Skip to content

fix: publish beta17 with hosted provenance - #347

Merged
Obed0101 merged 1 commit into
devfrom
codex/beta17-provenance
Sep 23, 2026
Merged

Obed0101 merged 1 commit into
devfrom
codex/beta17-provenance

Conversation

@Obed0101

@Obed0101 Obed0101 commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Problem

Beta16 release metadata was attested on Blacksmith self-hosted infrastructure, while the updater intentionally rejects self-hosted attestations with --deny-self-hosted-runners. Checksums and signatures were valid, but updates were blocked by the runner policy.

Solution

  • Run the final release assembly and attestation job on GitHub-hosted ubuntu-24.04.
  • Fail closed if the job is ever scheduled outside GitHub-hosted infrastructure.
  • Keep the updater's self-hosted rejection unchanged.
  • Add beta17 release notes.

Validation

  • node --test script/release-index.test.mjs — 3 passed.
  • Ruby YAML parse — valid.
  • Release provenance workflow contract check — valid.
  • git diff --check — passed.
  • Reproduced beta16 rejection and confirmed a GitHub-hosted attestation passes the same gh attestation verify --deny-self-hosted-runners policy.

Rollout

After merge, run the release workflow for 0.1.44-beta.17. Existing beta16 installations should update to beta17 without a manual reinstall.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@Obed0101
Obed0101 merged commit 1327467 into dev Sep 23, 2026
6 checks passed
@Obed0101
Obed0101 deleted the codex/beta17-provenance branch September 23, 2026 23:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant