Commit graph

578 commits

Author SHA1 Message Date
rcourtman
b74789fcc6 Add a non-publishing Apple signing and notary preflight
On 2 Oct 2026 v6.4.6-rc.1 failed notarization because the Apple developer
agreement was unsigned, about an hour into the release. The maintainer's
nightly release rehearsal now dispatches release-signing-preflight.yml from
main on a hosted macos-15 runner. It imports the Developer ID certificate
into a throwaway keychain, requires the identity to be valid and at least 30
days from expiry, signs and verifies a probe binary with a secure timestamp,
and reads the notary submission history with the release key, which Apple
refuses while an agreement is unsigned or the key is revoked. The four
checks are independent and each reports one titled outcome, so one night
names every broken credential. It builds, uploads and publishes nothing.
2026-10-02 19:24:29 +01:00
pulse-triage[bot]
46d2727828 Validate final browser evidence without rewriting reviewed changes
Governance run 37016171545 rejected the original malformed timestamp even though a later reviewed receipt corrected it for identical runtime bytes. Use the existing fail-closed integration-range guard in CI while retaining per-commit canonical checks. Exercise the workflow shell with valid additive correction and invalid missing-base or unverified-content fixtures.

Change-source: pulse-maintainer
2026-10-02 15:04:12 +01:00
rcourtman
8c538b5c2f
Remove the echo-only release joins and trim unused artifact retention (#2374)
Some checks are pending
Core E2E Tests / E2E verdict (push) Blocked by required conditions
Build and Test / Backend tests (api-0) (push) Blocked by required conditions
Build and Test / Secret Scan (push) Waiting to run
Build and Test / Detect changed areas (push) Waiting to run
Build and Test / Provider pair Docker acceptance (push) Blocked by required conditions
Build and Test / Frontend (push) Blocked by required conditions
Build and Test / Backend tests (rest-0) (push) Blocked by required conditions
Build and Test / Backend tests (api-1) (push) Blocked by required conditions
Build and Test / Benchmarks (push) Blocked by required conditions
Canonical Governance / governance (push) Waiting to run
Canonical Private Governance / private-governance (push) Waiting to run
Helm CI / Lint and Render Chart (push) Waiting to run
Public docs / check (push) Waiting to run
Core E2E Tests / Playwright Core E2E (shard 2/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 3/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 4/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 5/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 6/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 7/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 8/8) (push) Blocked by required conditions
Core E2E Tests / Validate E2E tier selection (push) Waiting to run
Core E2E Tests / Offline Organization provisioning (push) Waiting to run
Core E2E Tests / Playwright Core E2E (shard 1/8) (push) Blocked by required conditions
Core E2E Tests / Agent registration lifecycle (push) Waiting to run
Unified Agent Native Verification / Linux ARM64 (push) Waiting to run
Unified Agent Native Verification / Linux x64 (push) Waiting to run
Unified Agent Native Verification / Windows x64 (push) Waiting to run
Unified Agent Native Verification / macOS ARM64 (push) Waiting to run
Unified Agent Native Verification / macOS Intel (push) Waiting to run
Unified Agent Native Verification / FreeBSD cross-build contract (push) Waiting to run
First step of the release simplification plan. create-release.yml loses
candidate_qualification and release_readiness, which only restated other
jobs' results. Their exact predicates move into publish_release_tag,
publish_docker, publish_helm_chart, activate_release and
release_commit_verdict, with cancellation unchanged.
recover-release-activation accepts both run shapes, so v6.4.6 and older
runs recover exactly as before. Failure-only diagnostics and the chart
artifact nobody downloads keep 3 days instead of 14 or 90. Only lines
cut from main after this land use it (release/v6.6 from 7 Oct). Reviewed
with gpt-6.1-sol, SAFE TO MERGE; predicate equivalence sampled over
2,784 cases.
2026-10-02 12:50:52 +01:00
pulse-triage[bot]
6cf72e6d88 Compose reviewed alert diagnostics and setup guidance with upstream CI correction
Preserve every accepted commit while incorporating the published setup-node advisory-cache repair. Upstream changes a separate workflow; retain the proved runtime and documentation candidate bytes.

Change-source: pulse-maintainer
2026-10-02 12:05:07 +01:00
rcourtman
fc9d85c640 Pin setup-node caching off in the dependency advisory watch
The scheduled watch reads each release line's lockfile in the default
branch's cache scope, so it deliberately writes no dependency cache.
It sets no cache input, but the pinned setup-node enables npm caching
on its own once package.json names npm as its packageManager. Nothing
declares that today; adding it later would silently reopen a
default-branch cache write here. Set package-manager-cache: false, as
five release workflows already do, assert it in the workflow test, and
say how the contract's no-dependency-cache promise is kept.
2026-10-02 11:30:08 +01:00
pulse-triage[bot]
439604c0bd Make getting-started installs fail closed and plans current
Chain signed installer downloads, verification and execution in the English, German and Spanish landing pages so a failed trust step cannot run stale or unverified bytes. Keep the pinned signer, namespace and release URLs, preserve real installer exits, and correct the existing plan and paired-app retirement guidance. Exercise the copyable Bash gate with offline command stubs and run those documentation regressions in Public docs CI.

Contract-Neutral: Public documentation and its secret-free CI validation only; no runtime, entitlement, release-selection or subsystem contract delta.
Change-source: pulse-maintainer
2026-10-02 02:53:31 +01:00
courtmanr@gmail.com
6ce41ae9d4 Fold the echo-only release joins into their public writers
candidate_qualification and release_readiness only restated other jobs'
results. publish_release_tag, publish_docker, publish_helm_chart and
activate_release now each carry the exact candidate predicate in their own
needs and if, guarded by !cancelled() with the same allowed integration
skip, and activation joins the tag and both registry publications directly.
The commit verdict restates every candidate result in place of the
readiness join.

recover-release-activation.yml accepts both shapes. A source run that has
release_readiness still has to prove only that join, as before. A run
without it has to prove publish_release_tag and at least one, and only
successful, jobs under the publish_docker and publish_helm_chart caller IDs.

Failure diagnostics and the inspection-only Helm chart artifact, which
nothing downloads, are kept for three days instead of 14 and 90.
2026-10-01 21:47:58 +01:00
pulse-triage[bot]
bb1903e48d Stop demo diagnostics at failed tailnet readiness
Failed setup now yields local-only, topology-free diagnostics. Require recognised Running state and successful tailnet ping before TCP, retain probe exits without raw private output or fallback probes, and exercise twenty synthetic readiness/privacy cases. Parent controls expose false success and private output on both channels. Keep workflow identities, secrets, action pins, mutation gates and release scope unchanged.

Change-source: pulse-maintainer
2026-10-01 17:36:26 +01:00
courtmanr@gmail.com
64d8dbc7fc Watch main and active release lines daily for new npm advisories
On 30 Sep-1 Oct 2026 GHSA-q2hr-2g5m-vwhr (brace-expansion) and
GHSA-p98j-92pf-mc4p (DOMPurify) failed the required "Audit complete
frontend dependency graph" step on every pull request to main,
release/v6.4 and release/v6.5. That held the v6.4.6 preparation PR and
the v6.5 RC for days with no owner. The scheduled audit in
security-scan.yml only informs and runs on the default branch, so
release lines were never checked.

dependency-advisory-watch.yml runs daily and on dispatch. It lists main
plus every release/v<major>.<minor> line at or newer than the latest
stable's line (all lines if that lookup fails), then audits each in a
fail-fast-free matrix. Each job fetches only that line's
frontend-modern/package.json and package-lock.json with git and runs
scripts/npm-audit-retry.sh all on them under the same Node.js pin that
build-and-test requires. npm audit reads the lockfile, so nothing is
installed. The job never checks out or runs the audited branch's code,
because a scheduled run holds the default branch's cache scope and
CodeQL flagged running npm ci there as cache poisoning.

A job fails when the audit fails, and its step summary and annotation
name the branch, the GHSA ids and the fix (npm audit fix
--package-lock-only plus raised floors in dependencySecurity.test.ts).
Read-only, hosted-only, no secrets, no uploads.
2026-10-01 11:46:12 +01:00
courtmanr@gmail.com
8f302e4520 Add shadow release lifecycle rehearsal workflow
Install a published release (latest stable by default) with its signed
install.sh, seed auth, a webhook and a PVE node through the API, upgrade with
the installed /bin/update --version helper, then roll back with the documented
/bin/update --version command. Each step checks /api/version and the binary
version, /api/health, unit state, the seeded settings against fixed
expectations and the pre-upgrade read-back, and data-dir survival, then
reports a phase table in the step summary.

The workflow is read-only, hosted-only, uploads nothing and no release job
depends on it.
2026-10-01 09:11:15 +01:00
pulse-triage[bot]
4101c37db5 Keep watchdog source observations separate from promotion gates
The exact no-mutation watchdog failed at published 6.4.5 because the release line has pending repairs but still declares its stable VERSION. Observe that governed source and its preceding stable reference without inventing a new promotion, while keeping candidate resolver gates unchanged and watchdog artifacts out of promotion-readiness records.

Change-source: pulse-maintainer
2026-10-01 02:56:58 +01:00
pulse-triage[bot]
2043f3dd76 Keep rehearsal policy checks aligned with watchdog admission
Replace two stale schema assertions with explicit watchdog omission and ordinary candidate rollback requirements. The actual workflow admission/source-selection shell tests preserve the fail-closed distinction.

Contract-Neutral: Tests and explanatory comments reflect the already recorded watchdog admission contract; no further runtime contract change.
Change-source: pulse-maintainer
2026-09-30 23:39:47 +01:00
pulse-triage[bot]
40037f0035 Bind on-demand release watchdogs to reviewed main
Retain the scheduled governed-source selection and no-mutation demo verdict in a separate fixed dispatch mode. Check its control SHA and candidate-free envelope before checkout, preserve ordinary rehearsal rollback and exact event-source guards, and skip candidate builds.

Change-source: pulse-maintainer
2026-09-30 23:27:54 +01:00
pulse-triage[bot]
dc75bd6e3b Keep pre-release evidence visible and identify running images
The feedback form forced screenshots into shell code fences and conflated a running container image with a non-container release asset. Preserve rendered attachments, ask for the Pulse image only on running containers, and keep failed-install evidence truthful.

Contract-Neutral: Community issue intake only; release and installation contracts unchanged.
Change-source: pulse-maintainer
2026-09-29 20:03:09 +01:00
pulse-triage[bot]
564a63a651 Accept unsafe one-off failures in community intake
The bug and v6 pre-release forms previously required reproduction steps even when a retry could cause a host outage, duplicate update, alert storm or data loss. Ask for the original sequence and safe evidence instead, and mirror the guidance in the public triage document.

Contract-Neutral: Community intake wording only; release and installation contracts unchanged.
Change-source: pulse-maintainer
2026-09-29 19:24:42 +01:00
pulse-triage[bot]
5d39c8623f Make failed-install issue intake truthful
Ask for the attempted release and installer provenance when Pulse never started, without forcing a false running-version attestation or a token-bearing command. Keep public triage guidance aligned and pin both forms in tests.

Contract-Neutral: Issue form provenance and wording change community intake only, not release promotion or artifact dispatch
Change-source: pulse-maintainer
2026-09-29 18:44:42 +01:00
pulse-triage[bot]
d7baa07dad Compose scoped Proxmox repair with protected main frontier
Retain the verified #2321 source and its original receipt while incorporating upstream release and browser range validation.

Change-source: pulse-maintainer
2026-09-29 17:36:27 +01:00
pulse-triage[bot]
498e2b12a2 Merge protected Pulse main with reviewed publication range
Preserve upstream browser verification for the newer Relay retirement surface; earlier action recovery proof remains in reviewed ancestry. Include current CI sharding and qualification canary without rewriting accepted commits.

Change-source: pulse-maintainer
2026-09-29 17:12:31 +01:00
courtmanr@gmail.com
c9915434d8 Let the RC attester read the lab's root-owned evidence
With the host-interface canary in place, v6.4.5-rc.4 passed the
schema-v7 systemd and rootful Docker lab (run 36594651903), but the
attestation step then failed with Permission denied on receipt.json,
which the privileged lab writes as root into the bind-mounted evidence
directory. Hand that directory to the runner user after a passing lab
and before attestation, without touching its content.
2026-09-29 17:12:27 +01:00
courtmanr@gmail.com
eafd48d197 Give RC qualification a local host-interface canary
The immutable RC systemd lab failed before installed acceptance because
its --network none container had no non-loopback IPv4 address to prove
the helper's private network cannot reach. Add a veth canary wholly
inside that namespace and assert no default route before the lab runs.

Also check out the repository in the demo resolver before it calls
scripts/write_github_output.py, so verification-only dry runs reach
their demo checks.

Split out of #2323 so the v6.4.5 promotion is not held behind the
unrelated action-review UI work in that PR.
2026-09-29 16:42:35 +01:00
courtmanr@gmail.com
341e8a7eb4 Calibrate internal/api shard weights to CI and record per-test seconds
The weights from #2324 came from one local run and left the api shards at
4.5, 8.8, 17.1 and 12.5 minutes on CI. Most of the 17.1 was not test time.
That shard ran `-run . -skip <1231 names>`, and the test binary caches only
its last compiled pattern, so alternating the two recompiled the 62 KB skip
regex for every test and subtest (about 50 ms each under -race locally, 30s
against 1.3s for 300 trivial tests). Two runs put that shard at 887s and
875s against roughly 450s of tests. The skip path now passes -skip alone.

Every api shard now runs go test -json through
.github/scripts/record-internal-api-test-seconds.py. It prints what plain go
test would (package lines and the output of failing or unfinished tests),
exits non-zero on any failure behind pipefail, and writes each top-level
test's seconds to an internal-api-test-seconds-N artifact that is uploaded
even when the shard fails. .github/scripts/refresh-internal-api-test-seconds.py
rebuilds the weights file from those artifacts (gh run download, median
across runs, DEFAULT_WEIGHT set to the mean of the unlisted tests, which the
selector now reads from the file).

Until those artifacts exist, the weights are a local -race -json run with
each region of go test's order scaled to what CI reported for it.
Equal-count quarters averaged 107, 437, 100 and 787s over four runs, and the
weighted cut gave 131s for the first 1187 tests, 350s for the next 23 and
608s for the last 21 over two. The last quarter and the last 21 tests
disagree on how the tail splits, so the tail takes the midpoint of an exact
fit and a pooled factor.

With these weights four shards still predict a slowest shard near 10
minutes, and a 20% slower runner on the tail would take it past the 11
minutes of Frontend and rest-1. Five shards predict about 131, 325, 280-340,
330-355 and 330-365s of tests, or 4.5 to 8.5 minutes a job with about 2.3
minutes of setup, so API_SHARD_COUNT goes to 5. Every test still runs
exactly once in contiguous go test order, and all five slices passed locally
from their new starting points. The required Backend tests (api) verdict
keeps its name.
2026-09-29 15:27:08 +01:00
pulse-triage[bot]
20c99e2e67 Preserve community decomposition decisions in issue label sync
An empty form field or unrelated edit cannot prove comment-raised topics were dispositioned. Only label newly declared topics, leaving removal to whole-thread triage and respecting a completed manual disposition.

Change-source: pulse-maintainer
2026-09-29 14:45:33 +01:00
pulse-triage[bot]
968e7c5a27 Make bug evidence intake truthful for non-container installs
Ask for the failing running version and a container image only where one exists. Accept symptom-appropriate screenshots or logs without forcing irrelevant log text, and state the matching triage rule.

Change-source: pulse-maintainer
2026-09-29 14:21:28 +01:00
pulse-triage[bot]
ffc295b8a7 Merge protected Pulse main at batch frontier
Change-source: pulse-maintainer
2026-09-29 14:02:16 +01:00
courtmanr@gmail.com
06d78b66d3 Balance internal/api race shards by measured run time
The four Backend tests (api-N) shards took equal-count quarters of go
test's list, which left them at 4.0, 10.6, 4.0 and 16.8 minutes on the
first PR run, and at 1.9, 8.0, 1.5 and 10.3 minutes of go test time on
the following main push (run 36560070496). Almost all of it sits in a
few tests. One contract mock chart test runs about six minutes on the
runner, and the 28 integration server tests at the end of the list take
about twenty seconds each, so the fourth quarter held nearly half the
package.

Shards are still contiguous runs of go test's own order, since some
tests depend on package state from their neighbours, but the cut points
now come from estimated seconds.
.github/scripts/select-internal-api-shard.sh weighs each test from
.github/scripts/internal-api-test-seconds.txt (the 199 tests at 0.5s or
more, seeded from a local -race -json run scaled to that main run's
shard totals, with a 0.05s default for anything unlisted), binary
searches the smallest per-shard budget that fits the list into four
slices, and fills up to it. The weights only move cut points. Every test
is assigned exactly one shard in a single pass, so a stale file can
unbalance shards but never drop or repeat a test, and no shard is ever
empty.

With today's list the slices hold 1187, 23, 2556 and 21 tests, estimated
at 1.9, 6.9, 6.5 and 6.7 minutes of tests, or about 9.5 minutes per job
with the roughly 2.6 minutes of setup and race compile. The 2556-test
slice would need a 124 KB -run pattern, so a shard passes -skip of the
other shards' tests whenever that is shorter, which runs the same tests
in the same order.
2026-09-29 13:14:27 +01:00
courtmanr@gmail.com
46fd0b713e Shard internal/api race tests and drop probation E2E from PRs
Across the last 25 bot PRs the median open to merge time was about 33
minutes for one PR and about 45 when three opened together. The critical
path was the required Backend tests (api) check, where one go test -race
./internal/api step took about 27 of its 31 minutes. Every other required
check finishes within about 12 minutes.

internal/api now runs as four Backend tests (api-N) shards. Each shard
lists the package's tests with go test -race -list from the commit under
test and runs one contiguous quarter of that list in go test's own order,
so every test, including ones added later, runs in exactly one shard, and
a shard that resolves no tests fails. The split is contiguous rather than
interleaved by name because some internal/api tests depend on package
state left by the tests just before them. A round-robin split by sorted
name failed dozens of tests locally (admin bypass and session store
globals), while the four contiguous slices and the full run all pass. A
Backend tests (api) verdict job keeps the required check name and fails
unless every shard succeeded. Backend tests (rest-0) and (rest-1) keep
their names and package split. Local non-race timings put the heaviest
slice at about 42 percent of the package, so the api check should drop
from about 31 minutes to roughly 14.

Core E2E no longer runs the non-gating probation tier on pull requests.
It could not gate a PR and the promotion rule counts only main runs, so
on a PR it only held each of the eight shard runners about eight minutes
longer, which fed the runner queueing seen with concurrent PRs. Push and
manual runs still execute it.

Go test steps still run for frontend-only changes. Go tests read
frontend sources directly (internal/api contract tests,
internal/unifiedresources walking frontend-modern/src, and the
internal/telemetry repository-wide wording scan), so skipping them by
path would drop real coverage.
2026-09-29 11:43:57 +01:00
pulse-triage[bot]
c54d361acf Keep same-RC secure-runtime canary inside isolated lab
Create the non-loopback veth canary only inside the no-network disposable systemd container before running the immutable release lab. Preserve packet authentication and fail closed when the local interface or no-default-route assertion is absent. Bind the workflow, source contract and installtests guard in one reviewed candidate.

Change-source: pulse-maintainer
2026-09-29 10:37:15 +01:00
pulse-triage[bot]
70acab1703 Checkout demo workflow before resolving output
The scheduled release dry run reached its reusable demo resolver before checkout, so the output helper was absent and the no-mutation demo check failed. Move the credential-free checkout ahead of resolution, guard the ordering in install tests, and record that precondition in the deployment-installability contract.

Change-source: pulse-maintainer
2026-09-29 09:10:22 +01:00
pulse-triage[bot]
e9f057c187 Run secure-runtime RC qualification from reviewed control
Dispatch the post-publication check from protected main while binding its packet to the immutable RC tag. Accept only canonical Pulse checkout origins before normalising the spelling required by the attester, and document the deployment contract and source guard together.

Change-source: pulse-maintainer
2026-09-28 21:34:44 +01:00
Richard Courtman
042b01a953 Soak release candidates for 24 hours before stable
The resolver refused a stable promotion until its candidate had soaked for
72 hours, or 168 for a minor. Few installs run previews: 35 of about 7,900
active installs ran v6.4.5-rc.3 in the week to 2026-09-28, so a longer
soak saw little the first day did not, while 75 percent of installs sat on
a stable build a month old. Richard set a 24 hour soak for every release
on 2026-09-28.

The minimums drop to 24 hours for minor and patch alike, the error text
reads the constants instead of repeating numbers, and the workflow and
trigger prompts, the promotion policy and the deployment contract say the
same. The content-drift check and the hotfix exception are unchanged.
2026-09-28 16:42:46 +01:00
pulse-triage[bot]
c0cfa8ef7e Keep Vitest major upgrades coordinated
The isolated coverage-v8 5 proposal cannot install beside Vitest 4 because its peer range requires Vitest 5. Ignore only version majors for both packages until a reviewed frontend migration can update and prove the pair together; retain grouped security updates and minor/patch updates.

Change-source: pulse-maintainer
2026-09-27 10:10:45 +01:00
pulse-triage[bot]
71c948fa55 Defer incompatible npm major updates to explicit migrations
Keep ESLint 10 and lucide-solid 1.x out of automatic version updates while their lockfile and icon-import contracts fail. Preserve minor and patch updates and guard the rule in Dependabot policy tests.

Change-source: pulse-maintainer
2026-09-26 23:17:00 +01:00
pulse-triage[bot]
d1c3ac82e1 test(release): gate provider-pair Docker isolation
Exercise two provider installations with the same tenant ID, unowned-network collision and cleanup isolation. Gate the release-line push before packet freeze and repeat against digest-verified candidate images during container qualification. Update the deployment-installability contract and pin both workflow gates in the release-asset verification suite.

Change-source: pulse-maintainer
2026-09-24 09:04:56 +01:00
pulse-triage[bot]
0168dd3be8 fix(ci): freeze reviewed action pins from Dependabot version updates
action_consumer_manifests.json pins each release-consumed action to an exact SHA plus the upstream action.yml sha256, and release_promotion_policy_test.py requires every workflow step to match. Dependabot's github-actions group bumps those SHAs, so every group proposal fails the manifest contract and cannot be repaired offline. Ignore the eight governed actions for version updates and guard the policy against the manifest so pin refreshes stay explicit reviewed work. This resolves the recurring failing actions-minor-patch proposal (#2139).

Change-source: pulse-maintainer
2026-09-23 08:04:21 +01:00
pulse-triage[bot]
dc42735008 chore(deps): keep TypeScript majors as explicit Dependabot work
Dependabot #2100 and #2101 propose TypeScript 5.9.3 -> 7.0.2, but the checked-in @typescript-eslint/eslint-plugin@8.70.0, @typescript-eslint/parser@8.70.0 and typescript-eslint@8.70.0 each declare a peer dependency of "typescript": ">=4.8.4 <6.1.0". The proposals therefore fail ERESOLVE and all frontend E2E shards, with no security advisory behind them.

Add a semver-major ignore for typescript in the npm ecosystem so majors stay explicit work alongside a lint-toolchain upgrade, and update the config guard test to pin both the browser-runtime and TypeScript ignores.

Change-source: pulse-maintainer
2026-09-23 06:32:54 +01:00
pulse-triage[bot]
f43a7a3e62 fix(release): verify the private Pro source pair before creating a draft
A 6.x release creates its draft release object before stage_private_pro_runtime dispatches the private Pro build, which resolves the payload by the exact frozen public commit (docs/release-source-pairs/<sha>.json). When that declaration is absent or names a different pulse_sha, the private build refuses and the run leaves an orphaned draft (v6.4.5-beta.2, v6.4.5-beta.3). Verify the declaration in prepare, before any draft exists, and fail with the exact path to create. This is an unconditional fact check independent of the opt-in harness gate in pulse-dev-infra #443/#444; the release steward still owns choosing the pair. Source issue: pulse-dev-infra #441.

Change-source: pulse-maintainer
2026-09-20 14:24:41 +01:00
pulse-triage[bot]
be6179c2d2 build(ci): refresh reviewed GitHub Actions pins
Dependabot #2094, #2095 and #2096 bump actions/setup-go 6.4.0 -> 7.0.0, signpath/github-action-submit-signing-request 2 -> 3.0 and actions/github-script 8.0.0 -> 9.0.0. Each proposal is blocked only by the reviewed pin constants, the workflow-trust allowlist, the release-consumer action manifest and the installer governance assertions that hard-code the previous revisions. Carry all three bumps with those artifacts in one commit so the proposals can be closed as superseded.

All three actions keep the node24 runtime and their existing inputs and outputs; no consumer interface, installer behaviour or public contract changes. The deployment-installability and agent-lifecycle workflow references are pin-only.

Contract-Neutral: Reviewed action pin refresh with identical node24 consumer interfaces and unchanged inputs/outputs; no public-contract or installer-behaviour delta.
Change-source: pulse-maintainer
2026-09-20 08:16:44 +01:00
pulse-triage[bot]
fbfa870b95 build(deps): pin Playwright to the offline browser runtime line
The npm-minor-patch group (Dependabot #2115) has been held since 17 Sep
because it bundles @playwright/test, playwright and playwright-core
1.56.1 -> 1.63.0 with 12 safe frontend updates. The offline
browser-verification runtime is pinned to Playwright 1.56.1, so a lockfile
bump breaks browser-proof parity; holding the whole group blocked the safe
updates instead.

Ignore Playwright version updates on the governed 1.56.1 line, matching the
docker governed-tag policy, so the remaining grouped updates can be reviewed
on their own. Security updates stay covered by the weekly npm-audit scan and
the frontend dependencySecurity proof. Extend the dependabot config guard to
lock the policy in.

Change-source: pulse-maintainer
2026-09-20 03:23:38 +01:00
rcourtman
092e988239 Cancel superseded pull request validation
Replacement PR checks were queued behind obsolete runs even after the
previous revision failed. Cancel prior validation only for pull_request
events, preserving completed verdicts for branch pushes and manual runs.

Contract-Neutral: Only PR concurrency changes. Semantic YAML comparison confirms all jobs and triggers, including frontend dependency security checks, are unchanged. No security verification change is warranted. The scheduling contract is updated.
2026-09-14 23:07:22 +01:00
pulse-triage[bot]
ae38b93c0c fix(release): stop public writer chain on workflow cancellation
Preserve successful qualification and optional skipped ancestors while rejecting workflow cancellation independently of completed needs. Cover tag, Docker, Helm, readiness, convergence dispatch and activation; retain evidence and cleanup joins.

Change-source: pulse-maintainer
2026-09-13 14:21:55 +01:00
pulse-triage[bot]
f9569426f5 fix(release): publish qualified tags after optional skipped checks
Use an explicit status guard while requiring successful preparation and qualification. Model the beta skipped-ancestor path and adverse direct prerequisites; retain immutable identity and all release gates.

Change-source: pulse-maintainer
2026-09-13 13:03:02 +01:00
rcourtman
c7c503994b
Merge pull request #2063 from rcourtman/fix/disposable-release-qualification
Some checks failed
Build and Test / Secret Scan (push) Waiting to run
Build and Test / Detect changed areas (push) Waiting to run
Build and Test / Frontend (push) Blocked by required conditions
Build and Test / Backend tests (api) (push) Blocked by required conditions
Build and Test / Backend tests (rest-0) (push) Blocked by required conditions
Build and Test / Backend tests (rest-1) (push) Blocked by required conditions
Build and Test / Script smoke tests & backend build (push) Blocked by required conditions
Build and Test / Benchmarks (push) Blocked by required conditions
Canonical Governance / governance (push) Waiting to run
Canonical Private Governance / private-governance (push) Waiting to run
Public docs / check (push) Waiting to run
Unified Agent Native Verification / Linux ARM64 (push) Has been cancelled
Unified Agent Native Verification / Linux x64 (push) Has been cancelled
Unified Agent Native Verification / Windows x64 (push) Has been cancelled
Unified Agent Native Verification / macOS ARM64 (push) Has been cancelled
Unified Agent Native Verification / macOS Intel (push) Has been cancelled
Unified Agent Native Verification / FreeBSD cross-build contract (push) Has been cancelled
Isolate release preparation and qualification on hosted VMs
2026-09-12 18:33:17 +01:00
rcourtman
051ce81a72 Isolate release preparation and qualification on hosted VMs
Persistent prerelease runners can retain state from earlier source execution
and influence later admission, build output or qualification. Use the
existing hosted stable-release path for every channel while preserving
exact-source checks, resource planning, watchdogs and release gates.
2026-09-12 15:44:11 +01:00
pulse-triage[bot]
34ba9a5ed9 Merge candidate 20260911T204017Z-core-runtime
Change-source: pulse-maintainer
2026-09-11 21:47:11 +01:00
pulse-triage[bot]
097422837b fix(release): preserve quarantined version identity
Reject historical draft reuse before PATCH when its retained target is not the exact checkout SHA, including missing targets and moving refs. Preserve same-source recovery and activation guards.

Depends on PR2056 qualification-first workflow and immutable tag checks. Executable absent-tag fixtures fail before repair and pass on PR head 9e5e18f0 plus this patch; 53 policy, 6 immutability and 42 trust tests pass. Update the deployment contract in the same commit.

Change-source: pulse-maintainer
2026-09-11 21:43:11 +01:00
rcourtman
9e5e18f008 fix(release): qualify candidates before public version writes
A draft GitHub release does not hide its public Git tag or registry
images. Publishing those before qualification consumed a beta identity
when the candidate later failed.

Stage drafts without Git refs, join exact-source checks before public
tag, Docker and Helm publication, and preserve exposed tag identities.
Keep final digest verification before release activation.
2026-09-11 21:04:46 +01:00
pulse-triage[bot]
9902c204d0 ci: collect fixed hosted root-route pair evidence
The completed local study did not explain the adverse hosted root comparison. Add an exact-source root-only collector with matched builds, ten alternating samples and retained layout and host evidence, rather than repeat full qualification or relax its threshold. Eight focused mocked collector tests pass; hosted execution remains after independent review and protected landing.

Change-source: pulse-maintainer
2026-09-10 19:03:01 +01:00
pulse-triage[bot]
ad1cfd33c3 fix(ci): qualify grouped release action pin consumers
The grouped action upgrade leaves signing, network and publication consumer assertions on superseded pins. Align those contracts and check every consumer against reviewed immutable upstream manifests, retaining exact dispatch and release trust boundaries without claiming hosted execution.

Change-source: pulse-maintainer
2026-09-10 00:35:47 +01:00
pulse-triage[bot]
9a6a5811a7 ci: qualify setup-node v7 consumer contracts
The standalone setup-node proposal lacked lifecycle and deployment evidence. Preserve Node 24, explicit cache controls and native Windows proof steps while upgrading the immutable action revision; add consumer regression coverage for the removed dummy auth-token assumption. Keep grouped signing and deployment action upgrades separate.

Change-source: pulse-maintainer
2026-09-09 19:29:17 +01:00
pulse-triage[bot]
13e16bfc83 test(e2e): provision offline signed organization entitlements
Keep a loopback ephemeral issuer alive for source-built managed browser runs and activate each organisation through the authenticated API. Verify installation bindings without billing-state injection or signature bypass, and retain a narrow CI provisioning proof separately from quarantine acceptance.

Change-source: pulse-maintainer
2026-09-09 11:27:23 +01:00