Dashboard › publish › Distillation
31228efe-a3a5-4c08-a61e-f0c7fa8a2acb["lore_tm_v1_qm-NTlPbObAKd0ai1RGpKpAMgHPuNezpBYnOSh996rA","lore_tm_v1_c1NJJLa9tmNaQjlpW-pGpPQotehk7_Q5Os177b_-9Yg","lore_tm_v1_FNyRw9nbYk6_iZWTEKfuuRGQSt8v8q6sKXZ12jjH4rc","lore_tm_v1_hbisWZMrx8fNtzJm9UmaAWh78yW97DeGM31zodKqr9g","lore_tm_v1_G2uWQnelRZIyxq0NzdY1Ia2q-Xmmu7-Hj5eZ604BYrY","lore_tm_v1_cttRcQr-P9QGGE0ldRpMirYXpUYn6ub2UGNsh7eO7sw","lore_tm_v1_lEO85KTrWr2cdrrrYwcz24MndgxA4XGQIFeUIRZIzBM","lore_tm_v1_9Wr78uBQOFWAZXA912piw_e9rnw10Uz92alQQia4OIU","lore_tm_v1_FLmKqbZozONwwitYNNECrnNcpLgRwv8Cw58y3ngFmVs","lore_tm_v1_Q4V-uB2zinMKreZwgwjhUMXS9RA-vQtuSt3QZX4WnZk","lore_tm_v1_YBdVk2ze8vdkx61ZMt1OyMihNI7PWbtjO3zJU7jtF3E","lore_tm_v1_URtXXg4X3xHZmq8p4Far6YQMOsZt5yT0_koMqr6FCmc","lore_tm_v1_8tisjsv8w1rPfXcpNUJpv0SLmwpnA_RBUJTBTuNsEt4","lore_tm_v1_4SFtD9rHO51r2aNhUrfkZSjxB_7-NvOyk-9O_uZmEUg"]
auto-approve-repos.txt at /home/byk/Code/getsentry/publish/auto-approve-repos.txt contains exactly 46 entries, ordered: 1. getsentry/arroyo, 2. getsentry/auto-type-annotate, 3. getsentry/devenv, 4. getsentry/infra-event-notifier, 5. getsentry/jest-sentry-environment, 6. getsentry/json-schema-diff, 7. getsentry/js-source-scopes, 8. getsentry/objectstore/clients, 9. getsentry/ophio, 10. getsentry/pdb, 11. getsentry/pyo3-python-tracing-subscriber, 12. getsentry/pytest-sentry, 13. getsentry/relay/py, 14. getsentry/responses, 15. getsentry/rust-proguard, 16. getsentry/rust-sourcemap, 17. getsentry/rust-usage-accountant, 18. getsentry/script-runner, 19. getsentry/sentry-api-schema, 20. getsentry/sentry-forked-djangorestframework-stubs, 21. getsentry/sentry-forked-django-stubs, 22. getsentry/sentry-forked-jsonnet, 23. getsentry/sentry-infra-tools, 24. getsentry/sentry-kafka-management, 25. getsentry/sentry-kafka-schemas, 26. getsentry/sentry-protos, 27. getsentry/sentry-redis-tools, 28. getsentry/service-registry, 29. getsentry/skrooge, 30. getsentry/snuba-sdk, 31. getsentry/statsdproxy, 32. getsentry/status-page-list, 33. getsentry/streams/sentry_streams, 34. getsentry/symbolic, 35. getsentry/taskbroker/clients, 36. getsentry/usage-accountant, 37. getsentry/watto, 38. getsentry/sentry, 39. getsentry/snuba, 40. getsentry/vroom, 41. getsentry/relay, 42. getsentry/symbolicator, 43. getsentry/taskbroker, 44. getsentry/uptime-checker, 45. getsentry/launchpad, 46. getsentry/self-hosted..github/workflows/auto-approve.yml (+26-line-scale change), .github/workflows/ci-poller.yml (+192-line-scale change), .github/workflows/cocoapods-keepalive.yml, .github/workflows/publish.yml (+140-line-scale change), .github/workflows/test.yml, AGENTS.md, README.md, docs/key_rotation_vault_changes.md, docs/rfc.md, src/libs/__tests__/github.js, src/libs/github.js, src/modules/__tests__/details-from-context.js, src/modules/__tests__/update-issue.js, src/modules/details-from-context.js, src/modules/post-workflow-details.js, src/modules/process-end-state.js, src/publish/inputs.js, src/publish/post-result.js, src/publish/post-workflow-details.js, and src/publish/update-issue.js..github/workflows/auto-approve.yml, .github/workflows/ci-poller.yml, .github/workflows/publish.yml, src/modules/__tests__/ci-poller-input.js, src/modules/__tests__/ci-poller-workflow.js, src/modules/__tests__/details-from-context.js, src/modules/__tests__/process-end-state.js, src/modules/__tests__/publish-location.js, src/modules/__tests__/publish-workflow.js, src/modules/__tests__/release-revision.js, src/modules/ci-poller-input.js, src/modules/process-end-state.js, src/modules/publish-location.js, src/modules/release-revision.js, src/publish/__tests__/discover-location.js, src/publish/__tests__/resolve-release-revision.js, src/publish/discover-location.js, src/publish/post-result.js, and src/publish/resolve-ci-poller-input.js.yarn check:generated && vitest run --printConsoleTrace succeeded under Yarn 1.22.22 and Vitest 4.1.0: generated parser check ran via node scripts/generate-publish-issue-title-parser.js --check; 27 test files passed and all 185 tests passed. Vitest duration was 5.15s (transform 509ms, import 2.75s, tests 4.08s, environment 13ms); total Yarn duration was 6.58s.eslint src .github --ignore-pattern '!.github' succeeded with no reported errors in 1.30s./home/byk/Code/getsentry/publish/package.json defines package publish, private true, version 0.0.1, description Approval-based publishing system for Sentry, main index.js, repository git@github.com:getsentry/publish.git, author Sentry Open Source <oss@sentry.io>, and license Apache-2.0.package.json pins Volta to Node 24.0.0 and Yarn 1.22.22, and resolves undici to ^6.23.0.package.json scripts are: generate → node scripts/generate-publish-issue-title-parser.js; check:generated → node scripts/generate-publish-issue-title-parser.js --check; test → yarn check:generated && vitest run; test:watch → vitest; lint → eslint src .github --ignore-pattern '!.github'; prettier → prettier --write src.package.json dev dependencies are eslint ^8.9.0, eslint-config-prettier ^8.3.0, eslint-plugin-yml ^0.13.0, peggy 5.1.0, prettier ^2.2.1, and vitest ^4.1.0; runtime dependencies are @actions/core ^2.0.0, @actions/github ^7.0.0, and @sentry/node ^10.0.0."X-GitHub-Api-Version": "2026-03-10" appears in src/publish/validate-approval-attestation.js line 14 and src/publish/authorize-approval.js line 45..lore.md lines 37, 43, and 230; src/publish/record-ci-ready-attestation.js line 11; tests src/publish/__tests__/record-ci-ready-attestation.js line 9, validate-approval-attestation.js line 5, and authorize-approval.js line 10; src/publish/current-accepted-event.js line 2; src/publish/record-auto-approval-attestation.js line 6; .github/workflows/publish.yml lines 72, 97, 240, and 374; .github/workflows/ci-poller.yml lines 168, 308, 330, and 382; and src/modules/__tests__/ci-poller-workflow.js lines 78, 87, and 321..lore.md documents that authorizeApproval() must fail closed when either getsantry[bot] or sentry-release-bot[bot] directly labels the other bot’s request; only sentry-internal-app[bot] may represent automated approval, backed by a matching github-actions[bot] request-bound attestation, with regressions for both direct-bot paths..lore.md documents that auto-approve.yml posts a github-actions[bot] request-bound proof before the Internal App adds accepted; an Internal App label without matching proof must be rejected..lore.md documents that publish approval requires requester/approver separation: authorize-approval.js fetches the live issue, fails closed if issue.user.login is missing, rejects a case-insensitive match with APPROVAL_ACTOR, and permits automatic approval only through an explicitly authenticated, request-bound automation path./home/byk/Code/getsentry/publish/.github/workflows contains exactly 6 files: auto-approve.yml, ci-poller-dispatch.yml, ci-poller.yml, cocoapods-keepalive.yml, publish.yml, and test.yml.getsentry/craft@sha256:9a4a5d5efa44a00c2215078ead39800d4aaa5a97908b94f45a64d7d506d6e14b in src/publish/discover-location.js line 10 and its test at src/publish/__tests__/discover-location.js line 36; the workflow uses docker://getsentry/craft@sha256:9a4a5d5efa44a00c2215078ead39800d4aaa5a97908b94f45a64d7d506d6e14b in .github/workflows/publish.yml line 399, asserted by src/modules/__tests__/publish-workflow.js line 93.gh issue edit supports editing one or multiple issues in the same repository and requires the project scope for project edits, obtainable with gh auth refresh -s project.gh issue edit label operations expose --add-label name and --remove-label name; other notable flags include --body, --body-file, --title, assignee add/remove, project add/remove, milestone set/remove, issue type set/remove, parent/sub-issue operations, and blocked-by/blocking relationships. Its inherited repository selector is -R, --repo [HOST/]OWNER/REPO.