CI Retry Gate v1.2.0 — State-Bound Reruns with Evidence-Gated Safety
LatestCI Retry Gate v1.2.0
CI Retry Gate now binds rerun authorization to the exact workflow state that produced the evidence.
This release strengthens the core principle:
Evidence before action.
Highlights
- Added EASL-compatible subject-state binding for pre-mutation validation.
- Full-workflow reruns now revalidate the exact:
- repository
- run ID
- run attempt
- head SHA
- workflow ID
- failed-job set
- Selective reruns now bind authorization to:
- run attempt
- head SHA
- workflow ID
- workflow lifecycle
- exact failed-job execution state
- Selective mode performs at most one mutation per evaluated workflow-state epoch.
- Any remaining candidate must be re-evaluated after the first mutation changes workflow state.
- Added canonical EASL subject-state conformance vectors for the Python compatibility layer.
- Added external consumer E2E coverage for the state-bound selective-rerun path.
Safety
- Workflow-state drift invalidates old rerun justification before mutation.
- Invalid or unavailable state bindings fail closed.
- Mutating GitHub API POST requests are not blindly replayed after ambiguous transport outcomes.
- Automatic reruns remain disabled by default.
- Causal Dominance remains research-only and does not participate in production retry authority.
External verification
A real external GitHub Actions consumer test demonstrated:
- Two failed jobs qualified as selective-safe candidates.
- Exactly one rerun mutation was issued from the evaluated state epoch.
- GitHub advanced the workflow to a new attempt.
- Exactly one job received a new execution.
- The other job was carried forward without a new execution timestamp.
- The new attempt was re-evaluated before any further write.
- No second mutation was authorized from the old state epoch.
The published @v1 line was also exercised from an external consumer against both ALLOW and fail-closed UNKNOWN evidence contracts.
Install
Use the stable major release:
- uses: achirothmane/workflow-failure-lab@v1Or pin this exact version:
- uses: achirothmane/workflow-failure-lab@v1.2.0Automatic reruns remain explicit opt-in.