Skip to content

Document release credentials and pin them to the workflows (T12) - #128

Merged
wallstop merged 1 commit into
mainfrom
t12/release-credential-docs
Oct 2, 2026
Merged

wallstop merged 1 commit into
mainfrom
t12/release-credential-docs

Conversation

@wallstop

@wallstop wallstop commented Oct 2, 2026 •

Copy link
Copy Markdown
Owner

The release chain is fully built, but no document recorded the credentials an owner must configure, and the roadmap named two that do not exist in the repository.

Behavior

  • .llm/references/RELEASING.md records the chain (prepare, tag, publish), the RELEASE_TOKEN secret and its scope, why the default GITHUB_TOKEN cannot complete a release, the npm Trusted Publisher fields, the rerun and recovery matrix, and the fail-closed guards.
  • scripts/lint-release-secrets.js cross-checks the documented credential set against the secrets the release workflows read, in both directions, and fails closed on a missing or empty documented block. Wired into lint:llm:full, llm-lint CI, and pre-commit.

Validation

  • 10 new self-tests: both drift directions, clean, empty, malformed, comment masking, both GitHub secret expression forms, and a check against this repository. Harness 18/18 files green.
  • Red on the real defect: documenting AUTO_COMMIT_APP_ID and AUTO_COMMIT_APP_PRIVATE_KEY fails as unread, and adding a secret to a release workflow without documenting it fails as undocumented.
  • Lint ladder green; npm pack payload unchanged at 172 files.

Risk / Rollback

  • Docs and one new check; no workflow, script, or production behavior change. Rollback by reverting this commit.

Refs T12.


Note

Low Risk
Documentation and harness lint only; release workflows and publish behavior are unchanged.

Overview
Adds owner-facing release documentation and a lint guard so release workflow secrets cannot drift from what the repo documents.

.llm/references/RELEASING.md describes the prepare → tag → publish chain, the required RELEASE_TOKEN (and why GITHUB_TOKEN alone can “succeed” without publishing), npm Trusted Publisher setup, rerun/recovery, and fail-closed release scripts. The bump-version-release skill now points readers there before a first release or after a partial failure.

scripts/lint-release-secrets.js parses secrets from release-prep.yml, release-tag.yml, and npm-publish.yml and compares them to the <!-- release-secrets:begin/end --> table in RELEASING.md (both directions; ignores GITHUB_TOKEN and YAML comments). It is wired into pre-commit, lint:llm:full, llm-lint CI (including path filters on the three release workflows), plus 10 self-tests in test-lint-release-secrets.ps1.

Reviewed by Cursor Bugbot for commit 2233e69. Bugbot is set up for automated code reviews on this repo. Configure here.

The release chain is fully built, but nothing recorded the credentials an
owner must configure, and the roadmap named two that do not exist.

## Behavior

- `.llm/references/RELEASING.md` records the chain (prepare -> tag ->
  publish), the `RELEASE_TOKEN` secret and its scope, why the default
  `GITHUB_TOKEN` cannot complete a release, the npm Trusted Publisher
  fields, the rerun and recovery matrix, and the fail-closed guards.
- `scripts/lint-release-secrets.js` cross-checks the documented credential
  set against the secrets the release workflows actually read, in both
  directions, and fails closed on a missing or empty documented block.
  Wired into `lint:llm:full`, llm-lint CI, and pre-commit.

## Validation

- 10 new self-tests, both drift directions, clean/empty/malformed cases,
  and a check against this repository. Harness 18/18 files green.
- Red on the real defect: documenting `AUTO_COMMIT_APP_ID` and
  `AUTO_COMMIT_APP_PRIVATE_KEY` fails as unread, and adding a secret to a
  release workflow without documenting it fails as undocumented.
- Lint ladder green; `npm pack` payload unchanged at 172 files.

## Risk / Rollback

- Docs and one new check; no workflow, script, or production behavior
  changes. Rollback by reverting this commit.

Refs T12.
@wallstop
wallstop merged commit 9bbd7f2 into main Oct 2, 2026
3 checks passed
@wallstop
wallstop deleted the t12/release-credential-docs branch October 2, 2026 04:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant