Repository navigation
v2.1.0
A new advisory rule for the moment a push is about to run a slow gate
inside its own connection.
Added
push-preflight, advising. Agit pushin a repository where amont
runs a test gate at push time, on a tree that has not been rehearsed, is
told to runamont run pre-pushfirst. git opens its connection to the
remote beforepre-pushand holds it idle for as long as the gate takes;
a remote that closes idle sessions — Forgejo's own git timeout is six
minutes — kills the push after the gate has already passed, and the
failure reads as network. Measured 2026-09-04: three pushes in a row died
that way, each paying the full suite, before a--no-verifyretry of the
already-attested tree went through — the bypass this rule exists to make
unnecessary. amont ≥ 1.27 stamps the tree a passed gate ran against and
amont run pre-pushstampsHEADwith no connection open, so the push
that follows skips the suite.examinefires on the shape of a push (not
--dry-run, not--no-verify, not amont's own notes push);confirm
stays silent unless amont guards the repository (an amont shim in
hooks/pre-push),amont list --json --stage pre-pushsays a test gate
runs, andrefs/notes/amont-gatecarries nopre-push-*token for
HEAD's tree.
Removed
-
packaging/amont-agent.rb, the seed used once to create the tap's formula.
It has saidversion "0.0.0"with zero checksums ever since, while the
real formula moved to 2.0.2 — a file that looks authoritative, is not, and
drifts further with every release. Nothing referenced it.The tap is the single source for the formula, and
scripts/bump-tap.py
rewrites it on each release. amont keeps no seed either.What is still missing, and is the real gap: nothing verifies that the
tap's formula can install what a release actually shipped.publish-tap
runsruby -c, which proves the file parses and nothing more. amont's own
formula kept abin.install "amont-agent"line for three releases after
that binary left the archive, sobrew installfailed outright the whole
time while every release went green — the checksums matched, the syntax
was valid, and nobody ran brew. A stale copy in this repository would not
have caught that; a post-publishbrew installfrom the tap would.
What's Changed
- remove: the formula seed, which was drifting by @fredericrous in #3
- build: verify brew can install what was published by @fredericrous in #4
- build: verify attestations with attest by @fredericrous in #5
- fix(install): drop a loop that ran once by @fredericrous in #6
- docs: attest joins the Related section by @fredericrous in #7
- feat: push-preflight advises rehearsing the gate by @fredericrous in #8
- chore(release): 2.1.0 by @fredericrous in #9
Full Changelog: v2.0.2...v2.1.0