Repository navigation
ci: route protected verification locally - #20
promisepreston wants to merge 11 commits into
Conversation
* ci: verify public preview portal * test: lock preview workflow boundary
* feat: add fail-closed preview release updater * fix: make preview release updates atomic
Resolve the updater repository independently of the caller directory. Includes regression coverage, temporary-directory cleanup, and a version-independent next-preview test.
Derive release test identities from the copied manifest and verify the same tests after the publisher stages the next preview.
Add a separate verified production deploy job behind a protected-branch environment, using an ephemeral GitHub-hosted runner and pinned Cloudflare tooling.
Publish the independently verified unsigned owner Preview manifest for source revision 4e163fbf476bfcee13cf9f62dd0b101cdcc153d1.
Co-authored-by: promisepreston <promisepreston@gmail.com>
Document the current friends-preview model evaluation scope without making origin-based quality or privacy claims.
Co-authored-by: promisepreston <promisepreston@gmail.com>
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
|
Closing after CI correctly enforced the public-repository trust boundary. RecordCove Preview verification and credentialed deployment remain GitHub-hosted by design under WO-013; no runner-routing change is required. |



Summary\n- keep public pull-request verification on GitHub-hosted compute\n- route only protected main verification to preston-shared\n- preserve the credentialed Cloudflare deployment job on GitHub-hosted compute\n- synchronize the current protected main history into develop\n\n## Validation\n- Actionlint\n- git diff check