Skip to content

fix(ci): isolate kache canary schemas and trusted credentials - #51

Merged
jmagar merged 1 commit into
mainfrom
codex/kache-canary-schema
Oct 1, 2026
Merged

jmagar merged 1 commit into
mainfrom
codex/kache-canary-schema

Conversation

@jmagar

@jmagar jmagar commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Kache 0.28.1 rejects schema-27 entries retained under the old shared canary prefix. Each trusted probe now uses a version-and-run-specific prefix, preserving both fresh-runner transfer and zero-miss assertions without deleting remote cache entries.

Shared cache credentials are confined to non-PR main events. PRs retain an explicit credentialless compile check. The official action is pinned to its current immutable v1 commit, and contract tests enforce the PR credential boundary and shared prefix.

Validation: workflow-library validator, Actionlint, focused canary security/schema contract, official-action pin test and diff checks pass. The prior probe reached MinIO on retry and identified the incompatible schema; the new trusted probe will verify real reuse after integration.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@jmagar
jmagar merged commit c70b668 into main Oct 1, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant