Repository navigation
fix(release): preserve marketplace assessment identities - #529
Conversation
Validation at fa8e469 covers #525, #526, #527 and #528. The four reproduced root causes now have shipped regressions: repository-configured filesystem hooks stay inert; native CI workflow paths qualified with the main ref are accepted while other workflows/refs refuse; publication assessment binds to the checkout selected by the workflow; and historical inspection preserves exact checkout names ending in newlines without sharing a line-based object-alternates path. The verifier passes 44 cases, release proposals 98, historical inspection 46, and the new actual workflow checkout-identity test four. Existing publication/proposal workflow guards, complete script lint, manifest/provenance checks, changed-workflow lint and diff checks pass. Independent whole-diff review exercised real Git checkouts, configured benign hooks and additional newline/linked-worktree controls; selected observations retained index/configuration/refs and object inventories, and no hook executed. These are exercised command and workflow assessment paths, not a production marketplace publication. Automatic publication remains disabled. CI is pending at this head, so promotion is not yet claimed. #526–#528 will be closed only after this PR merges and its shipped bytes are verified. |
Validation at 18600ab supersedes the earlier validation comment and covers #525, #526, #527 and #528. Native CI at the previous head reproduced an observation-completeness regression: the existing fault injector did not recognize the new explicit inert Git configuration. The test still requires the same truncated observation to be refused for the same reason; recognizing that exact command prefix restores the intended injection. All 15 observation-completeness controls now pass. The production changes remain identical to the independently reviewed earlier head. The verifier passes 44 cases, historical inspection 46, release proposal 98, workflow checkout identity four, release preparation 62, version gates 36, remote assessment 62, publication 73 and merged-release preparation 52. Existing publication/proposal workflow guards, full script lint, changed-workflow lint and diff checks pass. Independent whole-diff review of all eleven changed files at this exact head is clean, including the repaired negative control. Repository-configured filesystem hooks stay inert; native main-qualified CI workflow paths retain exact-head/event/workflow binding; assessment uses the actual selected checkout; and historical inspection preserves exact physical checkout names, including terminal newlines. Actual Git controls verified index, configuration, refs and object inventories, with no hook execution. Automatic publication remains disabled. These tests exercise release commands and workflow assessment, without claiming a production marketplace publication. Current-head CI is still pending. Companion issues #526–#528 will close only after merge and shipped-byte readback. |
@coderabbitai full review |
✅ Action performedFull review finished. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (11)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details🧰 Additional context used📓 Path-based instructions (2)Source excerpt: Preparation is opt-in and offline.📄 CodeRabbit inference engine (docs/marketplace-releases.md) Files:
Source excerpt: **Least-privilege permissions.**📄 CodeRabbit inference engine (AGENTS.md) Files:
🪛 LanguageTooldocs/marketplace-releases.md[uncategorized] ~309-~309: The official name of this software platform is spelled with a capital “H”. (GITHUB) [uncategorized] ~310-~310: The official name of this software platform is spelled with a capital “H”. (GITHUB) 🔇 Additional comments (5)
📝 WalkthroughWalkthroughThe publication assessment now resolves the release commit from checked-out Priority: ➖ Normal Severity of issue fixed: Medium Merge Risk: ⚪ Minimal · up to The release assessment, inspection, and CI identity changes appear ready to merge after normal checks. No specific unresolved failure was identified. Security Architecture ReviewSecurity architecture risk: ⚪ Minimal · up to The changes align release checks with the checkout actually examined and prevent a configured observation hook from running during verification. Repository, commit, successful-CI, and explicit publication controls remain intact. No material security risk was found to be introduced or worsened. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Important Pre-merge checks failedPlease resolve all errors before merging. Addressing warnings is optional. ❌ Failed checks (1 error)
✅ Passed checks (4 passed)
Full details: Out of Scope Changes checkExplanation The changes to
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
The selected review's scope finding is resolved at unchanged head 18600ab. The description now explicitly links all active companion requirements: #525 covers inert repository observation; #526 covers the supported successful-check identities; #527 covers the actual checkout selected for publication assessment; and #528 covers exact historical checkout paths. These issues were filed before implementation and their shipped regressions and actual command evaluations are recorded in the validation comment above. The primary closing reference remains #525 under the repository's single-closing-issue body convention. #526–#528 will be closed after actual merge and immutable shipped-byte readback. All four requirements concern the integrity of marketplace release assessment and inspection; the body change introduces no additional code or release authority. Automatic publication remains disabled. This resolution restarts review at the same commit without an empty commit. No code findings, review threads or maintainer requirements were discarded. |
There was a problem hiding this comment.
🤖 Generated by the Agentic Engineer
Self-review (fallback — CodeRabbit, Codex and Cursor Bugbot unavailable)
Reviewed commit: 18600ab
- CodeRabbit: the authenticated current-PR summary updated at 2026-10-05T16:33:34Z reports that the completed review consumed the included allowance, with zero remaining under the one-review-per-hour plan. Freshly read after the scope resolution; applicable to this PR's restarted round. Recovery is renewed included allowance; paid recovery is not authorized. Source: #529 (comment).
- Codex: the authenticated account usage-limit response remains unchanged at 2026-10-05T04:07:07Z on a fresh read. It identifies this account's exhausted code-review allowance and requires account credits/settings recovery; no paid recovery is authorized. Source: devantler-tech/agent-skills#246 (comment).
- Cursor Bugbot: the authenticated user/team usage-or-spend-limit response remains unchanged at 2026-10-05T04:08:02Z on a fresh read. Recovery requires a user/team administrator to change the limit; no paid recovery is authorized. Source: devantler-tech/agent-skills#246 (comment).
I reviewed the complete eleven-file diff against 796afb2 for correctness, security, complete observations, retained caller state, and the repository's review guidelines. The command-local filesystem-monitor override covers the tree diff that can consult the index; its native marker control detects execution and verifies unchanged caller index/configuration. Historical inspection preserves complete logical and physical checkout paths and copies immutable objects into its disposable repository without line-based alternates. Supported CI identities remain narrowly bound to repository, main branch, full commit, push event and completed success. Publication assessment resolves the actual selected checkout before invoking assessment, and a failed native identity read stops the step. Publication remains explicitly opt-in.
The selected review's scope finding was resolved before this round by linking the already active #526, #527 and #528 requirements alongside primary #525. These four requirements and their acceptance controls are covered by this diff; no extra code was added during resolution. LanguageTool's case suggestions concern literal, case-sensitive repository paths, which correctly retain their actual lowercase directory names. There are no unresolved code, scope, inline or non-thread findings and no maintainer requirements being overridden.
The verifier's 44, historical inspector's 46, proposal's 98 and actual workflow identity's four controls pass, with fifteen observation-completeness controls retaining the same negative producer fault and refusal reason. Independent whole-diff review is clean. All 46 native current-head CI checks are settled green, including CI - Required Checks. Actual native Git checkouts, unusual physical paths and the workflow's real assessment shell were exercised; production marketplace publication is not claimed.
Verdict: no P0/P1 findings
Ready at 18600ab: all 46 native CI checks are settled green, including CI - Required Checks; the base and owned worktree are freshly rebound; there are zero unresolved threads or remaining review/maintainer requirements. The current-head CodeRabbit code review is clean. Its scope finding has been resolved against the four active issue requirements, and the prescribed subsequent local review is posted and programmatically GREEN at this exact head. Native release commands and the workflow's actual assessment shell were exercised with normal, queued, malformed and unusual-path controls. Caller state remains unchanged and callbacks stay inert. Publication remains explicitly opt-in; no production marketplace publication is claimed. #526–#528 will close only after merge and immutable shipped-byte readback. |
Post-merge user-path proof is complete at signed main commit 52e20bf. From that exact archived source, the native release verifier passed 44 cases, historical inspector 46, proposal command 98, actual publication assessment shell four and observation completeness fifteen: 207 controls passed. These exercised the merged command implementations, retained caller state and negative producer controls. All eleven changed blobs also match the independently reviewed implementation. Publication remains explicitly opt-in; no production marketplace publication is claimed. |
Why
Valid marketplace releases could be refused after a queued dispatch or in unusual checkout paths, and verification could execute a local observation hook.
What
Release assessment now follows the checkout it actually examines, accepts matching native CI identities, and preserves safe offline inspection across supported checkout paths.
This also implements the related requirements in #526, #527 and #528.
Fixes #525