v4.60.0 — CI drafts the release a person publishes, and the dashboard stops promising a page a tag never made
LatestThis page covers v4.58.0, v4.59.0 and v4.60.0. None of them had a release
page: v4.58.0 was never tagged because its CI run failed, and v4.59.0 was
tagged before anything here could create a page.
Security checks that could not fail now can
- The shipped
sastchecks could never fail. Thechecks.yamltemplate
every scaffolded repository receives ran semgrep without--error, and
semgrep exits 0 even when it finds something — measured: 4 findings, exit 0.
Sosast,sast-authandsecure-coding-controlspassed in every repo that
used them. Their rule count also called a semgrep option that does not exist,
so it read 0 on every run. Both are fixed in the template. If you scaffolded
from an earlier version, run/productizer:upgradeto see the difference. secret-scanruns gitleaks for real. gitleaks 8.30.1, pinned, with its
download checked against a SHA-256 before extraction. On six planted
credentials in real issuer formats it caught 6. Running the actual binary
found four ways a scan can pass without scanning, each now guarded: an
unreadable file is skipped with exit 0, so coverage is read from gitleaks' own
log rather than its exit code; and the repository being scanned can switch
the scan off with.gitleaksignore, a root.gitleaks.toml, or an empty
config, each of which now fails the check instead of passing it.
/productizer:upgrade can only report
It promised to change nothing, but it granted unrestricted shell access, so
that promise rested on the model behaving. The model can no longer invoke it on
its own, file writes and edits are denied, and shell access is limited to
re-running its own report. Measured: five calls outside that scope were denied,
and the same five succeeded with the scope widened back. It also passes the
report's exit code to the model, which it silently dropped before.
A tag push drafts the release, and a person publishes it
Before v4.60.0, pushing a version tag published nothing: 22 of 81 version tags
had a release page, and no workflow had ever created one. Now a v* tag push
runs the checks on that tag first, and only then creates the GitHub release as
a draft. The job reads the release back and fails if it is anything but a
draft, never edits an existing release, and is the only job allowed to write.
This page is the first draft it produced.
The architecture view shows what a change did to the spec
The Visualizer compares the spec against the commit a change was measured
from, and marks each requirement NEW, CHANGED, SUPERSEDED, WITHDRAWN or
REMOVED. It does not claim a requirement's coverage changed, because that needs
a check run at the earlier commit too. Checks that take no file list now read
n/a instead of ?, which wrongly implied their count could not be read.
Also
contradiction-check.pyreports "not measured" and exits 4 when a file holds
no requirement it can read. It previously reported "0 requirements, 0 pairs"
and exited 0 on this repository's own spec./productizer:helplists commands as well as skills.build-release-notes.shhas a self-test covering its exit codes. Writing it
fixed paths that printed "no requirement changed" or "none found" before
failing.- CI actions moved to Node 24 releases, each pinned by a verified commit.
What this release does not do
- It does not backfill the 59 older tags that have no release page.
- Only
sastandsecret-scanrun here. This repository declares the
other shipped security checks but leaves them disabled or untriggered, each
with a written reason:dependency-audithas no package manifest to scan, two
checks need tags nothing passes yet, and one depends on a script that does not
exist. secret-scandoes not scan git history, only the working tree.- The upgrade command's permission limits were measured in headless runs.
In an interactive session an out-of-scope call should ask you rather than be
denied; that was not observed. - The generated notes' pull-request section lists the last 50 merged pull
requests rather than those in the release's range.
Evidence: commits 23f9402 (v4.58.0), fa8dace (v4.59.0), 5117f48 (v4.60.0).