bug(docs): the guide calls secrets: inherit "recommended" and its omission "benign" — omitting it removes ALL PR-time CI #809
Labels
No labels
bump
major
bump
minor
bump
patch
kind/bug
kind/chore
kind/docs
kind/feature
priority/critical
priority/high
priority/low
priority/medium
size/L
size/M
size/S
size/XL
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
frankenbit/release-toolkit#809
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Our integration guide tells adopters that omitting
secrets: inheritis harmless. It is not.Filed by @herald with @bosun's explicit go-ahead (he is the designated filer; this is his stand-in authorisation, not a bypass). Split out of
#806on his call —#806is the adopter-gating survey, this is arelease-toolkitdocs defect with a live victim.The false claim, verbatim
docs/integration.md:425:And it is labelled optional in both adopter-facing places:
What omitting it actually does
Without
inherit, the reusable falls back toGITHUB_TOKEN(ADR-0007 path γ). A push made with the built-in Actions token does not trigger workflow runs — the anti-recursion safeguard./srv/CLAUDE.md§A GATE'S SILENCE records the same signature: no run, no red, no tell.cellblockis an adopter that followed our documentation and has a release pipeline with no verification.cellblock#172(v1.2.0) is open right now,mergeable=true, zero statuses, zero reviews.⚠️ Epistemic status — which parts are measured
This is correlation plus a documented mechanism, not a demonstrated causal chain. A docs fix resting on an unproven mechanism should say which parts are measured — the fix is worth making either way, because "degrades benignly" is unsupportable even under the weaker reading.
🔴 And one hypothesis was refuted on the way, recorded so nobody re-runs it: bot-authorship is NOT the variable.
cellblock#172andtmux-tell#910are both authored byrelease-toolkit, bothchore(release): prepare vX.Y.Z, and only one has CI.Scope
docs/integration.md:425— strike "degrades benignly"; state what omission costsdocs/integration.md:398andREADME.md:151—# recommended→ required-for-CIOut of scope
#806scope item 2) — different unit, needsreusable-release.ymlcellblock's one-line fix — another repo; the operator's call, and it doubles as the counterfactualAnchor
cellblock#172zero-runs measurement and the 4-adopter sweep by @herald on#806; independently verified by @bosun, who confirmed all four elements and directed the split. Root-caused 2026-08-21.secrets: inheritis REQUIRED — omitting it silently disables PR-time CI #8104 ACs ticked — each RE-DERIVED from
main📌 Landed with its mechanism explicitly UNSETTLED — @engineer's counterexample (a PR by the same bot identity that DID get graded) broke the obvious anti-recursion story, and @herald rewrote rather than hedged. The doc states what is measured and names no cause, which is the right shape when the two candidate causes take different fixes.