release: revalidate evidence after manifest publication - #60
Conversation
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
|
@opencode-agent Implement the bounded GREEN slice for exact current test-only head The exact-head RED CI run Required production contract:
Credential-free local verification against the exact base plus this implementation already demonstrated: |
Test-first scope
This bounded stacked draft addresses #59 without changing workflows or credentials.
ccfd7809b352e95f4f6e646d0e886ac28e773698from PR release: bind sealed evidence to a canonical root path #58.d1c3bb80096f3c537f99fe79d0ad80c1a29cd5d5.31058973263.Four isolated regressions demonstrate that the current CLI reports success when:
Exact-head package acceptance and Ruff succeeded. Python 3.10–3.13 failed only at pytest on the four intentional RED regressions, confirming the missing post-publication contract without an unrelated quality or packaging regression.
The bounded implementation has been specified for the pinned OpenCode agent. Production code, documentation,
CHANGELOG.md, exact-head GREEN CI/security evidence, and automated review remain pending.Trust boundary
No
.githubfile, publication permission, signing identity, ref write, branch update workflow, conflict strategy, or model-executing credential path is introduced. This PR targets the exact stacked branch from PR #58 and remains draft. It must not be retargeted or merged before prerequisite stack integration, exact-head CI, SAST Semgrep, Security Scan, package acceptance, completed automated review, qualifying independent approval, and repository-policy gates all succeed.Progresses #59 and #46.