fix: manual-only CI/releases and safer Docker inventory - #17
Conversation
release: promote verified release workflow fixes to main
|
Local verification is now complete: cargo check --workspace --locked, cargo test --workspace --locked (420 passed; 16 fixture-dependent tests intentionally ignored), strict workspace/all-targets Clippy, cargo fmt, frontend 249 tests and production build all passed. Generated references for all 12 plugins agree across the three Skill roots. The full GitHub CI run was explicitly dispatched for head 443f0d8: https://github.com/veithly/vibeshell/actions/runs/36549655515. Merge remains gated on that run; no Release workflow was dispatched. |
|
Integration testing found an important GitHub constraint: checks from workflow_dispatch jobs do not directly satisfy required PR checks (GitHub documentation: https://docs.github.com/en/pull-requests/how-tos/merge-and-close-pull-requests/troubleshooting-required-status-checks#checks-from-some-workflow-jobs-are-not-evaluated). The follow-up commit adds two small jobs inside the manually dispatched CI: initialize the five existing commit-status contexts as pending, then publish each actual job result from GitHub's API for the exact repository, SHA, run and attempt. Only these two jobs have statuses:write; compilation/test jobs remain read-only. Failed, skipped, missing, duplicate or incomplete job evidence cannot produce a successful context. Superseded and cancelled runs do not publish stale successes. Every status links to the real run. All 19 local Node regression tests passed, including failure/cancellation/supersession cases. No protection requirements were removed, no checks were manually fabricated and no administrator merge override was used. A fresh full manual CI run will validate both the code and the PR-status reporting before merge. |
Summary
Completed local verification
GitHub verification
The first explicitly dispatched full CI passed on 443f0d8: https://github.com/veithly/vibeshell/actions/runs/36549655515.
A fresh full manual run verifies the status-reporting fix on the current head 0af85c2: https://github.com/veithly/vibeshell/actions/runs/36551625273. Its initializer has successfully made all five required contexts visible to the PR. Merge is still gated on all final results, not on the previous commit's success.
GitHub's workflow event restriction is documented at https://docs.github.com/en/pull-requests/how-tos/merge-and-close-pull-requests/troubleshooting-required-status-checks#checks-from-some-workflow-jobs-are-not-evaluated.
Scope
Refs #9 and #12, does not close either. Inventory groundwork is not an independent Docker session; proxy support is a documented design, not an implemented feature. #10/#11 remain open with changes requested. No version bump, new tag, release publication, installed-app replacement or user-session termination.
Includes the reviewed main ancestry so the later dev-to-main promotion is up to date. No administrator merge override or removal of required checks is authorized by this change.