Skip to content

v4.60.0 — CI drafts the release a person publishes, and the dashboard stops promising a page a tag never made

Latest

Choose a tag to compare

@github-actions github-actions released this 15 Sep 07:53
· 4 commits to main since this release

This page covers v4.58.0, v4.59.0 and v4.60.0. None of them had a release
page: v4.58.0 was never tagged because its CI run failed, and v4.59.0 was
tagged before anything here could create a page.

Security checks that could not fail now can

  • The shipped sast checks could never fail. The checks.yaml template
    every scaffolded repository receives ran semgrep without --error, and
    semgrep exits 0 even when it finds something — measured: 4 findings, exit 0.
    So sast, sast-auth and secure-coding-controls passed in every repo that
    used them. Their rule count also called a semgrep option that does not exist,
    so it read 0 on every run. Both are fixed in the template. If you scaffolded
    from an earlier version, run /productizer:upgrade to see the difference.
  • secret-scan runs gitleaks for real. gitleaks 8.30.1, pinned, with its
    download checked against a SHA-256 before extraction. On six planted
    credentials in real issuer formats it caught 6. Running the actual binary
    found four ways a scan can pass without scanning, each now guarded: an
    unreadable file is skipped with exit 0, so coverage is read from gitleaks' own
    log rather than its exit code; and the repository being scanned can switch
    the scan off with .gitleaksignore, a root .gitleaks.toml, or an empty
    config, each of which now fails the check instead of passing it.

/productizer:upgrade can only report

It promised to change nothing, but it granted unrestricted shell access, so
that promise rested on the model behaving. The model can no longer invoke it on
its own, file writes and edits are denied, and shell access is limited to
re-running its own report. Measured: five calls outside that scope were denied,
and the same five succeeded with the scope widened back. It also passes the
report's exit code to the model, which it silently dropped before.

A tag push drafts the release, and a person publishes it

Before v4.60.0, pushing a version tag published nothing: 22 of 81 version tags
had a release page, and no workflow had ever created one. Now a v* tag push
runs the checks on that tag first, and only then creates the GitHub release as
a draft. The job reads the release back and fails if it is anything but a
draft, never edits an existing release, and is the only job allowed to write.
This page is the first draft it produced.

The architecture view shows what a change did to the spec

The Visualizer compares the spec against the commit a change was measured
from, and marks each requirement NEW, CHANGED, SUPERSEDED, WITHDRAWN or
REMOVED. It does not claim a requirement's coverage changed, because that needs
a check run at the earlier commit too. Checks that take no file list now read
n/a instead of ?, which wrongly implied their count could not be read.

Also

  • contradiction-check.py reports "not measured" and exits 4 when a file holds
    no requirement it can read. It previously reported "0 requirements, 0 pairs"
    and exited 0 on this repository's own spec.
  • /productizer:help lists commands as well as skills.
  • build-release-notes.sh has a self-test covering its exit codes. Writing it
    fixed paths that printed "no requirement changed" or "none found" before
    failing.
  • CI actions moved to Node 24 releases, each pinned by a verified commit.

What this release does not do

  • It does not backfill the 59 older tags that have no release page.
  • Only sast and secret-scan run here. This repository declares the
    other shipped security checks but leaves them disabled or untriggered, each
    with a written reason: dependency-audit has no package manifest to scan, two
    checks need tags nothing passes yet, and one depends on a script that does not
    exist.
  • secret-scan does not scan git history, only the working tree.
  • The upgrade command's permission limits were measured in headless runs.
    In an interactive session an out-of-scope call should ask you rather than be
    denied; that was not observed.
  • The generated notes' pull-request section lists the last 50 merged pull
    requests rather than those in the release's range.

Evidence: commits 23f9402 (v4.58.0), fa8dace (v4.59.0), 5117f48 (v4.60.0).