fix(release): bind review receipts to native Codewith lineage - #267
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
RELEASE_REVIEWER_AGENTand the signed payload to name the exact native Codewith sub-agent lineage (/root/...) fixed for the release candidateTodos: T-00065 (
f2474658-faf8-4f97-b908-68bc80fc980a)Exact candidate
8862c1d9421f03fea1e183ec6aa5c2c9f5b3272109d8f9bec7e4b939b8db0686120bae5df8421be8322f97c7208eabaa7b820f60ce655e506d11e43cgit revert 09d8f9bec7e4b939b8db0686120bae5df8421be8Validation
12 pass / 1 fail; expectedrelease-agent-review-reviewer-runtime, received no failure for matchingAnscombe41 pass / 1 skip / 0 failbun test: exit 0; output contained1305 pass / 77 skip / 0 fail36 pass / 1 skip / 0 failbun run verify:release: exit 0; package/install smoke printed0.15.22, exact commit/tree matched this PR, and the package-owned extracted-artifact scanner passed twice1 commits scanned./no leaks foundArtifact-scan distinction: a direct generic Gitleaks scan of the
.tgzwas vacuous (scanned ~0 bytes) and is not counted. Extracting the tarball made the generic scan cover 19.46 MB and report six pre-existing identifier-onlyidempotencyKeyfalse positives in unchanged bundled CLI/server/MCP code;git diffagainst the base for those bundled source lanes returned 0. The package-owned extracted-artifact scanner is the applicable gate and passed twice.Review stop condition
One independent native Codewith sub-agent reviews this exact head/tree. The PR advances on GO with zero concrete reachable in-scope P0/P1 blockers; P2/P3, pre-existing, optional-hardening, and unrelated findings are non-blocking follow-ups.
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.