Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/actions/vantio-prove/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ runs:
using: composite
steps:
- name: Setup Node
uses: actions/setup-node@v4
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4
with:
node-version: "22"

Expand All @@ -41,7 +41,7 @@ runs:
fi

- name: Upload proof
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
with:
name: vantio-proof
path: ${{ inputs.working-directory }}/${{ inputs.output-path }}
Expand Down
4 changes: 2 additions & 2 deletions docs/programs/release-engineering/00-INVENTORY.md
Original file line number Diff line number Diff line change
Expand Up @@ -39,9 +39,9 @@ Python wheel `vantio_agent_sdk-3.1.0-py3-none-any.whl` is pinned at 39235 bytes,
- Root `packageManager` names pnpm `11.13.0` and carries a `sha512` integrity string.
- `pnpm-lock.yaml` is present. Its SHA-256 is in the pin report. Lockfile importers record resolved versions for the workspace dependency ranges.
- `scripts/release/stage_sealed_pypi.py` pins the Python 3.1.0 filenames, byte lengths, and SHA-256 values. Dispatch inputs cannot replace them.
- Workflow files under `.github/workflows/` pin third-party actions to commit SHAs with tag comments. The pin report records those as `owner/name@sha # tag` with `digest_pinned: true`. `.github/actions/vantio-prove/action.yml` still uses floating `@v4` refs, and those two stay `digest_pinned: false`.
- Workflow files under `.github/workflows/` and the local composite `.github/actions/vantio-prove/action.yml` pin third-party actions to commit SHAs with tag comments. The pin report records those as `owner/name@sha # tag` with `digest_pinned: true`.
- `packages/vantio-agent-sdk-py/pyproject.toml` requires `hatchling` with no version comparator.
- CI and the provenance workflow install with `pnpm install --frozen-lockfile`. That binds the install to the lockfile. The local composite action refs and the Python build backend stay unpinned.
- CI and the provenance workflow install with `pnpm install --frozen-lockfile`. That binds the install to the lockfile. The Python build backend stays unpinned.

`npm-publish.yml`, `pypi-publish.yml`, and `mcp-registry-publish.yml` trigger on `workflow_dispatch`. `ci.yml` triggers on push and builds candidate artifacts. The candidate job packs and builds. It performs no registry write.

Expand Down
16 changes: 1 addition & 15 deletions docs/programs/release-engineering/dossiers/optics-public.json
Original file line number Diff line number Diff line change
Expand Up @@ -56,20 +56,6 @@
"name": "cli-tarball",
"required_for_publish": true,
"value": "UNRECORDED"
},
{
"accepted_as_pin": false,
"kind": "unpinned",
"name": ".github/actions/vantio-prove/action.yml actions/setup-node@v4",
"required_for_publish": true,
"value": "actions/setup-node@v4"
},
{
"accepted_as_pin": false,
"kind": "unpinned",
"name": ".github/actions/vantio-prove/action.yml actions/upload-artifact@v4",
"required_for_publish": true,
"value": "actions/upload-artifact@v4"
}
],
"private_distribution": {
Expand All @@ -90,7 +76,7 @@
"builds": [],
"formal_claim": false,
"reasons": [
"Workflow third-party actions are commit SHA pins with tag comments. The local composite .github/actions/vantio-prove still uses floating @v4 refs.",
"All tip third-party action uses in workflows and the local composite .github/actions/vantio-prove are commit SHA pins with tag comments.",
"The Python build-system requirement is hatchling with no version comparator.",
"No second build digest is recorded in this force."
],
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@
"release_success": false,
"requirements": [
{
"detail": "pin python-build-hatchling is unpinned; pin node-toolchain is unpinned; pin cli-tarball is unrecorded; pin .github/actions/vantio-prove/action.yml actions/setup-node@v4 is unpinned; pin .github/actions/vantio-prove/action.yml actions/upload-artifact@v4 is unpinned",
"detail": "pin python-build-hatchling is unpinned; pin node-toolchain is unpinned; pin cli-tarball is unrecorded",
"id": "R1",
"status": "GAP"
},
Expand Down
8 changes: 4 additions & 4 deletions docs/programs/release-engineering/generated/pin-report.json
Original file line number Diff line number Diff line change
@@ -1,14 +1,14 @@
{
"actions": [
{
"digest_pinned": false,
"digest_pinned": true,
"file": ".github/actions/vantio-prove/action.yml",
"uses": "actions/setup-node@v4"
"uses": "actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4"
},
{
"digest_pinned": false,
"digest_pinned": true,
"file": ".github/actions/vantio-prove/action.yml",
"uses": "actions/upload-artifact@v4"
"uses": "actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4"
},
{
"digest_pinned": true,
Expand Down
2 changes: 1 addition & 1 deletion scripts/release/ws11/characterize.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -193,7 +193,7 @@ export function characterizeOptics(root, inventory = buildInventory(root)) {
...actionPins,
],
reproducibility: assessment([
"Workflow third-party actions are commit SHA pins with tag comments. The local composite .github/actions/vantio-prove still uses floating @v4 refs.",
"All tip third-party action uses in workflows and the local composite .github/actions/vantio-prove are commit SHA pins with tag comments.",
"The Python build-system requirement is hatchling with no version comparator.",
"No second build digest is recorded in this force.",
]),
Expand Down
7 changes: 2 additions & 5 deletions scripts/release/ws11/ws11.test.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -277,7 +277,7 @@ test("actionUses keeps SHA pins that carry a tag comment", () => {
]);
});

test("pin report records SHA-pinned workflow actions and the sealed Python hashes", () => {
test("pin report records SHA-pinned workflow and composite actions and the sealed Python hashes", () => {
const { artifacts } = allGenerated(ROOT);
const report = artifacts["pin-report.json"];
assert.equal(report.package_manager.name, "pnpm");
Expand All @@ -287,10 +287,7 @@ test("pin report records SHA-pinned workflow actions and the sealed Python hashe
const pinned = report.actions.filter((action) => action.digest_pinned === true);
assert.deepEqual(
floating.map((action) => `${action.file} ${action.uses}`),
[
".github/actions/vantio-prove/action.yml actions/setup-node@v4",
".github/actions/vantio-prove/action.yml actions/upload-artifact@v4",
],
[],
);
assert.ok(pinned.length > 0);
assert.equal(pinned.length, report.actions.length - floating.length);
Expand Down
Loading