Skip to content

v2.1.0

Choose a tag to compare

@github-actions github-actions released this 04 Sep 14:57
· 67 commits to main since this release
a081445

A new advisory rule for the moment a push is about to run a slow gate
inside its own connection.

Added

  • push-preflight, advising. A git push in a repository where amont
    runs a test gate at push time, on a tree that has not been rehearsed, is
    told to run amont run pre-push first. git opens its connection to the
    remote before pre-push and holds it idle for as long as the gate takes;
    a remote that closes idle sessions — Forgejo's own git timeout is six
    minutes — kills the push after the gate has already passed, and the
    failure reads as network. Measured 2026-09-04: three pushes in a row died
    that way, each paying the full suite, before a --no-verify retry of the
    already-attested tree went through — the bypass this rule exists to make
    unnecessary. amont ≥ 1.27 stamps the tree a passed gate ran against and
    amont run pre-push stamps HEAD with no connection open, so the push
    that follows skips the suite. examine fires on the shape of a push (not
    --dry-run, not --no-verify, not amont's own notes push); confirm
    stays silent unless amont guards the repository (an amont shim in
    hooks/pre-push), amont list --json --stage pre-push says a test gate
    runs, and refs/notes/amont-gate carries no pre-push-* token for
    HEAD's tree.

Removed

  • packaging/amont-agent.rb, the seed used once to create the tap's formula.
    It has said version "0.0.0" with zero checksums ever since, while the
    real formula moved to 2.0.2 — a file that looks authoritative, is not, and
    drifts further with every release. Nothing referenced it.

    The tap is the single source for the formula, and scripts/bump-tap.py
    rewrites it on each release. amont keeps no seed either.

    What is still missing, and is the real gap: nothing verifies that the
    tap's formula can install what a release actually shipped. publish-tap
    runs ruby -c, which proves the file parses and nothing more. amont's own
    formula kept a bin.install "amont-agent" line for three releases after
    that binary left the archive, so brew install failed outright the whole
    time while every release went green — the checksums matched, the syntax
    was valid, and nobody ran brew. A stale copy in this repository would not
    have caught that; a post-publish brew install from the tap would.


What's Changed

Full Changelog: v2.0.2...v2.1.0