Dashboard › publish › Distillation
34456cbd-5bb9-41c1-86fe-25287319a409["lore_tm_v1_NNOpDgQKNafbQFR7aZnZXfxYWwfUlV7HoVQNPidLEvE","lore_tm_v1_DiNaQcHDZ8m1-9PWpKSstnqcnDgXBW33knriQRks-wM","lore_tm_v1_z-Jd_UyDkBy1hSB7k9i9k2kVmyvrQ0pRLLne9pk85HU","lore_tm_v1_r0QLQvR13M55Rt7hV3brxeldLzecBw6gbnok9wJpdNo"]
Date: Sep 9, 2026
MUST-FIX/CONCERN/PASS, with exact current file:line evidence and test evidence, ending exactly MERGE or DO-NOT-MERGE; or (2) begin BLOCKED with the exact tool/error and end DO-NOT-MERGE.SENTRY_INTERNAL_APP_PRIVATE_KEY and SENTRY_RELEASE_BOT_PRIVATE_KEY as a pre-existing Security issue; it is not a blocker unless the current diff worsens it.83d210b29553ea6f4d97508821724a834c43856e..github/workflows/auto-approve.yml, .github/workflows/ci-poller.yml, .github/workflows/cocoapods-keepalive.yml, .github/workflows/publish.yml, .github/workflows/test.yml, AGENTS.md, README.md, docs/key_rotation_vault_changes.md, docs/rfc.md, src/libs/__tests__/github.js, src/libs/github.js, src/modules/__tests__/details-from-context.js, src/modules/__tests__/update-issue.js, src/modules/details-from-context.js, src/modules/post-workflow-details.js, src/modules/process-end-state.js, src/modules/update-issue.js, src/publish/inputs.js, src/publish/post-result.js, src/publish/post-workflow-details.js, and src/publish/update-issue.js..github/workflows/ci-poller-dispatch.yml, .lore.md, src/modules/__tests__/approval-attestation.js, src/modules/__tests__/approval-authorizer.js, src/modules/approval-attestation.js, src/modules/approval-authorizer.js, src/publish/__tests__/authorize-approval.js, src/publish/__tests__/auto-approval-workflow.js, src/publish/__tests__/ci-poller-workflow.js, src/publish/__tests__/current-accepted-event.js, src/publish/__tests__/publish-workflow.js, src/publish/__tests__/record-auto-approval-attestation.js, src/publish/__tests__/record-ci-ready-attestation.js, src/publish/__tests__/validate-approval-attestation.js, src/publish/__tests__/workflow-action-pinning.js, src/publish/authorize-approval.js, src/publish/current-accepted-event.js, src/publish/record-auto-approval-attestation.js, src/publish/record-ci-ready-attestation.js, and src/publish/validate-approval-attestation.js..github/workflows/ci-poller-dispatch.yml=570dcb023ae08f4fb8338923496a55bf1c2e012a944f9969650bc31feadd485c, .lore.md=3461658c70288911f3f6eb8be89c1b35ed1dfb5c5915c5c4c86f4824d14dbb55, src/modules/approval-attestation.js=51898ad7a79e99d1a22a116a40953e5b52030a8e90c9eda5c46eb3ed3998b701, src/modules/approval-authorizer.js=c9ca690c7ca173c6cdc973e511dadb5479ff10cd958f9b0c4f10f83017e6ec55, src/modules/__tests__/approval-attestation.js=7b09762838a38df35f923c5abf900cb5627c6038bfa83900655ca5d76137a7b7, and src/modules/__tests__/approval-authorizer.js=c6f64660b2fa5339b7b7936608ce90455518d5445c0ce3ff0298f1035e48a407.src/publish/authorize-approval.js=7ced3d4b0d6137122942a8e3978a992ea20a30d0f12625ef9c04bf03d9bccb5a, src/publish/current-accepted-event.js=89327251626058674db523d8e541475bb9bf94cce2359adba06a85f99e359895, src/publish/record-auto-approval-attestation.js=dc1dee4b851b54efec8ab987fbc6e27210c5ed099b7094112b48511a9bfd9382, src/publish/record-ci-ready-attestation.js=ae06156794d4bb8b0559b1c5473d75b35bf1816960678c58e46f5f4c387dce3a, and src/publish/validate-approval-attestation.js=943aacefbec471c91f264dca602f0a37199f7a29875cc41adaa2429828693fa7.src/publish/__tests__/authorize-approval.js=a4806a0195dcbe120845c401b555afd9b6e20281b48430fc2a2171f8a9bc56fb, src/publish/__tests__/auto-approval-workflow.js=e24b83d30238402ed9d79d6995f21e3d0ac39354e148f4ca77d2da1d43f64c2a, src/publish/__tests__/ci-poller-workflow.js=a549e01d0420a6c1d82f33d1416c304ef259f2228a391f2adb4068dc4a9dd07f, src/publish/__tests__/current-accepted-event.js=bf5e5eddd6ab87e0caf1497bda6f8948e1b403ccc543319966de949b85b1e545, and src/publish/__tests__/publish-workflow.js=ae2d49aa0a56ce879081073ececc857d7d3870f09cee2c8ca722e0255f58da64.src/publish/__tests__/record-auto-approval-attestation.js=9b4d7bc1a8d6061e5f13eedf13fcbfda6c104880c5e8a4d2482b4939ac16dc0e, src/publish/__tests__/record-ci-ready-attestation.js=c1185ee6b13be4a2be575696511c297e0a5450f596198923e6601f634f1a99f5, src/publish/__tests__/validate-approval-attestation.js=a341596df1a5eb1bc0081e951ffda220ba3022f3163171ab8c05d4cbaf04ac02, and src/publish/__tests__/workflow-action-pinning.js=f81aaf26af172b638b9ff9ef7c2eec036f0833dbe87d0b46c7e36c0c552c6e9a..github/workflows/ci-poller-dispatch.yml:51, this is the invariant for handling workflow_dispatch, which can target any ref..github/workflows/ci-poller-dispatch.yml:121-122 binds each poll cycle to the current accepted-label event before inspecting CI..github/workflows/ci-poller-dispatch.yml:273 documents this invariant before the accepted-event revalidation logic..github/workflows/ci-poller-dispatch.yml uses pinned actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 and actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1; the latter appears for separate token-creation steps around lines 60 and 71..github/workflows/ci-poller-dispatch.yml:81 identifies a cross-repository API token installed on all getsentry repositories; line 91 invokes GitHub API calls as GH_TOKEN="$RELEASE_TOKEN" gh api "$@"..github/workflows/publish.yml:176 explains that this prevents the publish job from racing with waiting-for-ci on the same event..github/workflows/publish.yml:23 states that the publish job requires ci-ready, so it cannot run until that label is present; around lines 198-206, approval validation sets REQUIRE_CI_READY_ATTESTATION: "true"..github/workflows/publish.yml uses pinned actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38; line 240 runs node .__publish__/src/publish/post-workflow-details.js..github/workflows/publish.yml:350 uses the invalid-approval remediation comment: Approval is invalid or could not be verified. Re-add the accepted label to retry after resolving the issue.