Skip to content

release: isolate website production authority - #106

Merged
0thernet merged 4 commits into
mainfrom
codex/dedicated-app-controls-after-pr105-20260830
Aug 30, 2026
Merged

release: isolate website production authority#106
0thernet merged 4 commits into
mainfrom
codex/dedicated-app-controls-after-pr105-20260830

Conversation

@0thernet

Copy link
Copy Markdown
Member

Summary

  • keeps the tag-triggered Release workflow limited to immutable release publication
  • moves website-production promotion into a current-main workflow with read-only baseline and outcome jobs
  • scopes the only ref write to a short-lived, one-repository GitHub App token and an explicit expected-old Git lease
  • binds immutable tag, npm, GitHub Release, Latest Release, Vercel deployment, and terminal provider evidence fail closed
  • documents and tests the later dedicated-App environment, ruleset, and persistent-canary activation boundary

This source change is version-neutral and does not claim that the App, environment, permanent rulesets, or live canary are already active.

Verification

  • bun test --no-orphans --timeout 180000 scripts/npm-stage-workflow.test.ts (29/29, 2,857 assertions)
  • node --check scripts/release-provider-outcome.mjs
  • node --check scripts/release-app-token.mjs
  • node --check scripts/release-ref-writer.mjs
  • bun run typecheck
  • bun run check
  • two independent exact-head adversarial reviews: GO

Exact base: f09a6106b9992e7121dfed5299528967c00a31eb

@vercel

vercel Bot commented Aug 30, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
wrench Ready Ready Preview Aug 30, 2026 6:30am

Request Review

@0thernet
0thernet marked this pull request as ready for review August 30, 2026 07:13
@0thernet
0thernet merged commit 4aed45b into main Aug 30, 2026
5 checks passed
@0thernet
0thernet deleted the codex/dedicated-app-controls-after-pr105-20260830 branch August 30, 2026 07:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant