Skip to content

Block marketplace releases without verified production tags - #9

Closed
Paul Yuknewicz (paulyuk) wants to merge 2 commits into
paulyuk-production-authoring-marketplacefrom
paulyuk-enforce-production-marketplace-ci
Closed

Paul Yuknewicz (paulyuk) wants to merge 2 commits into
paulyuk-production-authoring-marketplacefrom
paulyuk-enforce-production-marketplace-ci

Conversation

@paulyuk

@paulyuk Paul Yuknewicz (paulyuk) commented Sep 24, 2026 •

Copy link
Copy Markdown
Member

Summary

Add an always-present production-marketplace-release pull-request check that can be required without leaving unrelated PRs pending. It inspects changed filenames through GitHub's paginated, read-only pull-request API; only marketplace, product, verifier, workflow, or related release-file edits fetch full Git history and tags, set up Node 22, run the existing marketplace tests, and run the unmodified default strict production verifier. An API error fails the job, and GitHub's 3,000-file response ceiling triggers verification rather than a skip. Renames check both old and new paths. This changes only the workflow and release-gate documentation; no product, checksum, or verifier bytes change.

Release and governance checks

  • Human review of this CI gate and any applicable security/legal/licensing/notice requirements.
  • No internal-only payloads, credentials, tags, or plugin installations are added.
  • Canvas package release process: not applicable; this PR does not distribute a package.

Validation and release hold

  • node --test test/plugin-marketplace.test.mjs: 7 passing.
  • node scripts/verify-plugin-marketplace.mjs: expected failure, azure-functions-hosted-skills@0.5.1: expected exactly one reviewed immutable release tag. No synthetic refs or bypasses were used; remote production tags are absent.
  • Parsed workflow YAML and exercised the exact changed-path script with unrelated docs/README (skip), manifest/product/verifier/workflow edits (verify), renamed release file (verify), 3,000 files (verify), and failed API (job fails). Confirmed conditional checkout/setup/tests, full tag checkout, and no Azure SRE references.

Stack: base is #8 (paulyuk-production-authoring-marketplace), not main; #6 and #7 remain upstream. Relevant changes remain intentionally red until approved product PRs merge and all three real production tags exist; rerun after tag publication. Unrelated PRs get the same successful named check without running the verifier. Do not treat this PR as release approval. An administrator must require production-marketplace-release on protected release branches; the workflow alone does not enforce merging policy. No reviewer is requested pending user-authorized production review signoff and a staging strict pass against real tags.

Paul Yuknewicz and others added 2 commits September 24, 2026 01:26
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@paulyuk

Copy link
Copy Markdown
Member Author

Closing this optional CI-gate proposal at the release owner’s direction. It is not a dependency for the production release: verify against genuine production tags with the existing strict verifier and reviewed receipts after the product PRs merge. No provisional refs or merge bypasses.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant