Dashboard › craft › Session 0pacOhGGVJ30
0pacOhGGVJ30mcjXaPerform a strict final READ-ONLY, immutable adversarial audit of the current uncommitted diffs and relevant source in BOTH worktrees. Do not edit or run mutating commands.
IMPORTANT: getsentry/craft:latest is an intentional REQUIRED Publish contract. It must remain floating so controller always has latest released Craft workspace capabilities. The CI-approved target SHA checkout and craft publish --rev bind repository operations. Do not report the latest image as a finding.
The preceding audit found malformed braces were accepted because invalid expansion returned [] and Array.every returned true. Recheck that exact issue and tests first:
packages/{cli and packages/{cli} must fail validation before Glob access;packages/{cli,mcp} must work;Then review the full release contract: poller semantic repo/version/path validation before release/API work; lossless identical Craft/Publish state-version encoding; action pre-side-effect path/workspace validation and clearing inherited CRAFT_WORKSPACE; full exact workspace title and mutual exclusion; SHA checkout then discovery with exact match/missing-config fallback; fresh accepted ci-ready gate; external state and --rev; parser/generated/docs/test parity; diff hygiene.
Return severity-ranked cited findings (current file:line only). Give PASS/CONCERN/MUST-FIX for each contract. End exactly MERGE or DO-NOT-MERGE. If tooling blocks you, begin BLOCKED and state exact tool/error. Never return empty.
<path>/home/byk/Code/getsentry/craft-workspace-action-propagation</path> <type>directory</type> <entries> .craft.yml .dockerignore .eslintcache .git .github/ .gitignore .lore.md .nojekyll .npmignore .prettierignore .prettierrc.yml .tsbuildinfo .vscode/ action.yml AGENTS.md blog-post-draft.md build.mjs CHANGELOG.md CONTRIBUTING.md dist/ Dockerfile docs/ eslint.config.mjs img/ LICENSE node_modules/ package.json pnpm-lock.yaml README.md src/ tsconfig.build.json tsconfig.json vitest.config.mts (33 entries) </entries>