Skip to content

fix: harden release-branch.yml, disclose persistent caches, require hooks in the release tree - #873

Merged
fdaviddpt merged 2 commits into
mainfrom
fix/856
Oct 2, 2026
Merged

fdaviddpt merged 2 commits into
mainfrom
fix/856

Conversation

@fdaviddpt

Copy link
Copy Markdown
Contributor

Three follow-ups to the #853 release-branch.yml review, plus two disclosure/guard fixes found alongside it.

New/updated tests across tests/test_version_order_856.py, tests/test_release_branch_check_851.py, tests/test_release_branch_smoke_851.py, tests/test_readme_discloses_854.py. Full detail (red/green evidence per file, both self-review spawns in full, compliance and docs surveys) is kept outside the diff.

Closes #856, Closes #857, Closes #858

🤖 Generated with Claude Code

[AI-generated]

fdaviddpt and others added 2 commits October 2, 2026 22:10
…aches, require hooks in the release tree

#856: `publish` now refuses to push a `release` tree whose plugin.json version
is not strictly greater than release's current one (override:
workflow_dispatch allow_version_regression), pins pyyaml to an exact version
in both jobs, and fixes the concurrency comment, which still described a
force-push race the push stopped being capable of.

#857: README's disclosure section now names the three remember-* caches that
persist across every hook invocation by design, rather than describing all of
them as per-save temp files an EXIT trap always cleans up.

#858: check_release_tree.py and smoke_release_tree.py now fail loudly on a
release tree with no hooks/hooks.json, or one declaring zero command hooks,
instead of passing silently -- this plugin works only through its hooks.

Co-Authored-By: Claude Sonnet 5 <[email protected]>
test_validate_required_without_a_claude_binary_fails_loudly,
test_validate_skipped_says_so_out_loud and
test_hooks_json_with_zero_command_hooks_fails_the_smoke switched their
fixture trees from a hookless tree to one with a real SessionStart hook (so
the new #858 zero-command-hooks check in smoke_release_tree.py wouldn't fire
for the wrong reason). That hook actually runs via subprocess.Popen(["/bin/sh",
...]), which does not exist on windows-latest, so all three failed on CI's
Windows legs with FileNotFoundError. Same @posix_only marker every other
hook-running test in this file already carries.

Co-Authored-By: Claude Sonnet 5 <[email protected]>
@fdaviddpt
fdaviddpt merged commit 3cbe1dc into main Oct 2, 2026
16 checks passed
@fdaviddpt
fdaviddpt deleted the fix/856 branch October 2, 2026 22:13
fdaviddpt added a commit that referenced this pull request Oct 3, 2026
Two new findings from round 2 of the v0.39.0 gate-3 audit (dispatch token
rel39-1791028178-23675-r2): haiku.py's auth-failure warning misattributes
which credential actually died (#870/#894 composition), and README.md's
cache-file disclosure still names the pre-v2 filename (#873/#875
composition). Both rank `misreports` -- non-blocking.

Co-Authored-By: Claude Sonnet 5 <[email protected]>
fdaviddpt added a commit that referenced this pull request Oct 3, 2026
* docs(trap.d): log round-1 release-audit findings for v0.39.0

Non-blocking findings from the v0.39.0 gate-3 audit (dispatch token
rel39-1791025656-14116): doctor.sh's NOTICE grep reads log history rather
than current presence (#894), two docs sweeps that missed stale
REMEMBER_OAUTH_TOKEN advice (#894), and a README line overstating the
new recovery token's isolation from nested claude -p sessions (#896).
All rank `misreports` -- non-blocking per skills/manager/phases/findings.md.

Co-Authored-By: Claude Sonnet 5 <[email protected]>

* docs(trap.d): log round-2 release-audit findings for v0.39.0

Two new findings from round 2 of the v0.39.0 gate-3 audit (dispatch token
rel39-1791028178-23675-r2): haiku.py's auth-failure warning misattributes
which credential actually died (#870/#894 composition), and README.md's
cache-file disclosure still names the pre-v2 filename (#873/#875
composition). Both rank `misreports` -- non-blocking.

Co-Authored-By: Claude Sonnet 5 <[email protected]>

---------

Co-authored-by: Claude Sonnet 5 <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment