOCTOU; publication setup/dependency/checkouts/location/workspace/state handoff; exact pre-Craft validation; consumed approvals; Craft success/failure/cancelled/skipped outcomes; label cleanup; target restoration; issue closing; comments/telemetry failures; and final dependency-free reconciliation.origin/main workspace-publish semantics and the generated parser.ci-ready event behavior.HEAD, tracked/staged diffs, and untracked paths plus contents, followed by verification that no mutation occurred.file:line evidence and each finding classified as MUST-FIX, CONCERN, or PASS.BLOCKED followed by the exact tool/error.MERGE or DO-NOT-MERGE.7c60ddb7f43040fe8fbfea70efc833f689c04e75; 2. inspect every changed and untracked file plus origin/main integration points and generated parser behavior; 3. trace correctness/lifecycle behavior and identify evidence-backed findings; 4. run read-only targeted/full checks and capture results; 5. capture the final fingerprint, prove no repository mutation, and deliver a binary verdict.origin/main, and avoid altering the worktree or index.main at 7c60ddb7f43040fe8fbfea70efc833f689c04e75, tracking origin/main, with divergence +0 -0.8f84385816f8a03dc4fd0f78cb397e0484a97a92, 1925ba64e2fe1c371d59fef2914ecda28b153395, and content fingerprint ac96e64101ef033a784fac9825f05b745ac3a63ab268322678ab2db5b15f0328.tar: The following options were used after non-option arguments. These options are positional and affect only arguments that follow them. Please, rearrange them properly. followed by tar: --no-recursion has no effect and tar: Exiting with failure status due to previous errors; a subsequent attempt returned the same content fingerprint ac96e64101ef033a784fac9825f05b745ac3a63ab268322678ab2db5b15f0328.959 insertions(+), 228 deletions(-)..github/workflows/auto-approve.yml, .github/workflows/ci-poller.yml, .github/workflows/cocoapods-keepalive.yml, .github/workflows/publish.yml, .github/workflows/test.yml, AGENTS.md, README.md, docs/key_rotation_vault_changes.md, docs/rfc.md, src/libs/__tests__/github.js, src/libs/github.js, src/modules/__tests__/ci-poller-input.js, src/modules/__tests__/ci-poller-workflow.js, src/modules/__tests__/details-from-context.js, src/modules/__tests__/process-end-state.js, src/modules/__tests__/publish-location.js, src/modules/__tests__/publish-workflow.js, src/modules/__tests__/release-revision.js, src/modules/__tests__/update-issue.js, src/modules/ci-poller-input.js, src/modules/details-from-context.js, src/modules/post-workflow-details.js, src/modules/process-end-state.js, src/modules/publish-location.js, src/modules/release-revision.js, src/publish/__tests__/discover-location.js, src/publish/__tests__/resolve-release-revision.js, src/publish/discover-location.js, src/publish/inputs.js, src/publish/post-result.js, src/publish/post-workflow-details.js, src/publish/resolve-ci-poller-input.js, and src/publish/update-issue.js.MM) files were .github/workflows/auto-approve.yml, .github/workflows/ci-poller.yml, .github/workflows/publish.yml, src/modules/__tests__/details-from-context.js, src/modules/process-end-state.js, and src/publish/post-result.js..M) tracked files were src/modules/__tests__/ci-poller-input.js, src/modules/__tests__/ci-poller-workflow.js, src/modules/__tests__/process-end-state.js, src/modules/__tests__/publish-location.js, src/modules/__tests__/publish-workflow.js, src/modules/__tests__/release-revision.js, src/modules/ci-poller-input.js, src/modules/publish-location.js, src/modules/release-revision.js, src/publish/__tests__/discover-location.js, src/publish/__tests__/resolve-release-revision.js, src/publish/discover-location.js, and src/publish/resolve-ci-poller-input.js.M.) tracked files were .github/workflows/cocoapods-keepalive.yml, .github/workflows/test.yml, AGENTS.md, README.md, docs/key_rotation_vault_changes.md, docs/rfc.md, src/libs/__tests__/github.js, src/libs/github.js, src/modules/__tests__/update-issue.js, src/modules/details-from-context.js, src/modules/post-workflow-details.js, src/publish/inputs.js, src/publish/post-workflow-details.js, and src/publish/update-issue.js..github/workflows/ci-poller-dispatch.yml, .lore.md, src/modules/__tests__/approval-attestation.js, src/modules/__tests__/approval-authorizer.js, src/modules/approval-attestation.js, src/modules/approval-authorizer.js, src/publish/__tests__/authorize-approval.js, src/publish/__tests__/auto-approval-workflow.js, src/publish/__tests__/ci-poller-workflow.js, src/publish/__tests__/current-accepted-event.js, src/publish/__tests__/post-result.js, src/publish/__tests__/publish-workflow.js, src/publish/__tests__/record-auto-approval-attestation.js, src/publish/__tests__/record-ci-ready-attestation.js, src/publish/__tests__/request-digest-from-event.js, src/publish/__tests__/validate-approval-attestation.js, src/publish/__tests__/workflow-action-pinning.js, src/publish/authorize-approval.js, src/publish/current-accepted-event.js, src/publish/record-auto-approval-attestation.js, src/publish/record-ci-ready-attestation.js, src/publish/request-digest-from-event.js, and src/publish/validate-approval-attestation.js.origin/main integration points, and generated parser behavior—was marked in progress; lifecycle tracing, checks, and final no-mutation verification remained pending..github/workflows/auto-approve.yml was inspected as a 57-line workflow named auto-approve non-sdks, triggered on newly opened issues, with contents: read and issues: write, an ubuntu-latest job using the production environment, and an actor/title guard for sentry-release-bot[bot] or getsantry[bot] plus titles starting with publish: ..github/workflows/auto-approve.yml uses pinned actions/checkout@11d5960a326750d5838078e36cf38b85af677262 with persist-credentials: false and pinned actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1, configured with vars.SENTRY_INTERNAL_APP_ID and secrets.SENTRY_INTERNAL_APP_PRIVATE_KEY..github/workflows/auto-approve.yml binds the request snapshot by running node src/publish/request-digest-from-event.js, records automated approval through node src/publish/record-auto-approval-attestation.js, posts the resulting attestation via gh issue comment, derives REPO using sed -n 's/^publish: \(.*\)@.*/\1/p', checks it with grep -qxF against auto-approve-repos.txt, and adds the accepted label when matched.ci-poller workflow excerpts showed: workflow_dispatch may target any ref, so trusted code is checked out; attempt input is accepted only when matching ^(0|[1-9]|[1-5][0-9])$; GitHub CLI token override is isolated in a subshell; issue processing binds each poll cycle to the current accepted-label event before CI inspection; branch HEAD is resolved and may differ from the issue SHA; inability to resolve branch HEAD falls back to the issue SHA; changed revisions are compared using if [[ "$sha" != "$issue_sha" ]]; commit statuses and paginated check runs are both inspected; approval-invalid paths remove/deny progression and comment that the accepted label should be re-added after resolution; approval is revalidated immediately before stale ci-ready handling; and final reconciliation sets CI_POLLER_HAS_PENDING to false when appropriate.