Commit Graph

410 Commits

Author SHA1 Message Date
dependabot[bot] 61d80b3ab8 chore: bump clechasseur/rs-cargo from 5.0.7 to 5.0.8 (#3829)
Bumps [clechasseur/rs-cargo](https://github.com/clechasseur/rs-cargo)
from 5.0.7 to 5.0.8.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/clechasseur/rs-cargo/releases">clechasseur/rs-cargo's
releases</a>.</em></p>
<blockquote>
<h2>v5.0.8</h2>
<p>New patch release with updated dependencies to fix some
vulnerabilities.</p>
<h2>What's Changed</h2>
<ul>
<li>chore(deps): bump undici from 6.27.0 to 6.28.0 in the npm_and_yarn
group across 1 directory by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/clechasseur/rs-cargo/pull/435">clechasseur/rs-cargo#435</a></li>
<li>chore(deps): bump the npm_and_yarn group across 1 directory with 1
update by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/clechasseur/rs-cargo/pull/436">clechasseur/rs-cargo#436</a></li>
<li>fix: <code>npm update</code> to get fixes, update
<code>@clechasseur/rs-actions-core</code> to 8.0.4, bump version to
5.0.8 by <a
href="https://github.com/clechasseur"><code>@​clechasseur</code></a> in
<a
href="https://redirect.github.com/clechasseur/rs-cargo/pull/437">clechasseur/rs-cargo#437</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/clechasseur/rs-cargo/compare/v5.0.7...v5.0.8">https://github.com/clechasseur/rs-cargo/compare/v5.0.7...v5.0.8</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/clechasseur/rs-cargo/commit/9a5c570d3347f8dee3916c8871f3ffaf38909956"><code>9a5c570</code></a>
fix: <code>npm update</code> to get fixes, update
<code>@clechasseur/rs-actions-core</code> to 8.0....</li>
<li><a
href="https://github.com/clechasseur/rs-cargo/commit/24c8a774d7e015322005aaca3336016bdc670085"><code>24c8a77</code></a>
chore(deps): bump the npm_and_yarn group across 1 directory with 1
update (<a
href="https://redirect.github.com/clechasseur/rs-cargo/issues/436">#436</a>)</li>
<li><a
href="https://github.com/clechasseur/rs-cargo/commit/b2652e1335c7ec927c51a006790e235ad741e1a7"><code>b2652e1</code></a>
chore(deps): bump undici in the npm_and_yarn group across 1 directory
(<a
href="https://redirect.github.com/clechasseur/rs-cargo/issues/435">#435</a>)</li>
<li><a
href="https://github.com/clechasseur/rs-cargo/commit/44bc6e9a0a8b85197cd377ad859fac1e3e9408bd"><code>44bc6e9</code></a>
chore(deps): update dependency rollup to ^4.62.4 (<a
href="https://redirect.github.com/clechasseur/rs-cargo/issues/432">#432</a>)</li>
<li><a
href="https://github.com/clechasseur/rs-cargo/commit/e914260698d7251b9589c737040ea88189e1d07e"><code>e914260</code></a>
chore(deps): update dependency oxlint to ^1.77.0 (<a
href="https://redirect.github.com/clechasseur/rs-cargo/issues/434">#434</a>)</li>
<li><a
href="https://github.com/clechasseur/rs-cargo/commit/952abcd19408ed276d2cb062ba1e680b5d564a1e"><code>952abcd</code></a>
chore(deps): update actions/checkout action to v7.0.1 (<a
href="https://redirect.github.com/clechasseur/rs-cargo/issues/431">#431</a>)</li>
<li><a
href="https://github.com/clechasseur/rs-cargo/commit/ebc623c7b9c4498bbb97ab84d0d7ef333f5645e0"><code>ebc623c</code></a>
chore(deps): update dependency ts-jest to ^29.4.12 (<a
href="https://redirect.github.com/clechasseur/rs-cargo/issues/428">#428</a>)</li>
<li><a
href="https://github.com/clechasseur/rs-cargo/commit/260bce3fe16b97604f986f900f052ddf2996f71c"><code>260bce3</code></a>
chore(deps): update dependency oxlint to ^1.75.0 (<a
href="https://redirect.github.com/clechasseur/rs-cargo/issues/430">#430</a>)</li>
<li>See full diff in <a
href="https://github.com/clechasseur/rs-cargo/compare/v5.0.7...v5.0.8">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=clechasseur/rs-cargo&package-manager=github_actions&previous-version=5.0.7&new-version=5.0.8)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-17 01:48:31 -07:00
dependabot[bot] 9c13f6e7d4 chore: bump taiki-e/install-action from 2.85.11 to 2.85.13 (#3828)
Bumps
[taiki-e/install-action](https://github.com/taiki-e/install-action) from
2.85.11 to 2.85.13.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's
releases</a>.</em></p>
<blockquote>
<h2>2.85.13</h2>
<ul>
<li>
<p>Update <code>tombi@latest</code> to 1.3.3.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.8.5.</p>
</li>
<li>
<p>Update <code>kingfisher@latest</code> to 1.113.0.</p>
</li>
<li>
<p>Update <code>cargo-shear@latest</code> to 1.13.4.</p>
</li>
<li>
<p>Update <code>bpf-linker@latest</code> to 0.11.0.</p>
</li>
</ul>
<h2>2.85.12</h2>
<ul>
<li>
<p>Update <code>zola@latest</code> to 0.23.3.</p>
</li>
<li>
<p>Update <code>wasm-tools@latest</code> to 1.256.0.</p>
</li>
<li>
<p>Update <code>tombi@latest</code> to 1.2.10.</p>
</li>
<li>
<p>Update <code>syft@latest</code> to 1.51.0.</p>
</li>
<li>
<p>Update <code>prek@latest</code> to 0.4.13.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.8.4.</p>
</li>
<li>
<p>Update <code>editorconfig-checker@latest</code> to 3.11.1.</p>
</li>
<li>
<p>Update <code>cargo-tarpaulin@latest</code> to 0.37.1.</p>
</li>
<li>
<p>Update <code>cargo-rdme@latest</code> to 2.2.1.</p>
</li>
<li>
<p>Update <code>biome@latest</code> to 2.5.8.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's
changelog</a>.</em></p>
<blockquote>
<h2>[2.85.13] - 2026-08-13</h2>
<ul>
<li>
<p>Update <code>tombi@latest</code> to 1.3.3.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.8.5.</p>
</li>
<li>
<p>Update <code>kingfisher@latest</code> to 1.113.0.</p>
</li>
<li>
<p>Update <code>cargo-shear@latest</code> to 1.13.4.</p>
</li>
<li>
<p>Update <code>bpf-linker@latest</code> to 0.11.0.</p>
</li>
</ul>
<h2>[2.85.12] - 2026-08-12</h2>
<ul>
<li>
<p>Update <code>zola@latest</code> to 0.23.3.</p>
</li>
<li>
<p>Update <code>wasm-tools@latest</code> to 1.256.0.</p>
</li>
<li>
<p>Update <code>tombi@latest</code> to 1.2.10.</p>
</li>
<li>
<p>Update <code>syft@latest</code> to 1.51.0.</p>
</li>
<li>
<p>Update <code>prek@latest</code> to 0.4.13.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.8.4.</p>
</li>
<li>
<p>Update <code>editorconfig-checker@latest</code> to 3.11.1.</p>
</li>
<li>
<p>Update <code>cargo-tarpaulin@latest</code> to 0.37.1.</p>
</li>
<li>
<p>Update <code>cargo-rdme@latest</code> to 2.2.1.</p>
</li>
<li>
<p>Update <code>biome@latest</code> to 2.5.8.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/taiki-e/install-action/commit/82cd3e7658a6f96c86c0234aeeda1748937cb0a1"><code>82cd3e7</code></a>
Release 2.85.13</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/4dd6c67d0ecd1fab76c6cecc5931e1239cc16add"><code>4dd6c67</code></a>
Update <code>tombi@latest</code> to 1.3.3</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/91cb1bb28383045bb69f87d336ede6db3c61927b"><code>91cb1bb</code></a>
Update <code>mise@latest</code> to 2026.8.5</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/83d968e89df664219ce13abb14808207a131cc64"><code>83d968e</code></a>
Update <code>kingfisher@latest</code> to 1.113.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/f7ab7f5d0a3e5a8120f10f39cfc442b2f40642b0"><code>f7ab7f5</code></a>
Update cargo-xwin manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/3faddd9e3002e0d2922192f5808a78c4118eb58c"><code>3faddd9</code></a>
Update <code>cargo-shear@latest</code> to 1.13.4</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/b4cb4b238691473c8bf1425b4d38120d5058dfc2"><code>b4cb4b2</code></a>
Update <code>bpf-linker@latest</code> to 0.11.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/b20dedce73af6905cdc30d6611090c9b67557c8d"><code>b20dedc</code></a>
Release 2.85.12</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/952d13c8bb10d7e37f96fa2c8131338550a62663"><code>952d13c</code></a>
ci: Skip cargo-rdme on x86_64 macOS</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/c8724e7258d0b8f8188a94aec0c00ae9da81edd7"><code>c8724e7</code></a>
Update <code>zola@latest</code> to 0.23.3</li>
<li>Additional commits viewable in <a
href="https://github.com/taiki-e/install-action/compare/v2.85.11...v2.85.13">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=taiki-e/install-action&package-manager=github_actions&previous-version=2.85.11&new-version=2.85.13)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-17 01:48:28 -07:00
Worktrunk Bot 1b278042de chore(ci): weekly renovation 2026-08-16 (#3826)
## Summary

Weekly CI renovation check found the following updates:

- `worktrunk`: 0.72.0 → 0.74.0 (MSRV 1.96, compatible with our 1.96.0) —
`ci.yaml` ×2, `nightly.yaml`
- `nushell`: 0.114.1 → 0.115.0 — `nightly.yaml`, `benchmarks.yaml`,
`coverage.yaml`, `actions/test-setup`, and
`scripts/codex-cloud/Taskfile.yaml`
- `pre-commit`: 4.6.1 → 4.6.2 — `scripts/codex-cloud/Taskfile.yaml`
- `PowerShell`: 7.6.4 → 7.6.5 — `scripts/codex-cloud/Taskfile.yaml` and
the root `Taskfile.yaml`'s `setup-web` task

The Codex Cloud archive checksums were recomputed from the new upstream
tarballs, and the resulting `Taskfile.yaml` digest (`f14dbc89…`) is
copied into both README launcher commands.

The `setup-web` PowerShell pin came in as a follow-up commit: the
initial sweep only grepped `.rs`/`.md`/`.toml` for stale versions, so
the root `Taskfile.yaml`'s `PWSH_VERSION="7.6.4"` was missed. Nothing
tests the two PowerShell pins against each other, so that one drifts
silently — worth a note for future renovation runs. The
`powershell_7.6.5-1.deb_amd64.deb` asset the `setup-web` branch
downloads is present in the v7.6.5 release.

## Already up to date

- Rust stable is 1.97.1, so MSRV and toolchain stay at 1.96 (latest
stable − 1) — `Cargo.toml`, `tests/helpers/wt-perf/Cargo.toml`,
`rust-toolchain.toml` need no change, and `flake.lock` is untouched.
- `cargo-insta` 1.48.0, `cargo-nextest` 0.9.143, `cargo-llvm-cov` 0.8.7,
`cargo-msrv` 0.19.3, `cargo-affected` 0.4.0, `cargo-udeps` 0.1.61,
`lychee` 0.24.2
- Task 3.52.0 (mise, Codex Cloud)
- Runner images: ubuntu-24.04, macos-15, windows-2022

## Held back: zola 0.22.1 → 0.23.3

Not bumped. Zola 0.23.0 shipped [Tera2 +
refactoring](https://github.com/getzola/zola/pull/3105), which is a
templating-engine swap rather than a routine release. Building `docs/`
with the 0.23.3 binary fails at the first line of `templates/base.html`:

```
ERROR error: Unknown tag
 --> base.html:1:4
  |
1 | {% import "macros.html" as macros %}
  |    ^^^^^^
```

`templates/base.html` and `templates/macros.html` are the two files that
use the `import`/`macro` pair, so the migration looks small, but it is
template work with its own review rather than a pin bump — kept out of
this PR so the rest can land. Raised separately.

<details><summary>Verification</summary>

- Every version above was read from the upstream source of truth:
`crates.io` for the cargo tools, `nushell/nushell` and
`PowerShell/PowerShell` releases, PyPI for pre-commit, and
`static.rust-lang.org/dist/channel-rust-stable.toml` for Rust stable
(1.97.1).
- Checksums were computed from the downloaded archives and the extracted
binaries were run (`nu --version` → `0.115.0`); the archive layouts
(`nu-<ver>-x86_64-unknown-linux-gnu/nu`, top-level `pwsh`) are
unchanged, so the `install_binary` paths still resolve.
- All six edited YAML files parse.
- The nushell bump was exercised against the shell-integration suite:
`cargo test --features shell-integration-tests --test integration --
nushell` with 0.115.0 on `PATH`. 13 of 14 pass;
`test_nushell_install_target_is_a_vendor_autoload_dir` fails — but it
fails identically on the currently-pinned 0.114.1, and passes on *both*
versions when run alone. It is a pre-existing shared-state race in the
sandbox, not a regression from this bump: the test asserts against the
real user `$nu.vendor-autoload-dirs` entry rather than one under its
temp `HOME` (nu resolves the home dir from the passwd database, so the
test's `HOME` override does not move it), and a sibling uninstall test
in the same filter removes `wt.nu` from that shared directory. Noted
rather than fixed here — it is unrelated to the pins.
- The zola failure above was reproduced with the official 0.23.3
`x86_64-unknown-linux-gnu` release binary against this repo's `docs/`.

</details>

---------

Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com>
2026-08-17 01:48:26 -07:00
Worktrunk Bot 1e2e05cfb4 chore: update tend workflows (0.1.17 → 0.1.18) (#3824)
Automated nightly regeneration of tend's workflow files, picking up tend
0.1.18.

**tend version:** 0.1.17 → 0.1.18

Notable changes:

- `tend-mention`: both halves of the 👀 reaction now live in the `handle`
job. Previously `verify` added the eyes and `handle` removed them, so a
burst of mentions on one thread could cancel a queued `handle` — which
allocates no runner and runs no steps, `always()` included — leaving the
reaction stranded (max-sixty/tend#990).
- `tend-review` / `tend-triage`: the eyes-removal lookup now paginates
(`--paginate`, `per_page=100`). A thread with more than 30 reactions
could push the bot's own eyes off the first page, so the removal
silently found nothing (max-sixty/tend#990).
- `tend check`: the secret audit now reports only org secrets this repo
can actually read, instead of every org secret (max-sixty/tend#994).
- `running-in-ci` skill: notes that fork PR reviews reach no successor
session, and scopes PR-description claims to the merge base
(max-sixty/tend#985, max-sixty/tend#992).

Full comparison:
https://github.com/max-sixty/tend/compare/0.1.17...0.1.18

Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com>
2026-08-17 01:48:21 -07:00
Worktrunk Bot e3b3482fd0 chore: update tend workflows (0.1.15 → 0.1.17) (#3822)
Automated nightly regeneration of tend's workflow files.

**tend version:** 0.1.15 → 0.1.17

**Notable changes**

- 👀 reactions now mark a session in flight: the bot reacts when an issue
or PR is opened, and the reaction comes off when the session ends
(max-sixty/tend#974, max-sixty/tend#979).
- Mention gating was reworked — coarser pre-check gates, tested poll
scripts, and an anchor-based run window replace the hand-rolled matching
(max-sixty/tend#965, max-sixty/tend#971).
- Self-initiated fixes are now gated on cost as well as evidence, so the
bot doesn't open a PR whose value doesn't justify the session
(max-sixty/tend#960).
- `tend check` reads the bot's own bypass verdict on repos where the
actor list is withheld, instead of reporting a false FAIL
(max-sixty/tend#976).
- Weekly no longer trusts a re-anchored approval on a rebased dependency
PR (max-sixty/tend#890), and review-reviewers is paused as a scheduled
sweep, kept as a manual spot-check (max-sixty/tend#966).

Compare: https://github.com/max-sixty/tend/compare/0.1.15...0.1.17

Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com>
2026-08-15 07:55:41 -07:00
Worktrunk Bot c31e827cba chore: update tend workflows (0.1.14 → 0.1.15) (#3814)
Automated nightly regeneration of tend's workflow files.

**tend version:** 0.1.14 → 0.1.15

**Notable changes**

- **Rate-limit handling**: a maintainer can approve past the spike limit
(max-sixty/tend#874), and `tend-mention` now skips comments on
`tend-rate-limit`-labelled issues as well as `tend-outage` ones — the
same self-trigger loop guard, widened to every issue tend files about
its own health.
- **Review flow**: a push is queued behind an examined-HEAD gate instead
of cancelling the in-flight review (max-sixty/tend#903), the review is
submitted before a fix is pushed (max-sixty/tend#834), a force-push
triggers a re-review rather than trusting the re-anchored SHA
(max-sixty/tend#884), and the `/code-review` second pass is
unconditional (max-sixty/tend#937).
- **CI monitoring**: both the check poll and the `gh run rerun --failed`
poll now end terminally when the cap is hit instead of reading as done
(max-sixty/tend#876, max-sixty/tend#951), and a failed GitHub-status
probe no longer reads as "no incident" (max-sixty/tend#913).
- **Nightly**: conflicted bot PRs are test-merged locally instead of
filtered on the lazy `mergeable` field (max-sixty/tend#898), and mention
runs skip the bot's own review and a third party's content-free approval
(max-sixty/tend#916, max-sixty/tend#955).
- **`tend check`**: an unreadable ruleset bypass list is reported as
unknown rather than ungated (max-sixty/tend#825), environment names are
read one per line and addressed encoded (max-sixty/tend#879), and
`credential-environments` no longer points at the setting it rejects
(max-sixty/tend#900) — this repo currently `SKIP`s that check, so its
wording should improve here.

Full comparison:
https://github.com/max-sixty/tend/compare/0.1.14...0.1.15

Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com>
2026-08-13 05:41:10 -07:00
dependabot[bot] ab76101b0b chore: bump taiki-e/install-action from 2.85.10 to 2.85.11 (#3801)
Bumps
[taiki-e/install-action](https://github.com/taiki-e/install-action) from
2.85.10 to 2.85.11.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's
releases</a>.</em></p>
<blockquote>
<h2>2.85.11</h2>
<ul>
<li>
<p>Update <code>zola@latest</code> to 0.23.2.</p>
</li>
<li>
<p>Update <code>wasm-bindgen@latest</code> to 0.2.127.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.12.3.</p>
</li>
<li>
<p>Update <code>osv-scanner@latest</code> to 2.5.0.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.8.3.</p>
</li>
<li>
<p>Update <code>kingfisher@latest</code> to 1.112.0.</p>
</li>
<li>
<p>Update <code>editorconfig-checker@latest</code> to 3.10.0.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's
changelog</a>.</em></p>
<blockquote>
<h2>[2.85.11] - 2026-08-09</h2>
<ul>
<li>
<p>Update <code>zola@latest</code> to 0.23.2.</p>
</li>
<li>
<p>Update <code>wasm-bindgen@latest</code> to 0.2.127.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.12.3.</p>
</li>
<li>
<p>Update <code>osv-scanner@latest</code> to 2.5.0.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.8.3.</p>
</li>
<li>
<p>Update <code>kingfisher@latest</code> to 1.112.0.</p>
</li>
<li>
<p>Update <code>editorconfig-checker@latest</code> to 3.10.0.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/taiki-e/install-action/commit/7f4eb899022d8fe70b20c4f3de697aa85c309026"><code>7f4eb89</code></a>
Release 2.85.11</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/c17da6245a7fe549cefa05b31e3614ce0b16c2af"><code>c17da62</code></a>
Update <code>zola@latest</code> to 0.23.2</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/97e8291c2ba440a7119c03ebe3ed1e584a1f9b7f"><code>97e8291</code></a>
Update <code>wasm-bindgen@latest</code> to 0.2.127</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/91f9e5c61a2dc7936a8f404d01b7c1551b9c581a"><code>91f9e5c</code></a>
Update <code>uv@latest</code> to 0.12.3</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/bd0cb00440414f36db2f79bca8e27971bb63b2a3"><code>bd0cb00</code></a>
Update <code>osv-scanner@latest</code> to 2.5.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/4def957aa80c252e2d4c61387c6a429d377907d1"><code>4def957</code></a>
Update <code>mise@latest</code> to 2026.8.3</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/3d149dc3890afe4774d158d353b5a3e55fe90f60"><code>3d149dc</code></a>
Update <code>kingfisher@latest</code> to 1.112.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/20d4381a5cf6917520fde30f9ff52387410bfb6e"><code>20d4381</code></a>
Update <code>editorconfig-checker@latest</code> to 3.10.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/583939ec0c8ee9c523cc60342d3d979ce6730f38"><code>583939e</code></a>
codegen: Ignore clippy::assert_is_empty lint</li>
<li>See full diff in <a
href="https://github.com/taiki-e/install-action/compare/v2.85.10...v2.85.11">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=taiki-e/install-action&package-manager=github_actions&previous-version=2.85.10&new-version=2.85.11)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-12 09:40:35 -07:00
dependabot[bot] ec2aa4d154 chore: bump taiki-e/install-action from 2.85.8 to 2.85.10 (#3793)
Bumps
[taiki-e/install-action](https://github.com/taiki-e/install-action) from
2.85.8 to 2.85.10.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's
releases</a>.</em></p>
<blockquote>
<h2>2.85.10</h2>
<ul>
<li>
<p>Update <code>uv@latest</code> to 0.12.2.</p>
</li>
<li>
<p>Update <code>tombi@latest</code> to 1.2.7.</p>
</li>
<li>
<p>Update <code>cosign@latest</code> to 3.1.3.</p>
</li>
<li>
<p>Update <code>coreutils@latest</code> to 0.10.0.</p>
</li>
<li>
<p>Update <code>cargo-rdme@latest</code> to 2.2.0.</p>
</li>
<li>
<p>Update <code>cargo-crap@latest</code> to 0.4.3.</p>
</li>
</ul>
<h2>2.85.9</h2>
<ul>
<li>
<p>Update <code>zola@latest</code> to 0.23.1.</p>
</li>
<li>
<p>Update <code>wild@latest</code> to 0.10.0.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.8.2.</p>
</li>
<li>
<p>Update <code>just@latest</code> to 1.58.0.</p>
</li>
<li>
<p>Update <code>jaq@latest</code> to 3.1.1.</p>
</li>
<li>
<p>Update <code>cargo-nextest@latest</code> to 0.9.143.</p>
</li>
<li>
<p>Update <code>cargo-crap@latest</code> to 0.4.2.</p>
</li>
<li>
<p>Update <code>biome@latest</code> to 2.5.7.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's
changelog</a>.</em></p>
<blockquote>
<h2>[2.85.10] - 2026-08-07</h2>
<ul>
<li>
<p>Update <code>uv@latest</code> to 0.12.2.</p>
</li>
<li>
<p>Update <code>tombi@latest</code> to 1.2.7.</p>
</li>
<li>
<p>Update <code>cosign@latest</code> to 3.1.3.</p>
</li>
<li>
<p>Update <code>coreutils@latest</code> to 0.10.0.</p>
</li>
<li>
<p>Update <code>cargo-rdme@latest</code> to 2.2.0.</p>
</li>
<li>
<p>Update <code>cargo-crap@latest</code> to 0.4.3.</p>
</li>
</ul>
<h2>[2.85.9] - 2026-08-06</h2>
<ul>
<li>
<p>Update <code>zola@latest</code> to 0.23.1.</p>
</li>
<li>
<p>Update <code>wild@latest</code> to 0.10.0.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.8.2.</p>
</li>
<li>
<p>Update <code>just@latest</code> to 1.58.0.</p>
</li>
<li>
<p>Update <code>jaq@latest</code> to 3.1.1.</p>
</li>
<li>
<p>Update <code>cargo-nextest@latest</code> to 0.9.143.</p>
</li>
<li>
<p>Update <code>cargo-crap@latest</code> to 0.4.2.</p>
</li>
<li>
<p>Update <code>biome@latest</code> to 2.5.7.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/taiki-e/install-action/commit/6c6fd71fe4fb72c3697d269963d0e15df8adedad"><code>6c6fd71</code></a>
Release 2.85.10</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/37cec23487191ef9aef8b1315865bd6dc584bef4"><code>37cec23</code></a>
Update zola manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/4914ea4fea5759852f8cda51753420130b883d65"><code>4914ea4</code></a>
Update <code>uv@latest</code> to 0.12.2</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/0ce64163d455e35fedc5f5925221d4a71f05c990"><code>0ce6416</code></a>
Update <code>tombi@latest</code> to 1.2.7</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/1f89e2fb52c482b53fcf083bf64b5abd5d6563ab"><code>1f89e2f</code></a>
Update osv-scanner manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/65ef13f21e6dd200e402682be3b1bc896f6aa862"><code>65ef13f</code></a>
Update kingfisher manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/9f6a5a8ec701c59d62ac1013b92714e7410b2cae"><code>9f6a5a8</code></a>
Update <code>cosign@latest</code> to 3.1.3</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/df08c38f9c0580a749efefc712ba563ff2107db5"><code>df08c38</code></a>
Update <code>coreutils@latest</code> to 0.10.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/dc7bb1f807a876bf372de55372b320860efe4019"><code>dc7bb1f</code></a>
Update <code>cargo-rdme@latest</code> to 2.2.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/9970698e35256036b84ecfb8a70b90fe068a934b"><code>9970698</code></a>
Update <code>cargo-crap@latest</code> to 0.4.3</li>
<li>Additional commits viewable in <a
href="https://github.com/taiki-e/install-action/compare/v2.85.8...v2.85.10">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=taiki-e/install-action&package-manager=github_actions&previous-version=2.85.8&new-version=2.85.10)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-11 15:52:48 -07:00
Worktrunk Bot ec574b6c35 ci: bump pinned cargo-nextest 0.9.143 and worktrunk 0.72.0 (#3783)
## Summary

Weekly CI pin check found the following drift (these inline `version:`
strings are invisible to Dependabot — it follows `Cargo.toml` deps and
`uses: foo@vN` refs, not pinned versions inside `with:` blocks):

- `cargo-nextest`: 0.9.140 → 0.9.143 (MSRV 1.91, compatible with our
1.96) — pinned in `coverage.yaml`, `actions/test-setup`, and
`actions/claude-setup`; all three moved together.
- `worktrunk`: 0.71.0 → 0.72.0 (MSRV 1.96, compatible with our 1.96) —
the CI-installed `wt` that runs `wt hook pre-merge`, bumped to the
current release; pinned in `ci.yaml` (×2) and `nightly.yaml`.

## Already up to date

- `cargo-affected`: 0.4.0, `cargo-insta`: 1.48.0, `cargo-llvm-cov`:
0.8.7, `cargo-msrv`: 0.19.3, `cargo-udeps`: 0.1.61, `lychee`: 0.24.2
- `hustcer/setup-nu` (nushell): 0.114.1 — matches the current nushell
release across all four call sites
- Runner images: ubuntu-24.04, windows-2022

## Notes

- windows-2022 stays pinned
([actions/runner-images#12677](https://github.com/actions/runner-images/issues/12677)
— windows-2025 lacks the D: drive).
- **cargo-nextest 0.9.143 has nothing config-facing to adjust.** The
0.9.140 → 0.9.143 range is dynamic-library-search-path fixes (build-dir
layout v2, `build.build-dir`, `[[example]]` targets), archive filterset
fixes, an opt-in `junit.report-skipped` setting we don't set, and a
listing progress bar. The one behavior change — ordering the Cargo
artifact directory ahead of `deps` on the dylib search path, matching
Cargo since 1.93 — doesn't affect this repo, which links no `dylib`
dependency.
- **worktrunk 0.72.0 is only exercised through `wt hook pre-merge`** in
these three jobs, so the release's `wt merge` / `wt step push` two-tree
changes and the `branch_outcome` JSON rename don't reach CI. The
relevant one is the opposite direction: 0.72.0 fixes `wt` writing ANSI
to a pipe and exiting 101 on `Broken pipe`, which is exactly the non-tty
shape these jobs run in.
- **`zola` is deliberately left at 0.22.1** — see below.

## Deferred: zola 0.22.1 → 0.23.2

`taiki-e/install-action`'s `tool: zola@0.22.1` in `check-docs` (and the
matching pin in `publish-docs.yaml`) is behind, but 0.23.0 is not a
routine bump. Upstream calls it "probably the most breaking version of
Zola that will happen"
([CHANGELOG](https://github.com/getzola/zola/blob/master/CHANGELOG.md)):
**shortcodes are removed entirely** and Tera is updated to v2 with its
own [migration
guide](https://github.com/Keats/tera/blob/master/MIGRATION.md).
`docs/templates/shortcodes/` and `docs/templates/macros.html` both
exist, so this needs a real docs-site migration rather than a
version-string change, and it would land in the same PR as the live-site
publish pin. Left for a separate change; flagging it here so it isn't
silently skipped each week.

Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com>
2026-08-09 04:56:50 -07:00
Maximilian Roos 00ab0ffa26 Canonicalize benchmark fixtures and variants (#3761)
Benchmark fixtures still encoded the benchmark that first needed each
repository state, which left overlapping recipes and variants after the
earlier harness consolidation. This change reduces the fixture catalog
to two provenance-based bases: `Generated` builds an ordinary Git
repository locally, while `Imported` copies the pinned `rust-lang/rust`
corpus. Worktree, branch, and remote-ref populations remain parameters
on `Generated`; prune candidates and backdrop are overlays that work
with either base.

The generated base deliberately combines heterogeneous worktree states,
history-spread branches, and optional remote refs so ordinary list,
completion, picker, first-output, alias, remove, and prune benchmarks
can share it. Imported history-spread branches and clean base-tip
worktrees carry their own commits, preserving the base populations
without making them incidental prune candidates when overlays advance
the default branch.

The benchmark matrix now keeps single-factor contrasts: list scaling
uses the 1- and 8-worktree endpoints; alias dispatch has a startup
floor, two population endpoints, and one warm/cold variable-resolution
pair; completion keeps one full-surface case; remove and prune vary
cache or hook state only where the command exercises it. Historical
recipes, redundant cache rows, and intermediate scaling points are
removed. Manual setup paths live under `target/`, and the benchmark
guide documents the resulting fixture and cache model.

Tests: `cargo run -- hook pre-merge --yes` after merging current `main`
(4,571 tests); targeted Criterion test-mode runs; `cargo test -p
wt-perf`; benchmark check, clippy, formatting, and diff checks.

> _This was written by Codex on behalf of max-sixty_
2026-08-08 13:38:00 -07:00
Maximilian Roos 683bc9b91b docs(ci): record that the release/signing environments admit any tag (#3775)
The `release` and `signing` deployment branch policies were pinned to
`v*` tags; they now admit any tag, and this records that.

The "Tag operations" ruleset covers `~ALL` tags, so the `v*` pattern
carried no part of the gate — tend's `_tags_admin_gated` credits a tag
entry on that ruleset alone and never reads the pattern. What the
pattern did do was duplicate `release.yaml`'s own tag filter, which is
broader: `**[0-9]+.[0-9]+.[0-9]+*` matches an unprefixed `1.2.3`, which
a `v*` policy would then refuse. A release cut under that name would
have stopped at `build-local-artifacts` — it names `signing` and waits
only on `plan`, so the refusal lands before an artifact is built, not at
a publish job. Dropping the pattern removes the only place the two could
drift.

This also brings the repo onto the shape install-tend's §3 recipe
documents (`-f name='*' -f type=tag`), which worktrunk had deviated
from. `uvx tend check` still reports 8/8.

Also updates a stale `v*` reference in the `signing` job's comment in
`release.yaml`.

> _This was written by Claude Code on behalf of max-sixty_

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-08 13:06:19 -07:00
Worktrunk Bot 2dc9380670 docs(ci): the tend environment-deployments gap closed with #3749 (#3764)
Nightly sweep finding: the last paragraph of "Environment protection" in
`.github/CLAUDE.md` describes a gap that closed the same night it was
written.

#3748 added the paragraph saying the generated `tend-*.yaml` files
"still carry the bare `environment: tend`" and that `tend check`'s
`environment-deployments` "fails until a `uvx tend@latest init` regen
lands them on tend ≥ 0.1.14". #3749 merged 3 hours later and did exactly
that regen — every generated job now reads `{name: tend, deployment:
false}`, and tonight's `tend check` reports `environment-deployments` as
`PASS`. Left as-is, the file tells the next reader to expect a failure
that no longer happens and a regen that already ran.

The rewrite keeps the durable half — the generated files aren't
hand-edited, because `uvx tend@latest init` overwrites them — and states
the resolution instead of the pending action.

<details><summary>Evidence</summary>

Current state of the generated files (all eight are identical in shape):

```
$ grep -A2 'environment:' .github/workflows/tend-nightly.yaml
    environment:
      name: tend
      deployment: false
```

Tonight's `tend check`, run by the nightly sweep:

```
  PASS  environment-deployments — No job files a deployment for the 'tend' environment
```

The three checks still failing (`credential-environments`,
`claude-auth`, `repo-secret-allowlist`) are tracked in #3729 and are
repository-settings changes, unrelated to this file. #3760 edits the
same section but not these lines, so the two don't conflict.

</details>

No test accompanies this — it's a documentation-only change to a file no
test reads.

Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com>
2026-08-07 16:11:32 -07:00
Maximilian Roos 5d4d0e8407 docs(ci): record the model credential as environment-scoped (#3760)
Documents `CLAUDE_CODE_OAUTH_TOKEN` moving out of repo-level storage and
into the `tend` environment — the last operational secret still sitting
where any workflow the repo runs could read it, and the remaining
`repo-secret-allowlist` failure after #3748. The environment copy is
set; the repo-level copy is deleted once this PR's own `tend-review` run
comes back green.

That run is the verification. An environment secret outranks a
repo-level one of the same name, so a job naming `environment: tend`
already reads the new value while both exist — which means the
credential is exercised end to end before anything is removed, rather
than after.

Nothing about who reads the token changes. All eight readers — `triage`,
`handle`, `fix-ci`, `nightly`, `review-runs`, `notifications`, `weekly`,
`review` — already declare `environment: tend`.

The lead sentence of "Environment protection" claimed environments hold
"credentials that grant write access". That was never the set — the
model credential grants no write access to anything in this repo, and it
now lives in one. It states the set directly instead, with the reason
`CODECOV_TOKEN` stays outside it.

The `tend` row's "Read by" cell also picks up semicolons. `every
tend-*.yaml job but relay, append-gist, both create-issue-on-*-failure
jobs` reads as one four-item exclusion list, which would say
`append-gist` doesn't read the token — it does.

> _This was written by Claude Code on behalf of max-sixty_

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-07 15:40:49 -07:00
dependabot[bot] 02a8dc829c chore: bump taiki-e/install-action from 2.85.7 to 2.85.8 (#3758)
Bumps
[taiki-e/install-action](https://github.com/taiki-e/install-action) from
2.85.7 to 2.85.8.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's
releases</a>.</em></p>
<blockquote>
<h2>2.85.8</h2>
<ul>
<li>
<p>Update <code>zizmor@latest</code> to 1.29.0.</p>
</li>
<li>
<p>Update <code>typos@latest</code> to 1.49.0.</p>
</li>
<li>
<p>Update <code>trivy@latest</code> to 0.73.0.</p>
</li>
<li>
<p>Update <code>tombi@latest</code> to 1.2.6.</p>
</li>
<li>
<p>Update <code>prek@latest</code> to 0.4.12.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.8.1.</p>
</li>
<li>
<p>Update <code>convco@latest</code> to 0.7.1.</p>
</li>
<li>
<p>Update <code>cargo-semver-checks@latest</code> to 0.50.0.</p>
</li>
<li>
<p>Update <code>cargo-crap@latest</code> to 0.4.1.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's
changelog</a>.</em></p>
<blockquote>
<h2>[2.85.8] - 2026-08-04</h2>
<ul>
<li>
<p>Update <code>zizmor@latest</code> to 1.29.0.</p>
</li>
<li>
<p>Update <code>typos@latest</code> to 1.49.0.</p>
</li>
<li>
<p>Update <code>trivy@latest</code> to 0.73.0.</p>
</li>
<li>
<p>Update <code>tombi@latest</code> to 1.2.6.</p>
</li>
<li>
<p>Update <code>prek@latest</code> to 0.4.12.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.8.1.</p>
</li>
<li>
<p>Update <code>convco@latest</code> to 0.7.1.</p>
</li>
<li>
<p>Update <code>cargo-semver-checks@latest</code> to 0.50.0.</p>
</li>
<li>
<p>Update <code>cargo-crap@latest</code> to 0.4.1.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/taiki-e/install-action/commit/cb33e69fad06166ca28a42b2575e4dadabf62ee8"><code>cb33e69</code></a>
Release 2.85.8</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/205431a517a990dfa58a0f22a02abd8cbef31c11"><code>205431a</code></a>
Update <code>zizmor@latest</code> to 1.29.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/e734f91b32f269a08deefc4ceb37d4aa4747a26b"><code>e734f91</code></a>
Update wild manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/2596ecb10ea03dec655fc75e41a3b0f4dad7bc42"><code>2596ecb</code></a>
Update <code>typos@latest</code> to 1.49.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/a44271eb2d867e7b1cf13602d4e4f0a93eec2f5e"><code>a44271e</code></a>
Update <code>trivy@latest</code> to 0.73.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/9b100e5f66ebcc3ef6c9e7380611a923118c93bd"><code>9b100e5</code></a>
Update <code>tombi@latest</code> to 1.2.6</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/f28498427840d9dc2242c579fe43460aad78fb48"><code>f284984</code></a>
Update <code>prek@latest</code> to 0.4.12</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/3b86746a2ded65050e00646b310ebba2a15bdaf6"><code>3b86746</code></a>
Update <code>mise@latest</code> to 2026.8.1</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/9287d185066eec8a77c1f11905ac9727db063430"><code>9287d18</code></a>
Update just manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/32702bef0f7f8c45b9b179686f51a0f2739378c3"><code>32702be</code></a>
Update <code>convco@latest</code> to 0.7.1</li>
<li>Additional commits viewable in <a
href="https://github.com/taiki-e/install-action/compare/v2.85.7...v2.85.8">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=taiki-e/install-action&package-manager=github_actions&previous-version=2.85.7&new-version=2.85.8)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-06 22:59:23 -07:00
Worktrunk Bot 6ad0439d79 chore: update tend workflows (0.1.13 → 0.1.14) (#3749)
Automated nightly regeneration of tend's workflow files.

**tend version:** 0.1.13 → 0.1.14

## Notable changes

- **Jobs now name the `tend` environment with `deployment: false`**
(max-sixty/tend#852), so GitHub stops filing a deployment record per run
and posting it on the pull request. This is what the current `tend
check` flags as `environment-deployments` (#3729) — regenerating clears
it, and max-sixty/tend#853 makes `check` refuse the old shape going
forward.
- **`id-token: write` dropped from every tend job** — a side effect of
removing the claude-smoke workflow and its `tend-manual` environment
(max-sixty/tend#820). None of the remaining jobs use OIDC, so the
permission was unused.
- **`tend-mention` counts bot engagement outside `jq`**
(max-sixty/tend#840). `gh api --paginate` applies `--jq` once per page,
so `| length` emitted one count per page; past 100 comments the shell
variable held `100\n7`, the numeric test errored, and the bot fell
through to `should_run=false` — going quiet on exactly its most-engaged
threads.
- **Review and triage skill fixes** — the review-record guards now
ignore synthetic reply containers (max-sixty/tend#835), `/code-review`
is ported into a tend-owned skill (max-sixty/tend#819), and triage
substitutes the real issue number into its PR-body templates instead of
leaving a placeholder (max-sixty/tend#844).
- **Outage reporting is more robust** — a stranded outage row now names
the trigger it points at (max-sixty/tend#823), and marking a
notification read tolerates a transient run-metadata fetch failure
(max-sixty/tend#843).

Full compare: https://github.com/max-sixty/tend/compare/0.1.13...0.1.14

Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com>
2026-08-06 22:59:21 -07:00
Maximilian Roos 59c7320a78 ci: read TEND_BOT_TOKEN from an environment in every job (#3748)
Closes worktrunk's half of the `tend` environment migration (tend's
`TODO.md`,
"Finish moving the operational secrets into the `tend` environment",
item 2).

The environment is a secret scope, not a deploy target: its deployment
branch
policy is what stops a workflow pushed to a feature branch from reading
the
bot's PAT. That gate closes only when the repo-level copy of the secret
is
gone, since a job naming an environment still reads repo-level secrets.
worktrunk kept one because these hand-maintained workflows read
`TEND_BOT_TOKEN` outside tend's generated set.

## What changed

| Job | Environment | Why that one |
|---|---|---|
| `benchmarks.yaml` `append-gist` (new) | `tend` | `schedule`-gated, so
it runs on `main` |
| `benchmarks.yaml` `create-issue-on-benchmark-failure` | `tend` |
already `schedule`-gated |
| `nightly.yaml` `create-issue-on-nightly-failure` | `tend` | already
`schedule`-gated |
| `release.yaml` `publish-winget` | `release` | runs on a `v*` tag push
|
| `release.yaml` `publish-homebrew` | `release` | runs on a `v*` tag
push |

Every job reading `TEND_BOT_TOKEN` now names an environment, so deleting
the
repo-level copy breaks nothing.

### The gist append moved into its own job

The `benchmarks` job has no `if` gate, so putting `tend` on it would
refuse a
`workflow_dispatch` against a non-`main` ref — on-demand runs against a
chosen
branch are what that trigger is documented for. A job GitHub skips never
requests its environment, so moving the append into a `schedule`-gated
`append-gist` job keeps the policy off the dispatch path entirely. It
reads
`target/criterion` back from the artifact the `benchmarks` job already
uploads.

`create-issue-on-benchmark-failure` now `needs` both jobs, so a failed
append
still files an issue — previously it failed the `benchmarks` job
directly.

### Why the release jobs get `release`, not `tend`

A tag push is not bot-steerable and tag creation and update are already
restricted to admins by the "Tag operations" ruleset, so a tag policy is
a
real boundary. The tag entry cannot go on `tend`: `tend check`'s
`check_environment` pins that policy to exactly the protected branches
and its
`--fix` deletes anything else. `release` already exists with a `v*` tag
policy
and already holds `AUR_SSH_PRIVATE_KEY`, so no new environment and no
new
credential — `TEND_BOT_TOKEN` is seeded into it as a second copy.

### `deployment: false`

Jobs naming `tend` use the mapping form. GitHub files a deployment
record for
every job that names an environment, against whatever ref the run
belongs to;
under `pull_request_target` that is the PR's own head, which is why PR
timelines grew a "worktrunk-bot deployed to tend" line on every push.
`deployment: false` drops the record and keeps the gate. The release
jobs keep
their records, which land in no PR timeline.

## Follow-up: one step, after merge

`TEND_BOT_TOKEN` is **already seeded into the `release` environment**
(read
from the local `worktrunk-bot` gh config dir at
`~/.config/gh-bots/worktrunk-bot`, so no new credential was minted and
nothing
was pasted). Verified: the token resolves to `worktrunk-bot` and has
push on
both `max-sixty/winget-pkgs` and `max-sixty/homebrew-worktrunk`.

That leaves one step, and it must come **after** this PR merges:

```
gh secret delete TEND_BOT_TOKEN --repo max-sixty/worktrunk
```

Not before. On `main` today the gist append, both
`create-issue-on-*-failure`
jobs, and the two publish jobs still read the token with no environment
named,
so deleting the repo-level copy first would break the next benchmarks
cron
(03:47 UTC daily). Merging this PR is what makes the deletion safe.

## What this does not fix

- `repo-secret-allowlist` still fails on `CLAUDE_CODE_OAUTH_TOKEN`, also
at
  repo level. It cannot be read back either; separate item.
- `environment-deployments` still fails on the generated `tend-*.yaml`,
which
  pin tend 0.1.13 and carry the bare `environment: tend`. Those are
regenerated by the published tend, and a regen also carries an unrelated
`gh api --paginate` fix in `tend-mention.yaml`, so it belongs in its own
PR.

## Verification

- The `append-gist` script was run end-to-end against a real
`benchmark-results-*` artifact from run 30976221483. It emits 40 rows
whose
`bench` names match the live gist's existing rows exactly, confirming
the
  artifact round-trip preserves paths relative to `target/criterion`.
- That a skipped `if` short-circuits the environment gate is confirmed
by run
31066000517: `publish-cargo`, which names `environment: release`,
completed
as *skipped* on a `pull_request` from a non-tag ref rather than failing
on
  the policy.
- `actionlint` reports the same eight pre-existing shellcheck notes as
`main`;
  no new findings. `pre-commit` passes.

> _This was written by Claude Code on behalf of max-sixty_
2026-08-06 02:58:00 -07:00
Maximilian Roos 970976bd32 Consolidate benchmark recipes and cases (#3721)
Benchmark fixtures had accumulated around individual call sites, leaving
the same repository shapes and command modes expressed several ways.
This change makes repository state the organizing concept: benchmark
groups select semantic `FixtureRecipe`s, share table-driven cases, and
retain separate fixtures only when a controlled contrast, destructive
precondition, or disproportionate setup cost requires one.

The real-repository list benchmarks now share one pinned
`rust-lang/rust` fixture with eight worktrees and fifty branches spread
across history. The list matrix keeps default, branch, warm, and cold
coverage without maintaining several “real” repository handles. Remove
and prune cases share the same case machinery, while the destructive
large-repository prune state remains separate.

The scheduled workflow now converts Criterion estimates directly with
`jq`, removing the one-off Python converter and its tests. The benchmark
guide records the canonical-fixture principle and the remaining
recipe-to-group mapping.

Tests: `cargo run -- hook pre-merge --yes` (4,551 tests); `cargo bench
--bench list large_repository -- --test`; `cargo test -p wt-perf`;
benchmark check, clippy, formatting, and diff checks.

> _This was written by Codex on behalf of max-sixty_.
2026-08-05 10:30:34 -07:00
dependabot[bot] 5a5f5795c9 chore: bump taiki-e/install-action from 2.85.5 to 2.85.7 (#3739)
Bumps
[taiki-e/install-action](https://github.com/taiki-e/install-action) from
2.85.5 to 2.85.7.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's
releases</a>.</em></p>
<blockquote>
<h2>2.85.7</h2>
<ul>
<li>
<p>Update <code>wasmtime@latest</code> to 47.0.3.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.12.1.</p>
</li>
<li>
<p>Update <code>rclone@latest</code> to 1.75.0.</p>
</li>
<li>
<p>Update <code>kingfisher@latest</code> to 1.110.0.</p>
</li>
</ul>
<h2>2.85.6</h2>
<ul>
<li>
<p>Update <code>wasm-tools@latest</code> to 1.255.0.</p>
</li>
<li>
<p>Update <code>tombi@latest</code> to 1.2.5.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.18.</p>
</li>
<li>
<p>Update <code>cargo-neat@latest</code> to 0.5.3.</p>
</li>
<li>
<p>Update <code>cargo-crap@latest</code> to 0.4.0.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's
changelog</a>.</em></p>
<blockquote>
<h2>[2.85.7] - 2026-08-02</h2>
<ul>
<li>
<p>Update <code>wasmtime@latest</code> to 47.0.3.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.12.1.</p>
</li>
<li>
<p>Update <code>rclone@latest</code> to 1.75.0.</p>
</li>
<li>
<p>Update <code>kingfisher@latest</code> to 1.110.0.</p>
</li>
</ul>
<h2>[2.85.6] - 2026-08-01</h2>
<ul>
<li>
<p>Update <code>wasm-tools@latest</code> to 1.255.0.</p>
</li>
<li>
<p>Update <code>tombi@latest</code> to 1.2.5.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.18.</p>
</li>
<li>
<p>Update <code>cargo-neat@latest</code> to 0.5.3.</p>
</li>
<li>
<p>Update <code>cargo-crap@latest</code> to 0.4.0.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/taiki-e/install-action/commit/67729d5c413db75907f0ad1e39bb04b9c868ff60"><code>67729d5</code></a>
Release 2.85.7</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/d247d7efe4dd236c2b4dee4c768ae8993e3df073"><code>d247d7e</code></a>
Update wasmtime manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/9197a82bb72ccea72eb87ca9bcf8dfeebceecb4a"><code>9197a82</code></a>
Update zizmor manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/68f6cd570d5902077df155f8ef44867ad5f57fe7"><code>68f6cd5</code></a>
Update <code>wasmtime@latest</code> to 47.0.3</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/377ee3f6a005506fab9f724afd7eae3134bc1154"><code>377ee3f</code></a>
Update <code>uv@latest</code> to 0.12.1</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/8724fbfce1efccf3c603dcdece7882571347b0c7"><code>8724fbf</code></a>
Update <code>rclone@latest</code> to 1.75.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/8d0062e663b7476d094ab4bc20c4436abdefb289"><code>8d0062e</code></a>
Update mise manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/28977a596b3205a34299d9607ece4eed2c6932eb"><code>28977a5</code></a>
Update <code>kingfisher@latest</code> to 1.110.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/b951679bfc703a3cdad770a495203180e58aeb3d"><code>b951679</code></a>
Update cargo-semver-checks manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/1beb33eee6d086258184383af9a538940be190ed"><code>1beb33e</code></a>
Release 2.85.6</li>
<li>Additional commits viewable in <a
href="https://github.com/taiki-e/install-action/compare/v2.85.5...v2.85.7">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=taiki-e/install-action&package-manager=github_actions&previous-version=2.85.5&new-version=2.85.7)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-05 09:11:22 -07:00
dependabot[bot] ecde50eabe chore: bump taiki-e/install-action from 2.85.4 to 2.85.5 (#3716)
Bumps
[taiki-e/install-action](https://github.com/taiki-e/install-action) from
2.85.4 to 2.85.5.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's
releases</a>.</em></p>
<blockquote>
<h2>2.85.5</h2>
<ul>
<li>
<p>Update <code>uv@latest</code> to 0.12.0.</p>
</li>
<li>
<p>Update <code>syft@latest</code> to 1.50.0.</p>
</li>
<li>
<p>Update <code>sccache@latest</code> to 0.17.0.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.16.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's
changelog</a>.</em></p>
<blockquote>
<h2>[2.85.5] - 2026-07-30</h2>
<ul>
<li>
<p>Update <code>uv@latest</code> to 0.12.0.</p>
</li>
<li>
<p>Update <code>syft@latest</code> to 1.50.0.</p>
</li>
<li>
<p>Update <code>sccache@latest</code> to 0.17.0.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.16.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/taiki-e/install-action/commit/6a1bd70eaac3c8bdf093356838d7ee09fda951cf"><code>6a1bd70</code></a>
Release 2.85.5</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/e55bdcf1dbf7a2b65f2a51365635e9b42fc25b1b"><code>e55bdcf</code></a>
Update <code>uv@latest</code> to 0.12.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/360695b5ac7cbf7052eb841633b06cd5e5cf73cd"><code>360695b</code></a>
Update <code>syft@latest</code> to 1.50.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/9dfbbc2988d91169e4279461e8b23ade4a670b52"><code>9dfbbc2</code></a>
Update <code>sccache@latest</code> to 0.17.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/acc58332f7353bf8d3e368d3838b46513a4a90cb"><code>acc5833</code></a>
Update <code>mise@latest</code> to 2026.7.16</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/deaa28d948b4684cf00f14feb5a9267ae3792577"><code>deaa28d</code></a>
Update cargo-neat manifest</li>
<li>See full diff in <a
href="https://github.com/taiki-e/install-action/compare/v2.85.4...v2.85.5">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=taiki-e/install-action&package-manager=github_actions&previous-version=2.85.4&new-version=2.85.5)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-03 13:36:10 -07:00
Maximilian Roos 1acfbeb7f4 chore: regenerate tend workflows with 0.1.13 (#3720)
Regenerates the `tend-*.yaml` workflows against [tend
0.1.13](https://github.com/max-sixty/tend/releases/tag/0.1.13).
Generated output only — no hand edits.

The change that matters is that every workflow now names `environment:
tend`, so the bot token and the model credential can live in a
deployment environment gated to `main` instead of as repo-level secrets,
which any workflow on any branch can read. `tend-mention` gains a
secretless `relay` job to go with it: a review or review-comment event
runs on `refs/pull/N/merge`, a ref no deployment-branch policy can
admit, so `relay` holds no secrets and re-posts only identifiers as a
`repository_dispatch`, which `verify` then re-reads from the API.

Merging this on its own changes nothing operationally. The `tend`
environment already exists on this repo with `TEND_BOT_TOKEN` in it, and
a job naming an environment can still read repo-level secrets, so the
gate closes only when the repo-level copies are deleted — a follow-up
once the model credential is in the environment too.

> _This was written by Claude Code on behalf of max-sixty_
2026-08-02 23:15:05 -07:00
Maximilian Roos dd453304ed test: fold the mock stub into the wt binary (#3712)
`cargo test --test integration` neither built nor rebuilt `mock-stub`: a
target filter deselects the dummy test that pulled it in, so a fresh
tree panicked ("mock-stub binary not found") and a warm one could run a
stale stub. The chain that compensated — the separate helper package,
its dummy `builds.rs`, the `default-members` entry, nextest's
experimental `build-bins` setup script, `workspace_bin()` — existed only
because cargo-dist ships every `[[bin]]`, and carried a TODO to collapse
once that changed. dist 0.30.2 does support per-binary exclusion now
(`[dist.binaries]`, since 0.29.0; verified with `dist plan`), but the
TODO's plan has a hole it predates: `cargo install worktrunk` installs
every feature-satisfied `[[bin]]`, and dist config doesn't govern
crates.io installs.

So the mock commands are now the `wt` binary itself. `mock_commands`
links `wt` under the mock's name (`gh`, `glab`, …), and `main()`
dispatches to the ported playback (`testing::mock_stub`) when
`WORKTRUNK_TEST_MOCK_CONFIG_DIR` is set, argv[0] is a foreign name, and
the config dir holds `<argv0>.json` for it. The existence check keeps wt
under a foreign argv[0] *without* a config being wt — the
argv0-validation security test symlinks it as `wt;touch` and must reach
wt's own rejection. The shipped binary already compiles the whole
`testing` module unconditionally, so this adds no new category of test
code to it. Windows links `wt.exe` with `hard_link` (copy fallback for
cross-drive dirs); the debug binary is ~67 MB, so per-mock copies stay
the fallback.

Every runner is now safe by construction — cargo rebuilds a package's
own binaries whenever its integration tests build, so there is no
separate artifact to go missing or stale. Deleted: the helper package,
the setup script plus `experimental = ["setup-scripts"]`, the
`default-members` trick, `workspace_bin()`, and `wt_bin()`'s dead
compile-time branch (unit-test targets get neither the runtime variable
nor the `option_env!` value, so the runtime resolution is the one
mechanism).

Validated locally: the pre-merge gate's full suite passes (4542/4542;
its doc step also caught unescaped `argv[0]` intra-doc links in the new
comments, fixed and `cargo doc -Dwarnings` re-verified). With all stub
artifacts purged from `target/`, plain `cargo test --test integration`
on mock-dependent tests builds them and passes — the command that used
to hit the trap. Two integration tests pin the dispatch's argv[0] edges
(an empty argv[0], and a non-UTF8 one), alongside the existing
`wt;touch` carve-out test.

The first commit is the investigation that preceded the fix: it verified
the `wt` binary itself was never subject to the staleness the mock-stub
was, and documented that in `tests/CLAUDE.md`; the fix then narrows that
paragraph further, since the gap it scoped no longer exists.

A two-reviewer subagent round (one prosecuting the diff against the
failure modes documented in the repo's own mock history — the #401/#407
Windows era, #547, #654, #127, #2544, #2730, #2744 — the other
adversarial) then hardened the dispatch. The reserved-name guard is
case-insensitive, matching the config probe, which goes through a
filesystem that equates `WT.json` with `wt.json` on macOS and Windows;
`command_name()` reads `args_os` — `env::args()` panics on a non-Unicode
argument, and this runs inside `main()` on every invocation (caught by
the tend review) — and returns `None` for a degenerate argv[0] instead
of panicking; the `.exe` suffix is stripped explicitly rather than via
`file_stem`, so a dotted mock name (`python3.11`) resolves identically
on every platform; and `copy_mock_binary` is now private —
`MockConfig::write` writes `<name>.json` before linking and is the only
way to create a mock, so a link cannot exist without its config, and the
dispatch's missing-config fall-through can only mean "wt under a foreign
name" (the argv0-validation tests' `wt;touch`), never a half-configured
mock that silently runs real wt with the mocked tool's arguments. The
`Option<&str>` mock helpers whose `None` arm produced exactly such
configless links lost the arm (every caller passed `Some`), and 25
redundant standalone link calls went with it.

The review also surfaced the one remaining spawn-a-stale-binary path
outside the suite: `wt-perf timeline` resolved a sibling `wt` by path,
checked only existence, and told the user to build it manually — so
`cargo run -p wt-perf -- timeline` after a `src/` edit silently measured
stale code. It now builds `wt` first and takes the artifact path from
cargo's `--message-format=json` report rather than deriving a sibling
location, so target-dir and profile overrides can't divert the build
away from where it's resolved; a release wt-perf builds and measures a
release wt. The build runs before the timeline's wall-clock measurement
starts, cargo's progress streams on stderr, and stdout keeps the
`--chrome` JSON contract.

> _This was written by Claude Code on behalf of max-sixty_

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-02 22:12:21 -07:00
Maximilian Roos 3c2b4e44bb docs(ci): widen the TEND_BOT_TOKEN row past the Claude workflows (#3711)
`WINGET_TOKEN` sat in the `release` environment with no reference
anywhere in the repo. Its last use was removed in December 2025; the
February 2026 environment migration carried it across anyway.
`publish-winget` also declares no `environment:`, so it could not have
read a `release`-scoped secret even if the workflow still named it.

What actually publishes to winget is `TEND_BOT_TOKEN`: as `GH_TOKEN` for
the fork-sync step, and as the `token:` input to
`vedantmgoyal9/winget-releaser`. Submission to `microsoft/winget-pkgs`
is a plain fork-and-PR — there is no separate winget publisher
credential — and the v0.71.0 PR there was opened by `worktrunk-bot`, the
account that token belongs to.

The secret is deleted. This commit closes the documentation gap that
made it look load-bearing: the Tokens table described `TEND_BOT_TOKEN`
as covering "All Claude workflows", which left winget publishing with no
credential named anywhere.

> _This was written by Claude Code on behalf of max-sixty_

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-02 12:14:01 -07:00
Worktrunk Bot 1db305f32f ci: bump pinned cargo-affected 0.4.0 and worktrunk 0.71.0 (#3708)
## Summary

Weekly CI pin check found the following drift (these `version:` strings
are invisible to Dependabot — it follows `Cargo.toml` deps and `uses:
foo@vN` refs, not inline pins):

- `cargo-affected`: 0.3.2 → 0.4.0 (MSRV 1.94, compatible with our 1.96)
— pinned twice in `affected.yaml` (`collect-affected` +
`affected-tests`); both moved together.
- `worktrunk`: 0.69.2 → 0.71.0 (MSRV 1.96, compatible with our 1.96) —
the CI-installed `wt`, bumped to the current release; pinned in
`ci.yaml` (×2) and `nightly.yaml`.

## Already up to date

- `cargo-insta`: 1.48.0, `cargo-nextest`: 0.9.140, `cargo-llvm-cov`:
0.8.7, `cargo-msrv`: 0.19.3, `cargo-udeps`: 0.1.61, `lychee`: 0.24.2
- `hustcer/setup-nu` (nushell): 0.114.1
- `zola`: 0.22.1 (taiki-e/install-action)
- Runner images: ubuntu-24.04, macos-15, windows-2022

## Notes

- windows-2022 stays pinned (actions/runner-images#12677 — windows-2025
lacks the D: drive).
- Both bumped tools' latest MSRVs are ≤ 1.96, so they stay compatible
with the current toolchain.
- **cargo-affected 0.4.0 DB compatibility:** the
`cargo-affected-db-v1-*` cache marker in `affected.yaml` does **not**
need bumping. The v0.3.2→v0.4.0 diff (`perf(collect): export each
binary's coverage map once`, `Make status predict what run does`)
touches `src/db.rs` only with `pub` → `pub(crate)` visibility changes —
no SQLite schema change to the `fingerprint_components` / coverage
tables — so an existing main DB deserializes unchanged.

Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com>
2026-08-02 09:30:13 -07:00
Maximilian Roos aa988b37bb ci(release): scope SIGNPATH_API_TOKEN to a dedicated signing environment (#3704)
`SIGNPATH_API_TOKEN` sits at repo level, where every workflow the repo
runs can read it. It is referenced once, by the "Submit SignPath signing
request" step in `build-local-artifacts`. This joins that job to a new
`signing` environment so the token can be held there instead.

The environment already exists, with a `v*` tag policy and no reviewer
rule. It holds no secret yet, and this PR is safe to merge before it
does: an environment secret *overrides* a repository one of the same
name rather than displacing access to it, so until `signing` holds a
token the job keeps reading the repo-level copy and signing behaves
exactly as it does today.

Two steps remain, and both need the token value, which is write-only and
so has to be set by hand — or re-issued from the SignPath console, which
rotates it at the same time:

```
gh secret set SIGNPATH_API_TOKEN --repo max-sixty/worktrunk --env signing
```

```
gh secret delete SIGNPATH_API_TOKEN --repo max-sixty/worktrunk
```

The delete is what clears the drift, and it is the one step with an
ordering constraint: run it after the environment secret exists, or the
next release signs with an empty token.

## Why a new environment rather than the existing `release`

Reusing `release` looks cheaper, and the usual objection to it turns out
to be false: `release` has no reviewer rule, so it would not have pulled
an approval gate into the build phase. Its only protection rule is a
`v*` tag policy, which is why `publish-cargo` and `publish-aur` deploy
to it unattended today.

The real problem is the other direction. A job that joins an environment
can read *every* secret in it, and `release` holds
`AUR_SSH_PRIVATE_KEY`. Putting `build-local-artifacts` there would give
the build phase the AUR deploy key, so the change would trade one
over-broad grant for another rather than removing one. `signing` holds
the single token its single consumer needs.

Allowlisting the secret in `.config/tend.yaml` was the third option. It
records "intentionally repo-wide", which is the wrong posture for a
credential that becomes a real code-signing key once the SignPath OSS
application clears. It is a self-signed test certificate today, which is
the argument for moving it now rather than after.

<details><summary>Verification</summary>

`.github/CLAUDE.md` claimed the `release` environment required
"deployment approval from `@max-sixty`". That was the source of the
approval-gate objection, and it was wrong:

```
$ gh api repos/max-sixty/worktrunk/environments/release
"protection_rules": [{"id": 48355233, "type": "branch_policy"}]

$ gh api repos/max-sixty/worktrunk/environments/release/deployment-branch-policies
{"branch_policies": [{"name": "v*", "type": "tag"}]}
```

No `required_reviewers` rule. The v0.71.0 deployment confirms it
behaviorally — `waiting` to `queued` in one second, with no approval in
between:

```
$ gh api repos/max-sixty/worktrunk/deployments/5682057674/statuses
success      2026-07-30T20:46:46Z
in_progress  2026-07-30T20:45:00Z
queued       2026-07-30T20:44:57Z
waiting      2026-07-30T20:44:56Z
```

That doc line is rewritten here, into a table of which environment holds
what and which job reads it.

Three other things worth confirming before touching a dist-generated
file:

- **Hand edits survive.** `dist-workspace.toml` sets `allow-dirty =
["ci"]`, and no job anywhere runs `dist generate --check`. The custom
`publish-cargo`, `publish-winget`, and `publish-aur` jobs already only
exist because of this.
- **The environment doesn't serialize the matrix.** `publish-cargo` and
`publish-aur` both target `release` and ran concurrently in the v0.71.0
release (started `20:44:58` and `20:44:59`), so the five matrix legs
won't queue behind each other.
- **tend only scans repo-level secrets.** `AUR_SSH_PRIVATE_KEY` and
`WINGET_TOKEN` sit in the `release` environment and `tend check` passes
them without complaint, so moving `SIGNPATH_API_TOKEN` to an environment
is what clears the check.

</details>

## Risk

Low. The repo-level token remains readable until it is deleted, so
signing is unaffected by the merge. Even with no token reachable at all,
the signing step is `continue-on-error: true` while the certificate is a
test one, so it would fail without blocking the crates.io, Homebrew,
winget, or AUR publishes — the one step that is deliberately not
`continue-on-error` just recomputes a checksum over whatever zip is in
place.

One coupling is now load-bearing and is noted in the workflow: the `v*`
tag policy means setting `pr-run-mode = "upload"` in
`dist-workspace.toml` would make GitHub reject this job on a PR ref.
Today `pr-run-mode` defaults to `plan`, so `build-local-artifacts` is
skipped on pull requests entirely — which also means this PR's own CI
does not exercise the change. The first real exercise is the next
release tag.

Ref #3572 — the issue closes once the repo-level secret is deleted.

> _This was written by Claude Code on behalf of max-sixty_

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-01 23:09:43 -07:00
dependabot[bot] 62cc0af7f8 chore: bump taiki-e/install-action from 2.85.3 to 2.85.4 (#3659)
Bumps
[taiki-e/install-action](https://github.com/taiki-e/install-action) from
2.85.3 to 2.85.4.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's
releases</a>.</em></p>
<blockquote>
<h2>2.85.4</h2>
<ul>
<li>
<p>Update <code>uv@latest</code> to 0.11.33.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.15.</p>
</li>
<li>
<p>Update <code>biome@latest</code> to 2.5.6.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's
changelog</a>.</em></p>
<blockquote>
<h2>[2.85.4] - 2026-07-29</h2>
<ul>
<li>
<p>Update <code>uv@latest</code> to 0.11.33.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.15.</p>
</li>
<li>
<p>Update <code>biome@latest</code> to 2.5.6.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/taiki-e/install-action/commit/065d6a08a14e61e89fb0a4c10eecdbdef39c7d8e"><code>065d6a0</code></a>
Release 2.85.4</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/971197ad86f8f6f161d7a8d91f1d711c4c21f628"><code>971197a</code></a>
Update <code>uv@latest</code> to 0.11.33</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/3fc72354cdfd0f85327736793faab9b90a6282bb"><code>3fc7235</code></a>
Update syft manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/7e230c19cf947f65a34e4e6f737c5f594c6779ba"><code>7e230c1</code></a>
Update sccache manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/51f77e860854ede202e22ff29a94094601feca62"><code>51f77e8</code></a>
Update <code>mise@latest</code> to 2026.7.15</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/87ddca437422cbc964934ac7b2d8423c1838090a"><code>87ddca4</code></a>
Update <code>biome@latest</code> to 2.5.6</li>
<li>See full diff in <a
href="https://github.com/taiki-e/install-action/compare/v2.85.3...v2.85.4">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=taiki-e/install-action&package-manager=github_actions&previous-version=2.85.3&new-version=2.85.4)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-30 10:15:39 -07:00
dependabot[bot] f1923e9344 chore: bump taiki-e/install-action from 2.85.2 to 2.85.3 (#3649)
Bumps
[taiki-e/install-action](https://github.com/taiki-e/install-action) from
2.85.2 to 2.85.3.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's
releases</a>.</em></p>
<blockquote>
<h2>2.85.3</h2>
<ul>
<li>
<p>Update <code>xh@latest</code> to 0.26.2.</p>
</li>
<li>
<p>Update <code>ubi@latest</code> to 0.10.0.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.14.</p>
</li>
<li>
<p>Update <code>martin@latest</code> to 1.13.0.</p>
</li>
<li>
<p>Update <code>cargo-shear@latest</code> to 1.13.3.</p>
</li>
<li>
<p>Update <code>cargo-binstall@latest</code> to 1.21.1.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's
changelog</a>.</em></p>
<blockquote>
<h2>[2.85.3] - 2026-07-28</h2>
<ul>
<li>
<p>Update <code>xh@latest</code> to 0.26.2.</p>
</li>
<li>
<p>Update <code>ubi@latest</code> to 0.10.0.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.14.</p>
</li>
<li>
<p>Update <code>martin@latest</code> to 1.13.0.</p>
</li>
<li>
<p>Update <code>cargo-shear@latest</code> to 1.13.3.</p>
</li>
<li>
<p>Update <code>cargo-binstall@latest</code> to 1.21.1.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/taiki-e/install-action/commit/18b1216eba7f8039b0f8d131d5473787f0edce68"><code>18b1216</code></a>
Release 2.85.3</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/3a7eb9d7de04335647f871d88d8831485be842be"><code>3a7eb9d</code></a>
Update <code>xh@latest</code> to 0.26.2</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/3d4a0c1c709bc0f907c2a23b1a17cf6296b08298"><code>3d4a0c1</code></a>
Update uv manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/9e4a53cd83bbbd84b17bc14008d4b067b9e99edb"><code>9e4a53c</code></a>
Update <code>ubi@latest</code> to 0.10.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/9f2f6a3c937466e1abfae58f471a04b8835bc6de"><code>9f2f6a3</code></a>
Update <code>mise@latest</code> to 2026.7.14</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/e026bd26eeb6a9542c62d43e1f98ced8d56ac346"><code>e026bd2</code></a>
Update <code>martin@latest</code> to 1.13.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/f72efa0e99d8d9c15bf7fa6f14f0d4eb369fd084"><code>f72efa0</code></a>
Update <code>cargo-shear@latest</code> to 1.13.3</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/d19664f75e59dd9c49e306b357f78fcb72cd2711"><code>d19664f</code></a>
Update <code>cargo-binstall@latest</code> to 1.21.1</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/4d9bbfb56af57e022493493eecb97d07bf4fddd5"><code>4d9bbfb</code></a>
Update biome manifest</li>
<li>See full diff in <a
href="https://github.com/taiki-e/install-action/compare/v2.85.2...v2.85.3">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=taiki-e/install-action&package-manager=github_actions&previous-version=2.85.2&new-version=2.85.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-29 20:04:34 -07:00
Maximilian Roos 1b35950a9c test: simplify the integration suite (#3657)
This reduces duplicated and false-confidence integration coverage while
preserving the suite's semantic and user-facing contracts.

## What changed

- Replaces three overlapping list-layout suites with two representative
CLI integrations, leaving exhaustive geometry at the direct layout
layer.
- Groups Git error render variants into labeled family snapshots and
removes command-by-shell wrapper cross-products while retaining
shell-specific conformance and regression cases.
- Updates test-authoring guidance around boundary choice, minimal
contrasts, and PTY use, and runs local and CI coverage through Nextest
isolation.

## Results

- Test catalog: 4,642 to 4,562
- Snapshots: 1,193 to 1,131
- Warm all-feature runtime: 84.70s to 78.17-80.35s
- Full coverage: 97.32% of lines

## Testing

- `cargo run -- hook pre-merge --yes`
- `cargo llvm-cov nextest --features shell-integration-tests
--summary-only`

> _This was written by Claude Code on behalf of max_.
2026-07-29 18:54:19 -07:00
Maximilian Roos 062cf57d8e ci(affected): pin cargo-affected to the published 0.3.2 (#3634)
Both `Install cargo-affected` steps in `affected.yaml` installed from
git with no rev, so the tool version on any run was whatever had last
merged to cargo-affected's default branch. That cut both ways today: an
upstream regression made `cargo affected run` abort with `git diff
stdout was not valid UTF-8: invalid utf-8 sequence of 1 bytes from index
136455` on all three OSes, turning the advisory legs red repo-wide, and
the fix (cargo-affected #69) then arrived the same way. Neither change
is visible in this repo's history.

cargo-affected publishes to crates.io as of 0.3.1, so it can carry a
`version: "=X.Y.Z"` pin like every other `baptiste0928/cargo-install`
block here. `=0.3.2` is what the unpinned installs already resolve to,
so nothing changes behaviorally today.

Two things it buys:

- The crate joins the weekly tend pin sweep, which reads `version:`
strings and now covers `affected.yaml`. The `cargo-install` action's own
drift annotation starts firing for it too.
- The existing "bump the `db-v{N}` cache marker if cargo-affected ships
an on-disk schema change" rule becomes enforceable. It was unfollowable
against a floating version, since the schema could change with no diff
to notice.

The pin appears twice, once per job, which is a new way to be wrong. A
drift between the two hits `migrate_legacy_tables`, which drops and
rebuilds the coverage tables rather than erroring, so selection silently
degrades while the advisory job stays green. That is recorded in the
workflow's cache-contract comment and in the tend skill's bump list.

`cargo-affected`'s `rust-version` is 1.94, against this repo's pinned
1.96.0 toolchain.

## Testing

The `affected tests (…, advisory)` legs on this PR exercise the change
directly: they resolve `=0.3.2` from crates.io rather than from git.

> _This was written by Claude Code on behalf of max_

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-07-28 13:11:00 -07:00
dependabot[bot] e6ca358846 chore: bump clechasseur/rs-cargo from 5.0.6 to 5.0.7 (#3624)
Bumps [clechasseur/rs-cargo](https://github.com/clechasseur/rs-cargo)
from 5.0.6 to 5.0.7.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/clechasseur/rs-cargo/releases">clechasseur/rs-cargo's
releases</a>.</em></p>
<blockquote>
<h2>v5.0.7</h2>
<p>Patch release with updates to vulnerable dependencies.</p>
<h2>What's Changed</h2>
<ul>
<li>chore(deps): bump fast-xml-parser from 5.9.3 to 5.10.1 in the
npm_and_yarn group across 1 directory by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/clechasseur/rs-cargo/pull/427">clechasseur/rs-cargo#427</a></li>
<li>fix: update <code>@clechasseur/rs-actions-core</code> to 8.0.3, run
<code>npm update</code> to get vulnerability fixes by <a
href="https://github.com/clechasseur"><code>@​clechasseur</code></a> in
<a
href="https://redirect.github.com/clechasseur/rs-cargo/pull/429">clechasseur/rs-cargo#429</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/clechasseur/rs-cargo/compare/v5.0.6...v5.0.7">https://github.com/clechasseur/rs-cargo/compare/v5.0.6...v5.0.7</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/clechasseur/rs-cargo/commit/8ccb6817fc46c9af3b058a5a7b31932edb82cf13"><code>8ccb681</code></a>
Merge pull request <a
href="https://redirect.github.com/clechasseur/rs-cargo/issues/429">#429</a>
from clechasseur/fix/update-deps</li>
<li><a
href="https://github.com/clechasseur/rs-cargo/commit/a11eddeaaecf8997cf0bcc3c24becc1f09624173"><code>a11edde</code></a>
fix: bump version to 5.0.7</li>
<li><a
href="https://github.com/clechasseur/rs-cargo/commit/76685bb9f52e212a4c00f3ddc44842dc5281ca3d"><code>76685bb</code></a>
fix: <code>npm update</code></li>
<li><a
href="https://github.com/clechasseur/rs-cargo/commit/48ea33b367c4c1b8b6fe7fefc203bce3d4e7158a"><code>48ea33b</code></a>
fix: update <code>@clechasseur/rs-actions-core</code> to 8.0.3</li>
<li><a
href="https://github.com/clechasseur/rs-cargo/commit/b5a8184fad32ef9f11f0e29418d46300fa1a1986"><code>b5a8184</code></a>
chore(deps): bump fast-xml-parser (<a
href="https://redirect.github.com/clechasseur/rs-cargo/issues/427">#427</a>)</li>
<li><a
href="https://github.com/clechasseur/rs-cargo/commit/5b3bb18517d1d95a02ac4aa47ff2a192c63da94a"><code>5b3bb18</code></a>
chore(deps): update dependency prettier to ^3.9.6 (<a
href="https://redirect.github.com/clechasseur/rs-cargo/issues/422">#422</a>)</li>
<li><a
href="https://github.com/clechasseur/rs-cargo/commit/95bd32da1610f3c33ea573b0248b59d5416eefee"><code>95bd32d</code></a>
chore(deps): update dependency oxlint to ^1.74.0 (<a
href="https://redirect.github.com/clechasseur/rs-cargo/issues/420">#420</a>)</li>
<li><a
href="https://github.com/clechasseur/rs-cargo/commit/de86f7e954c523dbb840a840196e75d2b3f5a56c"><code>de86f7e</code></a>
chore(deps): update actions-rust-lang/setup-rust-toolchain action to
v1.17.0 ...</li>
<li><a
href="https://github.com/clechasseur/rs-cargo/commit/24b0f4bdb30da53e2b0bd096f5936f516c683c38"><code>24b0f4b</code></a>
chore(deps): update dependency <code>@​types/node</code> to ^24.13.3 (<a
href="https://redirect.github.com/clechasseur/rs-cargo/issues/423">#423</a>)</li>
<li><a
href="https://github.com/clechasseur/rs-cargo/commit/3ad8301e71b20505890be273a34f0840a9f7701b"><code>3ad8301</code></a>
chore(deps): update actions/setup-node action to v7 (<a
href="https://redirect.github.com/clechasseur/rs-cargo/issues/426">#426</a>)</li>
<li>See full diff in <a
href="https://github.com/clechasseur/rs-cargo/compare/v5.0.6...v5.0.7">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=clechasseur/rs-cargo&package-manager=github_actions&previous-version=5.0.6&new-version=5.0.7)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-26 21:25:46 -07:00
dependabot[bot] 8ef63150b6 chore: bump taiki-e/install-action from 2.85.0 to 2.85.2 (#3623)
Bumps
[taiki-e/install-action](https://github.com/taiki-e/install-action) from
2.85.0 to 2.85.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's
releases</a>.</em></p>
<blockquote>
<h2>2.85.2</h2>
<ul>
<li>
<p>Update <code>prek@latest</code> to 0.4.11.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.13.</p>
</li>
<li>
<p>Update <code>kingfisher@latest</code> to 1.109.0.</p>
</li>
</ul>
<h2>2.85.1</h2>
<ul>
<li>
<p>Update <code>vacuum@latest</code> to 0.30.0.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.11.32.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.12.</p>
</li>
<li>
<p>Update <code>cyclonedx@latest</code> to 0.33.1.</p>
</li>
<li>
<p>Update <code>cargo-neat@latest</code> to 0.5.2.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's
changelog</a>.</em></p>
<blockquote>
<h2>[2.85.2] - 2026-07-26</h2>
<ul>
<li>
<p>Update <code>prek@latest</code> to 0.4.11.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.13.</p>
</li>
<li>
<p>Update <code>kingfisher@latest</code> to 1.109.0.</p>
</li>
</ul>
<h2>[2.85.1] - 2026-07-25</h2>
<ul>
<li>
<p>Update <code>vacuum@latest</code> to 0.30.0.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.11.32.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.12.</p>
</li>
<li>
<p>Update <code>cyclonedx@latest</code> to 0.33.1.</p>
</li>
<li>
<p>Update <code>cargo-neat@latest</code> to 0.5.2.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/taiki-e/install-action/commit/41049aa56687c35e0afa74eed4f09cec4f9afabf"><code>41049aa</code></a>
Release 2.85.2</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/dfcf36552b1b743e910b9b9b6b114a08e56a1e5e"><code>dfcf365</code></a>
Update <code>prek@latest</code> to 0.4.11</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/eea03ccfa855b965a301aa52424915fddc32f855"><code>eea03cc</code></a>
Update <code>mise@latest</code> to 2026.7.13</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/81ca2feb84748ed3fa514707ee1004f4f3ad715a"><code>81ca2fe</code></a>
Update martin manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/cc90ed04bc1a258ea90a83789f24b759a77c9671"><code>cc90ed0</code></a>
Update <code>kingfisher@latest</code> to 1.109.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/55639a3362f508fda5154d3451072205f5c32ca6"><code>55639a3</code></a>
Update cargo-shear manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/3d7d7cd5ac7f994c1892ae0c06165095b9139094"><code>3d7d7cd</code></a>
Release 2.85.1</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/d09ccb4fe2105ac9ead6376f7a423ff88defeb57"><code>d09ccb4</code></a>
Update <code>vacuum@latest</code> to 0.30.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/ac43dee1a92e482c0e244bdb0bb126908159e245"><code>ac43dee</code></a>
Update <code>uv@latest</code> to 0.11.32</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/49b16979f38f30e44b1f68af9115be9a6ffc5215"><code>49b1697</code></a>
Update prek manifest</li>
<li>Additional commits viewable in <a
href="https://github.com/taiki-e/install-action/compare/v2.85.0...v2.85.2">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=taiki-e/install-action&package-manager=github_actions&previous-version=2.85.0&new-version=2.85.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-26 20:49:12 -07:00
Maximilian Roos 4202cffe61 fix(ci): split ci by cadence so coverage uploads on every main commit (#3608)
## What prompted this

Getting #3605 green ran into codecov reporting a `base_commit` three
commits
older than the real merge-base. This audits whether our config causes
that.

## The cause

Codecov picks a PR's base by walking back to the newest ancestor that
has a
coverage report. It used the real merge-base for PRs #3480, #3532 and
#3602,
and a stale one for #3603 and #3605. The difference is whether the
merge-base
uploaded a report. **29 of the last 40 main commits did not.**

`ci` had one concurrency group for main pushes, and GitHub cancels the
*pending* run in a group whenever a newer one joins, even with
`cancel-in-progress: false`. So the question is how long a run holds the
group,
and a run isn't done until its slowest job is:

| job | duration on main |
|-----|------------------|
| `fast-checks` | 2 min |
| `code-coverage` | 3-4 min |
| `test (windows)` | 11 min |
| `collect affected coverage (windows)` | 110-129 min |

Each main run held the group for ~2 hours, so nearly every subsequent
main push
was cancelled while queued, taking the 4-minute coverage job with it.
Every
cancelled main run's `updated_at` lands within a second of the next
push's
`created_at`.

The 2 hours is real work, not queue: 2-5s from `created_at` to
`started_at`,
then 108 minutes inside `cargo affected collect` — 4181 tests under
`-C instrument-coverage` with a per-test LLVM profile, ~5 GB of profraw.

## The fix: one workflow per cadence

The three groups of jobs have incompatible needs, and one group was
serving all
of them.

| workflow | cadence on main | why |
|----------|-----------------|-----|
| `ci` | every commit, ~11 min | required gate + fast checks |
| `coverage` | every commit, keyed per-sha | a skipped upload leaves
later PRs on a stale base |
| `affected` | sampled, ~2 h | a DB a few commits old still anchors a
correct superset |

`affected` keeps exactly the grouping it has today, so its sampling is
unchanged and deliberate. It just no longer drags the other two along.

### Scope of the impact

The posted `codecov/patch` check scopes to the PR's own GitHub diff, so
a stale
base did **not** score PRs against other people's lines. On #3605 the
posted
91.66% is exactly `github.rs`'s 11/12, while the stale-base compare
object
reported 64/65 across 13 files. What a stale base costs:

- `codecov/project` reports "compared to \<stale sha\>"
- the patch `auto` target is the stale base's project coverage (0.02pp
here)
- the compare API object widens to `base..head`, which is what made the
  investigation look like silence

Separately, `test`/`lint`/`fast-checks` also stopped completing on main.
Nothing
load-bearing rode on that (they already ran on the PR), but it left
`tend-ci-fix` with nothing to watch, since it doesn't fire on cancelled
runs.

## Two smaller fixes

- `ignore: "**/tests/**"` compiles to `.*/tests/.*` (confirmed against
codecov's validator), which needs a leading directory and so never
matched
`tests/` itself. Inert today since `cargo llvm-cov` reports only `src/`
(verified against a downloaded `cobertura.xml`), but now correct if that
  changes. Now `tests/**`.
- `fail_ci_if_error` gated on `github.repository_owner`, which is the
*base*
repo's owner on a fork PR too, so the soft-fail its comment describes
never
  applied. It keys off the head repo now.

## Docs

The API behaviour was ours to misuse, not codecov's to explain. Three
traps,
all confirmed against the live API:

- `file_report/<path>/` 404s with `coverage info not found` because the
route
swallows the trailing slash into the path. Without it the endpoint
returns
  `line_coverage`.
- `?pullid=N` always compares the PR's **current** head. `?base=&head=`
asks
  about an earlier commit.
- the compare response has no `patch_totals` key, and `.name` is
`{base, head}` rather than a string, so a filename lookup silently
matches
  nothing.

A working recipe already existed in `running-tend`, but that skill is
scoped to
CI. `tests/CLAUDE.md` owns coverage investigation, so the queries go
there and
`running-tend` points at them instead of keeping a second copy.

Re-running the corrected query against #3605's failing commit reproduces
the
miss exactly: `src/git/remote_ref/github.rs:164`, the `gh repo
set-default`
hint, matching what the session eventually found by hand.

## This PR demonstrates it

It changes no Rust at all, only YAML and markdown. Codecov still
reported a
**10-file, 111-line patch** on its first commit, because it based the
comparison on `203603909` rather than the real merge-base `32f380a27`.
Every
main commit in between has no report:

| commit | ci run | report |
|--------|--------|--------|
| `32f380a27` | queued | no |
| `9645e3e13` | cancelled | no |
| `bcd1ffdfd` | cancelled | no |
| `8865f20ab` | cancelled | no |

Every one of those 111 patch lines belongs to somebody else's merged
commit. It
passed at 100% only because those commits are well covered.

> _This was written by Claude Code on behalf of @max-sixty_

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com>
2026-07-26 20:19:15 -07:00
Worktrunk Bot 901b79ab52 ci: bump pinned worktrunk to 0.69.2 (#3612)
Weekly CI pin bump. Only `worktrunk` drifted since last week — every
other `baptiste0928/cargo-install` pin (cargo-msrv `0.19.3`,
cargo-llvm-cov `0.8.7`, cargo-insta `1.48.0`, cargo-nextest `0.9.140`,
cargo-udeps `0.1.61`, lychee `0.24.2`), plus `setup-nu` `0.114.1` and
`zola@0.22.1`, is already at the latest upstream release.

- **worktrunk** `=0.68.0` → `=0.69.2` (3 sites: `ci.yaml` ×2,
`nightly.yaml`)

Compatibility: worktrunk `0.69.2` declares `rust-version = 1.96`,
matching the pinned toolchain (`rust-toolchain.toml` channel `1.96.0`),
so it builds under `baptiste0928/cargo-install`.

MSRV/toolchain needed no bump this week: current stable is `1.97.1`, so
latest−1 is `1.96`, which is already what `Cargo.toml`,
`tests/helpers/wt-perf/Cargo.toml`, and `rust-toolchain.toml` pin.

Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com>
2026-07-26 04:51:25 -07:00
Maximilian Roos f1f1b50d85 docs(release): trim the signing archaeology now the path is proven (#3593)
Follow-up to #3590, now that v0.69.2 has shipped a signed Windows binary
— verified against the published asset rather than the logs:

```
git-wt.exe: certificate table 8480 bytes
wt.exe:     certificate table 8472 bytes
c4343fb5…1a43 *worktrunk-x86_64-pc-windows-msvc.zip   (published .sha256 matches)
```

Comments only; no behavior change.

The signing comments were written while the mechanism was still being
guessed at, so they carried the failed attempts — a ten-line account of
the zip-of-a-zip failure, a six-line account of the `…zip.zip`
collision. The path is proven and the workflow now verifies itself, so
what a reader needs is the current mechanism. Trimmed to that.

One thing added rather than removed. `Recompute checksum` sits between
two `continue-on-error` steps and looks like it should fold into the
replace step above it. It must not: the signing steps are tolerant
because publishing can't depend on a self-signed test certificate, while
a checksum that doesn't match the shipped zip has to fail the release.
That asymmetry is invisible in the YAML, so it's now stated — the next
person to simplify this shouldn't have to rediscover it.

> _This was written by Claude Code on behalf of max_
2026-07-25 03:22:07 -07:00
Maximilian Roos 5e03e2863c docs(changelog): document the v0.69.2 drift (#3592)
Eleven commits landed on `main` while #3590 sat in CI, so they ship in
v0.69.2 with no changelog entry. Most are user-facing, and three are
data-loss fixes — exactly the drift the release skill's step-12 check
exists to catch. The tag is held until this lands.

Entries added, most-impactful first:

- **#3589** — two ways shell integration deleted user data on a
substring guess: an rc line that only *quotes* the init command, and a
user's own `conf.d/wt.fish` deleted outright by `install`'s legacy
cleanup. Plus forge detection moving from `host.contains("github")` to
label-wise matching.
- **#3585 + #3591** — truncate-in-place rc writes replaced by
write-temp-then-rename, then generalized to every user-file write.
- **#3578** — despite its `docs(step):` subject this carries three
behavior fixes, including `wt step push` succeeding mid-rebase and
moving the target branch onto a half-replayed history.
- **#3588 + #3587** — conflict markers can no longer reach a commit via
`wt step relocate --commit`, and `wt merge` refuses in its own name.
- **#3554** — OpenCode marker writes could land in another session's
worktree (thanks @4i3n6, who both reported and fixed it).

Not documented, per convention: #3574 (doc comments only, no runtime or
docs-site surface) and the three dependency bumps.

Also corrects `.github/CLAUDE.md`, which lists three required status
checks; there are four — `fast-checks` is required too, confirmed
against the branch-protection API.

Entries verified against the diffs by subagent. Two corrections came
back and are folded in: the #3589 entry originally promised "two of them
deleted" and described only one, and the #3578 entry mis-quoted the
success line as `✓ Pushed to main` when it carries a commit count.

> _This was written by Claude Code on behalf of max_
2026-07-24 20:27:42 -07:00
Maximilian Roos 6b29c2802b Release v0.69.2 (#3590)
Cuts v0.69.2, and fixes the Windows code-signing path it depends on.

## The signing fix

v0.69.1 shipped an unsigned `wt.exe` under a green run and a
**Completed** SignPath signing request. `archive: false` (#3566) had
already made the GitHub artifact name
`worktrunk-x86_64-pc-windows-msvc.zip`, and SignPath names its download
after the artifact — so with `output-artifact-directory: target/distrib`
the signed zip landed at `worktrunk-x86_64-pc-windows-msvc.zip.zip`,
beside the untouched unsigned build. The checksum step and the release
upload both kept reading the original. Confirmed by parsing the
published asset's PE certificate table: `size=0`.

The download now goes to a scratch directory and whatever single file
lands there replaces the built zip, so SignPath's naming isn't
load-bearing.

## Verification, because this failure is invisible

Signing is `continue-on-error` by design (self-signed test certificate
pending SignPath's OSS review), so nothing in the logs distinguishes
"signed" from "silently unsigned" — which is how it slipped through
twice, two different ways. `.github/verify-windows-signature.py` reads
the zip's PE certificate tables directly, and runs at two points with
distinct jobs:

- **before the overwrite** — an unsigned release is tolerable while the
certificate is a test one; a corrupt one never is, so the replacement
has to verify before it can clobber a good build.
- **after** — reports what the release actually ships, which is the
question the logs never answered.

## Rehearsed before landing

The signing path only runs on a tag, so each question about it used to
cost a release. This chain was instead run on a Windows runner against
the already-published v0.69.1 zip (identical bytes, no build):

```
saved to …\target\signpath\worktrunk-x86_64-pc-windows-msvc.zip.zip
git-wt.exe: certificate table 8480 bytes
wt.exe:     certificate table 8472 bytes
→ mv → target/distrib/worktrunk-x86_64-pc-windows-msvc.zip
target/distrib/worktrunk-x86_64-pc-windows-msvc.zip: all 2 executables signed
worktrunk-x86_64-pc-windows-msvc.zip: OK   (checksum matches)
```

That also settled the open question behind #3556: SignPath returns the
signed zip itself, not a wrapper, so `skip-decompress: true` is correct
— the extract mode does explode it into loose files.

## Release contents

`wt remove`'s fsmonitor sweep (#3581), the troubleshooting doc trim, and
this fix. The two refactors in range (#3582, #3584) are
behavior-preserving and omitted per convention.

Local gate green (4547 passed). Changelog entries verified against the
diffs by subagent; two claims corrected (the doc entry's rationale, and
an overclaim attributing v0.69.0's unsigned binary to this bug rather
than the separate upload failure #3566 fixed). Data-loss surface
reviewed across the cumulative diff.

> _This was written by Claude Code on behalf of max_
2026-07-24 20:02:13 -07:00
Worktrunk Bot eda641546f chore: update tend workflows (0.1.11 → 0.1.12) (#3573)
Automated nightly regeneration of tend's workflow files via `uvx
tend@latest init`, picking up the tend release since the last regen.

**tend version:** 0.1.11 → 0.1.12

**Notable changes:**

- **Notifications workflow tolerates transient `gh api` blips** — the
notifications fetch now retries on non-JSON responses (e.g. an HTML
error page returned with a 200 during an API blip) and skips the cycle
cleanly instead of aborting the step red (max-sixty/tend#780).
- **`review-runs` fails loud on transient `gh` errors** — a failed run
enumeration no longer reports a false all-clear; it surfaces the error
so the run isn't silently treated as clean (max-sixty/tend#784).
- **`running-in-ci` guidance** — the bot no longer asks outside
contributors to do work it can't do itself (max-sixty/tend#789).
- **Harness bumps** — Claude harness version bumped to 2.1.215
(max-sixty/tend#782) and the default harness timeout raised to 5h50m
(max-sixty/tend#790).

Compare: https://github.com/max-sixty/tend/compare/0.1.11...0.1.12

Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com>
2026-07-24 18:55:22 -07:00
dependabot[bot] 4ea2fe46a3 chore: bump taiki-e/install-action from 2.84.0 to 2.85.0 (#3570)
Bumps
[taiki-e/install-action](https://github.com/taiki-e/install-action) from
2.84.0 to 2.85.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's
releases</a>.</em></p>
<blockquote>
<h2>2.85.0</h2>
<ul>
<li>
<p>Support <code>wild</code> (alias: <code>wild-linker</code>). (<a
href="https://redirect.github.com/taiki-e/install-action/pull/1949">#1949</a>)</p>
</li>
<li>
<p>Support <code>bpf-linker</code>. (<a
href="https://redirect.github.com/taiki-e/install-action/pull/1950">#1950</a>)</p>
</li>
<li>
<p>Support <code>rafn</code>. (<a
href="https://redirect.github.com/taiki-e/install-action/pull/1935">#1935</a>,
thanks <a
href="https://github.com/DarkWanderer"><code>@​DarkWanderer</code></a>)</p>
</li>
<li>
<p>Update <code>cargo-neat@latest</code> to 0.5.1.</p>
</li>
<li>
<p>Update <code>zizmor@latest</code> to 1.28.0.</p>
</li>
<li>
<p>Update <code>wasmtime@latest</code> to 47.0.2.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.11.31.</p>
</li>
<li>
<p>Update <code>syft@latest</code> to 1.49.0.</p>
</li>
</ul>
<h2>2.84.1</h2>
<ul>
<li>
<p>Update <code>wasmtime@latest</code> to 47.0.1.</p>
</li>
<li>
<p>Update <code>wasm-tools@latest</code> to 1.254.0.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.11.30.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.11.</p>
</li>
<li>
<p>Update <code>cargo-neat@latest</code> to 0.5.0.</p>
</li>
<li>
<p>Update <code>cargo-crap@latest</code> to 0.3.1.</p>
</li>
<li>
<p>Update <code>biome@latest</code> to 2.5.5.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's
changelog</a>.</em></p>
<blockquote>
<h2>[2.85.0] - 2026-07-23</h2>
<ul>
<li>
<p>Support <code>wild</code> (alias: <code>wild-linker</code>). (<a
href="https://redirect.github.com/taiki-e/install-action/pull/1949">#1949</a>)</p>
</li>
<li>
<p>Support <code>bpf-linker</code>. (<a
href="https://redirect.github.com/taiki-e/install-action/pull/1950">#1950</a>)</p>
</li>
<li>
<p>Support <code>rafn</code>. (<a
href="https://redirect.github.com/taiki-e/install-action/pull/1935">#1935</a>,
thanks <a
href="https://github.com/DarkWanderer"><code>@​DarkWanderer</code></a>)</p>
</li>
<li>
<p>Update <code>cargo-neat@latest</code> to 0.5.1.</p>
</li>
<li>
<p>Update <code>zizmor@latest</code> to 1.28.0.</p>
</li>
<li>
<p>Update <code>wasmtime@latest</code> to 47.0.2.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.11.31.</p>
</li>
<li>
<p>Update <code>syft@latest</code> to 1.49.0.</p>
</li>
</ul>
<h2>[2.84.1] - 2026-07-22</h2>
<ul>
<li>
<p>Update <code>wasmtime@latest</code> to 47.0.1.</p>
</li>
<li>
<p>Update <code>wasm-tools@latest</code> to 1.254.0.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.11.30.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.11.</p>
</li>
<li>
<p>Update <code>cargo-neat@latest</code> to 0.5.0.</p>
</li>
<li>
<p>Update <code>cargo-crap@latest</code> to 0.3.1.</p>
</li>
<li>
<p>Update <code>biome@latest</code> to 2.5.5.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/taiki-e/install-action/commit/7572810d7dd469b651bb7793945692cf78da5dd7"><code>7572810</code></a>
Release 2.85.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/d73fed906d8b5a8fbe1165c7635ef41dbf5e6ccd"><code>d73fed9</code></a>
Update changelog</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/20d0440ac8346c2da5bfa9bc79b6d50c30ee7658"><code>20d0440</code></a>
Support bpf-linker (<a
href="https://redirect.github.com/taiki-e/install-action/issues/1950">#1950</a>)</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/05a01b63a23569d0bf6dde483954e312dce7d417"><code>05a01b6</code></a>
Update vacuum manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/23a3cce147f42d0975d244f68a4af961ccd8fd53"><code>23a3cce</code></a>
Update <code>cargo-neat@latest</code> to 0.5.1</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/54ede987e296f0fc0b43f3f75d496577fad36a9c"><code>54ede98</code></a>
Support rafn (<a
href="https://redirect.github.com/taiki-e/install-action/issues/1935">#1935</a>)</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/411aa4ba3c7fb6ad60a7421c46e881a3a1ceb8ad"><code>411aa4b</code></a>
Support wild (<a
href="https://redirect.github.com/taiki-e/install-action/issues/1949">#1949</a>)</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/4427ee328dd40578670ed6724b4a766207e21f0e"><code>4427ee3</code></a>
Update <code>zizmor@latest</code> to 1.28.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/68a5a96ea71119471050840e296140c66135d7b8"><code>68a5a96</code></a>
Update <code>wasmtime@latest</code> to 47.0.2</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/f276a80345c4641da04f6613887cc496c332c232"><code>f276a80</code></a>
Update <code>uv@latest</code> to 0.11.31</li>
<li>Additional commits viewable in <a
href="https://github.com/taiki-e/install-action/compare/v2.84.0...v2.85.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=taiki-e/install-action&package-manager=github_actions&previous-version=2.84.0&new-version=2.85.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-24 18:55:20 -07:00
dependabot[bot] b636ae1a11 chore: bump max-sixty/tend from 0.1.11 to 0.1.12 (#3569)
Bumps [max-sixty/tend](https://github.com/max-sixty/tend) from 0.1.11 to
0.1.12.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/max-sixty/tend/releases">max-sixty/tend's
releases</a>.</em></p>
<blockquote>
<h2>0.1.12</h2>
<h3>Improved</h3>
<ul>
<li><strong>The default harness timeout rises from 3 hours (10800s) to
5h50m (21000s)</strong> in both Claude harnesses
(<code>claude/action.yaml</code> headless,
<code>claude-interactive/action.yaml</code> PTY), leaving a 10-minute
buffer under GitHub Actions' hard 6-hour job cap instead of cutting long
sessions off at 3 hours. (<a
href="https://redirect.github.com/max-sixty/tend/pull/790">#790</a>)</li>
</ul>
<h3>Fixed</h3>
<ul>
<li><strong>The bot no longer asks an upstream maintainer to do
verification work it couldn't do itself.</strong> When a check needs
hardware or an environment CI doesn't have, the
<code>running-in-ci</code> skill now escalates in order — do it
yourself, add the capability to your own repo, ask a contributor, ask
your own maintainer — and never hands the ask outward to someone
reviewing the bot's change as a favor. (<a
href="https://redirect.github.com/max-sixty/tend/pull/789">#789</a>)</li>
<li><strong><code>list-recent-runs.sh</code> fails loud on a transient
<code>gh</code> API error instead of silently reporting zero
runs.</strong> A dropped <code>gh workflow list</code>/<code>gh run
list</code> call previously read as a false all-clear that permanently
skipped that window; it now retries with backoff and exits non-zero if
every attempt fails. (<a
href="https://redirect.github.com/max-sixty/tend/pull/784">#784</a>)</li>
<li><strong>The notifications workflow tolerates a transient non-JSON
response from the GitHub API</strong> instead of failing the step
outright. (<a
href="https://redirect.github.com/max-sixty/tend/pull/780">#780</a>)</li>
</ul>
<h3>Internal</h3>
<ul>
<li>Bumped pinned <code>claude_version</code> to 2.1.215. (<a
href="https://redirect.github.com/max-sixty/tend/pull/782">#782</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/max-sixty/tend/blob/main/CHANGELOG.md">max-sixty/tend's
changelog</a>.</em></p>
<blockquote>
<h2>0.1.12</h2>
<h3>Improved</h3>
<ul>
<li><strong>The default harness timeout rises from 3 hours (10800s) to
5h50m (21000s)</strong> in both Claude harnesses
(<code>claude/action.yaml</code> headless,
<code>claude-interactive/action.yaml</code> PTY), leaving a 10-minute
buffer under GitHub Actions' hard 6-hour job cap instead of cutting long
sessions off at 3 hours. (<a
href="https://redirect.github.com/max-sixty/tend/pull/790">#790</a>)</li>
</ul>
<h3>Fixed</h3>
<ul>
<li><strong>The bot no longer asks an upstream maintainer to do
verification work it couldn't do itself.</strong> When a check needs
hardware or an environment CI doesn't have, the
<code>running-in-ci</code> skill now escalates in order — do it
yourself, add the capability to your own repo, ask a contributor, ask
your own maintainer — and never hands the ask outward to someone
reviewing the bot's change as a favor. (<a
href="https://redirect.github.com/max-sixty/tend/pull/789">#789</a>)</li>
<li><strong><code>list-recent-runs.sh</code> fails loud on a transient
<code>gh</code> API error instead of silently reporting zero
runs.</strong> A dropped <code>gh workflow list</code>/<code>gh run
list</code> call previously read as a false all-clear that permanently
skipped that window; it now retries with backoff and exits non-zero if
every attempt fails. (<a
href="https://redirect.github.com/max-sixty/tend/pull/784">#784</a>)</li>
<li><strong>The notifications workflow tolerates a transient non-JSON
response from the GitHub API</strong> instead of failing the step
outright. (<a
href="https://redirect.github.com/max-sixty/tend/pull/780">#780</a>)</li>
</ul>
<h3>Internal</h3>
<ul>
<li>Bumped pinned <code>claude_version</code> to 2.1.215. (<a
href="https://redirect.github.com/max-sixty/tend/pull/782">#782</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/max-sixty/tend/commit/f90bacaf61dc655fa6331ff558006cb730501772"><code>f90baca</code></a>
chore: release 0.1.12 (<a
href="https://redirect.github.com/max-sixty/tend/issues/791">#791</a>)</li>
<li><a
href="https://github.com/max-sixty/tend/commit/a843719b8c32b66a5e2c4408b7512dccb93771d7"><code>a843719</code></a>
chore: bump harness timeout default to 5h50m (<a
href="https://redirect.github.com/max-sixty/tend/issues/790">#790</a>)</li>
<li><a
href="https://github.com/max-sixty/tend/commit/ba5a7dee5fe23776255a5c759137269bd5a09c0a"><code>ba5a7de</code></a>
fix(running-in-ci): don't ask outsiders to do work the bot can't do
itself (#...</li>
<li><a
href="https://github.com/max-sixty/tend/commit/bbeb9d2cc5df849ed3cc517c8f5ce59ef38f7066"><code>bbeb9d2</code></a>
fix(list-recent-runs): fail loud on transient gh errors instead of a
false al...</li>
<li><a
href="https://github.com/max-sixty/tend/commit/8d217418307c9365e2a8e1d67c8e3435c6c675e6"><code>8d21741</code></a>
chore: bump claude_version to 2.1.215 (<a
href="https://redirect.github.com/max-sixty/tend/issues/782">#782</a>)</li>
<li><a
href="https://github.com/max-sixty/tend/commit/c3fd0c46d5f9bf4d202ffe7991b56e042f2b0348"><code>c3fd0c4</code></a>
fix(notifications): tolerate transient non-JSON gh api responses (<a
href="https://redirect.github.com/max-sixty/tend/issues/780">#780</a>)</li>
<li><a
href="https://github.com/max-sixty/tend/commit/44beffddf7930a82932ab7d7f70a9697b5d1200b"><code>44beffd</code></a>
chore: regenerate workflows with tend 0.1.11 (<a
href="https://redirect.github.com/max-sixty/tend/issues/778">#778</a>)</li>
<li>See full diff in <a
href="https://github.com/max-sixty/tend/compare/0.1.11...0.1.12">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=max-sixty/tend&package-manager=github_actions&previous-version=0.1.11&new-version=0.1.12)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-24 18:55:17 -07:00
Maximilian Roos 7b741d0791 fix(release): stop double-zipping the SignPath upload artifact (#3566)
## Summary
- `actions/upload-artifact` wraps every upload in its own GitHub storage
zip unless `archive: false`. The uploaded file here is already a zip
(`worktrunk-x86_64-pc-windows-msvc.zip`), so the default produced a
zip-of-a-zip — SignPath treated the outer storage wrapper as "the
artifact" and the configured `<pe-file path="wt.exe">` never matched
anything inside it.
- Root-caused this against the real v0.69.0 release run: the SignPath
dashboard shows the failed request's unsigned artifact as
`unsigned-windows-zip.zip` (16.8MB, matching GitHub's storage-wrapper
name, not the real filename) with error `Expected path to match exactly
1 item, but found 0` for `wt.exe`.
- `archive: false` uploads the file as-is (single-file only, which is
what we have), so SignPath receives the real zip directly, one level
shallower — matching the artifact configuration as originally written.
- Also fixes the v0.69.0 CHANGELOG's SignPath entry, which read "Signed
with a test certificate" — overclaiming, since the actual signing
attempt on that release failed. Reworded to describe the pipeline's
intent rather than a specific run's result.

v0.69.0 shipped with an unsigned Windows binary as a result (signing
failure was masked by the intentional `continue-on-error`, so the
release itself succeeded — this is exactly the non-blocking behavior
that was designed in). This fix should make the next release's signing
attempt succeed for real.

## Test plan
- [x] `actionlint .github/workflows/release.yaml` — no new warnings
- [x] Root cause confirmed directly against the SignPath dashboard's
error details and artifact tab for the failed v0.69.0 signing request
- [x] Verified `archive: false` semantics against
`actions/upload-artifact@v7`'s own `action.yml` (single-file upload,
uploaded as-is)

> _This was written by Claude Code on behalf of Max_
2026-07-23 19:30:19 -07:00
Maximilian Roos 481125801f ci: publish to crates.io via trusted publishing (#3564)
## What

`publish-cargo` now mints its crates.io credential per run through
`rust-lang/crates-io-auth-action` (GitHub Actions OIDC) instead of
reading
the `CARGO_REGISTRY_TOKEN` environment secret. The job gains
`id-token: write` for the OIDC exchange and `contents: read` for
checkout,
narrowing it from the workflow-level `contents: write`.

The token lives for about 30 minutes and the action's post step revokes
it,
so no long-lived publish credential exists anywhere.

## Why

The stored token expires on a schedule, and each expiry is a silent
trap:
nothing breaks until the next release tag, which is exactly when you
don't
want to discover it.

## Prerequisite, already in place

A Trusted Publisher is configured for `worktrunk` on crates.io —
repository `max-sixty/worktrunk`, workflow `release.yaml`, environment
`release`. It had to land before this merge, since otherwise
`publish-cargo` would fail at the auth step on the next release tag.

`CARGO_REGISTRY_TOKEN` can be deleted from the `release` environment
once a release has gone out this way. `AUR_SSH_PRIVATE_KEY` stays.

> _This was written by Claude Code on behalf of max_
2026-07-23 18:46:12 -07:00
Maximilian Roos 8f55d15301 fix(release): preserve signed Windows zip filename, match checksum format (#3556)
## Summary
- The SignPath action's `skip-decompress` defaults to `false`, so it
would have extracted the returned zip's contents as loose files into
`target/distrib/` instead of saving back a signed
`worktrunk-x86_64-pc-windows-msvc.zip`. The checksum step would have
silently hashed the still-unsigned zip, and the release would have
shipped unsigned Windows binaries with no CI failure to flag it.
- `sha256sum` without `-b` omits the `*` binary-mode marker;
cargo-dist's own checksums use `<hash> *<filename>` (confirmed against a
real release asset). Added `-b` to match.

Confirmed via `gh run view` on #3553's own CI run that
`build-local-artifacts` is skipped on PRs in this repo, so this code
path has never actually executed — this is the first real fix before it
runs for real on a tagged release.

## Test plan
- [x] `actionlint .github/workflows/release.yaml` — no new warnings
(same pre-existing shellcheck style notes as before)
- [x] Verified `skip-decompress` behavior against the action's own
`action.yml` input spec
- [x] Verified checksum format against a real downloaded release asset
(`v0.68.0`)

> _This was written by Claude Code on behalf of Max_
2026-07-23 16:13:30 -07:00
Maximilian Roos 5f8c301dec feat(release): sign Windows binaries via SignPath (#3553)
## Summary
- Signs the Windows release zip (`wt.exe` + `git-wt.exe`) via
[SignPath](https://signpath.io)'s free OSS code-signing program, using
the `test-signing` policy (self-signed test certificate) while the
project's Foundation-program application is under review.
- Non-blocking (`continue-on-error`) so a signing hiccup can't take down
crates.io/homebrew/winget/AUR publishing.
- Recomputes the `.sha256` checksum after signing, since the signed
zip's bytes differ from the unsigned one.
- Uses a dedicated low-privilege `CI builds` SignPath identity
(submitter-only), not an admin account.

## Test plan
- [x] `actionlint` clean (only pre-existing shellcheck style warnings
elsewhere in the file)
- [x] Artifact configuration (zip containing `wt.exe` + `git-wt.exe`)
validated against SignPath's own XML parser and against the real file
layout inside a downloaded `v0.68.0` Windows release zip
- [ ] First real Windows build after merge will be the first live
signing round-trip through GitHub Actions — watch that release's CI run

> _This was written by Claude Code on behalf of Max_

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-23 12:19:32 -07:00
Maximilian Roos a7c4a7a120 refactor(wt-perf): place fixtures under target/wt-perf, not the cache dir (#3547)
## What

Move every `wt-perf` on-disk fixture out of the per-user cache dir and
under the cargo target dir at `<target>/wt-perf/`, resolved by a renamed
`wt_perf_fixture_dir()`:

- `setup <config>` fixtures → `<target>/wt-perf/<config>` (was
`~/.cache/wt-perf/<config>`).
- The rust-lang/rust clone and `prune-real` fixtures →
`<target>/wt-perf/bench-repos/` (was `~/.cache/wt-perf/bench-repos/`).
- `wt_perf_cache_dir()` → `wt_perf_fixture_dir()`. The target dir is
derived from the **running executable's own path** (it lives inside
whichever dir cargo built into — `<target>/debug/wt-perf`,
`<target>/release/deps/<bench>`), so it honors `CARGO_TARGET_DIR`, a
config-file `build.target-dir`, and cargo-llvm-cov's
`target/llvm-cov-target/` — none of which a bare `CARGO_TARGET_DIR` env
read covers. Falls back to `<workspace>/target` if the binary isn't
under a recognizable profile dir. The `etcetera` dependency is dropped.
- The `WT_PERF_CACHE_DIR` env override (and the empty-value guard it
required) is removed; the benchmarks workflow now caches the
deterministic `target/wt-perf/bench-repos` path directly.
- In-process throwaway fixtures (`create_repo`) are unchanged — they
keep using `tempfile::TempDir`.

This reverses the location decision from #3542, which had moved these
into `~/.cache/wt-perf`.

## Why

`target/` is the conventional home for build/test-generated artifacts —
gitignored, reaped by `cargo clean`, and already where criterion writes
(`target/criterion`). Keeping every wt-perf fixture there gives one
predictable location under the repo that `cargo clean` fully resets.
Deriving the target dir from the running binary (rather than assuming
`<workspace>/target`) keeps that property intact even when the target
dir is relocated.

## Tradeoff (accepted)

`target/` is **not** shared across git worktrees (worktrees don't share
it) and is wiped by `cargo clean`. So the ~15 GiB `prune-real` rust
clone re-clones per worktree and after every `cargo clean` — the cost
#3542 avoided by using the cache dir. This is deliberate and documented
on `wt_perf_fixture_dir`; it's cheap for the synthetic `setup` fixtures,
which rebuild in seconds.

## Testing

- `cargo build -p wt-perf --all-targets`, `cargo test -p wt-perf` —
clean.
- New unit test `target_dir_from_exe_finds_cargo_target` covers the
resolution logic (relocated `CARGO_TARGET_DIR`, bench binary under
`release/deps/`, cargo-llvm-cov's nested target, closest-profile-wins,
and the outside-any-target fallback).
- `pre-commit run --all-files` (fmt, clippy, yaml, typos, cargo-lock,
custom hooks) — clean.
- Smoke-tested end-to-end: `setup branches-2` lands at
`<worktree>/target/wt-perf/branches-2` and writes nothing to
`~/.cache/`; a copy of the binary run from a fake `<dir>/debug/wt-perf`
correctly resolves fixtures to `<dir>/wt-perf/`, proving a relocated
target dir is honored.

> _This was written by Claude Code on behalf of Maximilian_

---------

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-22 13:44:50 -07:00
Maximilian Roos 4121dc979c refactor(wt-perf): cache fixtures in the platform cache dir, not /tmp or target/ (#3542)
## What

Move `wt-perf`'s benchmark/debug fixture repos out of
`std::env::temp_dir()` and `target/bench-repos/` into the per-user cache
dir, resolved by a new `wt_perf_cache_dir()`:

- `$WT_PERF_CACHE_DIR` if set, else `<cache>/wt-perf` via
`etcetera::choose_base_strategy().cache_dir()` — `~/.cache/wt-perf` (or
`$XDG_CACHE_HOME/wt-perf`) on Linux **and** macOS. This matches
worktrunk's own base-dir convention (`src/config/user/path.rs` resolves
user config through the same XDG-on-macOS strategy).
- `setup <config>` fixtures → `<cache>/<config>` (was
`temp_dir()/wt-perf-<config>`). `--path` still overrides.
- Real cloned fixtures (`prune-real`, the rust-lang/rust clone) →
`<cache>/bench-repos/` (was `target/bench-repos/`).
- In-process throwaway fixtures (`create_repo`) are unchanged — they
keep using `tempfile::TempDir`.

## Why

Both old homes were wrong for a *reused* fixture (these are given stable
names, persist between runs, and are referenced from docs and `-C
<path>` — that's a cache, not a temp file):

- **A fixed name in a shared `/tmp` (Linux)** collides across users:
`/tmp` is sticky (`1777`), so a second user's `setup` hits
`remove_dir_all().unwrap()` on a dir they don't own → `EPERM` → panic.
It's also a predictable-path/TOCTOU hazard, and `systemd-tmpfiles` reaps
`/tmp` per-file at 10 days by `max(atime,mtime,ctime)` — on a `noatime`
mount an actively-*read* fixture still loses cold
`.git/objects/pack/*.pack` mid-use → silent git corruption.
- **On macOS**, `temp_dir()` is already `/var/folders/.../T` (per-user,
`0700`), so the docs' `/tmp/wt-perf-*` paths were simply wrong there.
- **`target/`** is per-worktree (git worktrees don't share it) and wiped
by `cargo clean`, so the ~15 GiB rust clone was re-cloned per worktree —
worst for the most expensive fixture, in a worktree-heavy workflow.

The cache dir is per-user (no collision, no TOCTOU), stable and
discoverable (docs/`-C` references still work), shared across worktrees
(clone once per machine), and survives `cargo clean` — matching sccache,
cargo, rustup, Go, Bazel, and Hugging Face, which all place large
reusable caches there rather than in `/tmp`.

## Migration notes

- First bench/setup run after this rebuilds the cache under the new
location (the old `target/bench-repos/` is no longer read). Existing
fixtures can be dropped with `rm -rf target/bench-repos`.
- `.github/workflows/benchmarks.yaml` sets `WT_PERF_CACHE_DIR` and
caches `$WT_PERF_CACHE_DIR/bench-repos`, so the cached path and the path
wt-perf writes stay pinned together (no drift if a runner sets
`$XDG_CACHE_HOME`); key unchanged.
- Docs (`benches/CLAUDE.md`, `src/commands/CLAUDE.md`) updated to the
new paths, noting that `wt-perf setup` prints the exact path.

## Testing

- `cargo build --workspace --all-targets`, `cargo clippy --workspace
--all-targets --features shell-integration-tests -- -D warnings` —
clean.
- `cargo test -p wt-perf` — passes.
- Smoke-tested default resolution (`~/.cache/wt-perf/…` on macOS),
`$WT_PERF_CACHE_DIR` override, and the `prune-real --path` rejection
(now names the resolved cache path).

> _This was written by Claude Code on behalf of Maximilian_

---------

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-22 03:05:10 -07:00
dependabot[bot] 89b58e2522 chore: bump taiki-e/install-action from 2.83.3 to 2.84.0 (#3529)
Bumps
[taiki-e/install-action](https://github.com/taiki-e/install-action) from
2.83.3 to 2.84.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's
releases</a>.</em></p>
<blockquote>
<h2>2.84.0</h2>
<ul>
<li>
<p>Support <code>d2</code>. (<a
href="https://redirect.github.com/taiki-e/install-action/pull/1944">#1944</a>)</p>
</li>
<li>
<p>Support <code>protoc-gen-connect-openapi</code>. (<a
href="https://redirect.github.com/taiki-e/install-action/pull/1922">#1922</a>,
thanks <a
href="https://github.com/JasterV"><code>@​JasterV</code></a>)</p>
</li>
<li>
<p>Update <code>convco@latest</code> to 0.7.0. (<a
href="https://redirect.github.com/taiki-e/install-action/pull/1941">#1941</a>,
thanks <a
href="https://github.com/graelo"><code>@​graelo</code></a>)</p>
</li>
<li>
<p>Update <code>just@latest</code> to 1.57.0.</p>
</li>
<li>
<p>Update <code>cargo-semver-checks@latest</code> to 0.49.0.</p>
</li>
<li>
<p>Update <code>tombi@latest</code> to 1.2.4.</p>
</li>
<li>
<p>Update <code>cosign@latest</code> to 3.1.2.</p>
</li>
</ul>
<h2>2.83.4</h2>
<ul>
<li>
<p>Update <code>vacuum@latest</code> to 0.29.10.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.11.29.</p>
</li>
<li>
<p>Update <code>syft@latest</code> to 1.48.0.</p>
</li>
<li>
<p>Update <code>prek@latest</code> to 0.4.10.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.7.</p>
</li>
<li>
<p>Update <code>cargo-shear@latest</code> to 1.13.2.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's
changelog</a>.</em></p>
<blockquote>
<h2>[2.84.0] - 2026-07-20</h2>
<ul>
<li>
<p>Support <code>d2</code>. (<a
href="https://redirect.github.com/taiki-e/install-action/pull/1944">#1944</a>)</p>
</li>
<li>
<p>Support <code>protoc-gen-connect-openapi</code>. (<a
href="https://redirect.github.com/taiki-e/install-action/pull/1922">#1922</a>,
thanks <a
href="https://github.com/JasterV"><code>@​JasterV</code></a>)</p>
</li>
<li>
<p>Update <code>convco@latest</code> to 0.7.0. (<a
href="https://redirect.github.com/taiki-e/install-action/pull/1941">#1941</a>,
thanks <a
href="https://github.com/graelo"><code>@​graelo</code></a>)</p>
</li>
<li>
<p>Update <code>just@latest</code> to 1.57.0.</p>
</li>
<li>
<p>Update <code>cargo-semver-checks@latest</code> to 0.49.0.</p>
</li>
<li>
<p>Update <code>tombi@latest</code> to 1.2.4.</p>
</li>
<li>
<p>Update <code>cosign@latest</code> to 3.1.2.</p>
</li>
</ul>
<h2>[2.83.4] - 2026-07-17</h2>
<ul>
<li>
<p>Update <code>vacuum@latest</code> to 0.29.10.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.11.29.</p>
</li>
<li>
<p>Update <code>syft@latest</code> to 1.48.0.</p>
</li>
<li>
<p>Update <code>prek@latest</code> to 0.4.10.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.7.</p>
</li>
<li>
<p>Update <code>cargo-shear@latest</code> to 1.13.2.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/taiki-e/install-action/commit/a6b2e2dcd845ddd7f509ce4f3ed3d922b80cc5d9"><code>a6b2e2d</code></a>
Release 2.84.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/fbdd9c50c029b1f2d5667c090563e4a31cc3f43c"><code>fbdd9c5</code></a>
Update cargo-neat manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/424c5f90440984601897d473b7936cc3fd52bda8"><code>424c5f9</code></a>
Update changelog</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/a1fa02c1f9b8ef65d443ad6b3f0b99f5863b6f4f"><code>a1fa02c</code></a>
Support <code>protoc-gen-connect-openapi</code> (<a
href="https://redirect.github.com/taiki-e/install-action/issues/1922">#1922</a>)</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/9e22773f98774c41688b7cc39a5f7f7eaa4ca97d"><code>9e22773</code></a>
Update DEVELOPMENT.md</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/8d5009fee2da9de26fee96bb727c2df318ffce42"><code>8d5009f</code></a>
Support d2</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/5193316cc852ca0f37d4819875e939522c4f7c47"><code>5193316</code></a>
Update <code>tombi@latest</code> to 1.2.4</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/4c740c71c8320819d812216022c3ff178e1a3394"><code>4c740c7</code></a>
Update <code>tombi@latest</code> to 1.2.3</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/de240ff26f6e8b33bacd85a1a7c621c92d8d7c70"><code>de240ff</code></a>
Update <code>just@latest</code> to 1.57.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/dfca8548668aebabd66da598ea31d87a03819d43"><code>dfca854</code></a>
Update <code>cargo-semver-checks@latest</code> to 0.49.0</li>
<li>Additional commits viewable in <a
href="https://github.com/taiki-e/install-action/compare/v2.83.3...v2.84.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=taiki-e/install-action&package-manager=github_actions&previous-version=2.83.3&new-version=2.84.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-21 18:46:09 -07:00
dependabot[bot] 013d1cc221 chore: bump KSXGitHub/github-actions-deploy-aur from 4.1.3 to 4.2.0 (#3472)
Bumps
[KSXGitHub/github-actions-deploy-aur](https://github.com/ksxgithub/github-actions-deploy-aur)
from 4.1.3 to 4.2.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/ksxgithub/github-actions-deploy-aur/releases">KSXGitHub/github-actions-deploy-aur's
releases</a>.</em></p>
<blockquote>
<h2>v4.2.0</h2>
<p>Add a feature to sync AUR repo (<a
href="https://redirect.github.com/KSXGitHub/github-actions-deploy-aur/pull/52">KSXGitHub/github-actions-deploy-aur#52</a>).</p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/KSXGitHub/github-actions-deploy-aur/commit/084b0d9b15415bf9cdb65d44dad1efe37a354050"><code>084b0d9</code></a>
style: consistency (<a
href="https://redirect.github.com/ksxgithub/github-actions-deploy-aur/issues/55">#55</a>)</li>
<li><a
href="https://github.com/KSXGitHub/github-actions-deploy-aur/commit/9e2f21095c586521806151200746082d8e02bb90"><code>9e2f210</code></a>
fix: force-add <code>PKGBUILD</code> and <code>.SRCINFO</code> in the
asset_dir/assets path (<a
href="https://redirect.github.com/ksxgithub/github-actions-deploy-aur/issues/53">#53</a>)</li>
<li><a
href="https://github.com/KSXGitHub/github-actions-deploy-aur/commit/7acb32fe8c43848121eee16dd39d8294ec2bf25b"><code>7acb32f</code></a>
feat: full asset sync (<a
href="https://redirect.github.com/ksxgithub/github-actions-deploy-aur/issues/52">#52</a>)</li>
<li>See full diff in <a
href="https://github.com/ksxgithub/github-actions-deploy-aur/compare/v4.1.3...v4.2.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=KSXGitHub/github-actions-deploy-aur&package-manager=github_actions&previous-version=4.1.3&new-version=4.2.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-19 11:21:35 -07:00
dependabot[bot] 99704db62f chore: bump taiki-e/install-action from 2.83.2 to 2.83.3 (#3497)
Bumps
[taiki-e/install-action](https://github.com/taiki-e/install-action) from
2.83.2 to 2.83.3.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's
releases</a>.</em></p>
<blockquote>
<h2>2.83.3</h2>
<ul>
<li>
<p>Update <code>release-plz@latest</code> to 0.3.160.</p>
</li>
<li>
<p>Update <code>prek@latest</code> to 0.4.9.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.6.</p>
</li>
<li>
<p>Update <code>dprint@latest</code> to 0.55.2.</p>
</li>
<li>
<p>Update <code>cargo-dinghy@latest</code> to 0.8.5.</p>
</li>
<li>
<p>Update <code>cargo-binstall@latest</code> to 1.21.0.</p>
</li>
<li>
<p>Update <code>biome@latest</code> to 2.5.4.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's
changelog</a>.</em></p>
<blockquote>
<h2>[2.83.3] - 2026-07-16</h2>
<ul>
<li>
<p>Update <code>release-plz@latest</code> to 0.3.160.</p>
</li>
<li>
<p>Update <code>prek@latest</code> to 0.4.9.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.6.</p>
</li>
<li>
<p>Update <code>dprint@latest</code> to 0.55.2.</p>
</li>
<li>
<p>Update <code>cargo-dinghy@latest</code> to 0.8.5.</p>
</li>
<li>
<p>Update <code>cargo-binstall@latest</code> to 1.21.0.</p>
</li>
<li>
<p>Update <code>biome@latest</code> to 2.5.4.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/taiki-e/install-action/commit/ed67fa35ac944f3a9b33f12c4dd43b6f31a47e20"><code>ed67fa3</code></a>
Release 2.83.3</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/618fa5589cc587c869ec39ae0606a6cf6ef03c0b"><code>618fa55</code></a>
Update prek manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/47579092c792f14738b668ee240d199bcad0d8e2"><code>4757909</code></a>
Update zizmor manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/f1fa00538cc2e7231cb60e4d47c24597e0c387b7"><code>f1fa005</code></a>
Update uv manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/aa8dc906017e56077bc125256c4d9301b1cde72a"><code>aa8dc90</code></a>
Update <code>release-plz@latest</code> to 0.3.160</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/b9654978ff643e657a453245addf012127caa2c5"><code>b965497</code></a>
Update <code>prek@latest</code> to 0.4.9</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/7aab3a9c373d60a23a5b89c212174c0baa6a0fa0"><code>7aab3a9</code></a>
Update <code>mise@latest</code> to 2026.7.6</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/bfee8d1ca4d6f82a5c3f7151f046e75e6c202ff5"><code>bfee8d1</code></a>
Update kingfisher manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/b65771b2e228b44f33eb596fbf78979075cd8aa7"><code>b65771b</code></a>
Update <code>dprint@latest</code> to 0.55.2</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/20468927b3c1d5f14e6c4c1379ced0c6cc1ed103"><code>2046892</code></a>
Update <code>cargo-dinghy@latest</code> to 0.8.5</li>
<li>Additional commits viewable in <a
href="https://github.com/taiki-e/install-action/compare/v2.83.2...v2.83.3">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=taiki-e/install-action&package-manager=github_actions&previous-version=2.83.2&new-version=2.83.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-19 11:21:30 -07:00
Worktrunk Bot 5967df2dfc chore(ci): weekly renovation 2026-07-19 (#3518) 2026-07-19 08:39:31 -07:00
Worktrunk Bot a1332d46bd chore: update tend workflows (0.1.10 → 0.1.11) (#3500)
Automated nightly regeneration of tend's workflow files, picking up the
upstream release.

**tend version:** 0.1.10 → 0.1.11

**Notable changes** (consumer-relevant):

- Skip no-op `tend-mention` sessions triggered by the bot's own comments
— a new pre-mention guard in the generated `tend-mention.yaml`
short-circuits before the engagement heuristics (max-sixty/tend#751).
- Respond to actionable bot self-reviews instead of exiting as a
self-loop: a review the review workflow leaves on its own PR is the
bot's reviewer role, so it gets actioned rather than silently skipped
(max-sixty/tend#762).
- Sandbox: adopter levers to reach inside the Claude-family sandbox, and
derive the sandbox `PATH` from the runner's `PATH` (max-sixty/tend#768,
max-sixty/tend#767).
- `running-in-ci`: permit maintainer-invited upstream contributions, and
prohibit self-authored attribution sign-offs (max-sixty/tend#770,
max-sixty/tend#773).
- Action reliability: self-heal duplicate `tend-outage` issues from
concurrent leg failures, and recover dropped cron ticks in
list-recent-runs via a previous-run anchor (max-sixty/tend#744,
max-sixty/tend#753).

Compare: https://github.com/max-sixty/tend/compare/0.1.10...0.1.11

Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com>
2026-07-17 12:59:12 -07:00
dependabot[bot] 8ab797f595 chore: bump max-sixty/tend from 0.1.10 to 0.1.11 (#3496) 2026-07-16 23:00:21 -07:00