Skip to content

chore: sync public mirror from internal - #696

Merged
haasonsaas merged 1 commit into
mainfrom
sync/public-release-mirror
May 30, 2026
Merged

chore: sync public mirror from internal#696
haasonsaas merged 1 commit into
mainfrom
sync/public-release-mirror

Conversation

@haasonsaas

@haasonsaas haasonsaas commented May 30, 2026

Copy link
Copy Markdown
Contributor

Summary

  • sync the sanitized public tree from evalops/maestro-internal
  • keep evalops/maestro as a generated public mirror of the private source of truth
  • preserve public-owned CI and trusted-publishing workflows from the public checkout
  • internal source SHA: d8894bf42184134bda64d93353d3bd78b7534187
  • last generated public sync base: 78c2e99aa3228c18fe2b8b8ba00496e08537c2dd
  • previewed public-tree drift: 8 file(s) to copy/update and 0 stale file(s) to delete
  • public-only commits since last generated sync: 4

Source-of-truth status

Public Mirror Drift Audit

  • package: @evalops/maestro
  • private source: https://github.com/evalops/maestro-internal@main (d8894bf42184)
  • public projection: https://github.com/evalops/maestro@main (6f61ff670edd)
  • files to copy or update: 8
  • stale files to delete: 0
  • result: drift detected
  • invariant: public_projection_has_drift

Sample Changed Paths

  • copy/update CHANGELOG.md
  • copy/update docs/protocols/release-surface-conformance.json
  • copy/update docs/protocols/release-surface-conformance.md
  • copy/update package.json
  • copy/update scripts/check-release-surface-conformance.mjs
  • copy/update scripts/plan-ci-checks.mjs
  • copy/update test/scripts/ci-guardrails.test.ts
  • copy/update test/scripts/release-surface-conformance.test.ts

Guidance

Let internal main generate and merge the public sync PR before relying on public main.

Drift sample

  • copy/update CHANGELOG.md
  • copy/update docs/protocols/release-surface-conformance.json
  • copy/update docs/protocols/release-surface-conformance.md
  • copy/update package.json
  • copy/update scripts/check-release-surface-conformance.mjs
  • copy/update scripts/plan-ci-checks.mjs
  • copy/update test/scripts/ci-guardrails.test.ts
  • copy/update test/scripts/release-surface-conformance.test.ts

Public-only commits since last generated sync

Validation

  • generated by the sync-public-release-mirror workflow in public-tree mode

Test Plan

  • generated by the sync-public-release-mirror workflow in public-tree mode
  • public-source-provenance require-internal-pr check confirms internal source PR lineage
  • CI, integration, rust-hosted-conformance, coverage, Socket, and Cursor checks must pass before merge

Staged Rollout

  • Staging is unnecessary for this generated mirror PR: it does not independently promote user-visible behavior. It mirrors already-reviewed internal source from evalops/maestro-internal@d8894bf42184134bda64d93353d3bd78b7534187, including existing hidden/evaluation surfaces, and keeps public package parity behind the established public-source-provenance gate.

Supersedes

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: af6e4eb0f9

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread test/scripts/ci-guardrails.test.ts
@haasonsaas
haasonsaas force-pushed the sync/public-release-mirror branch from af6e4eb to df28e9c Compare May 30, 2026 05:50
@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm ioredis is 96.0% likely obfuscated

Confidence: 0.96

Location: Package overview

From: package.jsonnpm/ioredis@5.11.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/ioredis@5.11.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@haasonsaas
haasonsaas merged commit 5cf8a40 into main May 30, 2026
11 of 12 checks passed
@haasonsaas
haasonsaas deleted the sync/public-release-mirror branch May 30, 2026 05:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant