Dashboard › craft › Distillation
529d1eed-ff38-4014-b081-b1d49b556562["lore_tm_v1_QFblws8ihxltt2glTNHqtK-C_rIX7rNxeESh4Ai749s","lore_tm_v1_Z-p8Q8EtlmA4RWkptXlBlanS32tlmYsGUYp2FC7erGo","lore_tm_v1_V_X6V3hV1SoY2souFBel8DdH8SU0PhC7DWK2ozUar50","lore_tm_v1_OTrwGdNFAWVHUgXv5jJHosYA2jxFGIMaTrvfdg3UkOs","lore_tm_v1_P4J7WhVgNnqDk3Xj4iQ134MAqDFhM4wkGOV_9G7n9TU","lore_tm_v1_1Pm8DxTHsxvK6IJgqpkjEEiLHXYG-H1xFVXgVxI__uk","lore_tm_v1_lOgl0hJ2EkDQW9FWkIpptBb0zaQy0penxCEB_373xA4","lore_tm_v1_fonFxyIwB9WyYHOmLZxu7g0q5IGe38EXBjLNvu0ktcM","lore_tm_v1_Fszn5u5BBzmZpPQgQ7G0bgx2kH24nUmazKBQ2z-lJCo","lore_tm_v1_i1CmcEYkQVcZY5_baiuk-KEHZuFzNxuAqKgA6U5nwgE","lore_tm_v1_ytkCfIWfG6SkDA4zxwPV4MbARHd-5EEMa58r8ReIcC0","lore_tm_v1_Uvcqz-Ag-uZ4h2yur_h8kO31W1BGehLFttPLQrF5cSI","lore_tm_v1_A9f4OwlAnJZb1eEpPfOe0pE11LeXGBsr3FQfIr_rXoQ","lore_tm_v1_JArvLqDRF1PeUBPBBKhHZxDqFQbthL7ZCZE2GtyrMcM","lore_tm_v1_rOEt_6kb2B-KMNOGtMCD6ObEneEcVvH5h_N68hqvANM","lore_tm_v1_TjJmCEw5cTgfMD7Q2foaMLmN1lmEv50AOd7LDUhcP8U","lore_tm_v1_oiUbogOlMH8j_Vu3al0WNEE4nhoiqiVH15pKbQ8CS68","lore_tm_v1_vtKmrKWcsYK-WZaElufEW9tbG31ZVIbkcwE_v2hFLY0","lore_tm_v1_gi_b0rqe5ytlAwrsKnbF835_QAo5CCULYF3Zo9sscd0","lore_tm_v1_rzOnSPsU6rCvL-b-giQnuflNWSs8ZSYrydl7Rhbu0n4","lore_tm_v1_so6Va37OXKBkQRGxKdtpF_tFJrVbHWmhXRfbGXKRMT8","lore_tm_v1_AtzShPecGJnmF13OgPPg80zeJJn1dKOXy2CvWkugSzg","lore_tm_v1_yfa3ghyKO2X4nKgnhyRrp3vvrn4NDmYuK2bWPEkfao8","lore_tm_v1_pPZR9urm0MQaGfIgi7zdmroBvB8CYjwXJgtNQO1eOA8","lore_tm_v1_SQaDVJo0cOW-PS1T8a-4K0spVyC4_rlUjUxEU_kerJo","lore_tm_v1_HnK1qTUISD1PPwnzkYFVXJntGh2OrhcuonDaB6GboZk","lore_tm_v1_uJfDQUOW6CQZW1wmkhrHLgAPutSzkYgaphHDlAjLcyc","lore_tm_v1_3Qb39XRrZlXB_7Vkb8Np42U_84fazpE3IiYh1G2-e8E","lore_tm_v1_T4MvHbFsKLK-VRufF4MNszA06ooBH7Dw05hc0T-Q6oQ","lore_tm_v1_CAgdoWYNtV4MFWgAscsB5EQbrw2kjlmY2ivr6p93zhk","lore_tm_v1_4C00fTsu8lgvCHoU26xf34_1-Slv2Yd-b_EIbkmFqFA","lore_tm_v1__8q6mSSUBVO1aH-q0oFf7Y3asm2RyhpYby1rk_0Msm4","lore_tm_v1_68MX8bltLAcgq7qGhWZrPIUPek-wRK_um5NE0n_57eM","lore_tm_v1_w311Jrf5e2uydhvLPs9FBt2F-2Jb_wwejtUKT2IexXg","lore_tm_v1_3T7meP81adVIT2QFd5sE1bqrrmuvXoesnF5weqiRQkQ","lore_tm_v1_jiBpx4h9e_xE2jmhXUHDBO8_KTJL-Pvrs_qOO87M2SM","lore_tm_v1__twwg7uCxdtQBQbeNxPaGIQqTWA4bVJ_veLNSccVB3E","lore_tm_v1_1TeFMqMiZh7KTgVTlLsSzAb2oOPSPjGhbXpRqs312Jo","lore_tm_v1_E8Eo27wf2Vp7adcKlxE3D-SLdtTLV1Lcgy1YMAq2Mc4","lore_tm_v1_1krS5tMandfYWJX9XZUOBkAjCpbOzWfnHYWFeyuAWq8","lore_tm_v1_QWteEVtT1CU4hbLiyA31MDlYpuZBbdlVlPUDgoGasiY","lore_tm_v1_tGoWtG89hfmMHqBZp7dHjNS7BytJ_Cs5u8Wghdkw1EA","lore_tm_v1_0xTYUPkeigX0KCf180YjJ0-3_aGAWFvK4BGxcYVBERM","lore_tm_v1_dtYvcTk6KIXkdVHJLTqZyp9QLjw6UEJmN3eoQ4lFqWI","lore_tm_v1_3pCFTxUQdjK0gN5n3lAd-47ft0rcXB0CqA4KC-Xbz68","lore_tm_v1_yhJandEDEjg3p_hR5o8zcBEGc54JRyQ65RZMFPj70Oc","lore_tm_v1_QyGmRPVvClQKoocNICdkziOyXbru3vd-pLbBWVADuyQ","lore_tm_v1_7rE9Io2mEogVoaSUgBGz2TmNULnZPxy0i_D2Gr0Ehl0","lore_tm_v1_PCB4a21Sp-uZ8CnPAwmpMX06iXO1Mmu3qlOuEu6JnpU","lore_tm_v1__5BSLhHrgUZu1mMXWBK69AMMscVWTT-MZoVFmpQDm1s","lore_tm_v1_H3rKOH5h_uZXjeGVPNinpeCmD86lwWWDrnJUTN1NNm0","lore_tm_v1_xikF0FpzQlZ0TvRA0RXByoCWTsc_d5ZgAsl-JX-XsvM","lore_tm_v1_nOLXd6bNIyakhdy_lYWZZ5O_b_6yLB2M6rBdtfDQd_8","lore_tm_v1_P2VH0VFe1CMF0Gksa8tGM_0KgUKlE-_p9pEfTN8llhg","lore_tm_v1_26JSVrJOBb9FqOMmyUuel-mIN8SAaLW_ASq2qlyroF4","lore_tm_v1_J8Jo3t2bBP_sMVI6WCveZ3ccBzM7_F8WkWOuKQCRSyM","lore_tm_v1_mwfvV-t6MOsT2-9mT3__fvtFhCvCFk0cTJ9kyvy9mZw","lore_tm_v1_Mca4LBFZwj8OavMeJ2S6qyr1ytSlpm4fV_3xTUcMWKY","lore_tm_v1_VMyJuPxajlqzYVD0LhVHh30H1UM0Dgb6NjqGER2spB0","lore_tm_v1_Jftry5qzIpiklioIvs9vjiCZ2_aXNZB8YlwA0ny6wzY","lore_tm_v1_TaOnzpKKMsJa9EwY1jxqk7d7AxNQav9heirreZOry8M","lore_tm_v1_ojZujScacyGNoLgdUsQJ7Od6Rb44_sbJCZc5Q9cd7Ak","lore_tm_v1_fNODYp3UEGtayorKb1Gfsnhn0S1pU4BnFjSF3hBffuM","lore_tm_v1_QTyIB43h6sju43cKQ3T0b0QO0OKP4Yb5eV14_VA_Ha8","lore_tm_v1_txLUzoUdFT4m6tETtBQeBvBbA0KVrl4g1Jhwfw3LvMM","lore_tm_v1_GlYR1DBXGFwfRHvvs43b0bmLRmVawIg5Zfy8vQ1NWi8","lore_tm_v1_4d2DCVZ1CU3dDxtExIqfLAwFhYk8bHQp1Hx_iV9avmE","lore_tm_v1_mn2JEiO49WApe7nxxaA8hoG-Kn-mAQBAr8--MQz6Hts","lore_tm_v1_qIVYSbQPWLMtfODcnCHOBenKtm8de4l4sCgu0O8Hsps","lore_tm_v1_aFKalSHOKRusMb4Us_WVIfe2usyWS_3v8dv1s4FiX0Q","lore_tm_v1_Co6RUPqwNt9we1dJtUiFn4IajPwcruHSpOlAk_nvjFg","lore_tm_v1_c9zWBxAsxMotslbhmWxRsyn6HYF8LpwqUdgT4DDvwtM","lore_tm_v1_kDk5kliaVKiiWv5E0fT-zOF62cL_D_6VhhXZb1ZGXTI","lore_tm_v1_yGO1mrLEU0w2Rhq4w3knisTuRyMabWPauKhuMgQJd7M","lore_tm_v1_k_19SDJR6UqLWnSgtn294urFkxSxR0bQRdgJAunhz9k","lore_tm_v1_AM2c5iT1TnPJtF-lR0MLzVMUX_Jv6YWiKszdtHOW_NQ","lore_tm_v1_khxtVCmQNxFxroubPRXNU1OiFA5eS-lRNsI7wWKFSWY","lore_tm_v1_OCBKv3PsRsHiPMtFl_OaqkOsAwIAQvTDX8m8ha6m3kA","lore_tm_v1_BJfHUoQb0JBMQBZrZ9lLdBrKataeGn7IEd52YyBPRpo","lore_tm_v1_AUNQPBFphsyioUjQ5pJkFXtBoKo1DDoxv4yKeOU64Ew","lore_tm_v1_8jzIiKiTKoZZ3tRTTY66v8Ozfm-i6a1ZLKQTbuq2MAw","lore_tm_v1_dFbYz3Vul-Bp5uT0CmDJ8dpgaPiTZvnXb-Plh177j5Q","lore_tm_v1_svxqcx49q1y-8p9MYQUay80gArhk9F6pE1UTXspET_8","lore_tm_v1_IL57cv9WWxSB5BdrIpd3qOVsB16i7Su8nZWntM51jp0","lore_tm_v1_27nVau4HWZlzbmis3mWcJRi27p9cv3iw3F4hRywUwKo","lore_tm_v1_VKMz9dcQ5-lmmMELLuzx6n9pA9jgec1QYWhsMwaG6Lg","lore_tm_v1_82IqDCUFlpwBlxjUZj3I8wA1jKQLnofIt6suIYS_-3o","lore_tm_v1_w-wZ6TcJWvqLKOv1p4c7KGHeW_0KQCLKMVHuRyyOIoI","lore_tm_v1_qbLVtfxibleUXfXpgfBMrouAb_yeM2JQ61l2KgLGQYQ","lore_tm_v1_D1aG-4ctgNBnTc8iXjxuMtx5g5Hd6it3vwsE4_kbwgA","lore_tm_v1_ASqgIOwLsmX9iDasBd1AaWE3B__JDFGPA1cweA3h7Gg","lore_tm_v1_HWL8D6g2uLajiNMvUI474hDihyIhRk42IOPHwEO8dRk","lore_tm_v1_oqS3gRabOQEZcs0zm48Dz-aswpWQWGqN4p3Hg2ev6Ik","lore_tm_v1_es7FbzkHYOrG-tsH2On5iHGwqdPf1VdKrWByXc73Jy0","lore_tm_v1_MddSZ4P3XaApGfYhAk6dl_oumf0uS7OUbqZY5bfLfoA","lore_tm_v1_A3-aMPvnZsrQWLBo2Y4e0za_94rnKjOut4jI2p7NmwE","lore_tm_v1_3H2GbyQGTYe0Q02-Y5qLYpG0qrEofW5RYfKF2buHkjM","lore_tm_v1_d1brCazygbr6ShHn4EQ_pavfg9pWUbEbakhir3dnyeY","lore_tm_v1_2Bi86_macP-eaOGOLAolgs384fQYpcb7uPmMYB0WrUg","lore_tm_v1_xvcrS-VlO53_WYH2Oz_NdRVF7c1bg2z9H-mk0tQ6Rfg"]
/home/byk/Code/getsentry/publish-workspace-acceptancefeat/workspace-acceptancefd1e1156ae878a12a276af401a15a656bfff8127 (fd1e115 fix: address publish workspace review feedback)main, still REVIEW_REQUIRED as of Sep 8 13:02.fd1e115 was pushed Sep 8 13:01, advancing remote feat/workspace-acceptance from a81ab03.fd1e115; next GitHub actions are reply/resolve threads and obtain updated review. At Sep 8 13:02, most checks were in progress; only Dependency Review and Socket Project Report had completed successfully./home/byk/Code/getsentry/craft-workspace-action-propagationfeat/workspace-action-propagationf174ceafa57355e71617f32ba1b0a030953be0a2 (f174cea test: describe workspace paths accurately)master; mergeable: MERGEABLE, but mergeStateStatus: BLOCKED and reviewDecision: REVIEW_REQUIRED.src/__tests__/config.test.ts, renaming allows legacy workspace names to allows multi-segment workspace paths, while retaining the valid cli/v2 behavior.COMMENTED reviews by BYK, not approvals.origin/master/merge base 21270a1d12a60b461c51fba93bd076b90d9cf4af completed Sep 8 16:59 with verdict MERGE, no MUST-FIX or CONCERN findings.NEUTRAL but opened one valid medium-severity review finding, bug ID 294d500e-a01e-4627-af9f-b3d497c9b290, discussion https://github.com/getsentry/craft/pull/872#discussion_r3960382720. It identifies that getWorkspaceGlobMatches() calls realpathSync() on each glob candidate before checking whether it is a directory; a broken symlink matched by packages/* throws ENOENT instead of being ignored.does not expand workspace globs through symlinked directories in src/__tests__/config.test.ts, reproduce the failure, then narrowly reorder/guard candidate resolution so disappeared/broken entries are skipped without weakening lexical/physical containment checks. A test-file modification was applied at Sep 8 17:10, but its exact content and test result have not yet been inspected/verified. Do not claim the Bugbot issue is fixed, commit, pushed, or resolved yet.repo-setup before situation skills..sentryclirc resolution must always check global locations as fallback after walking upward from cwd.--workspace --dry-run as a workspace name.node_modules must never be opened; default walks must not re-enter directories, including via symlinks when following them.ses_f7ecc9434ffeledouaoJSXmmtQ, started Sep 8 13:28 for CLI discovery inspection, completed Sep 8 13:49 with no directly reusable findings.ses_f7e3cf790ffean2YR8MT3hLull, started Sep 8 16:04 for independent Craft audit, completed Sep 8 16:59 with MERGE.AGENTS.md directs autonomous GitHub coding work in /workspace/repo, pipeline: triage → explore → plan → implement → review → ship; worker is a deprecated alias of implement.AGENTS.md / CONTRIBUTING.md first; long-term Outpost knowledge is in .lore.md if present..agents/skills/, generated from canonical skills/ by scripts/sync-skills.mjs.grok-build-0.1.publish: getsentry/<checkout-repository>/<full-concrete-workspace-path>@<version>.getsentry/ remains optional only for parsing existing issues.cli/v2 is a valid concrete multi-segment workspace directory path, not legacy compatibility syntax. Removing support would violate the full-path title/selection contract and break valid paths such as packages/CLI.[A-Za-z0-9_.-]+, excluding ., .., __proto__, and segments beginning -; versions are Craft-compatible semantic versions and may contain + build metadata.src/modules/publish-issue-validation.js; Peggy remains syntactic, and poller/controller validation remains required."." remains root; only exact ./<workspace> discovery matches are workspaces; otherwise suffix remains safe checkout path.workspaces: keys may be literal concrete paths or glob patterns. Patterns expand to concrete directories relative to .craft.yml; selected release runs require one concrete path through --workspace <path> or CRAFT_WORKSPACE.craft workspace list outputs concrete workspace paths as a JSON array for automation.., _, and -; no ., .., __proto__, leading -, backslashes, absolute paths, unsafe glob syntax, or matching files. Overlapping workspace keys/patterns are rejected.github.projectPath; workflows cannot provide both path and a workspace.prepare --config-from resolves relative config against git rev-parse --show-toplevel.*, ?, character classes/negated classes, globstar, finite balanced braces; extglob is rejected.realpathSync failures, but the fix must preserve the existing fail-closed behavior for unsafe patterns and all lexical/realpath containment guarantees. The intended narrow approach is to inspect directory status before resolving candidate realpath and/or catch only candidate disappearance/broken-link errors.minVersion: 2.29.0, global GitHub { owner: getsentry, repo: toolkit }, packages/* configured with releaseBranchPrefix: release/cli and GitHub tagPrefix: "cli@", and tools/mcp with releaseBranchPrefix: release/mcp and GitHub tagPrefix: "mcp@".tagPrefix values, Craft uses the first prefix for read-path operations and logs a warning. Independent products should use separate release workspaces.isLatestRelease uses the repository current Latest, so Latest may move between monorepo products; tags, changelogs, release branches, and version detection remain per-product..craft.yml workspace discovery → full-suffix classification → craft publish <version> --rev <revision>.$GITHUB_WORKSPACE/.craft-state/craft; state identity uses physical container cwd SHA-1, lossless base64url workspace identity, and conditional lossless version identity to avoid case/build-metadata collisions.CRAFT_PUBLISH_STATE_GITHUB_REPO identifies checkout repository, never workspace release-repository override.getsentry/craft:latest because it must understand formats in the exact checked-out revision. CI-approved SHA plus craft publish --rev bind the actual release revision; a fixed image cannot safely support all historical/configured workspace formats.getsentry/craft:2.31.0.workspace list and --rev; when root .craft.yml exists, discovery failure remains fail-closed because compact fallback could silently misroute a workspace request.@actions/core.setOutput() cannot safely transmit plain objects to fromJSON(): object outputs must use JSON.stringify.PUBLISH_ARGS absent/empty parses as "{}"; workspace-list input as "[]". Required repo and path checks provide contextual errors instead of raw JSON.parse syntax errors.resolve-release-revision.js missing repo error: Publish input must define a repository.discover-location.js missing path error: Publish input must define a path.src/modules/publish-issue-title.peggy is canonical for PublishIssueTitle, ReleaseRevision, and CheckRunsLinkCount; generated parser start rules are exactly ["PublishIssueTitle", "ReleaseRevision", "CheckRunsLinkCount"].ReleaseRevision requires canonical body-start header: requester, required Merge target, Quick links, View changes, then one repository-bound checks URL.{ repo, mergeTarget, revision }; details-from-context.js gets Merge target solely through getReleaseRevisionDetails(), not arbitrary body regex scanning.(default) becomes empty Craft merge_target; appended/decoy Merge target: fields cannot override canonical header.(default) or documented branch-token characters: letters, digits, _, ., /, and -; unrestricted arbitrary non-newline values such as main; not-a-branch are rejected.CheckRunsLinkCount counts all literal - [View check runs]( occurrences across body to reject inline/blockquote/trailing decoys.Expected exactly one View check runs link in Quick links for getsentry/${repo}.Expected a View check runs link for getsentry/${repo} in the publish issue body.Release revision must be a lowercase 40-character SHA.updateReleaseRevision() accepts only /^[0-9a-f]{40}$/, then replaces parser-recorded [start,end) SHA offsets only.jq -jr/jq -ejr file-backed body input/output and gh issue edit --body-file..issueBody must be a nonempty string; only then can the body file be submitted to gh issue edit. Invalid/malformed JSON, top-level non-object/scalar values, missing property, non-string (null, boolean, number), empty string, JSON failure, and resolver failure skip without edit.EXIT trap for body_file, resolver_output_file, and updated_body_file; failure/skip paths use exit 0 inside the subshell rather than invalid continue, so cleanup occurs before outer while advances.// BEGIN TITLE GRAMMAR / // END TITLE GRAMMAR; docs use <!-- BEGIN GENERATED TITLE GRAMMAR --> / <!-- END GENERATED TITLE GRAMMAR -->..github/workflows/publish.yml and controller checkout in .github/workflows/ci-poller.yml use actions/checkout@v7..github/workflows/test.yml or .github/workflows/auto-approve.yml in this PR; that is unrelated scope expansion.packages/cli/AGENTS.md and .cursor/rules/ultracite.mdc.packages/cli of a pnpm workspace; it is Node.js/pnpm/Stricli, with docs at apps/cli-docs.pnpm add -D <package> and remain in devDependencies; CI enforces this with pnpm run check:deps.Bun.*, bun:test, or Bun CLI. Use node:fs/promises read/write APIs, node:fs existsSync, child-process spawn/execFile/execSync, src/lib/which.ts, src/lib/scan/, and node:timers/promises.mkdirSync(dir, { recursive: true, mode: 0o700 }); prefer array-argument execFileSync for user-controlled values to avoid shell injection.@sentry/api API-response types rather than redundant Valibot schemas in src/types/sentry.ts.buildCommand from ../../lib/command.js, use async *func() generators, yield new CommandOutput(data), return { hint }, and let shared output rendering serialize the same data. Do not add custom JSON flags, write stdout manually, branch on flags.json, or write stderr from command files; use logger diagnostics and formatter modules.buildRouteMap from ../../lib/route-map.js, which supplies aliases such as list→ls, view→show, delete→remove/rm, and create→new..sentryclirc resolution already walks upward from cwd then applies global fallback locations afterward, using getGlobalPaths(), applyGlobalFallbacks(), tryApplyFile(), walkUpFrom(cwd), and loadSentryCliRc(). Global paths are cached in globalPaths, and tests reset it when SENTRY_CONFIG_DIR changes.packages/cli/src/lib/walk-up.ts provides async function* walkUpFrom(startDir: string), resolving the start path, yielding absolute ancestors, and using realpath() plus a seen set to stop on broken/denied paths or symlink cycles.packages/cli/src/lib/scan/walker.ts is a streaming DFS file scanner, not workspace discovery. It applies IgnoreMatcher before descent, ignores node_modules-like directories without opening them, emits sorted POSIX-normalized regular files only, skips symlinks unless enabled, and seeds visited inodes with root when following symlinks to prevent subtree re-entry. It supports deterministic serial walking and bounded parallel exhaustive scanning./home/byk/Code/getsentry/craft-workspace-action-propagationfeat/workspace-action-propagationd48b906 feat: support concrete release workspaces4862056..d48b906action.ymldocs/src/content/docs/targets/github.mdsrc/__tests__/action.test.tssrc/__tests__/config.test.tssrc/commands/prepare.tssrc/config.tssrc/schemas/project_config.tssrc/utils/__tests__/publishState.test.tssrc/utils/publishState.tsf174cea test: describe workspace paths accuratelyd48b906..f174cea.f174ceafa57355e71617f32ba1b0a030953be0a2.src/__tests__/config.test.ts only: one insertion/one deletion, rename from allows legacy workspace names to allows multi-segment workspace paths.validateConfiguration({ workspaces: { 'cli/v2': {} } }) does not throw.src/config.ts#L249-L260: candidate filter calls realpathSync(resolvedMatch) at line 252 before lstatSync(resolvedMatch).isDirectory() at line 259.packages/* consequently throws ENOENT, failing workspace listing/config resolution instead of being skipped.does not expand workspace globs through symlinked directories test in src/__tests__/config.test.ts.src/__tests__/config.test.ts at Sep 8 17:10, but the new content/result has not yet been reviewed. Production src/config.ts was not yet confirmed modified.loadConfigurationFromString(configContent, workspaceDirectory = process.cwd()); config-from resolves against Git top-level.src/config.ts:210-229: a concrete workspace matching multiple configured patterns throws ConfigurationError: Workspace "${workspaceName}" matches multiple workspace patterns: ${matchingKeys.join(', ')}.src/config.ts:231-263: getWorkspaceGlobMatches() validates glob safety, uses globSync(... { absolute: false, cwd: root, dot: true, ignore: ['**/node_modules/**'], posix: true }), and currently admits sorted safe lexical/realpath-contained directories—but has the newly identified broken-symlink ordering bug.src/config.ts:269-390 contains path/glob safety and balanced-brace helpers duplicating analogous project_config.ts helpers. isWorkspacePattern() uses hasMagic(... { magicalBraces: true }).src/config.ts:392-409: isVersionGteMinVersion() is a pure config-resolution-safe check and returns false for absent/unparseable versions.src/schemas/project_config.ts:208-215: WorkspaceSchema accepts release-unit fields and partial GitHub config but rejects workspace github.projectPath with Workspace github.projectPath is not supported.src/schemas/project_config.ts:219-334: workspace glob safety rejects unsafe empty/dot/parent/prototype/leading-dash segments; supports safe glob magic and finite balanced brace alternatives; unsafe paths raise Workspace paths must use safe ASCII segments.src/schemas/project_config.ts:322-334: literal multi-segment paths are accepted without normalization.src/commands/prepare.ts:806-812 resolves remote config workspace globs relative to Git top-level; src/config.ts:597-606 accepts the explicit root for string config.action.yml:74-92: validate before side effects; :191-224: clear inherited CRAFT_WORKSPACE; :245-275: emit complete exact titles.src/utils/publishState.ts:51-105: preserve workspace/version identities losslessly.CalVerConfigSchema: optional offset: z.number() (default documented as 14) and optional format: z.string() (default %y.%-m; supports %y, %m, %-m).VersioningConfigSchema: optional policy of auto, manual, or calver, plus optional calver.ChangelogConfigSchema: string or object with optional filePath, policy (auto, simple, none), and scopeGrouping.releaseUnitFields: optional github, targets, preReleaseCommand, postReleaseCommand, releaseBranchPrefix, changelog, changelogPolicy, requireNames, statusProvider, artifactProvider, versioning, and noMerge; noMerge defaults to true for compiled GitHub Actions with dist/.WorkspaceSchema uses all optional release-unit fields, with partial workspace GitHub settings that inherit missing top-level values.WorkspaceNameSchema errors:
Workspace name "__proto__" is not supported.Workspace names cannot be "." or "..".Workspace paths must use safe ASCII segments.CraftProjectConfigSchema.superRefine() rejects top-level github.projectPath when workspaces exist with Workspace configurations cannot use github.projectPath..tsc --noEmit, format, build, and git diff --check passed.vitest run -- src/__tests__/config.test.ts actually ran the full suite: 61 test files passed, 1,197 tests passed, 1 skipped (1,198 total), duration 62.99s.src/targets/__tests__/symbolCollector.test.ts:58-60,68-70 that assignments to imported checkExecutableIsPresent will throw; it also logged remote-ref/branch fetch failures that used cached refs.pnpm exec tsc --noEmit --incremental false; Prettier on every changed file; focused Vitest across 5 files with 141 passing; full Vitest across 61 files with 1,197 passing / 1 skipped; ESLint 0 errors. Five unchanged no-unused-vars warnings in publish.ts also exist on origin/master.prepareMain mock assertion that --config-from passes git rev-parse --show-toplevel into workspace resolution; existing loadConfigurationFromString coverage verifies equivalent root contract.docs/src/content/docs/targets/github.md:89, original line 87, comment PRRC_kwDOCDHbwM7pfr4E, created Sep 2 18:33:13 UTC.src/__tests__/config.test.ts:164, original line 163, comment PRRC_kwDOCDHbwM7pftIQ, created Sep 2 18:33:53 UTC. Reply/resolve occurred Sep 8 17:00 at https://github.com/getsentry/craft/pull/872#discussion_r3960329900.src/config.ts#L249-L260, bug ID 294d500e-a01e-4627-af9f-b3d497c9b290, discussion https://github.com/getsentry/craft/pull/872#discussion_r3960382720./home/byk/Code/getsentry/craft: b06435e4f20ff8cb0470de98ee113051978b3d63, byk/fix/commit-on-repo/home/byk/.local/share/opencode/worktree/55fa901aca64a01fa4b5c2abce1c85c1c27475e7/calm-circuit: 5d533c854ad481c31162c4e003cabe23ac5e900a, feat/ci-ready-signal.../calm-squid: 347ade0345dc9f46bce480600ca2beef66100c8f, fix/postcss-security-alert.../stellar-falcon: fc4c1d00d721eb76d9ccc46f841cb2b4b03ed665, byk/fix/dependabot-alerts-865.../swift-squid: 752a693b6ddc3d9b855ddb921e3f91d6e3a847b8, fix/flaky-zip-test/home/byk/Code/getsentry/craft-vercel-prebuilt-output: 3f701f5458f5dee92c730b9c7352d1e5b6ef2b56, fix/vercel-prebuilt-output/home/byk/Code/getsentry/craft-vercel-project-config: 3cceffbf4d6e697c535ec11f83652bcb11800a06, fix/vercel-project-config/home/byk/Code/getsentry/craft-workspaces-schema: ab635721cdaee8a3fe5ec853505e68ff76f8b9c5, feat/workspaces-schema/tmp/opencode/pr865: 51cab289873990824bcfc9c17e7309c430ea2059, byk/pr865-fixes; marked prunable because its gitdir points to a nonexistent location./home/byk/Code/getsentry/publish-workspace-acceptancefeat/workspace-acceptanceb658ffa fix: validate publish workspace JSON, 52ef600 feat: resolve compact workspace publish requests, a81ab03 feat: resolve workspace publish paths.a81ab03 was pushed Sep 5 03:46 (52ef600..a81ab03), with 13 files / 308 insertions / 539 deletions and new src/modules/publish-issue-validation.js.fd1e115 fix: address publish workspace review feedbacka81ab03..fd1e115.src/modules/__tests__/ci-poller-workflow.jssrc/modules/__tests__/generate-publish-issue-title-parser.jssrc/publish/__tests__/discover-location.jssrc/publish/__tests__/resolve-location.jssrc/publish/__tests__/resolve-release-revision.jssrc/publish/discover-location.js.github/workflows/ci-poller.yml.github/workflows/publish.ymldocs/publish-issue-format.mdscripts/generate-publish-issue-title-parser.jssrc/modules/__tests__/details-from-context.jssrc/modules/__tests__/publish-workflow.jssrc/modules/__tests__/release-revision.jssrc/modules/details-from-context.jssrc/modules/publish-issue-title.jssrc/modules/publish-issue-title.peggysrc/modules/release-revision.jssrc/publish/inputs.jssrc/publish/resolve-ci-poller-input.jssrc/publish/resolve-location.jssrc/publish/resolve-release-revision.jssrc/modules/publish-location.js validates safe paths/workspace names; discovery-invalid error: Craft workspace discovery returned an invalid workspace list. Exact matching is case-sensitive.details-from-context.js and ci-poller-input.js validate title fields before state, checkout, Craft, network, or cross-repository API work.ci-ready, accepted + ci-ready, open issue, no pending/failed labels, 90-minute timeout.ref: ${{ steps.release-revision.outputs.revision }}, path __repo__, Release Bot token, fetch-depth: 0; craft publish ... --rev and state behavior remain preserved.workflow_dispatch remains in ci-poller.yml, optional internal attempt default "0".src/publish/inputs.js: core.setOutput("result", JSON.stringify(result)).src/publish/resolve-location.js: parses PUBLISH_ARGS || "{}" and CRAFT_WORKSPACE_NAMES || "[]", serializes location output.src/publish/resolve-release-revision.js: parses PUBLISH_ARGS || "{}" and requires repo.src/publish/discover-location.js exports getWorkspaceNames({ repositoryDirectory, exists = existsSync, execFile = execFileSync }) and discoverLocation(...); missing root .craft.yml returns []; root config invokes Docker/Craft workspace list; blank/malformed/non-array/unsafe lists fail closed; serialized output..github/workflows/publish.yml invokes node .__publish__/src/publish/discover-location.js with PUBLISH_ARGS and PUBLISH_REPOSITORY_DIRECTORY: __repo__..github/workflows/publish.yml:120 and :159, plus .github/workflows/ci-poller.yml:52, use actions/checkout@v7; unrelated test.yml:19 and auto-approve.yml:16 remain unchanged.src/modules/publish-issue-title.peggy:7-34 contains title grammar markers; :36-85 contains canonical strict release header/merge-target parsing.checks URL with a lowercase SHA; supports LF/CRLF and optional terminal /checks/ slash; starts at body byte zero.NonNewline yielded merge-target character arrays) was fixed via string capture conversion; parser regenerated.src/modules/release-revision.js:7-45 uses generated parser, globally counts duplicate check-runs link prefixes, validates repository binding, and indexed-replaces only canonical SHA offsets.src/modules/details-from-context.js:54-75 draws Merge target only from canonical parser output.src/publish/resolve-ci-poller-input.js reads UTF-8 PUBLISH_ISSUE_BODY_FILE when set, otherwise PUBLISH_ISSUE_BODY || ""..github/workflows/ci-poller.yml:157-162 rejects invalid rewrite shapes and requires a nonempty string .issueBody.src/modules/__tests__/ci-poller-workflow.js executes extracted actual workflow shell with fake node, mktemp, and gh..issueBody, resolver failure, exact valid-body preservation, no issue edit on failures, and temporary-file cleanup. It covers six error/body-preservation paths.scripts/generate-publish-issue-title-parser.js:26-49 rejects missing, duplicate, and malformed marker-like generated documentation regions.src/modules/publish-issue-title.peggy:7-34 and docs/publish-issue-format.md:12-41.git diff --check passed.git diff --check a81ab03, generated check, lint), but full test was intentionally not run under read-only constraint.yarn vitest run src/modules/__tests__/ci-poller-workflow.js passed 1 file/6 tests in 704 ms. Full verification then passed: ESLint, generated check, Vitest 14 files/94 tests in 3.86s, and git diff --check.src/modules/__tests__/ci-poller-workflow.js:40-49,146-150 creates/deletes temp files, contrary to read-only audit constraints.24.0.0, Yarn 1.22.22.generate, check:generated, test = yarn check:generated && vitest run, lint = eslint src .github --ignore-pattern '!.github'.Error: There is no jj repo in "."; use Git.34229471266 job 102071692353; CodeQL Analyze (javascript), same run job 102071692687; Secret Scan run 34229476340 job 102071704595; Test/unit tests run 34229476353 job 102071704707; Warden run 34229476597 job 102071706138; Cursor Bugbot; Seer Code Review; Socket Security Pull Request Alerts; semgrep-cloud-platform/scan.34229476334 job 102071704447 (13:01:47–13:01:57); Socket Security Project Report (13:01:48–13:01:55), SBOM 04da4c5d-3d7e-41d4-b361-42d238cc300f.d48b906 feat: support concrete release workspaces created Sep 5 03:34, pushed 03:43.a81ab03 feat: resolve workspace publish paths created Sep 5 03:40, pushed 03:46.a81ab03 and required review.fd1e115 (21 files, +1,509/-96) and pushed successfully.fd1e1156ae878a12a276af401a15a656bfff8127; review decision remained REVIEW_REQUIRED, with CI beginning.repo-setup before situation skills; Outpost AGENTS.md instructions were read.cli/v2 is a valid concrete path, not legacy syntax; user explicitly requested test renaming instead of removal..sentryclirc upward/global resolution, walk-up.ts, and scan walker.it(...); actual test used test('allows legacy workspace names', ...).allows multi-segment workspace paths.globSync discovery; recommended against introducing async walker complexity unless profiling proves a workspace-expansion bottleneck.f174cea at 16:03; exact PR head became f174ceafa57355e71617f32ba1b0a030953be0a2.NEUTRAL and opened a valid medium-severity finding: broken symlink workspace glob candidates throw from realpathSync before directory filtering.src/config.ts:249-260, and selected placement for the regression test beside symlinked-directory glob tests.src/__tests__/config.test.ts at 17:10; inspect its contents, reproduce current failure, complete minimal production fix, and rerun verification before any readiness claim.