Releases: achirothmane/workflow-failure-lab
Release list
CI Retry Gate v1.2.0 — State-Bound Reruns with Evidence-Gated Safety
CI Retry Gate v1.2.0
CI Retry Gate now binds rerun authorization to the exact workflow state that produced the evidence.
This release strengthens the core principle:
Evidence before action.
Highlights
- Added EASL-compatible subject-state binding for pre-mutation validation.
- Full-workflow reruns now revalidate the exact:
- repository
- run ID
- run attempt
- head SHA
- workflow ID
- failed-job set
- Selective reruns now bind authorization to:
- run attempt
- head SHA
- workflow ID
- workflow lifecycle
- exact failed-job execution state
- Selective mode performs at most one mutation per evaluated workflow-state epoch.
- Any remaining candidate must be re-evaluated after the first mutation changes workflow state.
- Added canonical EASL subject-state conformance vectors for the Python compatibility layer.
- Added external consumer E2E coverage for the state-bound selective-rerun path.
Safety
- Workflow-state drift invalidates old rerun justification before mutation.
- Invalid or unavailable state bindings fail closed.
- Mutating GitHub API POST requests are not blindly replayed after ambiguous transport outcomes.
- Automatic reruns remain disabled by default.
- Causal Dominance remains research-only and does not participate in production retry authority.
External verification
A real external GitHub Actions consumer test demonstrated:
- Two failed jobs qualified as selective-safe candidates.
- Exactly one rerun mutation was issued from the evaluated state epoch.
- GitHub advanced the workflow to a new attempt.
- Exactly one job received a new execution.
- The other job was carried forward without a new execution timestamp.
- The new attempt was re-evaluated before any further write.
- No second mutation was authorized from the old state epoch.
The published @v1 line was also exercised from an external consumer against both ALLOW and fail-closed UNKNOWN evidence contracts.
Install
Use the stable major release:
- uses: achirothmane/workflow-failure-lab@v1Or pin this exact version:
- uses: achirothmane/workflow-failure-lab@v1.2.0Automatic reruns remain explicit opt-in.
CI Retry Gate v1.1.0
CI Retry Gate v1.1.0
This release introduces the Evidence Producer and a verifiable runtime evidence boundary for CI retry authorization.
Highlights:
- Policy-free Evidence Producer
- Canonical evidence-producer.ci.v1 EvidenceBundle
- Canonical evidence.json runtime artifact
- SHA-256 integrity verification before authorization
- Separate-process Evidence Gate
- New outputs:
- evidence-bundle-path
- evidence-bundle-sha256
- Missing, malformed, conflicting, or tampered evidence fails closed to BLOCK
- Retry policy remains separate from evidence
- Recovery and recurrence checks remain conservative outer guards
Verification:
- 353 Python tests passed
- CI passed
- Compatibility Matrix passed
- Remote v1 Consumer E2E passed
- Clean-install verification passed
- Release Readiness passed
Automatic reruns remain disabled by default.
CI Retry Gate v1.0.2
CI Retry Gate v1.0.2
Evidence-gated CI retry decisions are now backed by a broader real-world regression contract and external consumer verification.
Highlights
- Added recovery and recurrence evidence across workflow attempts.
- Kept failure-cause evidence separate from retry-outcome evidence.
- Added cutoff-safe historical reliability evidence that remains supporting-only, never authorizing by itself.
- Preserved fail-closed behavior when public GitHub job logs are unavailable.
- Added bounded evidence acquisition with explicit rate-limit and evidence-budget states.
- Strengthened regression coverage using real-world CI failure patterns.
- Improved zero-install Public Run Analysis for evaluating failed public GitHub Actions runs.
- Updated the README around a faster zero-install proof path.
- Hardened Node/Jest/Vitest compatibility with isolated locked dependency graphs and a verified npm resolver.
- Fixed GitHub Action Marketplace metadata and stable
@v1consumer validation.
Release verification
Before promotion to the stable v1 line:
- the full producer test suite passed;
- remote
@v1compatibility checks passed; - the release candidate was exercised from an independent consumer repository;
- root Action, pytest, Jest, Vitest, Setup Doctor, and ownership/JUnit checks passed externally.
Automatic reruns remain disabled by default.
Install
uses: achirothmane/workflow-failure-lab@v1CI Retry Gate v1.0.1
CI Retry Gate v1.0.1
Marketplace-ready patch release for CI Retry Gate.
Changed
- Shortened the GitHub Action description to satisfy the GitHub Marketplace metadata limit.
- Added a CI guard to prevent future Marketplace description regressions.
- Updated stable installation guidance for the
@v1release line.
CI Retry Gate
CI Retry Gate analyzes failed GitHub Actions jobs before a rerun is allowed.
It helps prevent blind retries by using:
- failure classification
- execution provenance
- failure-step provenance
- side-effect detection
- retry-attempt limits
- selective rerun safety gates
- recurring-failure fingerprints
- CI waste analysis
Safety by default
Automatic reruns remain disabled by default.
auto-rerun: 'false'
selective-rerun: 'false'Users must explicitly opt into rerun behavior.
Installation
- uses: othy19904-eng/workflow-failure-lab@v1
with:
github-token: ${{ github.token }}
auto-rerun: 'false'
selective-rerun: 'false'Marketplace
Primary category: Continuous integration
Secondary category: Utilities
Research features
Causal Dominance remains research-only and is not enabled in production retry authority.
Current independent real positive-control evidence: 2/3.
License
MIT License.
CI Retry Gate v1.0.0
CI Retry Gate v1.0.0
First production-ready release of CI Retry Gate.
CI Retry Gate analyzes failed GitHub Actions jobs before a rerun is allowed, helping teams avoid blindly rerunning deterministic failures or workflows with side effects.
Highlights
- Conservative CI failure classification
- Safe retry gating for transient infrastructure and dependency/network failures
- Selective rerun of individually safe failed jobs
- Execution Provenance to bind transient evidence to the actual failed step
- Recovery Ground Truth based on real step re-execution
- Failure fingerprints and recurring-failure analysis
- CI waste measurement
- Conservative retry-policy learning
- Policy Shadow Mode
- Cross-repository Benchmark Mode
- Coverage Attribution and Rejection Intelligence
- UNKNOWN failure research and promotion gates
- Side-effect detection and retry-attempt limits
Safety by default
Automatic reruns are disabled by default.
auto-rerun: 'false'
selective-rerun: 'false'Users must explicitly opt into rerun behavior.
Deploy, publish, migration, release, and other side-effect signals remain blocked by the safety gate.
Causal Dominance research
The Causal Dominance work remains research-only and is not enabled in production retry authority.
Current independent real positive-control evidence: 2/3.
This does not block the v1 release because the experimental override remains disabled.
Installation
- uses: othy19904-eng/workflow-failure-lab@v1
with:
github-token: ${{ github.token }}
auto-rerun: 'false'
selective-rerun: 'false'License
MIT License.
workflow-failure-lab v0.1.0
First public release of Workflow Failure Lab.
Highlights:
- Deterministic Markdown incident reports from local workflow execution logs
- Three-state certainty model: SUCCEEDED, FAILED_CONFIRMED, INDETERMINATE
- Fail-closed retry and reconciliation guidance
- Stable CLI and exit-code contract
- Dependency-direction and import-cycle enforcement
- Clean-install release verification gate
- GitHub Actions CI