Repository navigation
v0.8.0: reliable requests and verifiable audit inspection - #13
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Webhook retries could repeat a completed workflow, older state stores could fail during upgrade, and run history did not record engine runs. This release adds reliable request handling and verifiable audit inspection for version 0.8.0.
Validation: complete short Go suite; voice-tagged suite; race checks for the new concurrency, storage, binding, and audit regressions; golangci-lint with zero new issues; configuration validation with zero errors; npm tests, package-content verification, and native launcher smoke tests; native builds for Linux, macOS, and Windows on amd64 and arm64.
Review notes: based on master at
741c2ec; no other open PRs were present when work started. Changes cover request admission, tool consumption, SQLite persistence, audit commands, tests, upgrade documentation, and release packaging. Provider integrations and the experimental cryptographic circuits are unchanged. Existing receipt signatures keep their v1/v2 formats. Start the engine once to migrate an older store before read-only inspection; existing v0.7.0 unconsumed permits need fresh approvals because the policy binding now includes operator authorization. Numeric token spelling is part of retry identity. Offline verification checks signed fields rather than export completeness or unsigned lifecycle metadata.The package version is 0.8.0. A version-tag workflow verifies the release, builds native assets and checksums, publishes GitHub/GHCR artifacts, smoke-tests the native installer, and publishes npm with trusted publishing or an
NPM_TOKEN. Publishing remains pending review and a version tag; npm publisher authentication must be configured before running the tag workflow.