You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
release: every workflow names the predicate type the statement actually carries
The third thing the first real release found, and this refusal was correct.
Phase C stopped with "the release notes tell people to pass --predicate-type
https://spdx.dev/Document and the statement that was just made is
https://spdx.dev/Document/v2.3". That check exists precisely because the
provenance plan wrote the URI down as a promise taken from the action's
documentation rather than from an attestation, and said out loud it was
unmeasured. It has now been measured: the statement carries the versioned one.
The value was written in five places across three files and only one of them
was being checked. Three of the five are not checks at all - they are the
commands a person copies out of the release notes, and with the wrong URI gh
answers "no attestation found", which reads exactly like a release nobody
attested.
It cannot be written once: three workflows are three files and a workflow
cannot read a constant out of another one. So the guard asks for agreement
rather than for a single home - it collects every spdx.dev URI in
.github/workflows and refuses when there are two different ones.
The lesson worth keeping: read a predicate type out of a bundle, not out of
documentation. base64 -d on dsseEnvelope.payload and predicateType is inside.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
0 commit comments