Conversation
release-candidate.yml pasted `${{ inputs.tag }}` straight into the
dagger-for-github `args`, which the action splices into bash. A crafted tag
could inject arguments or commands. The tag now reaches the step only as the
TAG environment variable and the args hold only double-quoted variables, the
same shape as edge-proc#76. publish.yml gets the same treatment for the
workflow_run head SHA.
The workflow test that asserted `--tag=${{ inputs.tag }}` in the args is
inverted: it asserted the defect as the contract.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015oBArfm762nN1r4F4Fst5a
Debian published libjq1 1.7.1-6+deb13u4, so the u3 jq pin can no longer be installed and the Dagger base image fails with exit 100. This is the same one-line bump as #73, so the two branches merge cleanly in either order. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015oBArfm762nN1r4F4Fst5a
Both publish jobs (PyPI and npm) now start with portfolio-foundation's release-lineage, pinned at hseshadr/ci#50 head 3de1c4b. The job `if` (head_branch == default_branch) also passes for a dispatch on a tag named `main`; the lineage call proves from GitHub's run records that the candidate is a successful release-candidate.yml dispatch for exactly HEAD_SHA and that main contains it, before any artifact is downloaded. Jobs gain contents:read (compare/ and branches/main). Contract tests that pinned the old two-permission set and step lists are updated; the surface budget moves 700 -> 720 for the two required lineage steps. Draft: re-pin to the ci merge SHA after hseshadr/ci#50 merges. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015oBArfm762nN1r4F4Fst5a
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Reopened from #75, which GitHub closed when its stacked base (#74, now squash-merged) was deleted. Same branch.
TL;DR
Draft on purpose. Pinned to hseshadr/ci#50 head
3de1c4b. That commit is not on cimainuntil #50 merges. Re-pin to the ci merge SHA after ci merges, then mark ready.Stacked on #74 (
fix/release-tag-injection), which already moves event values inpublish.ymlintoenv:. Base is #74's branch; GitHub retargets tomainonce #74 merges.Both publish jobs (
publish-python,publish-npm) now start withportfolio-foundation'srelease-lineage, exactly the step ci#50's fleet policy accepts. The jobif(head_branch == default_branch) also passes for aworkflow_dispatchon a tag namedmain. The lineage call proves from GitHub's run records that the candidate run is a successfulrelease-candidate.ymldispatch here for exactlyHEAD_SHA, and thatmaincontains it, before any artifact is downloaded.Claim touched: "a publisher only publishes bytes whose candidate run came from main".
Contract changes (called out on purpose)
contents: read: the lineage proof readscompare/andbranches/main.test_workflow_securityandtest_release_contractpinned{actions: read, id-token: write}; they now pin the three-key set the fleet policy allows (same as edgeproc-core#60 / privacy-core#49).test_should_reduce_the_total_dagger_and_workflow_surfacebudget: 700 → 720 lines, for the two required lineage steps. No repository logic added.Evidence
test_workflow_security.py,test_workflow_contract.py)--publish-run-idpublisher-lineage${{ github.event.workflow_run.head_sha }}into lineage argsfeat/require-publish-lineage)validate_workflowon all four workflowspoe lint,fmt-check,typecheck,complexity,workflow-security(zizmor),workflow-lint(actionlint)poe testlocallygit merge-treevsmain, #74, #73Merge order
module:SHA to ci#50's merge SHA and mark ready.feat/require-publish-lineage(which makes the lineage step required).Not verified
🤖 Generated with Claude Code
https://claude.ai/code/session_015oBArfm762nN1r4F4Fst5a