Skip to content

Add non-publishing release preflight and gate all destinations - #4

Open
foundev wants to merge 1 commit into
masterfrom
brb/release-zk2ru7fcybnys7c5vzfhgbgyzv
Open

Add non-publishing release preflight and gate all destinations#4
foundev wants to merge 1 commit into
masterfrom
brb/release-zk2ru7fcybnys7c5vzfhgbgyzv

Conversation

@foundev

@foundev foundev commented Sep 10, 2026

Copy link
Copy Markdown
Collaborator

Release validation currently needs an already-published GitHub release and finalizes it before npm validation. Allow a proposed-version publish=false dispatch at a preparation commit, build native and npm deliverables in one workflow, and check all versions plus the actual publishing job credentials before any final upload. Finalize GitHub only after all npm packages verify, and preserve conflicts during partial recovery.

Add independent exact-commit checks, payload-aware archive verification, and document all seven destinations and their credentials. npm authorization deliberately fails if direct publishing trust cannot be inspected; an OIDC exchange alone can also authorize staging-only publication.

Validation: 28 Python tests passed locally, including wrong-SHA/failed-run rejection, conflicting tags, permission failure before uploads, compression differences, and read-only recovery. Exact-commit GitHub CI and non-publishing preflight will be inspected before completion. No release tags, public releases, final assets, or registry packages are published by this PR or its branch pushes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant