Skip to content

v4.1.3

Choose a tag to compare

@github-actions github-actions released this 06 Oct 16:56
· 446 commits to main since this release
67b77d4

"Honest Gates" (LOG #99): the plan's second release, nothing in the game, everything in what guards it; the CI made
worthy of trust before the refactorings of 4.1.4 and 4.1.5 lean on it.

Changes

  • The gates, made trustworthy before the refactorings (4.1.3, the plan's second release). The workflows read only
    (permissions: contents: read; Pages asks for its own), cancel a run a newer push supersedes, stop after a
    deadline (timeout-minutes on every job), run on ubuntu-24.04 by name, and pin every action to a commit. The
    unit suite runs once per push (check, and coverage under V8) where it ran five times: the second game and
    the reference chapter build with npm run build:game (the game's gates and the bundle, no tsc, no unit suite),
    which npm run build now composes with check and test:assets. The CPU-bound solver tests (the abstraction
    audits, the canonical owner, the memo and ownership proofs, the reference chapter's proof: 14 tests with
    five-minute ceilings, the push suite's whole instability) leave the push: npm run test:heavy runs them every
    night, npm test and test:coverage exclude them. A node-24 job runs the quality checks and the unit suite on
    the next Node. tools/coverage-ratchet.ts compares the floors with what the tests reach and names a floor at
    least three points behind (the coverage summary is an artifact); the floors of 4.1.2 are raised where it said so.
    npm run quality:baseline says what behaviour it moves when it rewrites the baseline, and --check names a
    policy measure that got better (a ratchet to make on purpose): a rewrite is no longer silent. release-check
    runs what CI runs (quality, test:coverage, reality:xcheck, test:mutation:core) before the proofs and the
    audits. .github/CODEOWNERS: the frozen behaviour, the public surface, the named mutants, the floors and the
    workflows ask for the maintainer's review. On GitHub: a ruleset on main (the gates required, no force push, no
    deletion), merges by pull request, Dependabot alerts and security updates on, merged branches deleted, topics.

Manual passes (D12: reported, not blocking)

8 of 11 done.

Pass Status Who, when Device, OS, browser, versions What failed
1 a workflow can write with the default token, run without a deadline, or pull an action by a moving tag permissions: contents: read, timeout-minutes on every job, every action pinned to a commit (.github/workflows/*.yml)
2 the unit suite runs more than once per push check and coverage run it; the second game and the reference chapter use build:game
3 a CPU-bound solver test can make a push red on a slow runner the 14 tests with five-minute ceilings run in nightly (test:heavy), excluded from test and test:coverage
4 a coverage floor can stay silently behind what the tests reach tools/coverage-ratchet.ts in the coverage job; five floors raised at the tag
5 the baseline can be rewritten without saying what moved npm run quality:baseline prints the behaviour it moves and the policy it ratchets
6 release-check runs less than CI quality, coverage, the Rust cross-check and mutation of the core are steps of it
7 main can take a force push, a deletion, or a merge its gates did not pass the ruleset (set after this release's merge; the first merge under it is 4.1.4's)
Pass Status Who, when Device, OS, browser, versions What failed
The seven field passes (docs/en/FIELD.md) not done
The 88 surviving mutants of the reality set killed or named not done
Signed tag (git tag -s) not done