Dashboard › publish › Distillation
45d4d096-2023-43a1-9591-9de1bfe50adb["lore_tm_v1_Vk-mLYrTmBfffF3mFCVTimA68G-Zurx57aE2nZnfV0A","lore_tm_v1_WxkFap_YnssJIs2TLY1o4YzMJzj4kvwY4iQljjeHRes","lore_tm_v1_ikpT3-Ga-NcXvp9UwkcKJ-JQy2qvhgiZ1Rrrwn6X2DA","lore_tm_v1_1Mky795vSkX_9Ct91Q4ouAvzEoYbCPJBpmqS4BzNmTA","lore_tm_v1_d6nJ_bt7ByvudJYhIjqj9MXUDHX42UZVDxFF9IiFhU8","lore_tm_v1_f-OzG49Sa8Ua6_lWNYiXSdQp7f7hAtZRCjqS9eKnF9k","lore_tm_v1_XwMDOsOapGnnze2TgTAhnrQRFISTnq-gmtwJ3VH4Bhw","lore_tm_v1_dH8QcweT1bkrTDtf9pfUE5KQKNu8y2n4GTAfEPqfrl8","lore_tm_v1__J-lGf-0KYiez6CRF_zetFzC9LaWo9sul8CymPIm4W0"]
π΄ (23:43) User-provided worktree inventory for /home/byk/Code/getsentry/publish showed 15 top-level entries: .eslintrc.js, .git/, .github/, .gitignore, .lore.md, AGENTS.md, auto-approve-repos.txt, docs/, LICENSE, node_modules/, package.json, README.md, src/, vitest.config.js, and yarn.lock.
π΄ (23:43) User-provided git status showed 21 tracked modifications: .github/workflows/auto-approve.yml, .github/workflows/ci-poller.yml, .github/workflows/cocoapods-keepalive.yml, .github/workflows/publish.yml, .github/workflows/test.yml, AGENTS.md, README.md, docs/key_rotation_vault_changes.md, docs/rfc.md, src/libs/__tests__/github.js, src/libs/github.js, src/modules/__tests__/details-from-context.js, src/modules/__tests__/update-issue.js, src/modules/details-from-context.js, src/modules/post-workflow-details.js, src/modules/process-end-state.js, src/modules/update-issue.js, src/publish/inputs.js, src/publish/post-result.js, src/publish/post-workflow-details.js, and src/publish/update-issue.js.
π΄ (23:43) User-provided git status showed 19 untracked files: .github/workflows/ci-poller-dispatch.yml, .lore.md, src/modules/__tests__/approval-attestation.js, src/modules/__tests__/approval-authorizer.js, src/modules/approval-attestation.js, src/modules/approval-authorizer.js, src/publish/__tests__/authorize-approval.js, src/publish/__tests__/auto-approval-workflow.js, src/publish/__tests__/ci-poller-workflow.js, src/publish/__tests__/current-accepted-event.js, src/publish/__tests__/publish-workflow.js, src/publish/__tests__/record-auto-approval-attestation.js, src/publish/__tests__/record-ci-ready-attestation.js, src/publish/__tests__/validate-approval-attestation.js, src/publish/__tests__/workflow-action-pinning.js, src/publish/authorize-approval.js, src/publish/current-accepted-event.js, src/publish/record-auto-approval-attestation.js, src/publish/record-ci-ready-attestation.js, and src/publish/validate-approval-attestation.js.
π΄ (23:44) User-provided repository state was HEAD 83d210b29553ea6f4d97508821724a834c43856e; the tracked diff contained 499 insertions and 117 deletions across 21 files and had SHA-256 8ca4aa7afcb6a1c171f695d488a06b8cf4d08436a414a3223a18b33a08db4fc6.
π΄ (23:44) User-provided SHA-256 values for untracked implementation files were: .github/workflows/ci-poller-dispatch.yml β 570dcb023ae08f4fb8338923496a55bf1c2e012a944f9969650bc31feadd485c; .lore.md β 1582e43bb3cf41677ddfd0713647732cbfc0e48ca3f44bd2848d678e529ae7f9; src/modules/approval-attestation.js β 51898ad7a79e99d1a22a116a40953e5b52030a8e90c9eda5c46eb3ed3998b701; src/modules/approval-authorizer.js β c9ca690c7ca173c6cdc973e511dadb5479ff10cd958f9b0c4f10f83017e6ec55; src/publish/authorize-approval.js β 7ced3d4b0d6137122942a8e3978a992ea20a30d0f12625ef9c04bf03d9bccb5a; src/publish/current-accepted-event.js β 89327251626058674db523d8e541475bb9bf94cce2359adba06a85f99e359895; src/publish/record-auto-approval-attestation.js β dc1dee4b851b54efec8ab987fbc6e27210c5ed099b7094112b48511a9bfd9382; src/publish/record-ci-ready-attestation.js β ae06156794d4bb8b0559b1c5473d75b35bf1816960678c58e46f5f4c387dce3a; src/publish/validate-approval-attestation.js β 943aacefbec471c91f264dca602f0a37199f7a29875cc41adaa2429828693fa7.
π΄ (23:44) User-provided SHA-256 values for untracked tests were: src/modules/__tests__/approval-attestation.js β 7b09762838a38df35f923c5abf900cb5627c6038bfa83900655ca5d76137a7b7; src/modules/__tests__/approval-authorizer.js β c6f64660b2fa5339b7b7936608ce90455518d5445c0ce3ff0298f1035e48a407; src/publish/__tests__/authorize-approval.js β a4806a0195dcbe120845c401b555afd9b6e20281b48430fc2a2171f8a9bc56fb; src/publish/__tests__/auto-approval-workflow.js β e24b83d30238402ed9d79d6995f21e3d0ac39354e148f4ca77d2da1d43f64c2a; src/publish/__tests__/ci-poller-workflow.js β a549e01d0420a6c1d82f33d1416c304ef259f2228a391f2adb4068dc4a9dd07f; src/publish/__tests__/current-accepted-event.js β bf5e5eddd6ab87e0caf1497bda6f8948e1b403ccc543319966de949b85b1e545; src/publish/__tests__/publish-workflow.js β ae2d49aa0a56ce879081073ececc857d7d3870f09cee2c8ca722e0255f58da64; src/publish/__tests__/record-auto-approval-attestation.js β 9b4d7bc1a8d6061e5f13eedf13fcbfda6c104880c5e8a4d2482b4939ac16dc0e; src/publish/__tests__/record-ci-ready-attestation.js β c1185ee6b13be4a2be575696511c297e0a5450f596198923e6601f634f1a99f5; src/publish/__tests__/validate-approval-attestation.js β a341596df1a5eb1bc0081e951ffda220ba3022f3163171ab8c05d4cbaf04ac02; src/publish/__tests__/workflow-action-pinning.js β f81aaf26af172b638b9ff9ef7c2eec036f0833dbe87d0b46c7e36c0c552c6e9a.
π΄ (23:44) User established the recovery invariant: βAlways allow workflow_dispatch for manual recovery.β
π΄ (23:44) User established the dispatch trust-boundary invariant: βAlways run trusted codeβ; the associated workflow comment explains that workflow_dispatch can target any ref.
π΄ (23:44) User established the mutation-safety invariant: βNever move a release to ci-ready after it changes.β
π΄ (23:44) User established that a renamed or re-approved issue βnever reaches ci-ready.β
π΄ (23:44) User-provided diff showed workflow actions being pinned to immutable commit SHAs, including actions/checkout@11d5960a326750d5838078e36cf38b85af677262, actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1, and actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38.
π΄ (23:44) User-provided task state marked βCapture exact worktree state and enumerate all changed and untracked filesβ completed; security-critical inspection was in progress; running yarn test --printConsoleTrace, yarn lint, and git diff --check and producing the final evidence-backed verdict remained pending.
π‘ (23:44) Assistant reported that the frozen review scope contained 21 tracked modifications and 19 untracked files at abbreviated HEAD 83d210b, and that it was tracing live-state and provenance checks end to end, including which token posts each proof and which actor applies each label.
π΄ (23:44) In .github/workflows/auto-approve.yml:1-16, user-provided current code defines the auto-approve non-sdks workflow for newly opened issues, grants contents: read and issues: write, runs the auto-approve job on ubuntu-latest in the production environment, and gates it to actors sentry-release-bot[bot] or getsantry[bot] with issue titles beginning publish: .
π΄ (23:44) In .github/workflows/auto-approve.yml:18-27, current code checks out only auto-approve-repos.txt using pinned actions/checkout@11d5960a326750d5838078e36cf38b85af677262 with sparse-checkout-cone-mode: false, then creates a GitHub App token via pinned actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1, vars.SENTRY_INTERNAL_APP_ID, and secrets.SENTRY_INTERNAL_APP_PRIVATE_KEY.
π΄ (23:44) In .github/workflows/auto-approve.yml:28-43, current code records an automated approval attestation by running node src/publish/record-auto-approval-attestation.js with APPROVAL_TOKEN=${{ github.token }}, issue number/repository/title, and AUTO_APPROVER=${{ github.actor }}; on success it posts ${{ steps.attestation.outputs.auto_approval_attestation }} to the issue using GH_TOKEN=${{ github.token }}.
π΄ (23:44) In .github/workflows/auto-approve.yml:44-54, current code uses the GitHub App token ${{ steps.token.outputs.token }} to parse REPO from titles matching publish: <repo>@..., checks it exactly with grep -qxF against auto-approve-repos.txt, and applies the accepted label only when the parsed repository is non-empty and allowlisted.