Skip to content

Releases: heavy-duty/ceremony

0.7.8

Choose a tag to compare

@github-actions github-actions released this 31 Aug 21:11
6661f01

Added

  • Adoption now ends by recording the board in the operator's catalog:
    docs/CONSUMERS.md's bootstrap and conversion checklists both carry the
    step, and neither names a repository or a filename as the destination
    (#576).
  • The cost of skipping it is stated where the step is: a board absent from
    the catalog is not enumerated by the censuses that a taxonomy change, a
    pin bump or a label retirement each run first (#576).
  • Added a sweep-derived builder owner-class label as the complement of hand-set operator. (#562).
  • bin/ceremony-upgrade moves a consumer's every ceremony uses: reference to
    one tag and re-syncs the doctrine mirror by calling docs-sync --fix.
    --check is the default and changes not one byte; --source <dir> previews
    a move against an unreleased ceremony tree (#561).
  • The pin move refuses where it would cross a migration — a tag whose
    docs/CONSUMERS.md note asks something of the consumer's tree — naming every
    crossed tag in order with its section, and refuses a tree with no pin, an
    ungradeable pin, a target that was never cut, and a downgrade (#561).
  • A refused move leaves the tree byte-identical, however deep the refusal
    comes from: --fix snapshots everything it and docs-sync can touch before
    the first byte, verifies the rewrite against the plan it announced, and
    restores the snapshot on any failure — a docs-sync refusal included (#561).
  • docs-sync gains a third file class, the guarded scaffold: ceremony owns a
    marked block in the consumer's .github/pull_request_template.md and the
    consumer owns every byte outside it, so a repo-specific template stops
    drifting from the engine that renders into it (#559).
  • The scaffolded set is read from the pin's docs/SCAFFOLDED.txt, so a bump
    that adds or drops one re-shapes it with no second list; the bump and the
    docs-sync --fix run are one PR (#559).
  • docs-sync --fix now says where its changes landed when a guarded scaffold
    is among them, instead of reporting .ceremony/ for work outside it; a run
    with no scaffold work prints the sentence it always has (#559).
  • A fleet-worked repository with no ceremony pin reads doctrine at the latest published, non-draft, non-prerelease ceremony release tag rather than main, and docs/CONSUMERS.md names the command that resolves it (#558).

Changed

  • TRIAGE.md's builder-owned paragraph no longer assumes every builder
    session has the same boundary: such a criterion may require a named session
    capability, and where it does it says so in its own text (#575).
  • That statement carries three things — builder-owned and not operator-owned,
    the capability required, and that a builder lacking it releases the claim
    rather than substituting documentation for the evidence (#575).
  • The reach axis stays two-valued: a named capability is a property of the
    criterion and not a third owner class, so an issue whose criteria name one
    is builder-owned like any other (#575).
  • Clarify that operator covers external conditions only the operator can resolve, while excluding third-party waits (#573).
  • Made the fleet-wide claim-slot assertion an explicit precondition and documented recovery from a false assertion. (#565).
  • Document that doctrine-mirrored repositories carry a release caller even without artifact publication, and make docs-sync say so when it is missing (#553).
  • Retired creation of the post-merge queue row while leaving existing consumer label objects in place, and clarified re-flag ladder carve-outs. (#540, #544).
  • Triage now splits after-close work at the mint: a criterion whose evidence cannot exist before the PR merges is not carried by the issue at all, but minted as its own issue declaring the first as its blocker (#151, #536).
  • The successor issue carries the outstanding criteria verbatim, has one owner class, and names its evidence surface, its command or observation, and its wake condition (#536).
  • A same-repo PR always carries Closes #N. A criterion a builder cannot check before the merge is a defect in the issue, reported to triage, never a reason to write Refs #N (#151, #536).
  • Refs #N on an acceptance-criteria PR is no longer blessed by the reviewer authority list; the shape is now the round-cap cut predecessor's alone (#536).
  • The post-merge completion queue is retired; merge-door splitting now keeps after-close work out of the closing issue entirely (#538, #540).
  • TRIAGE.md's reach axis names no repealed mechanism: reach is the one axis classified at mint. The three-part evidence rule, #491's issue-level reversal and the verbatim relocation are unchanged (#536).
  • Let triage batch relocated operator-owned criteria when one invocation on the same evidence surface proves them, while keeping batching optional and forbidding cross-surface batches (#532).
  • Require shared operator issues to enumerate criteria per origin and let each gated issue declare the shared operator node alone (#532).
  • A needs-ruling flag borne by an issue whose escalation reads Default: none — hard block no longer fires the ladder's 24h and past-24h rungs. The flag waits for the human and no timer replaces them (#490, #526).
  • The setter now owes a published re-read of the default at each of those two rungs — the 12h rung's act extended, so the carve-out adds a duty rather than removing one (#490, #526).
  • Record why the late rungs are carved out: their safety is the merge gate, and on an issue there is no second look, so the pick is terminal (#490, #526).
  • State the carve-out's three exclusions. A PR-borne flag runs the full ladder; an issue-borne timed reversible default still expires at 0–12h; the 0–12h and 12h rungs are unchanged on every surface (#526).
  • Say in one sentence that a discussion carries no labeled event and therefore no ladder, which the anchor rule already implied (#490, #526).
  • TRIAGE.md outcome 3's past-24h duty to pick now reads as conditional rather than unconditional, matching the ladder's two other copies (#526).
  • Relocate operator-owned acceptance criteria into their own issue instead of holding the original open: the remainder is left wholly PR-checkable and its PR merges with Closes #N (#488, #525).
  • Require the relocation to happen before the merge, and to enumerate the moved criteria one at a time on both the new issue and the original (#488, #525).
  • An issue is now builder-owned or operator-owned and never both, replacing the rule that a lone operator-owned criterion left the issue unmarked (#491, #488).
  • Read issue ownership off its criteria's class. The two axes stay independent per criterion; only the issue level collapses (#491, #488).
  • Give a relocated issue ready + operator at its own mint, carrying the evidence surface, the command or observation, and the wake condition (#488, #525).
  • Add the builder-owned issue -> operator-owned issue -> gated issue graph to Dependencies. The gated issue declares the operator-owned one alone (#488, #525).
  • Rewrite builder park shape 3 as the transient wait for triage's relocation, keeping its number. An operator-owned remainder no longer parks a finished claim (#488, #336).
  • Make a governed board's label-taxonomy repair operator-owned and exempt it from issue minting when required queue labels are missing (#524).

Fixed

  • Put the engine-mediated panel-request exception beside the review-round instruction it qualifies, so builders signal and mark ready while the engine requests reviewers (#574).
  • changelog.d/README.md and docs/CONSUMERS.md now state the entry bound
    changelog-armed has always enforced: at most 300 characters, counted after
    continuation lines are joined and whitespace collapsed, so it bounds the
    whole entry and never one line of it (#571).
  • The citation rule is stated as its admitted shape rather than as a
    prohibition: exactly one issue-citation group ends an entry, with the final
    . after it, and that group may carry several comma-separated references,
    cross-repo ones included. A second group anywhere is what fails (#571).
  • The conversion checklist no longer reads as though deriving a filename were
    all an entry's own #N has to satisfy: a moved ## Unreleased entry meets
    both entry rules too, and one citing several issues folds them into its
    single closing group (#571).
  • Release closed issues' queue labels, assignees and attention in the sweep; pin bumps deliver the repair while triage covers older boards. (#549).
  • The 24-hour ruling comment now asks the setter to re-read an issue-borne hard block instead of instructing withdrawn builder and triage picks; pull requests and timed issue defaults retain the full ladder (#537).
  • The 7-day ruling nudge no longer counts the flag-setter's own comments as
    activity, so the party owing a published re-read can no longer silence the
    reminder addressed to the party owing the decision (#526, #534).
  • The ruling clock now runs from the current needs-ruling labeled event
    instead of falling back to the item's creation date, so a long-open item
    flagged an hour ago is no longer reported as quiet for months (#534).
  • The operator label description restores or observation, the string #508
    decided and the build dropped, so the row a consumer's board renders is no
    longer narrower than the LABELS.md and TRIAGE.md doctrine it summarizes
    (#508, #530).
  • The five-round cap now lets a passing fifth round hand off and cuts only if a later push would open round six on that pull request (#523).
  • The issue-flow reconciler no longer reports reconciled. over a board write
    it lost: each staged write's status is tested, the failing act is named
    without its comment body, and the pass summary counts the issues affected
    (#519).
  • A lost board write still leaves the remaining staged effects applied and the
    hourly sweep green, so nothing is rolled back and one skipped issue still
    never reddens a run (#95, #101, #51...
Read more

0.7.7

Choose a tag to compare

@github-actions github-actions released this 27 Aug 23:40
fc6325e

Fixed

  • The operator core label's description measured 106 characters, over
    GitHub's 100-character cap, so POST /labels answered 422 and every fresh
    taxonomy bootstrap died on that row. It is reworded and unchanged in meaning
    (#508).
  • bootstrap_labels() created labels in a loop with no per-row tolerance, so
    under set -e that one 422 aborted the run (#508).
  • Every row after the failing one was therefore never attempted — including the
    consumer's whole scope:* set, which is appended after the core rows (#508).
  • The loop now logs a failed row and continues, matching the contract the retire
    loop below it already had, and fails the run at the end with every missing row
    named in one line (#508).
  • test/labels-reconcile.test.sh now asserts the cap across the whole core
    registry, so a future over-long row reds here rather than in a consumer's
    first bootstrap (#508).
  • The label taxonomy bootstrap runs in its own labels-sweep.yml job under
    its own concurrency group, so an operator's bootstrap=yes press is no
    longer evicted from the sweep's shared queue and cancelled with no steps
    (#506, #503).
  • The reconcile sweep keeps group: labels-reconcile and never
    bootstraps: it passes the literal bootstrap: "no", and the gate that
    computed that value now decides whether the bootstrap job runs (#506).
  • actions/labels-reconcile accepts bootstrap_only, off by default,
    which upserts the taxonomy and returns before reading the pull request
    list. No consumer caller, input or permission changes (#506).
  • The bootstrap press now reports whether it survived the queue.
    docs/CONSUMERS.md told an operator to re-dispatch after a pin bump and
    stopped there, and gh workflow run prints the same confirmation whether
    the run executes or is evicted (#505, #503).
  • Both documented run resolvers select the operator's own run by actor.login
    over the REST API. --event workflow_dispatch with --limit 1 takes the
    trigger job's dispatch on any board with traffic, so the on-boarding block
    could report a false green (#505).
  • A cancelled conclusion is stated to mean the taxonomy was not touched, and
    the retry sits beside the core_label_rows() hand-create for an operator who
    has lost several presses (#505).
  • ### The pin-bump procedure names the re-dispatch it owes and links the
    verification block; a grep of it for bootstrap returned nothing before
    (#505).
  • The missing core label(s) warning no longer reads as "your pin is wrong" to
    an operator whose pin is right: it names queue eviction as a cause and points
    at the verified press (#505).
  • The release-shape guard now says so on the pull request. Its ::warning::
    attaches to the sweep's own check run on the default branch, so it reached no
    surface a builder, a reviewer or the merger reads: it fired 21 times over
    ceremony#500, which merged unlabelled and published nothing (#130, #501).
  • That notice is posted once per episode and retracted when release arrives;
    a PR that loses and regains the label is told again. The annotation stays
    beside it, and the reconciler still never writes the label — notice is not a
    guess (#501).
  • docs/CONSUMERS.md named no surface for that notice, which made its claim
    that the sweep says so first true of nothing a consumer could read (#501).

0.7.6

Choose a tag to compare

@github-actions github-actions released this 26 Aug 14:07
8ebe4e4

Added

  • Let release callers declare a logged non-release tag namespace while the
    empty default keeps every unmatched tag failure unchanged (#497).
  • Document the return path for doctrine: a consumer blocked by the vendored
    set raises a discussion here, in a four-part shape, and cites it where the
    local workaround lives. The generated .ceremony/README.md now names and
    links that flow (#492).
  • Add an operator issue-owner label, owner-neutral ready semantics, and a
    quiet-work nudge for operator-owned issues (#491).
  • Triage classifies every acceptance criterion at mint by who can produce its
    evidence, not only by when it can be checked. Evidence needing a surface a
    builder's session cannot reach is operator-owned, and says so, with its
    command and its wake condition, in its own text (#487).
  • The drill record carries a sixth and last section, ## Known gaps — coverage
    no probe drives at all, declared with a repeatable --gap '<title>|<body>'
    and rendered on every emission, with or without one (#484).
  • A gap renders as - **<title>** — <body> and the parse cuts at the first
    ** — , so a body may carry that sequence and a title may not — refused
    when the gap is declared and again when it is rendered (#484).
  • drill/rehearsal.sh --amend-record <path> --gap … adds a gap to a committed
    record by re-rendering it: no probe, no scratch repo, no network call. It
    refuses a record that does not already round-trip (#484).

Fixed

  • drill/**, test/drill-rehearsal.test.sh and
    .github/scripts/record-roundtrip.sh derive scope:release-flow. The record
    was mapped from the start; the instrument that writes it was not (#484, #476).

0.7.5

Choose a tag to compare

@github-actions github-actions released this 19 Aug 21:52
d8a9b61

Added

  • Add independent release auto-merge and release-dispatch controls to the labels sweep (#468, #458, #464).
  • Allow opted-in consumers to dispatch a release pinned to its merged commit, while keeping non-opted-in callers dry (ceremony#467, ceremony#458).
  • A post_merge_workflow input on the labels sweep, empty by default. When set,
    a successful auto-merge dispatches that workflow, restoring the
    push-triggered run a GITHUB_TOKEN merge does not raise (#461, #458).
  • The dispatch fires only after a merge that landed, goes through run() so
    DRY_RUN=1 narrates it, and a failed dispatch is one log line naming the PR,
    the workflow and the reason — never a failed pass (#461).
  • The auto-merge provenance comment now says when the same pass requested the
    human's review moments earlier, and omits the line when it did not (#461,
    #458).
  • The labels reconciler now performs the merge its auto_merge verdict
    authorises: last in the pass, behind a confirmation read of the PR's state,
    head and release label, pinned to the graded head, and through run() so
    DRY_RUN=1 narrates instead of merging (#460, #458).
  • A merge GitHub refuses is logged on one line and never retried in the pass; a
    merge that lands posts one comment naming the head, the method, the toggle
    that authorised it and the decide_state verdict that triggered it (#460).
  • Add an inert, opt-in auto-merge verdict with fleet-author and mergeability gates (#459, #458).

Changed

  • The consumer guide now gates fleet-worked repositories on a sourced minimum
    label set, a verified taxonomy bootstrap, and only then repos.txt
    registration, preventing partial claims on unprepared boards (#474, crew#459).
  • Doctrine now states "only humans merge" conditionally: nine sites across
    AGENTS.md, REVIEWER.md, LABELS.md, FLEET.md and CONTRIBUTING.md
    name auto_merge, its off default and that it is the consumer's setting
    (#462, #458).
  • FLEET.md keeps its identity invariant and gains the workflow token's own
    sentence beside it: no fleet identity gains a permission in this arc
    (#462, #458).
  • docs/CONSUMERS.md gains the auto-merge operating manual — the two inputs,
    the two caller permissions, the five refusals, the push-run cost and the
    approval-latency note (#462, #458).
  • The ceremony fleet roster now admits both builder identities to service
    builder-raised rerun-owed requests without changing either builder's
    review panel (#452, #424, #435).
  • docs/CONSUMERS.md now states the board-shape tripwire set as the four
    families 0.7.4 ships, stalled included, with its three-term firing
    condition, its head-only placement, and how it reconciles with
    blocker:ci-red and rerun-owed (#448, #440, #441).

Fixed

  • labels-reconcile now marks the human review request it makes itself, with
    a hidden comment marker, and withdraws only what it marked once the round
    stops passing. A maintainer's request carries no mark and is never withdrawn
    (#479).
  • A machine-made request no longer reads as a maintainer's deliberate early
    claim: a round with a required verdict missing lands on state:addressing
    with blocker:unrequested instead of telling the human a head nobody
    reviewed is theirs to merge (#479).
  • Map changes to the fleet doctrine file to the documentation scope (#476).
  • labels-reconcile now bootstraps the taxonomy only when the caller asks
    for it. bootstrap=no was unobeyable: the gate read the event name, and
    every trigger-woken sweep is a workflow_dispatch (#472, #466).
  • A ceremony pin bump that adds a core label no longer installs it on the
    next board event. Dispatch the sweep caller, as docs/CONSUMERS.md says;
    the scheduled sweep warns until you do (#472, #466).
  • CONTRIBUTING.md's roster now agrees with panel=: the departed
    grok-bot-andresmgsl row is gone, and the panel rule names no verdict
    count — the required set is the review bench minus the PR's author, with
    which rows are the bench made explicit so triage is not read into it
    (#456).
  • ci-rerun's fleet roster now names each identity once, in the order the
    conf names it: load_fleet dedups on append, so a repo whose per-author
    panel[<login>]= rows repeat its panel= reviewers reads a clean list in
    the gate-1 refusal comment. Admission is unchanged (#453, #424).

0.7.4

Choose a tag to compare

@github-actions github-actions released this 16 Aug 16:38
c64e066

Added

  • The issue-flow sweep flags a stalled chain head: a blocker chain three or
    more issues deep, counting the head, whose claimed head has a red open PR.
    Comment-only, on the head alone, naming the remedy — service the red, or
    re-order the chain (#440, #426).
  • lib/checks.sh — the rollup classifier both reconcilers now source, so the
    tripwire grades a head with the same instrument that decides
    blocker:ci-red and the two can never disagree (#440, #136, #139, #208).
  • Flag idle queues, deeply serial blocker chains, and dependency cycles from the issue-flow sweep's existing board snapshot (#426).
  • Triage now puts measured flow-wide breakage at the front of a collision
    chain while ordinary work keeps arrival order (#425).
  • Front-row insertion records its evidence and edge direction, preserves a
    claimed issue's labels, and orders overlapping work at merge (#425).
  • actions/ci-rerun: a base-repo workflow that services rerun-owed by
    starting the rerun a fork PR's author cannot. Its job holds actions: write
    for one run, checks out nothing from the head, and runs no PR-authored code
    (#424).
  • Four gates, all measured at service time and none inherited from the label:
    the actor is a fleet identity in .github/labels.conf, the head still is the
    one the evidence names, the run concluded failure, and it is on attempt 1
    (#424).
  • A started rerun removes rerun-owed and comments the new attempt's URL; a
    refusal leaves the label standing and comments which gate refused and what a
    human would have to do. There is no schedule and no retry — the workflow acts
    on one label event and stops (#424).
  • Consumers get the servicing at their next pin bump: docs/CONSUMERS.md
    carries the caller stub and the permissions block, without which the
    workflow refuses every time (#424).
  • Only a run created before the evidence comment that names the head is a
    rerun candidate: a pull_request_target run carries the head's SHA, so the
    workflows the label event itself wakes are in that list too and must never
    be rerun in the red run's place (#424).
  • rerun-owed: a PR-only label for a head that is red on a rerun no agent may
    start. The builder sets it with evidence opening 🔁 rerun owed at head <sha>; the reconciler clears it when that head's checks leave failing, or
    when the named head is no longer the head (#423).
  • While rerun-owed stands at a head, blocker:ci-red is not asserted there:
    that label says the builder owes a fix, and on a fork PR's base-repo run the
    builder owes nothing. It is not a blocker and never enters the set (#423).
  • A sixth park shape: a red head whose rerun is a right the builder does not
    hold parks the claim and frees the build slot. Every other red head is still
    the builder's, and the ci-red wake skips the labelled one (#423).
  • rerun-owed is not exempt from the 48-hour staleness clock: a head standing
    under it still goes stale, and that stale asks for a poke of whoever
    services the rerun, never a fix from the builder. A flag earns an exemption
    only by carrying an escalation clock of its own (#423).

Changed

  • Document the issue-flow sweep's comment-only idle, deep-chain and cycle
    tripwires, including placement, shape-keyed deduplication and shared
    threshold ownership (#441).
  • The ci-rerun roster precondition in docs/CONSUMERS.md drops its census
    of the governed repositories' .github/labels.conf files, which was false:
    identities that build as well as review are named in the roster the gate
    reads (#437).
  • In its place the paragraph gives a directive the reader runs against their
    own conf — the three fields gate 1 reads — rather than a measurement of
    other repositories that nothing re-checks when a roster changes (#437).
  • The one-build-at-a-time slot is stated as the builder's own, across every
    repository they work in: the self-check is whether an unparked claim is
    held anywhere, never whether the board in front of you is clean (#430).
  • The slot sentence stops carrying a second test for when a build ends. A
    claim holds the slot until it is parked or released, so the park list is
    the only definition of finishing and the two can no longer disagree (#430).
  • The claim comment now asserts the slot: no unparked claim in any
    repository, naming any parked claims held elsewhere with their shape
    (#430).
  • AGENTS.md's router row now sends the builder to an ordered chain of PRs,
    normally one — the fourth surface of the singular arithmetic, and the one
    the mint's regex could not see behind its backticked ready (#420, #429).
  • One issue now means an ordered chain of PRs, normally one. A PR carries at
    most five rounds; at the close of round 5 the builder continues the branch
    in a successor PR and the predecessor closes as the ledger (#420).
  • The cap is a consensus-surface rule and not a byte defence: the longer a PR
    runs, the harder it is to bring the whole panel onto one head (#417, #420).
  • A cut spends every approval. The review target becomes the successor, no
    verdict is owed on the closed predecessor, and rounds are numbered per PR
    so the successor's first round is round 1 (#420).
  • The issue gains a triage-maintained ## Pull requests list in chain order,
    present only once a chain exists and triggered by the builder's cut
    comment; it is the only place a chain stays navigable (#420).
  • Triage now sizes accepted work for bounded review rounds and splits oversized work into ideally disjoint epic children, treating later round growth as evidence for the next mint (#419).
  • The PR body's ## Round log is a rolling summary rather than a verbatim
    mirror of each round's reply: ### Current state is rewritten every
    round, ### Rounds gains one row of facts plus two prose cells, and
    handoff waits on those cells being filled (#418).
  • A round's reply shrinks to a short comment naming the round and the head,
    so the comment thread stops growing with the body it used to duplicate
    (#418).

0.7.3

Choose a tag to compare

@github-actions github-actions released this 15 Aug 09:04
931eb90

Changed

  • Made vendored review and release doctrine self-contained by replacing cross-repository references with local records. (#408).

Fixed

  • Every early-exiting reader in lib/changelog.sh and the two label
    actions is fed from a variable instead of a pipe. A reader that exits
    early left its writer taking EPIPE, so pipefail failed the pipeline
    although the reader had succeeded (#364, #411).
  • changelog-armed no longer fabricates a changelog shape violation
    against a repository whose published section is large, and no longer
    passes a real one in silence (#411).
  • A scope label whose glob matches early in a large PR's changed-file
    list is applied instead of silently dropped (#411).

0.7.2

Choose a tag to compare

@github-actions github-actions released this 13 Aug 10:06
a7b9b91

Added

  • Add a guard that rejects unpinned third-party actions and reusable workflows (#399).
  • runner-isolated takes pr-code-runner-labels: the runner labels a
    consumer asserts PR-authored code may execute on. Empty by default, so a
    caller passing nothing keeps the verdict it had on every file that
    executes PR code; the axis correction above is what moves the rest
    (#395).

Changed

  • Pin checkout references to v4.4.0, including the refs-guard.yml upgrade from v4.2.2 (#399).
  • docs-sync names the fault it saw: a 404 asks about the pin, a 5xx says
    the pin is fine and the failure is transient, a connection failure claims
    nothing about the ref, and an archive that will not unpack says so (#393).
  • Refuse a taken explicit drill fork ref before creating a scratch repository, and print a runnable retry using the first free paired attempt (#387).

Fixed

  • runner-isolated reads runs-on: in its block-mapping form: a
    labels: key one level in is the runner spec's label set, in both of
    its spellings — a value beside the key, or a sequence beneath it
    (#402).

  • A pull_request file naming a self-hosted tier that way passed with an
    empty allowlist and now fails. Vouch for the tier in
    pr-code-runner-labels, or split the workflow (#402).

  • runner-isolated leaves a runs-on: mapping's other keys inert, so a
    group: above or below the labels: neither contributes a label nor
    closes the window. A group named self-hosted with no labels: key
    still passes: a group name is not a label (#402, #395).

  • runner-isolated asks whether a file executes PR-authored code, not
    whether it is PR-triggered: a pull_request_target file that checks out a
    PR ref now fails, and one that checks out none passes however it is
    routed (#395).

  • runner-isolated reads a self-hosted label passed through a with: input,
    the shape a reusable-workflow caller uses, so a label named there is judged
    exactly as one named in runs-on: (#395).

  • A label is read in whatever spelling it is written — quoted, flow, block
    scalar, a flow collection opening on the line after its key, or an alias to
    an anchor the same file defines — in a with: input and in runs-on:
    alike (#395).

  • A value written on the line after its key is read when it is a scalar as
    well: a wrapped '["self-hosted","ci-runner"]' names its labels. A
    *name inside a quoted scalar stays that scalar's text (#395).

  • A label opening with a dash is read whole, so -self-hosted and a quoted
    "- pr-runner" are vouched for by those exact strings; only a - YAML
    uses as a sequence indicator is punctuation (#395).

  • docs-sync retries the doctrine tarball (four attempts over ~15 s) and
    downloads it to a file before extracting, so a transient 503 from GitHub's
    archive endpoint no longer reds a consumer's required check (#393).

0.7.1

Choose a tag to compare

@github-actions github-actions released this 12 Aug 15:45
a9def9f

Added

  • Let reusable labels, labels-sweep, and release callers route every job to a JSON-encoded hosted label or self-hosted label set (#383).
  • Grade the drill record by re-render: CI parses a bare-version tree's record back into the inputs that would render it and requires the bytes back, so a hand-edited record fails where a shape check passed it (#313, #373).

Changed

  • BUILDER.md tells a builder whose handoff was taken back to clear the
    blocker rather than re-set the label, the stop condition the "optimistic
    write" sentence left out (#377).
  • Make release-drill scratch repositories public by default, with an explicit private mode and records based on observed visibility (#372).
  • Number rehearsal scratch attempts and route default names around archived leftovers without reclaiming repositories or refs (#371).

Fixed

  • The reconciler says why it took a handoff back: a PR carrying
    state:needs-human that degrades to state:addressing because a
    blocker:* stands now gets one PR comment naming the take-back, the exact
    blockers standing, and the precondition (#377).
  • That comment is marked with the blocker set and the head SHA, so a sweep
    posts it once per episode — a new head or a changed blocker set earns one
    new comment, the same head with the same blockers never a second (#377).
  • It speaks only for a take-back that landed: a label edit that failed, or one
    skipped because the repo has no state:addressing, leaves the handoff
    standing and says nothing — and marks no episode, so the pass where the edit
    does land still speaks (#377).
  • The other three ways state:needs-human degrades — a draft, a pending
    ruling, a directed hold — stay silent, each already carrying a visible
    label that says why (#377).
  • Make drill probes fail on unread fragment, release, or branch data instead of scoring an answer no read established (#375).
  • Setup aborts now emit separate, non-releasable evidence records and archive any scratch repository they created (#370).
  • The drill instrument retries every read it makes after a write, bounded by
    DRILL_READ_TRIES and DRILL_READ_NAP_SECONDS, so a stale or transient
    answer from GitHub no longer aborts the setup (#369).
  • A drill read that never answers says so — naming the read, its target and
    the attempt count — instead of asserting that the write it followed failed
    (#369).
  • drill_gh_soft tells an absent answer from a failed one: a 404 is still
    exit 0 and empty, and anything else is non-zero for the caller to retry or
    abort on (#369).
  • A drill record no longer states what a read said when the read never
    answered: the re-arm rows, the changelog comparisons and the label
    confirmation before a merge each report the unread read instead of a claim
    about the repository derived from it (#369).
  • A drill setup no longer writes on a read that never answered: an existence
    read that fails to the end of its budget aborts the commit rather than
    reading as "this repository is empty" and sending the bootstrap write to a
    branch that already has a head (#369).
  • A candidate verification that read no workflow file refuses instead of
    reporting the candidate SHA as verified — a verification that took no
    measurement is not a verification (#369).
  • A disposal whose flag reads back archived: false for the whole retry
    budget is recorded as an archive that did not land, distinctly from a read
    that never answered at all — the first is a measurement, the second is the
    absence of one (#369).

0.7.0

Choose a tag to compare

@github-actions github-actions released this 10 Aug 20:11
2b637d0

Added

  • The release drill rehearses the rc legs: an rc cut probe asserting a
    prerelease, an untouched CHANGELOG.md and surviving fragments, and a
    promotion probe asserting the assembled final section while the candidate
    stays a prerelease (#321).
  • drill/rehearsal.sh runs the release drill: scratch repo, armed fixture,
    caller stub at a rewritten fork pin, the six doctrine probes and the
    record. Every refusal probe's nothing-created claim is a before/after tag
    and release count (#313).
  • The instrument archives and never deletes, printing the operator's delete
    step instead of retrying a 403 wall, and refuses to pin the caller stub at
    a tag-named ref on this repo (#135, #313).

Changed

  • Release-init step 1 now covers the member that arrives by re-opening a
    closed issue: re-point its declaration at the epic and verify the parse
    before the re-open, so the sweep cannot promote it in between (#325).
  • Release doctrine now covers cumulative prerelease cuts, deterministic rc
    re-arming, and the changelog precondition for adopting that path (#322).
  • Release doors now publish candidates as prereleases with fragment-assembled notes and automatically re-arm the next candidate (#320).
  • Changelog guards now preserve fragments and leave the changelog untouched for tag-only release candidates (#319).
  • Release candidates now re-arm deterministically to the next numbered rc development tree (#318).

Fixed

  • The issue-flow sweep survives a long release body: the membership record
    reaches its parser from a variable rather than a pipe, so the parser's
    bounding exit can no longer break the writer feeding it (#364).
  • A pre-loop failure in that sweep names its stage — the board read, the
    membership parse, or the flag computation — instead of a bare jq
    message and an exit code (#364).
  • Make the closing-issue graph authoritative for Refs pull requests and stop treating quoted closing keywords in code spans as defects (#359).
  • The epic task-list parse takes every CommonMark list marker, not just
    - and *; rows and headings indented past three spaces open nothing
    (#349).
  • Neither section parser reads a heading or a row inside a fenced code
    block, and an indented heading now closes its section instead of running
    the parse into the next one (#349).
  • Skip an issue when its dependency state cannot be read instead of accusing a valid blocker declaration (#345).

0.6.3

Choose a tag to compare

@github-actions github-actions released this 09 Aug 04:38
cf28921

Changed

  • A release issue records its window membership under a ## Members heading, read by heading and one bare #N per row; its Blocked by line answers the predecessor gate and nothing else (#343).
  • The standing-window decision and the non-member flag read that record, with no fallback to the gate: a release issue that enumerates no membership stands no window and draws no flag (#343).

Fixed

  • Prevent release-window carriers from joining their own gates and suppress stale board-flag claims after an issue pass changes queue state (#327).