Repository navigation
refactor(release): share provenance verification plumbing - #1233
Conversation
|
@codex review the current head SHA. |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The refactor preserves validation order, command arguments, diagnostics, and recovered provenance checks.
Review effort: Balanced
Findings: None
What changed in this PR
Refactors release provenance verification while preserving existing validation behavior.
Changes:
- Extracts shared SLSA provenance decoding.
- Consolidates four verifier CLI branches without changing command guards.
- Preserves conditional GitHub provenance parsing and recovery revalidation.
| File | Description |
|---|---|
sdk/typescript/scripts/release-automation.mjs |
Shares provenance parsing and verifier command plumbing. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
Codex Review: Didn't find any major issues. Can't wait for the next one! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
alandelong-oai
left a comment
There was a problem hiding this comment.
Reviewed the actual PR diff at edfb3254fd5bbbd3f55e2f0ce0578976a41aad4e against explicit base b96739d5ba184bc745f7ce97605781f97eaf0a66 with three independent HIGH full-diff passes and root synthesis, including every changed test and fixture. No supported introduced issue was identified.
Read all159 actual GitHub diff lines and touched provenance/dispatch context. Extracted parsing and shared dispatch preserve argument counts, values, selected environment parsing and validation calls. Actual GitHub merge base differs from explicit base; the touched file has no inherited-base difference. No release or signature operation executed.
Static source review only; no local tests, builds, release operations or models were run. Source approval does not establish current CI, integration or deployment.
Summary
Release verification repeats provenance-bundle decoding and CLI input/output plumbing. Share that code while retaining normal and recovered verification behavior.
Changes
Testing
Passed on commit
edfb3254fd5b:pnpm --dir sdk/typescript run build:ci— passed.sdk/typescript:pnpm run build:plugin,pnpm run types, andpnpm run format— passed.sdk/typescript:bun test --timeout 30000 --seed 12345 tests-ts/release-automation.test.ts tests-ts/release-pr.test.ts tests-ts/release-cut-workflow.test.ts— 367 passed, 0 failed.sdk/typescript:pnpm run test --seed 12345— 3,566 passed, 53 skipped, 0 failed.sdk/typescript:pnpm run test— 3,566 passed, 53 skipped, 0 failed; randomized seed2899968562.Three independent Codex reviews and separate verification completed without findings.
Risk and rollout
This code checks release provenance. Validation order, diagnostics, archive checks and recovered-run verification must remain intact. No release command syntax, publication permission or provenance requirement changes are introduced.
Public disclosure review