chore(release): v0.63.0 #1448

Merged
bosun merged 1 commit from release-prep/rolling into main 2026-09-07 23:42:49 +02:00
Member

Changelog density — clean

  • PASS — check 7 (sentence length): all sentences ≤ 25 words. Lists, tables and blockquotes are measured too (#632).
  • PASS — check 8 (paren nesting): all paragraphs ≤ depth 2
  • PASS — check 9 (paragraph length): all paragraphs ≤ 75 words. Lists, tables and blockquotes are measured too (#632).

Advisory mirror of the cut-time gate, computed when this description was written. It carries no authority: the cut re-runs these checks against the section as it stands then, and this branch is recreated from main on every compose.

Added

  • adoption: mirror-release.yml gains a guarded force_recreate (#1426).

Changed

None.

Fixed

  • adoption: a corrected release note now reaches the public mirror (#1426).
  • release-state: v0.62.4 is recorded in the manifest, so the release gate stops refusing every push (#1444).
  • prepared-uncut-check: published interrupted cuts now name manifest-only recovery and correct SHA/time semantics (#1452).
  • fragment-check: local runs now refuse with COULD-NOT-GRADE when PR coverage inputs are absent (#1456).
  • decide: the pending-cut message no longer recommends a destructive recovery on a shipped release (#1457)
  • release gate: digest-pin-verify distinguishes stale anchors from wrong tags (#1458)

Removed

None.

Deprecated

None.

Upgrade

None.

Internal

  • ci: the drift report now reopens its tracker before commenting (#1348)
  • docs: the integration guide's adoption path carries no historical asides (#1407)
  • fix: the worked-example provenance check no longer reports a documented section as undocumented (#1421)
  • internal: the Status rule says which numbers it is about (#1423).
  • docs: six passages no longer assume the reader knows our internal vocabulary (#1427)
  • test: the cut path's doc-staging step is now covered (#1438)
  • ci: mirror-drift-check now grades the newest release instead of excluding it permanently (#1445)
  • internal: manifest pushes retry on concurrent base advances; fail closed on unchanged, non-linear, unrelated, conflicting, or repeated rejection (#1447).
  • internal: anchor-check now runs in the pull-request docs gate and preserves could-not-grade diagnostics (#1451).
  • internal: pull-request docs checks now reject tags whose action image digest is still the all-zero placeholder (#1453).
<!-- rt:density-verdict --> ### Changelog density — clean - **PASS** — check 7 (sentence length): all sentences ≤ 25 words. Lists, tables and blockquotes are measured too (#632). - **PASS** — check 8 (paren nesting): all paragraphs ≤ depth 2 - **PASS** — check 9 (paragraph length): all paragraphs ≤ 75 words. Lists, tables and blockquotes are measured too (#632). _Advisory mirror of the cut-time gate, computed when this description was written._ _It carries no authority: the cut re-runs these checks against the section as it stands then, and this branch is recreated from `main` on every compose._ <!-- /rt:density-verdict --> ### Added - **adoption**: `mirror-release.yml` gains a guarded `force_recreate` (#1426). ### Changed None. ### Fixed - **adoption**: a corrected release note now reaches the public mirror (#1426). - **release-state**: v0.62.4 is recorded in the manifest, so the release gate stops refusing every push (#1444). - **prepared-uncut-check**: published interrupted cuts now name manifest-only recovery and correct SHA/time semantics (#1452). - **fragment-check**: local runs now refuse with COULD-NOT-GRADE when PR coverage inputs are absent (#1456). - **decide**: the pending-cut message no longer recommends a destructive recovery on a shipped release (#1457) - **release gate**: `digest-pin-verify` distinguishes stale anchors from wrong tags (#1458) ### Removed None. ### Deprecated None. ### Upgrade None. ### Internal - **ci**: the drift report now reopens its tracker before commenting (#1348) - **docs**: the integration guide's adoption path carries no historical asides (#1407) - **fix**: the worked-example provenance check no longer reports a documented section as undocumented (#1421) - **internal**: the Status rule says which numbers it is about (#1423). - **docs**: six passages no longer assume the reader knows our internal vocabulary (#1427) - **test**: the cut path's doc-staging step is now covered (#1438) - **ci**: `mirror-drift-check` now grades the newest release instead of excluding it permanently (#1445) - **internal**: manifest pushes retry on concurrent base advances; fail closed on unchanged, non-linear, unrelated, conflicting, or repeated rejection (#1447). - **internal**: anchor-check now runs in the pull-request docs gate and preserves could-not-grade diagnostics (#1451). - **internal**: pull-request docs checks now reject tags whose action image digest is still the all-zero placeholder (#1453).
chore(release): prepare v0.63.0
Some checks failed
check-self-bootstrap / check (pull_request) Has been skipped
fork-pr-approval-notice / explain fork workflow approval (pull_request_target) Successful in 5s
gitea-twin-check / check (pull_request) Successful in 6s
go-ci / record reviewed vs landed commit (pull_request) Has been skipped
base-divergence-check / check (pull_request) Successful in 24s
ac-closure-check / ac-closure check (pull_request) Successful in 43s
go-ci / lint + build + test (pull_request) Successful in 31s
changelog-body-check / changelog body Cold-Read linter (pull_request) Successful in 45s
ac-closure-check / check (pull_request) Successful in 0s
changelog-body-check / check (pull_request) Successful in 0s
tests / workflow-schema (pull_request) Successful in 4s
fragment-check / changelog fragment-kind (pull_request) Successful in 46s
prep-order-check / check (pull_request) Successful in 32s
fragment-check / check (pull_request) Successful in 0s
tests / contract-paths (pull_request) Successful in 4s
readme-pin-check / check (pull_request) Failing after 29s
workflow-parse-check / toolkit-self parse guard and controls (pull_request) Successful in 4s
manifest-check / manifest-vs-tag consistency (pull_request) Successful in 49s
manifest-check / check (pull_request) Successful in 0s
go-ci / page landing-tree failure (pull_request) Has been skipped
tests / shellcheck (pull_request) Successful in 24s
register-check / register-drift check (pull_request) Successful in 51s
tests / dated-examples (pull_request) Successful in 38s
register-check / check (pull_request) Successful in 0s
workflow-parse-check / workflow parse and schema (pull_request) Successful in 31s
workflow-parse-check / check (pull_request) Successful in 0s
toolkit-self-gates / toolkit-self gates (PR's own rt) (pull_request) Successful in 55s
tests / bats (pull_request) Successful in 1m23s
ec96f54870
Generated by release-toolkit rt prep.

Tracker: frankenbit/release-toolkit#1
release-bot force-pushed release-prep/rolling from ec96f54870
Some checks failed
check-self-bootstrap / check (pull_request) Has been skipped
fork-pr-approval-notice / explain fork workflow approval (pull_request_target) Successful in 5s
gitea-twin-check / check (pull_request) Successful in 6s
go-ci / record reviewed vs landed commit (pull_request) Has been skipped
base-divergence-check / check (pull_request) Successful in 24s
ac-closure-check / ac-closure check (pull_request) Successful in 43s
go-ci / lint + build + test (pull_request) Successful in 31s
changelog-body-check / changelog body Cold-Read linter (pull_request) Successful in 45s
ac-closure-check / check (pull_request) Successful in 0s
changelog-body-check / check (pull_request) Successful in 0s
tests / workflow-schema (pull_request) Successful in 4s
fragment-check / changelog fragment-kind (pull_request) Successful in 46s
prep-order-check / check (pull_request) Successful in 32s
fragment-check / check (pull_request) Successful in 0s
tests / contract-paths (pull_request) Successful in 4s
readme-pin-check / check (pull_request) Failing after 29s
workflow-parse-check / toolkit-self parse guard and controls (pull_request) Successful in 4s
manifest-check / manifest-vs-tag consistency (pull_request) Successful in 49s
manifest-check / check (pull_request) Successful in 0s
go-ci / page landing-tree failure (pull_request) Has been skipped
tests / shellcheck (pull_request) Successful in 24s
register-check / register-drift check (pull_request) Successful in 51s
tests / dated-examples (pull_request) Successful in 38s
register-check / check (pull_request) Successful in 0s
workflow-parse-check / workflow parse and schema (pull_request) Successful in 31s
workflow-parse-check / check (pull_request) Successful in 0s
toolkit-self-gates / toolkit-self gates (PR's own rt) (pull_request) Successful in 55s
tests / bats (pull_request) Successful in 1m23s
to c63143695a
All checks were successful
fragment-check / changelog fragment-kind (pull_request) Successful in 8s
fragment-check / check (pull_request) Successful in 0s
ac-closure-check / ac-closure check (pull_request) Successful in 47s
ac-closure-check / check (pull_request) Successful in 0s
toolkit-self-gates / toolkit-self gates (PR's own rt) (pull_request) Successful in 1m15s
2026-09-07 20:56:37 +02:00
Compare
release-bot force-pushed release-prep/rolling from c63143695a
All checks were successful
fragment-check / changelog fragment-kind (pull_request) Successful in 8s
fragment-check / check (pull_request) Successful in 0s
ac-closure-check / ac-closure check (pull_request) Successful in 47s
ac-closure-check / check (pull_request) Successful in 0s
toolkit-self-gates / toolkit-self gates (PR's own rt) (pull_request) Successful in 1m15s
to a768bd2096
All checks were successful
check-self-bootstrap / check (pull_request) Has been skipped
fork-pr-approval-notice / explain fork workflow approval (pull_request_target) Successful in 22s
go-ci / record reviewed vs landed commit (pull_request) Has been skipped
base-divergence-check / check (pull_request) Successful in 30s
prep-order-check / check (pull_request) Successful in 6s
gitea-twin-check / check (pull_request) Successful in 27s
ac-closure-check / ac-closure check (pull_request) Successful in 47s
register-check / register-drift check (pull_request) Successful in 7s
changelog-body-check / changelog body Cold-Read linter (pull_request) Successful in 47s
ac-closure-check / check (pull_request) Successful in 0s
register-check / check (pull_request) Successful in 0s
changelog-body-check / check (pull_request) Successful in 0s
readme-pin-check / check (pull_request) Successful in 28s
fragment-check / changelog fragment-kind (pull_request) Successful in 47s
fragment-check / check (pull_request) Successful in 0s
tests / workflow-schema (pull_request) Successful in 32s
tests / bats (pull_request) Successful in 31s
manifest-check / manifest-vs-tag consistency (pull_request) Successful in 52s
tests / contract-paths (pull_request) Successful in 33s
manifest-check / check (pull_request) Successful in 0s
workflow-parse-check / workflow parse and schema (pull_request) Successful in 4s
workflow-parse-check / check (pull_request) Successful in 0s
tests / dated-examples (pull_request) Successful in 40s
tests / shellcheck (pull_request) Successful in 28s
go-ci / lint + build + test (pull_request) Successful in 1m10s
go-ci / page landing-tree failure (pull_request) Has been skipped
workflow-parse-check / toolkit-self parse guard and controls (pull_request) Successful in 27s
toolkit-self-gates / toolkit-self gates (PR's own rt) (pull_request) Successful in 54s
2026-09-07 21:19:51 +02:00
Compare
release-bot force-pushed release-prep/rolling from a768bd2096
All checks were successful
check-self-bootstrap / check (pull_request) Has been skipped
fork-pr-approval-notice / explain fork workflow approval (pull_request_target) Successful in 22s
go-ci / record reviewed vs landed commit (pull_request) Has been skipped
base-divergence-check / check (pull_request) Successful in 30s
prep-order-check / check (pull_request) Successful in 6s
gitea-twin-check / check (pull_request) Successful in 27s
ac-closure-check / ac-closure check (pull_request) Successful in 47s
register-check / register-drift check (pull_request) Successful in 7s
changelog-body-check / changelog body Cold-Read linter (pull_request) Successful in 47s
ac-closure-check / check (pull_request) Successful in 0s
register-check / check (pull_request) Successful in 0s
changelog-body-check / check (pull_request) Successful in 0s
readme-pin-check / check (pull_request) Successful in 28s
fragment-check / changelog fragment-kind (pull_request) Successful in 47s
fragment-check / check (pull_request) Successful in 0s
tests / workflow-schema (pull_request) Successful in 32s
tests / bats (pull_request) Successful in 31s
manifest-check / manifest-vs-tag consistency (pull_request) Successful in 52s
tests / contract-paths (pull_request) Successful in 33s
manifest-check / check (pull_request) Successful in 0s
workflow-parse-check / workflow parse and schema (pull_request) Successful in 4s
workflow-parse-check / check (pull_request) Successful in 0s
tests / dated-examples (pull_request) Successful in 40s
tests / shellcheck (pull_request) Successful in 28s
go-ci / lint + build + test (pull_request) Successful in 1m10s
go-ci / page landing-tree failure (pull_request) Has been skipped
workflow-parse-check / toolkit-self parse guard and controls (pull_request) Successful in 27s
toolkit-self-gates / toolkit-self gates (PR's own rt) (pull_request) Successful in 54s
to 70964794fd
All checks were successful
check-self-bootstrap / check (pull_request) Has been skipped
fork-pr-approval-notice / explain fork workflow approval (pull_request_target) Successful in 5s
go-ci / record reviewed vs landed commit (pull_request) Has been skipped
gitea-twin-check / check (pull_request) Successful in 25s
base-divergence-check / check (pull_request) Successful in 28s
go-ci / lint + build + test (pull_request) Successful in 35s
tests / workflow-schema (pull_request) Successful in 5s
changelog-body-check / changelog body Cold-Read linter (pull_request) Successful in 48s
changelog-body-check / check (pull_request) Successful in 0s
fragment-check / changelog fragment-kind (pull_request) Successful in 49s
fragment-check / check (pull_request) Successful in 0s
ac-closure-check / ac-closure check (pull_request) Successful in 52s
ac-closure-check / check (pull_request) Successful in 0s
readme-pin-check / check (pull_request) Successful in 30s
prep-order-check / check (pull_request) Successful in 35s
manifest-check / manifest-vs-tag consistency (pull_request) Successful in 55s
manifest-check / check (pull_request) Successful in 0s
tests / contract-paths (pull_request) Successful in 29s
register-check / register-drift check (pull_request) Successful in 50s
go-ci / page landing-tree failure (pull_request) Has been skipped
register-check / check (pull_request) Successful in 0s
tests / shellcheck (pull_request) Successful in 27s
tests / bats (pull_request) Successful in 33s
tests / dated-examples (pull_request) Successful in 39s
workflow-parse-check / toolkit-self parse guard and controls (pull_request) Successful in 31s
workflow-parse-check / workflow parse and schema (pull_request) Successful in 29s
workflow-parse-check / check (pull_request) Successful in 0s
toolkit-self-gates / toolkit-self gates (PR's own rt) (pull_request) Successful in 55s
2026-09-07 21:24:11 +02:00
Compare
release-bot force-pushed release-prep/rolling from 70964794fd
All checks were successful
check-self-bootstrap / check (pull_request) Has been skipped
fork-pr-approval-notice / explain fork workflow approval (pull_request_target) Successful in 5s
go-ci / record reviewed vs landed commit (pull_request) Has been skipped
gitea-twin-check / check (pull_request) Successful in 25s
base-divergence-check / check (pull_request) Successful in 28s
go-ci / lint + build + test (pull_request) Successful in 35s
tests / workflow-schema (pull_request) Successful in 5s
changelog-body-check / changelog body Cold-Read linter (pull_request) Successful in 48s
changelog-body-check / check (pull_request) Successful in 0s
fragment-check / changelog fragment-kind (pull_request) Successful in 49s
fragment-check / check (pull_request) Successful in 0s
ac-closure-check / ac-closure check (pull_request) Successful in 52s
ac-closure-check / check (pull_request) Successful in 0s
readme-pin-check / check (pull_request) Successful in 30s
prep-order-check / check (pull_request) Successful in 35s
manifest-check / manifest-vs-tag consistency (pull_request) Successful in 55s
manifest-check / check (pull_request) Successful in 0s
tests / contract-paths (pull_request) Successful in 29s
register-check / register-drift check (pull_request) Successful in 50s
go-ci / page landing-tree failure (pull_request) Has been skipped
register-check / check (pull_request) Successful in 0s
tests / shellcheck (pull_request) Successful in 27s
tests / bats (pull_request) Successful in 33s
tests / dated-examples (pull_request) Successful in 39s
workflow-parse-check / toolkit-self parse guard and controls (pull_request) Successful in 31s
workflow-parse-check / workflow parse and schema (pull_request) Successful in 29s
workflow-parse-check / check (pull_request) Successful in 0s
toolkit-self-gates / toolkit-self gates (PR's own rt) (pull_request) Successful in 55s
to e1f4d3d49d
All checks were successful
check-self-bootstrap / check (pull_request) Has been skipped
changelog-body-check / changelog body Cold-Read linter (pull_request) Successful in 7s
changelog-body-check / check (pull_request) Successful in 0s
gitea-twin-check / check (pull_request) Successful in 6s
fork-pr-approval-notice / explain fork workflow approval (pull_request_target) Successful in 22s
go-ci / record reviewed vs landed commit (pull_request) Has been skipped
base-divergence-check / check (pull_request) Successful in 27s
ac-closure-check / ac-closure check (pull_request) Successful in 47s
ac-closure-check / check (pull_request) Successful in 0s
go-ci / lint + build + test (pull_request) Successful in 32s
fragment-check / changelog fragment-kind (pull_request) Successful in 46s
fragment-check / check (pull_request) Successful in 0s
readme-pin-check / check (pull_request) Successful in 27s
prep-order-check / check (pull_request) Successful in 35s
manifest-check / manifest-vs-tag consistency (pull_request) Successful in 48s
manifest-check / check (pull_request) Successful in 0s
tests / workflow-schema (pull_request) Successful in 30s
tests / contract-paths (pull_request) Successful in 29s
tests / shellcheck (pull_request) Successful in 28s
tests / bats (pull_request) Successful in 34s
go-ci / page landing-tree failure (pull_request) Has been skipped
tests / dated-examples (pull_request) Successful in 38s
register-check / register-drift check (pull_request) Successful in 51s
register-check / check (pull_request) Successful in 0s
workflow-parse-check / toolkit-self parse guard and controls (pull_request) Successful in 30s
workflow-parse-check / workflow parse and schema (pull_request) Successful in 29s
workflow-parse-check / check (pull_request) Successful in 0s
toolkit-self-gates / toolkit-self gates (PR's own rt) (pull_request) Successful in 57s
2026-09-07 21:48:03 +02:00
Compare
release-bot force-pushed release-prep/rolling from e1f4d3d49d
All checks were successful
check-self-bootstrap / check (pull_request) Has been skipped
changelog-body-check / changelog body Cold-Read linter (pull_request) Successful in 7s
changelog-body-check / check (pull_request) Successful in 0s
gitea-twin-check / check (pull_request) Successful in 6s
fork-pr-approval-notice / explain fork workflow approval (pull_request_target) Successful in 22s
go-ci / record reviewed vs landed commit (pull_request) Has been skipped
base-divergence-check / check (pull_request) Successful in 27s
ac-closure-check / ac-closure check (pull_request) Successful in 47s
ac-closure-check / check (pull_request) Successful in 0s
go-ci / lint + build + test (pull_request) Successful in 32s
fragment-check / changelog fragment-kind (pull_request) Successful in 46s
fragment-check / check (pull_request) Successful in 0s
readme-pin-check / check (pull_request) Successful in 27s
prep-order-check / check (pull_request) Successful in 35s
manifest-check / manifest-vs-tag consistency (pull_request) Successful in 48s
manifest-check / check (pull_request) Successful in 0s
tests / workflow-schema (pull_request) Successful in 30s
tests / contract-paths (pull_request) Successful in 29s
tests / shellcheck (pull_request) Successful in 28s
tests / bats (pull_request) Successful in 34s
go-ci / page landing-tree failure (pull_request) Has been skipped
tests / dated-examples (pull_request) Successful in 38s
register-check / register-drift check (pull_request) Successful in 51s
register-check / check (pull_request) Successful in 0s
workflow-parse-check / toolkit-self parse guard and controls (pull_request) Successful in 30s
workflow-parse-check / workflow parse and schema (pull_request) Successful in 29s
workflow-parse-check / check (pull_request) Successful in 0s
toolkit-self-gates / toolkit-self gates (PR's own rt) (pull_request) Successful in 57s
to d1458fd213
All checks were successful
check-self-bootstrap / check (pull_request) Has been skipped
fork-pr-approval-notice / explain fork workflow approval (pull_request_target) Successful in 5s
go-ci / record reviewed vs landed commit (pull_request) Has been skipped
gitea-twin-check / check (pull_request) Successful in 24s
base-divergence-check / check (pull_request) Successful in 30s
go-ci / lint + build + test (pull_request) Successful in 31s
tests / workflow-schema (pull_request) Successful in 4s
prep-order-check / check (pull_request) Successful in 30s
ac-closure-check / ac-closure check (pull_request) Successful in 48s
ac-closure-check / check (pull_request) Successful in 0s
changelog-body-check / changelog body Cold-Read linter (pull_request) Successful in 49s
changelog-body-check / check (pull_request) Successful in 0s
fragment-check / changelog fragment-kind (pull_request) Successful in 54s
fragment-check / check (pull_request) Successful in 0s
readme-pin-check / check (pull_request) Successful in 34s
manifest-check / manifest-vs-tag consistency (pull_request) Successful in 52s
manifest-check / check (pull_request) Successful in 0s
tests / shellcheck (pull_request) Successful in 25s
tests / bats (pull_request) Successful in 32s
go-ci / page landing-tree failure (pull_request) Has been skipped
tests / contract-paths (pull_request) Successful in 31s
register-check / register-drift check (pull_request) Successful in 53s
register-check / check (pull_request) Successful in 0s
workflow-parse-check / toolkit-self parse guard and controls (pull_request) Successful in 29s
tests / dated-examples (pull_request) Successful in 47s
workflow-parse-check / workflow parse and schema (pull_request) Successful in 32s
workflow-parse-check / check (pull_request) Successful in 0s
toolkit-self-gates / toolkit-self gates (PR's own rt) (pull_request) Successful in 59s
2026-09-07 21:52:38 +02:00
Compare
release-bot force-pushed release-prep/rolling from d1458fd213
All checks were successful
check-self-bootstrap / check (pull_request) Has been skipped
fork-pr-approval-notice / explain fork workflow approval (pull_request_target) Successful in 5s
go-ci / record reviewed vs landed commit (pull_request) Has been skipped
gitea-twin-check / check (pull_request) Successful in 24s
base-divergence-check / check (pull_request) Successful in 30s
go-ci / lint + build + test (pull_request) Successful in 31s
tests / workflow-schema (pull_request) Successful in 4s
prep-order-check / check (pull_request) Successful in 30s
ac-closure-check / ac-closure check (pull_request) Successful in 48s
ac-closure-check / check (pull_request) Successful in 0s
changelog-body-check / changelog body Cold-Read linter (pull_request) Successful in 49s
changelog-body-check / check (pull_request) Successful in 0s
fragment-check / changelog fragment-kind (pull_request) Successful in 54s
fragment-check / check (pull_request) Successful in 0s
readme-pin-check / check (pull_request) Successful in 34s
manifest-check / manifest-vs-tag consistency (pull_request) Successful in 52s
manifest-check / check (pull_request) Successful in 0s
tests / shellcheck (pull_request) Successful in 25s
tests / bats (pull_request) Successful in 32s
go-ci / page landing-tree failure (pull_request) Has been skipped
tests / contract-paths (pull_request) Successful in 31s
register-check / register-drift check (pull_request) Successful in 53s
register-check / check (pull_request) Successful in 0s
workflow-parse-check / toolkit-self parse guard and controls (pull_request) Successful in 29s
tests / dated-examples (pull_request) Successful in 47s
workflow-parse-check / workflow parse and schema (pull_request) Successful in 32s
workflow-parse-check / check (pull_request) Successful in 0s
toolkit-self-gates / toolkit-self gates (PR's own rt) (pull_request) Successful in 59s
to 8ec5220611
All checks were successful
check-self-bootstrap / check (pull_request) Has been skipped
fragment-check / changelog fragment-kind (pull_request) Successful in 10s
go-ci / record reviewed vs landed commit (pull_request) Has been skipped
fragment-check / check (pull_request) Successful in 0s
manifest-check / manifest-vs-tag consistency (pull_request) Successful in 8s
fork-pr-approval-notice / explain fork workflow approval (pull_request_target) Successful in 23s
manifest-check / check (pull_request) Successful in 0s
base-divergence-check / check (pull_request) Successful in 29s
readme-pin-check / check (pull_request) Successful in 8s
gitea-twin-check / check (pull_request) Successful in 30s
prep-order-check / check (pull_request) Successful in 31s
changelog-body-check / changelog body Cold-Read linter (pull_request) Successful in 48s
ac-closure-check / ac-closure check (pull_request) Successful in 48s
changelog-body-check / check (pull_request) Successful in 0s
ac-closure-check / check (pull_request) Successful in 0s
tests / workflow-schema (pull_request) Successful in 33s
tests / bats (pull_request) Successful in 33s
workflow-parse-check / workflow parse and schema (pull_request) Successful in 5s
workflow-parse-check / check (pull_request) Successful in 0s
tests / shellcheck (pull_request) Successful in 26s
tests / contract-paths (pull_request) Successful in 30s
register-check / register-drift check (pull_request) Successful in 54s
register-check / check (pull_request) Successful in 0s
tests / dated-examples (pull_request) Successful in 44s
go-ci / lint + build + test (pull_request) Successful in 1m13s
go-ci / page landing-tree failure (pull_request) Has been skipped
workflow-parse-check / toolkit-self parse guard and controls (pull_request) Successful in 27s
toolkit-self-gates / toolkit-self gates (PR's own rt) (pull_request) Successful in 59s
2026-09-07 22:19:06 +02:00
Compare
release-bot force-pushed release-prep/rolling from 8ec5220611
All checks were successful
check-self-bootstrap / check (pull_request) Has been skipped
fragment-check / changelog fragment-kind (pull_request) Successful in 10s
go-ci / record reviewed vs landed commit (pull_request) Has been skipped
fragment-check / check (pull_request) Successful in 0s
manifest-check / manifest-vs-tag consistency (pull_request) Successful in 8s
fork-pr-approval-notice / explain fork workflow approval (pull_request_target) Successful in 23s
manifest-check / check (pull_request) Successful in 0s
base-divergence-check / check (pull_request) Successful in 29s
readme-pin-check / check (pull_request) Successful in 8s
gitea-twin-check / check (pull_request) Successful in 30s
prep-order-check / check (pull_request) Successful in 31s
changelog-body-check / changelog body Cold-Read linter (pull_request) Successful in 48s
ac-closure-check / ac-closure check (pull_request) Successful in 48s
changelog-body-check / check (pull_request) Successful in 0s
ac-closure-check / check (pull_request) Successful in 0s
tests / workflow-schema (pull_request) Successful in 33s
tests / bats (pull_request) Successful in 33s
workflow-parse-check / workflow parse and schema (pull_request) Successful in 5s
workflow-parse-check / check (pull_request) Successful in 0s
tests / shellcheck (pull_request) Successful in 26s
tests / contract-paths (pull_request) Successful in 30s
register-check / register-drift check (pull_request) Successful in 54s
register-check / check (pull_request) Successful in 0s
tests / dated-examples (pull_request) Successful in 44s
go-ci / lint + build + test (pull_request) Successful in 1m13s
go-ci / page landing-tree failure (pull_request) Has been skipped
workflow-parse-check / toolkit-self parse guard and controls (pull_request) Successful in 27s
toolkit-self-gates / toolkit-self gates (PR's own rt) (pull_request) Successful in 59s
to 0ab48d11b6
Some checks failed
check-self-bootstrap / check (pull_request) Has been skipped
fork-pr-approval-notice / explain fork workflow approval (pull_request_target) Successful in 24s
go-ci / record reviewed vs landed commit (pull_request) Has been skipped
base-divergence-check / check (pull_request) Successful in 28s
gitea-twin-check / check (pull_request) Successful in 29s
ac-closure-check / ac-closure check (pull_request) Successful in 51s
ac-closure-check / check (pull_request) Successful in 0s
changelog-body-check / changelog body Cold-Read linter (pull_request) Successful in 52s
changelog-body-check / check (pull_request) Successful in 0s
fragment-check / changelog fragment-kind (pull_request) Successful in 57s
fragment-check / check (pull_request) Successful in 0s
prep-order-check / check (pull_request) Successful in 38s
readme-pin-check / check (pull_request) Failing after 42s
manifest-check / manifest-vs-tag consistency (pull_request) Successful in 1m0s
manifest-check / check (pull_request) Successful in 0s
tests / workflow-schema (pull_request) Successful in 35s
go-ci / lint + build + test (pull_request) Successful in 1m18s
tests / contract-paths (pull_request) Successful in 30s
register-check / register-drift check (pull_request) Successful in 59s
register-check / check (pull_request) Successful in 0s
go-ci / page landing-tree failure (pull_request) Has been skipped
tests / shellcheck (pull_request) Successful in 29s
tests / dated-examples (pull_request) Successful in 48s
workflow-parse-check / toolkit-self parse guard and controls (pull_request) Successful in 29s
workflow-parse-check / workflow parse and schema (pull_request) Successful in 29s
workflow-parse-check / check (pull_request) Successful in 0s
tests / bats (pull_request) Successful in 1m23s
toolkit-self-gates / toolkit-self gates (PR's own rt) (pull_request) Successful in 56s
2026-09-07 22:24:30 +02:00
Compare
release-bot force-pushed release-prep/rolling from 0ab48d11b6
Some checks failed
check-self-bootstrap / check (pull_request) Has been skipped
fork-pr-approval-notice / explain fork workflow approval (pull_request_target) Successful in 24s
go-ci / record reviewed vs landed commit (pull_request) Has been skipped
base-divergence-check / check (pull_request) Successful in 28s
gitea-twin-check / check (pull_request) Successful in 29s
ac-closure-check / ac-closure check (pull_request) Successful in 51s
ac-closure-check / check (pull_request) Successful in 0s
changelog-body-check / changelog body Cold-Read linter (pull_request) Successful in 52s
changelog-body-check / check (pull_request) Successful in 0s
fragment-check / changelog fragment-kind (pull_request) Successful in 57s
fragment-check / check (pull_request) Successful in 0s
prep-order-check / check (pull_request) Successful in 38s
readme-pin-check / check (pull_request) Failing after 42s
manifest-check / manifest-vs-tag consistency (pull_request) Successful in 1m0s
manifest-check / check (pull_request) Successful in 0s
tests / workflow-schema (pull_request) Successful in 35s
go-ci / lint + build + test (pull_request) Successful in 1m18s
tests / contract-paths (pull_request) Successful in 30s
register-check / register-drift check (pull_request) Successful in 59s
register-check / check (pull_request) Successful in 0s
go-ci / page landing-tree failure (pull_request) Has been skipped
tests / shellcheck (pull_request) Successful in 29s
tests / dated-examples (pull_request) Successful in 48s
workflow-parse-check / toolkit-self parse guard and controls (pull_request) Successful in 29s
workflow-parse-check / workflow parse and schema (pull_request) Successful in 29s
workflow-parse-check / check (pull_request) Successful in 0s
tests / bats (pull_request) Successful in 1m23s
toolkit-self-gates / toolkit-self gates (PR's own rt) (pull_request) Successful in 56s
to 4bea5600a3
Some checks are pending
workflow-parse-check / check (pull_request) Successful in 0s
tests / dated-examples (pull_request) Successful in 47s
toolkit-self-gates / toolkit-self gates (PR's own rt) (pull_request) Successful in 55s
prepared-uncut-check / toolkit-self prepared-uncut controls (push) Successful in 6s
tests / dated-examples (push) Successful in 5s
go-ci / record reviewed vs landed commit (push) Successful in 16s
tests / contract-paths (push) Successful in 4s
gitea-twin-check / check (push) Successful in 22s
check-self-bootstrap / check (push) Successful in 22s
tests / workflow-schema (push) Successful in 24s
tests / shellcheck (push) Successful in 19s
prepared-uncut-check / prepared-but-uncut release (push) Successful in 45s
prepared-uncut-check / check (push) Successful in 0s
release / decide + act (push) Successful in 58s
release / release (push) Successful in 0s
go-ci / lint + build + test (push) Successful in 1m5s
go-ci / page landing-tree failure (push) Has been skipped
release / fire-cut (push) Successful in 7s
tests / bats (push) Successful in 1m16s
release-toolkit/manifest-postcondition manifest-postcondition verdict=landed
build-ref-check / check (push) Successful in 5s
mirror-drift-check / drift no unmirrored asset-bearing release
mirror-drift-check / could-not-grade no unmirrored asset-bearing release
mirror-drift-check / newest-release NOT GRADED: v0.63.0 just published and was excluded from this run; the daily scheduled run grades it
mirror drift check / check (release) Successful in 34s
goreleaser / build + publish rt asset (push) Successful in 1m3s
goreleaser / the release actually holds its assets (push) Successful in 3s
goreleaser / publish the rt image + bake its digest (push) Successful in 25s
goreleaser / adopters can pull the published image (push) Successful in 4s
goreleaser / adopters can fetch the published asset (push) Successful in 25s
2026-09-07 22:28:36 +02:00
Compare
surveyor approved these changes 2026-09-07 23:40:41 +02:00
surveyor left a comment

APPROVED @ 4bea5600. The artifact is clean. There is one live red, it is real, it is not caused by this PR, and it cannot block — so my stamp is the only enforcement and I am saying explicitly why I am not using it to hold.

The artifact — graded, not skimmed

VERSION                0.62.4 -> 0.63.0
fragments consumed     17 deleted
CHANGELOG bullets      17 added; 16 distinct refs (#1426 appears in Added AND Fixed)
set difference         fragments \ changelog = EMPTY ; changelog \ fragments = EMPTY
                       (both sides non-empty: 16 and 16 — the control)
build-ref pins         18 files, EXACTLY one distinct - line and one distinct + line:
                       'v0.62.4' -> 'v0.63.0'
files                  37 of 37 (paginated; changed_files is the denominator)
required contexts      complement = 0 of 23, enable_status_check=true
approvals whitelist    team `crew`, and surveyor is in it — so this stamp counts

🔴 The red: readme-pin-check / check — reproduced locally, and it is the SECOND step

Not in status_check_contexts, so nothing holds the merge on it. I built rt from this head and ran the gate's exact argv:

readme-pin-check          rc=0   18 prescriptive pins across 11 documents, all @v0.62.4, all servable
tag-action-digest-check   rc=1   tag v0.62.4 carries the all-zero image-digest placeholder in action.yml

The docs pin exactly one version — @v0.62.4, 18 times — and that tag's action is unusable. An adopter following docs/integration.md today gets sha256:000…0.

⚠️ I nearly reported a mechanism that does not exist, and the correction is the useful part

My first pass read action.yml at each tag from a local clone and produced this:

v0.62.4 ZERO · v0.62.3 real · v0.62.2 real · v0.62.1 ZERO · v0.62.0 real
v0.61.1 ZERO · v0.61.0 ZERO · v0.60.0 ZERO

I was one paragraph from writing "the bake is intermittent — 3 of the last 5 succeeded, so a spot-check would have said it works." It is not intermittent. Three of those eight reads were STALE: git fetch --tags does not move a tag ref that already exists locally, and the bake step force-moves the tag after committing the digest. After git fetch --force --tags, v0.62.1, v0.61.0 and v0.60.0 all moved and all carry real digests — confirmed against the API, which never touched my clone.

v0.62.4  ALL-ZERO   goreleaser run 25965  FAILURE
v0.62.3  real                             success
v0.62.2  real                             success
v0.62.1  real                             success     <- I had this ZERO
v0.62.0  real                             success
v0.61.1  ALL-ZERO   goreleaser run 22680  FAILURE
v0.61.0  real                             success     <- I had this ZERO
v0.60.0  real                             success     <- I had this ZERO

Corrected, it is perfectly deterministic: exactly the two tags whose goreleaser run FAILED carry the placeholder, and every successful run baked a real digest. The mechanism is the job order — goreleaser publishes the release, publish-image bakes and force-moves the tag afterwards — so a failure anywhere downstream of publication leaves a published release whose tag never got its digest. Fail-closed protects the tag from a WRONG pin; it cannot un-publish the release.

📌 readme-pin-check.yml's own step does git fetch --force --tags and its comment explains only the MISSING-tag case ("A missing local tag is COULD-NOT-GRADE"). The --force is load-bearing for a second reason the comment does not name: a stale tag is not missing, it answers confidently, and it answers wrong. Worth one line in that comment — it is the failure I actually hit.

The number in #1453's title

Its title says "five tags pin an all-zeros image digest". Swept all 122 tags after the force-fetch:

122 tags · 40 carry a sha256 pin · 14 ALL-ZERO · 82 no action.yml or no pin
all-zero: v0.43.0 v0.44.0 v0.44.1 v0.44.2 v0.45.0 v0.45.1 v0.46.0 v0.46.1
          v0.47.0 v0.48.0 v0.50.0 v0.54.1 v0.61.1 v0.62.4
DOC-PINNED among them: v0.62.4, and only v0.62.4 — the docs pin one version.

Three different true numbers — 14 tag-wide, 2 in the last eight, 1 doc-pinned — and they answer three different questions. The one that describes adopter exposure is 1. I am not asking anyone to renumber the title; I am recording the scope beside each figure so the next reader does not reconcile them.

Why I am not holding on it

Merging cuts v0.63.0 and does not touch the doc pinsprep does not advance them; mirror-release.yml does, after a manual mirror publish. So at merge time the docs still say @v0.62.4 whatever happens.

cut succeeds   v0.63.0 gets a real digest.   Docs still @v0.62.4. Red unchanged.
cut fails      v0.63.0 joins the broken set. Docs still @v0.62.4. No NEW exposure.

Holding this PR does not repair v0.62.4 and does not protect anyone from it. It would block the release train to protest a defect in an already-published release — a delay that fixes nothing, which is the false-hold shape this file warns costs nothing visible and wears the clothing of caution.

🔴 The one thing that IS actionable, and it is an ORDERING

The path that advances the doc pins does not run the digest check.

mirror-release.yml           tag-action-digest hits: 0   <- this is what re-pins the docs
reusable-mirror-release.yml  tag-action-digest hits: 0
readme-pin-check.yml         tag-action-digest hits: 5   <- runs only on pull_request

mirror-release.yml's "point the README at what the mirror can now serve" job runs rt readme-pin-check --fix — mirror servability — and nothing grades the tag's action digest before the pin moves. That is how @v0.62.4 became the pinned version while carrying the placeholder, and the detector that would have caught it (#1453/#1462) landed in this release cycle, after the fact.

The ask, and it is not this PR's job to carry it: do not advance the doc pins to v0.63.0 until tag-action-digest-check passes on v0.63.0. Either add the digest check to the --fix job before it opens the pin PR, or add readme-pin-check / check to status_check_contexts so the pin PR cannot merge red. Today the only thing standing between a broken tag and the docs is a red on an advisory context.

¶41 — you asked me to read the composed sequence, and the trigger does not fire

#1447 (rt post-cut's manifest push, inside reusable-release.yml's cut path) and #1449 (mirror-drift-check.yml, on: release: [published]).

The trigger is both touch one ordered construct AND at least one MOVES state the other READS. The second half is false here: mirror-drift-check.yml contains zero references to manifest or last_released_sha — it reads gitea.com's mirror state, not the manifest post-cut writes. They are independent, not composed.

📌 And the ordering hazard that DOES live in that pair was already found and handled#1445's header: the release-event run cannot grade its own tag, EXCLUDE_TAG is set for the whole run, so the newest release had no drift signal until the next cut. The daily cron with an empty EXCLUDE_TAG is the fix, and the newest-release pending context makes the gap visible immediately. I checked for your hazard and found their remedy for a different one.

What I did NOT check

The .gitea twins are not byte-identical to their .forgejo counterparts (11 of them). I did not grade that and I am not reporting it: gitea-twin-check / check is required and green, and it is the gate that owns the invariant — a hand-rolled cmp here would be a first opinion with a false witness. I also did not re-verify the 17 fragments' individual prose; fragment-check and changelog-body-check are both required and both green.


⚠️ This is the ROLLING PR — the release bot force-pushes it on every base move, and dismiss_stale_approvals=true. This stamp is bound to 4bea5600 and expires the moment the base moves. Re-ping me if it does; do not merge on a dismissed row.

**APPROVED @ `4bea5600`.** The artifact is clean. There is one live red, it is real, it is not caused by this PR, and it cannot block — so my stamp is the only enforcement and I am saying explicitly why I am not using it to hold. ## The artifact — graded, not skimmed ``` VERSION 0.62.4 -> 0.63.0 fragments consumed 17 deleted CHANGELOG bullets 17 added; 16 distinct refs (#1426 appears in Added AND Fixed) set difference fragments \ changelog = EMPTY ; changelog \ fragments = EMPTY (both sides non-empty: 16 and 16 — the control) build-ref pins 18 files, EXACTLY one distinct - line and one distinct + line: 'v0.62.4' -> 'v0.63.0' files 37 of 37 (paginated; changed_files is the denominator) required contexts complement = 0 of 23, enable_status_check=true approvals whitelist team `crew`, and surveyor is in it — so this stamp counts ``` ## 🔴 The red: `readme-pin-check / check` — reproduced locally, and it is the SECOND step Not in `status_check_contexts`, so nothing holds the merge on it. I built `rt` from this head and ran the gate's exact argv: ``` readme-pin-check rc=0 18 prescriptive pins across 11 documents, all @v0.62.4, all servable tag-action-digest-check rc=1 tag v0.62.4 carries the all-zero image-digest placeholder in action.yml ``` **The docs pin exactly one version — `@v0.62.4`, 18 times — and that tag's action is unusable.** An adopter following `docs/integration.md` today gets `sha256:000…0`. ### ⚠️ I nearly reported a mechanism that does not exist, and the correction is the useful part My first pass read `action.yml` at each tag from a local clone and produced this: ``` v0.62.4 ZERO · v0.62.3 real · v0.62.2 real · v0.62.1 ZERO · v0.62.0 real v0.61.1 ZERO · v0.61.0 ZERO · v0.60.0 ZERO ``` I was one paragraph from writing *"the bake is intermittent — 3 of the last 5 succeeded, so a spot-check would have said it works."* **It is not intermittent. Three of those eight reads were STALE**: `git fetch --tags` does **not** move a tag ref that already exists locally, and the bake step force-moves the tag after committing the digest. After `git fetch --force --tags`, `v0.62.1`, `v0.61.0` and `v0.60.0` all moved and all carry real digests — confirmed against the API, which never touched my clone. ``` v0.62.4 ALL-ZERO goreleaser run 25965 FAILURE v0.62.3 real success v0.62.2 real success v0.62.1 real success <- I had this ZERO v0.62.0 real success v0.61.1 ALL-ZERO goreleaser run 22680 FAILURE v0.61.0 real success <- I had this ZERO v0.60.0 real success <- I had this ZERO ``` **Corrected, it is perfectly deterministic: exactly the two tags whose goreleaser run FAILED carry the placeholder, and every successful run baked a real digest.** The mechanism is the job order — `goreleaser` publishes the release, `publish-image` bakes and force-moves the tag afterwards — so a failure anywhere downstream of publication leaves a *published* release whose tag never got its digest. Fail-closed protects the tag from a WRONG pin; it cannot un-publish the release. 📌 **`readme-pin-check.yml`'s own step does `git fetch --force --tags` and its comment explains only the MISSING-tag case** (*"A missing local tag is COULD-NOT-GRADE"*). **The `--force` is load-bearing for a second reason the comment does not name: a stale tag is not missing, it answers confidently, and it answers wrong.** Worth one line in that comment — it is the failure I actually hit. ### The number in `#1453`'s title Its title says *"five tags pin an all-zeros image digest"*. Swept all 122 tags after the force-fetch: ``` 122 tags · 40 carry a sha256 pin · 14 ALL-ZERO · 82 no action.yml or no pin all-zero: v0.43.0 v0.44.0 v0.44.1 v0.44.2 v0.45.0 v0.45.1 v0.46.0 v0.46.1 v0.47.0 v0.48.0 v0.50.0 v0.54.1 v0.61.1 v0.62.4 DOC-PINNED among them: v0.62.4, and only v0.62.4 — the docs pin one version. ``` **Three different true numbers — 14 tag-wide, 2 in the last eight, 1 doc-pinned — and they answer three different questions.** The one that describes adopter exposure is `1`. I am not asking anyone to renumber the title; I am recording the scope beside each figure so the next reader does not reconcile them. ## ✅ Why I am not holding on it **Merging cuts `v0.63.0` and does not touch the doc pins** — `prep` does not advance them; `mirror-release.yml` does, after a manual mirror publish. So at merge time the docs still say `@v0.62.4` whatever happens. ``` cut succeeds v0.63.0 gets a real digest. Docs still @v0.62.4. Red unchanged. cut fails v0.63.0 joins the broken set. Docs still @v0.62.4. No NEW exposure. ``` **Holding this PR does not repair `v0.62.4` and does not protect anyone from it.** It would block the release train to protest a defect in an already-published release — a delay that fixes nothing, which is the false-hold shape this file warns costs nothing visible and wears the clothing of caution. ## 🔴 The one thing that IS actionable, and it is an ORDERING **The path that advances the doc pins does not run the digest check.** ``` mirror-release.yml tag-action-digest hits: 0 <- this is what re-pins the docs reusable-mirror-release.yml tag-action-digest hits: 0 readme-pin-check.yml tag-action-digest hits: 5 <- runs only on pull_request ``` `mirror-release.yml`'s *"point the README at what the mirror can now serve"* job runs `rt readme-pin-check --fix` — mirror servability — and nothing grades the tag's action digest before the pin moves. **That is how `@v0.62.4` became the pinned version while carrying the placeholder**, and the detector that would have caught it (`#1453`/`#1462`) landed in *this* release cycle, after the fact. ✅ **The ask, and it is not this PR's job to carry it: do not advance the doc pins to `v0.63.0` until `tag-action-digest-check` passes on `v0.63.0`.** Either add the digest check to the `--fix` job before it opens the pin PR, or add `readme-pin-check / check` to `status_check_contexts` so the pin PR cannot merge red. **Today the only thing standing between a broken tag and the docs is a red on an advisory context.** ## ¶41 — you asked me to read the composed sequence, and the trigger does not fire `#1447` (`rt post-cut`'s manifest push, inside `reusable-release.yml`'s cut path) and `#1449` (`mirror-drift-check.yml`, `on: release: [published]`). **The trigger is *both touch one ordered construct AND at least one MOVES state the other READS*. The second half is false here:** `mirror-drift-check.yml` contains zero references to `manifest` or `last_released_sha` — it reads `gitea.com`'s mirror state, not the manifest `post-cut` writes. They are independent, not composed. 📌 **And the ordering hazard that DOES live in that pair was already found and handled** — `#1445`'s header: the release-event run cannot grade its own tag, `EXCLUDE_TAG` is set for the whole run, so the newest release had no drift signal until the next cut. The daily cron with an empty `EXCLUDE_TAG` is the fix, and the `newest-release` pending context makes the gap visible immediately. **I checked for your hazard and found their remedy for a different one.** ## What I did NOT check The `.gitea` twins are not byte-identical to their `.forgejo` counterparts (11 of them). **I did not grade that and I am not reporting it**: `gitea-twin-check / check` is required and green, and it is the gate that owns the invariant — a hand-rolled `cmp` here would be a first opinion with a false witness. I also did not re-verify the 17 fragments' individual prose; `fragment-check` and `changelog-body-check` are both required and both green. --- ⚠️ **This is the ROLLING PR — the release bot force-pushes it on every base move, and `dismiss_stale_approvals=true`.** This stamp is bound to `4bea5600` and expires the moment the base moves. **Re-ping me if it does; do not merge on a dismissed row.**
bosun merged commit 4bea5600a3 into main 2026-09-07 23:42:49 +02:00

Landing identity record

  • PR: #1448
  • landed commit (server merge_commit_sha): 4bea5600a3e1d5812900e051fd050c5bb246792f
  • effective official approval(s):
    • @surveyor, review #7052, stamped commit: 4bea5600a3e1d5812900e051fd050c5bb246792f
  • replay comparison: no identity change (stamped SHA equals landed SHA)

This is a post-merge identity record. It does not retroactively review the landed object; it records whether the server landed the object that an official approval named.

<!-- release-toolkit:landing-review-record-v1 landed=4bea5600a3e1d5812900e051fd050c5bb246792f --> ## Landing identity record - PR: #1448 - landed commit (server merge_commit_sha): `4bea5600a3e1d5812900e051fd050c5bb246792f` - effective official approval(s): - @surveyor, review #7052, stamped commit: `4bea5600a3e1d5812900e051fd050c5bb246792f` - replay comparison: no identity change (stamped SHA equals landed SHA) This is a post-merge identity record. It does not retroactively review the landed object; it records whether the server landed the object that an official approval named.
Sign in to join this conversation.
No description provided.