Repository navigation
Merged
Conversation
…aches, require hooks in the release tree #856: `publish` now refuses to push a `release` tree whose plugin.json version is not strictly greater than release's current one (override: workflow_dispatch allow_version_regression), pins pyyaml to an exact version in both jobs, and fixes the concurrency comment, which still described a force-push race the push stopped being capable of. #857: README's disclosure section now names the three remember-* caches that persist across every hook invocation by design, rather than describing all of them as per-save temp files an EXIT trap always cleans up. #858: check_release_tree.py and smoke_release_tree.py now fail loudly on a release tree with no hooks/hooks.json, or one declaring zero command hooks, instead of passing silently -- this plugin works only through its hooks. Co-Authored-By: Claude Sonnet 5 <[email protected]>
test_validate_required_without_a_claude_binary_fails_loudly, test_validate_skipped_says_so_out_loud and test_hooks_json_with_zero_command_hooks_fails_the_smoke switched their fixture trees from a hookless tree to one with a real SessionStart hook (so the new #858 zero-command-hooks check in smoke_release_tree.py wouldn't fire for the wrong reason). That hook actually runs via subprocess.Popen(["/bin/sh", ...]), which does not exist on windows-latest, so all three failed on CI's Windows legs with FileNotFoundError. Same @posix_only marker every other hook-running test in this file already carries. Co-Authored-By: Claude Sonnet 5 <[email protected]>
fdaviddpt
added a commit
that referenced
this pull request
Oct 3, 2026
Two new findings from round 2 of the v0.39.0 gate-3 audit (dispatch token rel39-1791028178-23675-r2): haiku.py's auth-failure warning misattributes which credential actually died (#870/#894 composition), and README.md's cache-file disclosure still names the pre-v2 filename (#873/#875 composition). Both rank `misreports` -- non-blocking. Co-Authored-By: Claude Sonnet 5 <[email protected]>
fdaviddpt
added a commit
that referenced
this pull request
Oct 3, 2026
* docs(trap.d): log round-1 release-audit findings for v0.39.0 Non-blocking findings from the v0.39.0 gate-3 audit (dispatch token rel39-1791025656-14116): doctor.sh's NOTICE grep reads log history rather than current presence (#894), two docs sweeps that missed stale REMEMBER_OAUTH_TOKEN advice (#894), and a README line overstating the new recovery token's isolation from nested claude -p sessions (#896). All rank `misreports` -- non-blocking per skills/manager/phases/findings.md. Co-Authored-By: Claude Sonnet 5 <[email protected]> * docs(trap.d): log round-2 release-audit findings for v0.39.0 Two new findings from round 2 of the v0.39.0 gate-3 audit (dispatch token rel39-1791028178-23675-r2): haiku.py's auth-failure warning misattributes which credential actually died (#870/#894 composition), and README.md's cache-file disclosure still names the pre-v2 filename (#873/#875 composition). Both rank `misreports` -- non-blocking. Co-Authored-By: Claude Sonnet 5 <[email protected]> --------- Co-authored-by: Claude Sonnet 5 <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Three follow-ups to the #853 release-branch.yml review, plus two disclosure/guard fixes found alongside it.
publishin.github/workflows/release-branch.ymlnow refuses to push areleasetree whose.claude-plugin/plugin.jsonversion does not strictly move forward fromrelease's current parent version (new.github/scripts/check_version_order.py, overridable via a newworkflow_dispatchinputallow_version_regression). pyyaml is now pinned (6.0.3) in both theverifyandpublishjobs. The stale force-push-race comment aboveconcurrency:is rewritten to describe the actual current reasoning.docs/releasing.mddocuments the new guard and its override.$TMPDIR/remember-*files that persist by design across every hook invocation (remember-env-<key>,remember-config-cache-<key>,remember-detect-tools-cache), instead of implying the whole prefix is cleaned up by an EXIT trap every run.check_release_tree.pyandsmoke_release_tree.pynow fail (instead of silently passing) a release tree with nohooks/hooks.json, or one declaring zerocommandhooks -- this plugin works only through its hooks, so either case would ship a release that runs nothing.New/updated tests across
tests/test_version_order_856.py,tests/test_release_branch_check_851.py,tests/test_release_branch_smoke_851.py,tests/test_readme_discloses_854.py. Full detail (red/green evidence per file, both self-review spawns in full, compliance and docs surveys) is kept outside the diff.Closes #856, Closes #857, Closes #858
🤖 Generated with Claude Code
[AI-generated]