Skip to content

v1.9.1 — CI stamping now attests its driver, so the forward-only rule can fire

Choose a tag to compare

@markabrahams markabrahams released this 19 Aug 14:58
· 7 commits to main since this release

Fixed

  • defprod-stamp now sends driver: cicd on every commit-attributed stage report. The backend's forward-only rule for pipeline reporting turns on driver === cicd, and this script never sent the field at all — so the rule was unreachable from CI and shipped inert in v1.9.0. A re-swept commit could still rewind a change mid-review, which is the exact failure that rule was written to stop.

Why it is attested here rather than inferred

The backend cannot fill it in. An agent driving under a person's API key authenticates as that person, so the credential cannot distinguish automated pipeline reporting from a human action. And the value is never in doubt for this script: it derives the change and the stage from a git range on a build box, so every report it makes is automated pipeline reporting by construction.

Compatibility

Behaviour-preserving for the change records you already have. The field rides alongside commitSha on --start and finish only; --cancel and --fail carry no provenance and are unchanged. driver is first-report-wins per stage, so a stage already carrying one is not overwritten.

Pairs with a backend change that logs a warning whenever a commitSha-bearing report names no driver — so this can never again be silently inert for a consumer still pinned to an older version.

Upgrade

```
npx @defprod/scripts defprod-stamp --help
```

npx resolves unpinned by default, so an unpinned caller picks this up on its next invocation. Pinned consumers should move to `1.9.1`.

Full Changelog: v1.9.0...v1.9.1