Dashboard › craft › Session 11Z93ZIksjRD
11Z93ZIksjRDKnh07Perform the final strict, read-only adversarial audit of the current uncommitted review-fix worktree at /home/byk/Code/getsentry/publish-workspace-acceptance. Do NOT edit, format, regenerate, write files, or mutate repository state. Audit full diff vs branch baseline a81ab03 and relevant sources/tests. This replaces earlier audits and must inspect exact current content. Require exact cited results for: canonical request header begins at body start, exact repo binding, strict lowercase SHA and /checks with optional terminal slash, global duplicate check-runs detection, canonical merge-target authority and valid target grammar, validated indexed replacement and all non-revision bytes preserved; CI poller must safely skip errors without bad Bash control flow, never edit an issue with missing/invalid resolver body, preserve trailing bytes, clean temp files, and have executable harness coverage; docs generator must reject missing/malformed/duplicate markers and parser/docs remain generated-parity; output serialization and valid JSON fallbacks; actions checkout v7 in ci-poller and requested publish checkouts, preserving scope by not requiring unrelated workflow upgrades; fresh ci-ready label gating, workflow_dispatch, exact SHA checkout then fail-closed workspace discovery, intentional getsentry/craft:latest; test and diff hygiene incl no unrelated CocoaPods churn. Run only non-mutating checks. Report severity ordered findings with file:line, explicit PASS/FAIL each concern and test gaps. End exactly MERGE or DO-NOT-MERGE. If any blocker prevents review, name it and end DO-NOT-MERGE.
<path>/home/byk/Code/getsentry/publish-workspace-acceptance</path> <type>directory</type> <entries> .eslintrc.js .git .github/ .gitignore AGENTS.md auto-approve-repos.txt docs/ LICENSE node_modules/ package.json README.md scripts/ src/ vitest.config.js yarn.lock (15 entries) </entries>
<path>/home/byk/Code/getsentry/publish-workspace-acceptance/AGENTS.md</path> <type>file</type> <content> 1: # AGENTS.md - Coding Agent Guidelines 2: 3: This document provides guidelines for AI coding agents working in this repository. 4: 5: ## Project Overview 6: 7: This is the **Sentry Publish Repository** - a GitHub Actions-based approval system for publishing releases across multiple Sentry projects using [Craft](https://github.com/getsentry/craft). It's a pure JavaScript (Node.js 24.0.0) project using CommonJS modules. 8: 9: ## Build/Lint/Test Commands 10: 11: ### Package Manager 12: 13: - **Yarn 1.22.22** (classic) - Do NOT use npm 14: - Version management via Volta (pinned in package.json) 15: 16: ### Commands 17: 18: ```bash 19: # Install dependencies 20: yarn install 21: 22: # Run all tests 23: yarn test 24: 25: # Run tests in watch mode 26: yarn test:watch 27: 28: # Run a single test file 29: yarn test src/modules/__tests__/update-issue.js 30: 31: # Run tests ...
<path>/home/byk/Code/getsentry/publish-workspace-acceptance/package.json</path>
<type>file</type>
<content>
1: {
2: "name": "publish",
3: "private": true,
4: "version": "0.0.1",
5: "description": "Approval-based publishing system for Sentry",
6: "main": "index.js",
7: "repository": "git@github.com:getsentry/publish.git",
8: "author": "Sentry Open Source <oss@sentry.io>",
9: "license": "Apache-2.0",
10: "volta": {
11: "node": "24.0.0",
12: "yarn": "1.22.22"
13: },
14: "resolutions": {
15: "undici": "^6.23.0"
16: },
17: "scripts": {
18: "generate": "node scripts/generate-publish-issue-title-parser.js",
19: "check:generated": "node scripts/generate-publish-issue-title-parser.js --check",
20: "test": "yarn check:generated && vitest run",
21: "test:watch": "vitest",
22: "lint": "eslint src .github --ignore-pattern '!.github'",
23: "prettier": "prettier --write src"
24: },
25: "devDependencies": {
26: "eslint": ...
M .github/workflows/ci-poller.yml M .github/workflows/publish.yml M docs/publish-issue-format.md M scripts/generate-publish-issue-title-parser.js M src/modules/__tests__/details-from-context.js M src/modules/__tests__/publish-workflow.js M src/modules/__tests__/release-revision.js M src/modules/details-from-context.js M src/modules/publish-issue-title.js M src/modules/publish-issue-title.peggy M src/modules/release-revision.js M src/publish/inputs.js M src/publish/resolve-ci-poller-input.js M src/publish/resolve-location.js M src/publish/resolve-release-revision.js ?? src/modules/__tests__/ci-poller-workflow.js ?? src/modules/__tests__/generate-publish-issue-title-parser.js ?? src/publish/__tests__/ ?? ...
diff --git a/.github/workflows/ci-poller.yml b/.github/workflows/ci-poller.yml
index 324b63f8f042b1989178157ec71b76464f9db6c7..a04d7f8a5de3362d0ccd9d52479bd33b178af92a 100644
--- a/.github/workflows/ci-poller.yml
+++ b/.github/workflows/ci-poller.yml
@@ -49,7 +49,7 @@ jobs:
owner: getsentry # create token with access to all getsentry repos
- name: Check out publish controller
- uses: actions/checkout@v5
+ uses: actions/checkout@v7
with:
path: .__publish__
@@ -93,14 +93,19 @@ jobs:
# Check each issue's CI status
echo "$issues" | jq -c '.[]' | while read -r issue; do
+ (
number=$(echo "$issue" | jq -r '.number')
title=$(echo "$issue" | jq -r '.title')
- body=$(echo "$issue" | jq -r '.body')
+ body_file=$(mktemp)
+ resolver_output_file=""
+ updated_body_file=""
+ trap 'for file in "${body_file:-}" ...
/home/byk/Code/getsentry/publish-workspace-acceptance/src/publish/__tests__/discover-location.js /home/byk/Code/getsentry/publish-workspace-acceptance/src/publish/__tests__/resolve-release-revision.js /home/byk/Code/getsentry/publish-workspace-acceptance/src/publish/__tests__/resolve-location.js
<path>/home/byk/Code/getsentry/publish-workspace-acceptance/src/modules/publish-issue-title.peggy</path>
<type>file</type>
<content>
1: {
2: function join(characters) {
3: return characters.join("");
4: }
5: }
6:
7: // BEGIN TITLE GRAMMAR
8: // Canonical grammar for publish issue titles. A path suffix is syntactic only:
9: // the controller resolves the complete suffix as a workspace after checking
10: // out the CI-approved revision.
11: PublishIssueTitle
12: = "publish: " "getsentry/"? repo:Repository path:Path? "@" version:Version !. {
13: return {
14: repo,
15: path: path || "",
16: version,
17: };
18: }
19:
20: Repository
21: = characters:RepositoryCharacter+ { return join(characters); }
22:
23: RepositoryCharacter
24: = [A-Za-z0-9_.-]
25:
26: Path
27: = segments:("/" segment:PathSegment { return `/${segment}`; })+ { return join(segments); }
28:
29: PathSegment
30: = characters:RepositoryCharacter+ { return ...
<path>/home/byk/Code/getsentry/publish-workspace-acceptance/src/modules/release-revision.js</path>
<type>file</type>
<content>
1: const { parse } = require("./publish-issue-title");
2:
3: function isRevision(revision) {
4: return /^[0-9a-f]{40}$/.test(revision);
5: }
6:
7: function getReleaseRevisionDetails({ issueBody, repo }) {
8: if (
9: parse(issueBody, { startRule: "CheckRunsLinkCount" }) !== 1
10: ) {
11: throw new Error(
12: `Expected exactly one View check runs link in Quick links for getsentry/${repo}.`
13: );
14: }
15:
16: let details;
17: try {
18: details = parse(issueBody, { startRule: "ReleaseRevision" });
19: } catch {
20: throw new Error(
21: `Expected a View check runs link for getsentry/${repo} in the publish issue body.`
22: );
23: }
24:
25: if (details.repo !== repo) {
26: throw new Error(
27: `Expected a View check runs link for getsentry/${repo} in the publish issue body.`
28: );
29: }
30: ...
<path>/home/byk/Code/getsentry/publish-workspace-acceptance/src/modules/ci-poller-input.js</path>
<type>file</type>
<content>
1: const { parse: parsePublishIssueTitle } = require("./publish-issue-title");
2: const {
3: getReleaseRevision,
4: updateReleaseRevision,
5: } = require("./release-revision");
6: const {
7: isPublishRepository,
8: isReleaseVersion,
9: } = require("./publish-issue-validation");
10: const { isPublishPath } = require("./publish-location");
11:
12: function getCiPollerInput({ title, issueBody, revision }) {
13: let parsedTitle;
14: try {
15: parsedTitle = parsePublishIssueTitle(title);
16: } catch {
17: throw new Error(`Invalid publish issue title: '${title}'`);
18: }
19: const { repo, version } = parsedTitle;
20: if (!isPublishRepository(repo)) {
21: throw new Error(`Invalid publish issue repository: '${repo}'`);
22: }
23: if (!isReleaseVersion(version)) {
24: throw new Error(`Invalid publish issue version: ...
<path>/home/byk/Code/getsentry/publish-workspace-acceptance/.github/workflows/ci-poller.yml</path> <type>file</type> <content> 1: name: CI Status Poller 2: 3: on: 4: schedule: 5: - cron: "*/5 * * * *" 6: workflow_dispatch: 7: inputs: 8: attempt: 9: description: Self-dispatch attempt counter (internal use) 10: required: false 11: default: "0" 12: 13: permissions: 14: contents: read 15: issues: read 16: 17: jobs: 18: check-ci: 19: runs-on: ubuntu-latest 20: environment: production 21: # Skip entirely (no runner provisioned) when there's nothing to check. 22: # Set to "true" by ci-pending.yml, reset to "false" here when done. 23: # Always allow workflow_dispatch for manual recovery. 24: if: vars.CI_POLLER_HAS_PENDING == 'true' || github.event_name == 'workflow_dispatch' 25: concurrency: 26: group: ci-status-poller 27: cancel-in-progress: false 28: steps: 29: # sentry-internal-app token ...
Found 48 matches
/home/byk/Code/getsentry/publish-workspace-acceptance/src/modules/release-revision.js:
Line 9: parse(issueBody, { startRule: "CheckRunsLinkCount" }) !== 1
Line 12: `Expected exactly one View check runs link in Quick links for getsentry/${repo}.`
Line 21: `Expected a View check runs link for getsentry/${repo} in the publish issue body.`
Line 27: `Expected a View check runs link for getsentry/${repo} in the publish issue body.`
/home/byk/Code/getsentry/publish-workspace-acceptance/src/modules/publish-issue-title.js:
Line 200: CheckRunsLinkCount: peg$parseCheckRunsLinkCount,
Line 209: const peg$c5 = "Merge target: ";
Line 213: const peg$c9 = "- [View check runs](https://github.com/getsentry/";
Line 216: const peg$c12 = "- [View check runs](";
Line 247: const peg$e8 = peg$literalExpectation("Merge target: ", false);
Line 252: "- [View check runs](https://github.com/getsentry/",
Line 266: const ...
<path>/home/byk/Code/getsentry/publish-workspace-acceptance/src/modules/__tests__/release-revision.js</path>
<type>file</type>
<content>
1: import { expect, test } from "vitest";
2:
3: const {
4: getReleaseRevision,
5: updateReleaseRevision,
6: } = require("../release-revision.js");
7:
8: const REVISION = "7e5ca7ed5581552de066e2a8bc295b8306be38ac";
9:
10: function requestBody(quickLinks) {
11: return `Requested by: @byk
12:
13: Merge target: (default)
14:
15: Quick links:
16: ${quickLinks}`;
17: }
18:
19: function canonicalQuickLinks(revision = REVISION) {
20: return `- [View changes](https://github.com/getsentry/toolkit/compare/1.2.2...release/1.2.3)
21: - [View check runs](https://github.com/getsentry/toolkit/commit/${revision}/checks/)`;
22: }
23:
24: test("gets the CI-approved revision from the request header", () => {
25: expect(
26: getReleaseRevision({
27: repo: "toolkit",
28: issueBody: requestBody(canonicalQuickLinks()),
29: })
30: ...
<path>/home/byk/Code/getsentry/publish-workspace-acceptance/src/modules/__tests__/ci-poller-workflow.js</path>
<type>file</type>
<content>
1: import {
2: mkdtempSync,
3: mkdirSync,
4: readFileSync,
5: readdirSync,
6: rmSync,
7: writeFileSync,
8: } from "fs";
9: import { tmpdir } from "os";
10: import { join } from "path";
11: import { spawnSync } from "child_process";
12:
13: import { afterEach, expect, test } from "vitest";
14:
15: const temporaryDirectories = [];
16: const INITIAL_REVISION = "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa";
17: const UPDATED_REVISION = "bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb";
18:
19: function getPollerScript() {
20: const workflow = readFileSync(
21: join(__dirname, "../../../.github/workflows/ci-poller.yml"),
22: "utf8"
23: );
24: const section = workflow.match(
25: / {6}- name: Check CI status for ci-pending issues[\s\S]*? {8}run: \|\n(?<script>[\s\S]*?)\n {6}- name: Check for remaining pending issues/
26: );
27: ...
<path>/home/byk/Code/getsentry/publish-workspace-acceptance/src/publish/discover-location.js</path>
<type>file</type>
<content>
1: const { execFileSync } = require("child_process");
2: const { existsSync } = require("fs");
3: const path = require("path");
4:
5: const core = require("@actions/core");
6:
7: const { resolvePublishLocation } = require("../modules/publish-location");
8:
9: function getWorkspaceNames({
10: repositoryDirectory,
11: exists = existsSync,
12: execFile = execFileSync,
13: }) {
14: if (!exists(path.join(repositoryDirectory, ".craft.yml"))) {
15: return [];
16: }
17:
18: const output = execFile(
19: "docker",
20: [
21: "run",
22: "--rm",
23: "--volume",
24: `${path.resolve(repositoryDirectory)}:/github/workspace/__repo__`,
25: "--workdir",
26: "/github/workspace/__repo__",
27: "getsentry/craft:latest",
28: "workspace",
29: "list",
30: ],
31: { encoding: "utf8" }
32: );
33: ...
<path>/home/byk/Code/getsentry/publish-workspace-acceptance/src/publish/__tests__/discover-location.js</path>
<type>file</type>
<content>
1: import { afterEach, expect, test, vi } from "vitest";
2:
3: const { discoverLocation, getWorkspaceNames } = require("../discover-location.js");
4:
5: afterEach(() => {
6: vi.restoreAllMocks();
7: });
8:
9: test("retains checkout-path behavior when the root config is absent", () => {
10: expect(
11: discoverLocation({
12: input: { path: "./packages/cli" },
13: repositoryDirectory: "__repo__",
14: exists: () => false,
15: })
16: ).toEqual({ path: "./packages/cli" });
17: });
18:
19: test("discovers exact workspace paths using the released Craft image", () => {
20: const execFile = vi.fn(() => '["packages/CLI"]');
21:
22: expect(
23: discoverLocation({
24: input: { path: "./packages/CLI" },
25: repositoryDirectory: "__repo__",
26: exists: () => true,
27: execFile,
28: })
29: ...
<path>/home/byk/Code/getsentry/publish-workspace-acceptance/src/publish/__tests__/resolve-location.js</path>
<type>file</type>
<content>
1: import { spawnSync } from "child_process";
2: import { expect, test } from "vitest";
3:
4: const script = new URL("../resolve-location.js", import.meta.url).pathname;
5:
6: test("rejects missing workflow input through location validation", () => {
7: const result = spawnSync(process.execPath, [script], {
8: encoding: "utf8",
9: env: {
10: ...process.env,
11: PUBLISH_ARGS: "",
12: CRAFT_WORKSPACE_NAMES: "[]",
13: },
14: });
15:
16: expect(result.status).not.toBe(0);
17: expect(result.stderr).toContain("Invalid publish path.");
18: expect(result.stderr).not.toContain("Unexpected end of JSON input");
19: });
(End of file - total 19 lines)
</content>
<path>/home/byk/Code/getsentry/publish-workspace-acceptance/src/publish/__tests__/resolve-release-revision.js</path>
<type>file</type>
<content>
1: import { spawnSync } from "child_process";
2: import { expect, test } from "vitest";
3:
4: const script = new URL("../resolve-release-revision.js", import.meta.url).pathname;
5:
6: test("rejects missing workflow input through release revision validation", () => {
7: const result = spawnSync(process.execPath, [script], {
8: encoding: "utf8",
9: env: {
10: ...process.env,
11: PUBLISH_ARGS: "",
12: PUBLISH_ISSUE_BODY: "",
13: },
14: });
15:
16: expect(result.status).not.toBe(0);
17: expect(result.stderr).toContain("Publish input must define a repository.");
18: expect(result.stderr).not.toContain("Unexpected end of JSON input");
19: });
(End of file - total 19 lines)
</content>
<path>/home/byk/Code/getsentry/publish-workspace-acceptance/src/modules/__tests__/generate-publish-issue-title-parser.js</path>
<type>file</type>
<content>
1: import { expect, test } from "vitest";
2:
3: const {
4: generateDocumentation,
5: } = require("../../../scripts/generate-publish-issue-title-parser.js");
6:
7: test("requires generated title grammar markers in the documentation", () => {
8: expect(() =>
9: generateDocumentation({
10: documentation: "# Publish Issue Format\n",
11: titleGrammar: 'PublishIssueTitle = "publish: "',
12: })
13: ).toThrow("Could not find the generated title grammar in the documentation.");
14: });
15:
16: test("rejects duplicate generated title grammar markers", () => {
17: expect(() =>
18: generateDocumentation({
19: documentation: `<!-- BEGIN GENERATED TITLE GRAMMAR -->
20: old
21: <!-- END GENERATED TITLE GRAMMAR -->
22: <!-- BEGIN GENERATED TITLE GRAMMAR -->
23: old
24: <!-- END GENERATED TITLE GRAMMAR ...
<path>/home/byk/Code/getsentry/publish-workspace-acceptance/src/modules/__tests__/ci-poller-input.js</path>
<type>file</type>
<content>
1: import { readFileSync } from "fs";
2: import { join } from "path";
3:
4: import { expect, test } from "vitest";
5:
6: const { getCiPollerInput } = require("../ci-poller-input.js");
7:
8: const REVISION = "7e5ca7ed5581552de066e2a8bc295b8306be38ac";
9: const issueBody = `Requested by: @byk
10:
11: Merge target: (default)
12:
13: Quick links:
14: - [View changes](https://github.com/getsentry/toolkit/compare/1.2.2...release/1.2.3)
15: - [View check runs](https://github.com/getsentry/toolkit/commit/${REVISION}/checks/)`;
16:
17: test("parses root and full-path publish titles", () => {
18: expect(
19: getCiPollerInput({
20: issueBody,
21: title: "publish: getsentry/toolkit/cli@1.2.3",
22: })
23: ).toEqual({
24: repo: "getsentry/toolkit",
25: revision: REVISION,
26: version: "1.2.3",
27: });
28:
29: ...
<path>/home/byk/Code/getsentry/publish-workspace-acceptance/src/publish/inputs.js</path>
<type>file</type>
<content>
1: const github = require('@actions/github');
2: const core = require('@actions/core');
3: const { detailsFromContext } = require('../modules/details-from-context');
4:
5: async function inputs() {
6: const result = await detailsFromContext({
7: context: github.context,
8: });
9: core.setOutput('result', JSON.stringify(result));
10: }
11:
12:
13: inputs();
(End of file - total 13 lines)
</content>
<path>/home/byk/Code/getsentry/publish-workspace-acceptance/.github/workflows/publish.yml</path>
<type>file</type>
<content>
1: name: Publish
2: on:
3: issues:
4: types: [labeled]
5:
6: concurrency:
7: # Use the issue title (e.g. "publish: getsentry/foo@1.2.3") so duplicate
8: # issues for the same repo@version share a concurrency group.
9: group: ${{ github.event.issue.title }}
10: cancel-in-progress: false
11:
12: permissions:
13: contents: read
14: issues: write
15: packages: write
16:
17: jobs:
18: # When accepted is added to a publish issue:
19: # - Add ci-pending (and remove ci-failed if retrying)
20: # - Enable the poller via CI_POLLER_HAS_PENDING=true
21: # - Comment on the issue
22: # - Trigger the poller immediately so we don't wait for the next cron tick
23: # The publish job below requires ci-ready, so it will not fire until the
24: # poller flips ci-pending → ci-ready (which also prevents publishing without
25: # CI ...
Found 5 matches /home/byk/Code/getsentry/publish-workspace-acceptance/.github/workflows/test.yml: Line 19: - uses: actions/checkout@v6 /home/byk/Code/getsentry/publish-workspace-acceptance/.github/workflows/publish.yml: Line 120: uses: actions/checkout@v6 Line 159: - uses: actions/checkout@v6 /home/byk/Code/getsentry/publish-workspace-acceptance/.github/workflows/ci-poller.yml: Line 52: uses: actions/checkout@v7 /home/byk/Code/getsentry/publish-workspace-acceptance/.github/workflows/auto-approve.yml: Line 16: - uses: actions/checkout@v4
yarn run v1.22.22 $ yarn check:generated && vitest run --printConsoleTrace $ node scripts/generate-publish-issue-title-parser.js --check [1m[46m RUN [49m[22m [36mv4.1.0 [39m[90m/home/byk/Code/getsentry/publish-workspace-acceptance[39m warning From Yarn 1.0 onwards, scripts don't require "--" for options to be forwarded. In a future version, any explicit "--" will be forwarded as-is to the scripts. [2m Test Files [22m [1m[32m14 passed[39m[22m[90m (14)[39m [2m Tests [22m [1m[32m91 passed[39m[22m[90m (91)[39m [2m Start at [22m 03:48:35 [2m Duration [22m 2.37s[2m (transform 275ms, setup 0ms, import 1.40s, tests 1.26s, environment 5ms)[22m Done in 3.58s.
yarn run v1.22.22 $ eslint src .github --ignore-pattern '!.github' Done in 1.19s.
<path>/home/byk/Code/getsentry/publish-workspace-acceptance/docs/publish-issue-format.md</path> <type>file</type> <content> 1: # Publish Issue Format 2: 3: The Publish workflow treats a publish issue as a release request. The title identifies 4: the release; the body supplies the merge target and selected targets. Do not edit the 5: title by hand unless it remains valid under this format. 6: 7: ## Title 8: 9: Every title starts with `publish: `. The following canonical Peggy grammar is 10: generated from `src/modules/publish-issue-title.peggy`: 11: 12: <!-- BEGIN GENERATED TITLE GRAMMAR --> 13: ```peggy 14: // Canonical grammar for publish issue titles. A path suffix is syntactic only: 15: // the controller resolves the complete suffix as a workspace after checking 16: // out the CI-approved revision. 17: PublishIssueTitle 18: = "publish: " "getsentry/"? repo:Repository path:Path? "@" version:Version !. ...
<path>/home/byk/Code/getsentry/publish-workspace-acceptance/src/modules/details-from-context.js</path>
<type>file</type>
<content>
1: const { parse: parsePublishIssueTitle } = require("./publish-issue-title");
2: const { getReleaseRevisionDetails } = require("./release-revision");
3: const { isPublishPath } = require("./publish-location");
4: const {
5: isPublishRepository,
6: isReleaseVersion,
7: } = require("./publish-issue-validation");
8:
9: /**
10: * Matches the entire "Targets" section of a github publish issue body.
11: */
12: const TARGETS_SECTION_PARSER_REGEX =
13: /^(?!### Targets$\s)(?: *- \[[ xX]\] \S+\s*$(?:\r?\n)?)+/m;
14:
15: /**
16: * Matches all targets of a github publish issue body in a section that was already matched and extracted with `TARGETS_PARSER_REGEX`.
17: * The "id" of the targets is captured within a capture group. ...
<path>/home/byk/Code/getsentry/publish-workspace-acceptance/src/modules/__tests__/publish-workflow.js</path>
<type>file</type>
<content>
1: import { spawnSync } from "child_process";
2: import { mkdtempSync, readFileSync, rmSync, writeFileSync } from "fs";
3: import { tmpdir } from "os";
4: import { join } from "path";
5:
6: import { afterEach, expect, test } from "vitest";
7:
8: const { resolvePublishLocation } = require("../publish-location.js");
9:
10: const temporaryDirectories = [];
11:
12: function getWorkflow() {
13: return readFileSync(
14: join(__dirname, "../../../.github/workflows/publish.yml"),
15: "utf8"
16: );
17: }
18:
19: function getSetTargetsScript() {
20: const workflow = getWorkflow();
21: const section = workflow.match(
22: / {6}- name: Set targets[\s\S]*? {8}run: \|\n(?<script>[\s\S]*?)\n {6}- uses: docker:\/\/getsentry\/craft:latest/
23: );
24: if (!section?.groups?.script) {
25: throw new Error("Missing Set targets workflow ...
/home/byk/Code/getsentry/publish-workspace-acceptance/src/publish/inputs.js
<path>/home/byk/Code/getsentry/publish-workspace-acceptance/src/publish/resolve-release-revision.js</path>
<type>file</type>
<content>
1: const core = require("@actions/core");
2: const { getReleaseRevision } = require("../modules/release-revision");
3:
4: function resolveReleaseRevision() {
5: const { repo } = JSON.parse(process.env.PUBLISH_ARGS || "{}");
6: if (!repo) {
7: throw new Error("Publish input must define a repository.");
8: }
9:
10: core.setOutput(
11: "revision",
12: getReleaseRevision({
13: issueBody: process.env.PUBLISH_ISSUE_BODY || "",
14: repo,
15: })
16: );
17: }
18:
19: resolveReleaseRevision();
(End of file - total 19 lines)
</content>
<path>/home/byk/Code/getsentry/publish-workspace-acceptance/src/modules/publish-location.js</path>
<type>file</type>
<content>
1: function resolvePublishLocation({ path, workspaceNames }) {
2: if (!isPublishPath(path)) {
3: throw new Error("Invalid publish path.");
4: }
5:
6: if (!workspaceNames.every(isWorkspaceName)) {
7: throw new Error(
8: "Craft workspace discovery returned an invalid workspace list."
9: );
10: }
11:
12: if (path === ".") {
13: return { path };
14: }
15:
16: const workspace = path.slice(2);
17: if (workspaceNames.includes(workspace)) {
18: return { path: ".", workspace };
19: }
20:
21: return { path };
22: }
23:
24: function isPublishPath(path) {
25: return (
26: typeof path === "string" &&
27: (path === "." ||
28: (path.startsWith("./") &&
29: path
30: .slice(2)
31: .split("/")
32: .every(isSafeWorkspaceSegment)))
33: );
34: }
35:
36: function ...
M .github/workflows/ci-poller.yml M .github/workflows/publish.yml M docs/publish-issue-format.md M scripts/generate-publish-issue-title-parser.js M src/modules/__tests__/details-from-context.js M src/modules/__tests__/publish-workflow.js M src/modules/__tests__/release-revision.js M src/modules/details-from-context.js M src/modules/publish-issue-title.js M src/modules/publish-issue-title.peggy M src/modules/release-revision.js M src/publish/inputs.js M src/publish/resolve-ci-poller-input.js M src/publish/resolve-location.js M src/publish/resolve-release-revision.js ?? src/modules/__tests__/ci-poller-workflow.js ?? src/modules/__tests__/generate-publish-issue-title-parser.js ?? src/publish/__tests__/ ?? ...
empty issueBody accepted
CRITICAL — empty resolver body can erase an issue.
.github/workflows/ci-poller.yml:157 accepts any string, including ""; line 162 then edits the issue from that empty file. A read-only jq check confirmed {"issueBody":""} passes. The harness only covers a missing property at src/modules/__tests__/ci-poller-workflow.js:160-166, not an empty string.
MAJOR — required Publish checkouts remain on v6.
CI poller uses v7 at .github/workflows/ci-poller.yml:52, but both requested Publish checkouts remain actions/checkout@v6 at .github/workflows/publish.yml:120,159. src/modules/__tests__/publish-workflow.js:63-97 does not assert the required versions.
MINOR — indexed-replacement preservation lacks a strict regression.
src/modules/release-revision.js:38-45 correctly validates the replacement SHA and slices only its parsed offsets, but src/modules/__tests__/release-revision.js:127-134 only asserts toContain. Add an equality assertion covering CRLF, trailing bytes, and unrelated appended content.
| Concern | Result | Evidence |
|---|---|---|
| Header starts at body start | PASS | publish-issue-title.peggy:38-47; test release-revision.js:116-125 |
| Exact repository binding | PASS | release-revision.js:25-29; test lines 60-72 |
| Lowercase 40-char SHA; /checks optional slash | PASS | Grammar lines 46, 50-56; tests lines 42-58, 136-146 |
| Global duplicate check-runs detection | PASS | Grammar lines 58-62; release-revision.js:7-14; tests lines 74-102 |
| Canonical merge-target authority and grammar | PASS | Grammar lines 41-47, 81-83; details-from-context.js:54-72 |
| Indexed update implementation | PASS, test gap above | release-revision.js:38-45 |
| Poller error skips use isolated subshell exits | PASS | Workflow lines 95-109, 171-200, 255 |
| Missing/non-string resolver body is blocked | PASS | Workflow lines 157-161 |
| Empty resolver body is blocked | FAIL | Workflow ...
Date: September 8, 2026 * 🟡 (03:48) `yarn run v1.22.22` ran `eslint src .github --ignore-pattern '!.github'` successfully in `1.19s`. * 🔴 (03:49) User stated that new Craft requests always include the checkout repository identity. * 🔴 (03:49) User stated that a workspace release uses its full concrete path as the publish-issue title suffix, e.g. `publish: getsentry/sentry@21.3.1` and `publish:…
Date: September 8, 2026 * 🔴 (03:48) User stated that the CI poller always adds `ci-ready` after checking CI; `waiting-for-ci` removes any existing `ci-ready` first so the fresh label event triggers the publish happy path. * 🟡 (03:48) `.github/workflows/publish.yml` `waiting-for-ci` job runs in `production` on labeled, open `publish: ` issues when the added label is `accepted`; workflow concurre…
Date: September 8, 2026 * 🔴 (03:47) User stated/preferred: always allow `workflow_dispatch` for manual recovery. * 🟡 (03:47) `.github/workflows/ci-poller.yml` runs on schedule `*/5 * * * *` and `workflow_dispatch`, with optional `attempt` input defaulting to `"0"`; its `check-ci` job gate is `vars.CI_POLLER_HAS_PENDING == 'true' || github.event_name == 'workflow_dispatch'`, enabling manual reco…
Date: September 8, 2026 * 🔴 (03:46) User stated/preferred: always include the checkout repository identity. * 🟡 (03:46) `.github/workflows/ci-poller.yml` changes `actions/checkout@v5` to `actions/checkout@v7` for the “Check out publish controller” step, retaining checkout path `.__publish__`. * 🟡 (03:46) `.github/workflows/ci-poller.yml` refactors per-issue processing in the `while read -r iss…
Date: September 8, 2026 * 🟡 [requested-audit] (03:46) User requested a final strict, read-only adversarial audit of the current uncommitted review-fix worktree at `/home/byk/Code/getsentry/publish-workspace-acceptance`, superseding earlier audits. Audit must inspect the exact current content, full diff against baseline `a81ab03`, and relevant sources/tests. * 🔴 [enforced-read-only] (03:46) User…