mirror of
https://github.com/max-sixty/worktrunk.git
synced 2026-09-14 20:00:38 +08:00
codex/remove-codex-cloud-specific-tests
410 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
61d80b3ab8 |
chore: bump clechasseur/rs-cargo from 5.0.7 to 5.0.8 (#3829)
Bumps [clechasseur/rs-cargo](https://github.com/clechasseur/rs-cargo) from 5.0.7 to 5.0.8. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/clechasseur/rs-cargo/releases">clechasseur/rs-cargo's releases</a>.</em></p> <blockquote> <h2>v5.0.8</h2> <p>New patch release with updated dependencies to fix some vulnerabilities.</p> <h2>What's Changed</h2> <ul> <li>chore(deps): bump undici from 6.27.0 to 6.28.0 in the npm_and_yarn group across 1 directory by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/clechasseur/rs-cargo/pull/435">clechasseur/rs-cargo#435</a></li> <li>chore(deps): bump the npm_and_yarn group across 1 directory with 1 update by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/clechasseur/rs-cargo/pull/436">clechasseur/rs-cargo#436</a></li> <li>fix: <code>npm update</code> to get fixes, update <code>@clechasseur/rs-actions-core</code> to 8.0.4, bump version to 5.0.8 by <a href="https://github.com/clechasseur"><code>@clechasseur</code></a> in <a href="https://redirect.github.com/clechasseur/rs-cargo/pull/437">clechasseur/rs-cargo#437</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/clechasseur/rs-cargo/compare/v5.0.7...v5.0.8">https://github.com/clechasseur/rs-cargo/compare/v5.0.7...v5.0.8</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/clechasseur/rs-cargo/commit/9a5c570d3347f8dee3916c8871f3ffaf38909956"><code>9a5c570</code></a> fix: <code>npm update</code> to get fixes, update <code>@clechasseur/rs-actions-core</code> to 8.0....</li> <li><a href="https://github.com/clechasseur/rs-cargo/commit/24c8a774d7e015322005aaca3336016bdc670085"><code>24c8a77</code></a> chore(deps): bump the npm_and_yarn group across 1 directory with 1 update (<a href="https://redirect.github.com/clechasseur/rs-cargo/issues/436">#436</a>)</li> <li><a href="https://github.com/clechasseur/rs-cargo/commit/b2652e1335c7ec927c51a006790e235ad741e1a7"><code>b2652e1</code></a> chore(deps): bump undici in the npm_and_yarn group across 1 directory (<a href="https://redirect.github.com/clechasseur/rs-cargo/issues/435">#435</a>)</li> <li><a href="https://github.com/clechasseur/rs-cargo/commit/44bc6e9a0a8b85197cd377ad859fac1e3e9408bd"><code>44bc6e9</code></a> chore(deps): update dependency rollup to ^4.62.4 (<a href="https://redirect.github.com/clechasseur/rs-cargo/issues/432">#432</a>)</li> <li><a href="https://github.com/clechasseur/rs-cargo/commit/e914260698d7251b9589c737040ea88189e1d07e"><code>e914260</code></a> chore(deps): update dependency oxlint to ^1.77.0 (<a href="https://redirect.github.com/clechasseur/rs-cargo/issues/434">#434</a>)</li> <li><a href="https://github.com/clechasseur/rs-cargo/commit/952abcd19408ed276d2cb062ba1e680b5d564a1e"><code>952abcd</code></a> chore(deps): update actions/checkout action to v7.0.1 (<a href="https://redirect.github.com/clechasseur/rs-cargo/issues/431">#431</a>)</li> <li><a href="https://github.com/clechasseur/rs-cargo/commit/ebc623c7b9c4498bbb97ab84d0d7ef333f5645e0"><code>ebc623c</code></a> chore(deps): update dependency ts-jest to ^29.4.12 (<a href="https://redirect.github.com/clechasseur/rs-cargo/issues/428">#428</a>)</li> <li><a href="https://github.com/clechasseur/rs-cargo/commit/260bce3fe16b97604f986f900f052ddf2996f71c"><code>260bce3</code></a> chore(deps): update dependency oxlint to ^1.75.0 (<a href="https://redirect.github.com/clechasseur/rs-cargo/issues/430">#430</a>)</li> <li>See full diff in <a href="https://github.com/clechasseur/rs-cargo/compare/v5.0.7...v5.0.8">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
9c13f6e7d4 |
chore: bump taiki-e/install-action from 2.85.11 to 2.85.13 (#3828)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.85.11 to 2.85.13. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.85.13</h2> <ul> <li> <p>Update <code>tombi@latest</code> to 1.3.3.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.5.</p> </li> <li> <p>Update <code>kingfisher@latest</code> to 1.113.0.</p> </li> <li> <p>Update <code>cargo-shear@latest</code> to 1.13.4.</p> </li> <li> <p>Update <code>bpf-linker@latest</code> to 0.11.0.</p> </li> </ul> <h2>2.85.12</h2> <ul> <li> <p>Update <code>zola@latest</code> to 0.23.3.</p> </li> <li> <p>Update <code>wasm-tools@latest</code> to 1.256.0.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.2.10.</p> </li> <li> <p>Update <code>syft@latest</code> to 1.51.0.</p> </li> <li> <p>Update <code>prek@latest</code> to 0.4.13.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.4.</p> </li> <li> <p>Update <code>editorconfig-checker@latest</code> to 3.11.1.</p> </li> <li> <p>Update <code>cargo-tarpaulin@latest</code> to 0.37.1.</p> </li> <li> <p>Update <code>cargo-rdme@latest</code> to 2.2.1.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.8.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.85.13] - 2026-08-13</h2> <ul> <li> <p>Update <code>tombi@latest</code> to 1.3.3.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.5.</p> </li> <li> <p>Update <code>kingfisher@latest</code> to 1.113.0.</p> </li> <li> <p>Update <code>cargo-shear@latest</code> to 1.13.4.</p> </li> <li> <p>Update <code>bpf-linker@latest</code> to 0.11.0.</p> </li> </ul> <h2>[2.85.12] - 2026-08-12</h2> <ul> <li> <p>Update <code>zola@latest</code> to 0.23.3.</p> </li> <li> <p>Update <code>wasm-tools@latest</code> to 1.256.0.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.2.10.</p> </li> <li> <p>Update <code>syft@latest</code> to 1.51.0.</p> </li> <li> <p>Update <code>prek@latest</code> to 0.4.13.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.4.</p> </li> <li> <p>Update <code>editorconfig-checker@latest</code> to 3.11.1.</p> </li> <li> <p>Update <code>cargo-tarpaulin@latest</code> to 0.37.1.</p> </li> <li> <p>Update <code>cargo-rdme@latest</code> to 2.2.1.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.8.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/82cd3e7658a6f96c86c0234aeeda1748937cb0a1"><code>82cd3e7</code></a> Release 2.85.13</li> <li><a href="https://github.com/taiki-e/install-action/commit/4dd6c67d0ecd1fab76c6cecc5931e1239cc16add"><code>4dd6c67</code></a> Update <code>tombi@latest</code> to 1.3.3</li> <li><a href="https://github.com/taiki-e/install-action/commit/91cb1bb28383045bb69f87d336ede6db3c61927b"><code>91cb1bb</code></a> Update <code>mise@latest</code> to 2026.8.5</li> <li><a href="https://github.com/taiki-e/install-action/commit/83d968e89df664219ce13abb14808207a131cc64"><code>83d968e</code></a> Update <code>kingfisher@latest</code> to 1.113.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/f7ab7f5d0a3e5a8120f10f39cfc442b2f40642b0"><code>f7ab7f5</code></a> Update cargo-xwin manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/3faddd9e3002e0d2922192f5808a78c4118eb58c"><code>3faddd9</code></a> Update <code>cargo-shear@latest</code> to 1.13.4</li> <li><a href="https://github.com/taiki-e/install-action/commit/b4cb4b238691473c8bf1425b4d38120d5058dfc2"><code>b4cb4b2</code></a> Update <code>bpf-linker@latest</code> to 0.11.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/b20dedce73af6905cdc30d6611090c9b67557c8d"><code>b20dedc</code></a> Release 2.85.12</li> <li><a href="https://github.com/taiki-e/install-action/commit/952d13c8bb10d7e37f96fa2c8131338550a62663"><code>952d13c</code></a> ci: Skip cargo-rdme on x86_64 macOS</li> <li><a href="https://github.com/taiki-e/install-action/commit/c8724e7258d0b8f8188a94aec0c00ae9da81edd7"><code>c8724e7</code></a> Update <code>zola@latest</code> to 0.23.3</li> <li>Additional commits viewable in <a href="https://github.com/taiki-e/install-action/compare/v2.85.11...v2.85.13">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
1b278042de |
chore(ci): weekly renovation 2026-08-16 (#3826)
## Summary Weekly CI renovation check found the following updates: - `worktrunk`: 0.72.0 → 0.74.0 (MSRV 1.96, compatible with our 1.96.0) — `ci.yaml` ×2, `nightly.yaml` - `nushell`: 0.114.1 → 0.115.0 — `nightly.yaml`, `benchmarks.yaml`, `coverage.yaml`, `actions/test-setup`, and `scripts/codex-cloud/Taskfile.yaml` - `pre-commit`: 4.6.1 → 4.6.2 — `scripts/codex-cloud/Taskfile.yaml` - `PowerShell`: 7.6.4 → 7.6.5 — `scripts/codex-cloud/Taskfile.yaml` and the root `Taskfile.yaml`'s `setup-web` task The Codex Cloud archive checksums were recomputed from the new upstream tarballs, and the resulting `Taskfile.yaml` digest (`f14dbc89…`) is copied into both README launcher commands. The `setup-web` PowerShell pin came in as a follow-up commit: the initial sweep only grepped `.rs`/`.md`/`.toml` for stale versions, so the root `Taskfile.yaml`'s `PWSH_VERSION="7.6.4"` was missed. Nothing tests the two PowerShell pins against each other, so that one drifts silently — worth a note for future renovation runs. The `powershell_7.6.5-1.deb_amd64.deb` asset the `setup-web` branch downloads is present in the v7.6.5 release. ## Already up to date - Rust stable is 1.97.1, so MSRV and toolchain stay at 1.96 (latest stable − 1) — `Cargo.toml`, `tests/helpers/wt-perf/Cargo.toml`, `rust-toolchain.toml` need no change, and `flake.lock` is untouched. - `cargo-insta` 1.48.0, `cargo-nextest` 0.9.143, `cargo-llvm-cov` 0.8.7, `cargo-msrv` 0.19.3, `cargo-affected` 0.4.0, `cargo-udeps` 0.1.61, `lychee` 0.24.2 - Task 3.52.0 (mise, Codex Cloud) - Runner images: ubuntu-24.04, macos-15, windows-2022 ## Held back: zola 0.22.1 → 0.23.3 Not bumped. Zola 0.23.0 shipped [Tera2 + refactoring](https://github.com/getzola/zola/pull/3105), which is a templating-engine swap rather than a routine release. Building `docs/` with the 0.23.3 binary fails at the first line of `templates/base.html`: ``` ERROR error: Unknown tag --> base.html:1:4 | 1 | {% import "macros.html" as macros %} | ^^^^^^ ``` `templates/base.html` and `templates/macros.html` are the two files that use the `import`/`macro` pair, so the migration looks small, but it is template work with its own review rather than a pin bump — kept out of this PR so the rest can land. Raised separately. <details><summary>Verification</summary> - Every version above was read from the upstream source of truth: `crates.io` for the cargo tools, `nushell/nushell` and `PowerShell/PowerShell` releases, PyPI for pre-commit, and `static.rust-lang.org/dist/channel-rust-stable.toml` for Rust stable (1.97.1). - Checksums were computed from the downloaded archives and the extracted binaries were run (`nu --version` → `0.115.0`); the archive layouts (`nu-<ver>-x86_64-unknown-linux-gnu/nu`, top-level `pwsh`) are unchanged, so the `install_binary` paths still resolve. - All six edited YAML files parse. - The nushell bump was exercised against the shell-integration suite: `cargo test --features shell-integration-tests --test integration -- nushell` with 0.115.0 on `PATH`. 13 of 14 pass; `test_nushell_install_target_is_a_vendor_autoload_dir` fails — but it fails identically on the currently-pinned 0.114.1, and passes on *both* versions when run alone. It is a pre-existing shared-state race in the sandbox, not a regression from this bump: the test asserts against the real user `$nu.vendor-autoload-dirs` entry rather than one under its temp `HOME` (nu resolves the home dir from the passwd database, so the test's `HOME` override does not move it), and a sibling uninstall test in the same filter removes `wt.nu` from that shared directory. Noted rather than fixed here — it is unrelated to the pins. - The zola failure above was reproduced with the official 0.23.3 `x86_64-unknown-linux-gnu` release binary against this repo's `docs/`. </details> --------- Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> |
||
|
|
1e2e05cfb4 |
chore: update tend workflows (0.1.17 → 0.1.18) (#3824)
Automated nightly regeneration of tend's workflow files, picking up tend 0.1.18. **tend version:** 0.1.17 → 0.1.18 Notable changes: - `tend-mention`: both halves of the 👀 reaction now live in the `handle` job. Previously `verify` added the eyes and `handle` removed them, so a burst of mentions on one thread could cancel a queued `handle` — which allocates no runner and runs no steps, `always()` included — leaving the reaction stranded (max-sixty/tend#990). - `tend-review` / `tend-triage`: the eyes-removal lookup now paginates (`--paginate`, `per_page=100`). A thread with more than 30 reactions could push the bot's own eyes off the first page, so the removal silently found nothing (max-sixty/tend#990). - `tend check`: the secret audit now reports only org secrets this repo can actually read, instead of every org secret (max-sixty/tend#994). - `running-in-ci` skill: notes that fork PR reviews reach no successor session, and scopes PR-description claims to the merge base (max-sixty/tend#985, max-sixty/tend#992). Full comparison: https://github.com/max-sixty/tend/compare/0.1.17...0.1.18 Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> |
||
|
|
e3b3482fd0 |
chore: update tend workflows (0.1.15 → 0.1.17) (#3822)
Automated nightly regeneration of tend's workflow files. **tend version:** 0.1.15 → 0.1.17 **Notable changes** - 👀 reactions now mark a session in flight: the bot reacts when an issue or PR is opened, and the reaction comes off when the session ends (max-sixty/tend#974, max-sixty/tend#979). - Mention gating was reworked — coarser pre-check gates, tested poll scripts, and an anchor-based run window replace the hand-rolled matching (max-sixty/tend#965, max-sixty/tend#971). - Self-initiated fixes are now gated on cost as well as evidence, so the bot doesn't open a PR whose value doesn't justify the session (max-sixty/tend#960). - `tend check` reads the bot's own bypass verdict on repos where the actor list is withheld, instead of reporting a false FAIL (max-sixty/tend#976). - Weekly no longer trusts a re-anchored approval on a rebased dependency PR (max-sixty/tend#890), and review-reviewers is paused as a scheduled sweep, kept as a manual spot-check (max-sixty/tend#966). Compare: https://github.com/max-sixty/tend/compare/0.1.15...0.1.17 Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> |
||
|
|
c31e827cba |
chore: update tend workflows (0.1.14 → 0.1.15) (#3814)
Automated nightly regeneration of tend's workflow files. **tend version:** 0.1.14 → 0.1.15 **Notable changes** - **Rate-limit handling**: a maintainer can approve past the spike limit (max-sixty/tend#874), and `tend-mention` now skips comments on `tend-rate-limit`-labelled issues as well as `tend-outage` ones — the same self-trigger loop guard, widened to every issue tend files about its own health. - **Review flow**: a push is queued behind an examined-HEAD gate instead of cancelling the in-flight review (max-sixty/tend#903), the review is submitted before a fix is pushed (max-sixty/tend#834), a force-push triggers a re-review rather than trusting the re-anchored SHA (max-sixty/tend#884), and the `/code-review` second pass is unconditional (max-sixty/tend#937). - **CI monitoring**: both the check poll and the `gh run rerun --failed` poll now end terminally when the cap is hit instead of reading as done (max-sixty/tend#876, max-sixty/tend#951), and a failed GitHub-status probe no longer reads as "no incident" (max-sixty/tend#913). - **Nightly**: conflicted bot PRs are test-merged locally instead of filtered on the lazy `mergeable` field (max-sixty/tend#898), and mention runs skip the bot's own review and a third party's content-free approval (max-sixty/tend#916, max-sixty/tend#955). - **`tend check`**: an unreadable ruleset bypass list is reported as unknown rather than ungated (max-sixty/tend#825), environment names are read one per line and addressed encoded (max-sixty/tend#879), and `credential-environments` no longer points at the setting it rejects (max-sixty/tend#900) — this repo currently `SKIP`s that check, so its wording should improve here. Full comparison: https://github.com/max-sixty/tend/compare/0.1.14...0.1.15 Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> |
||
|
|
ab76101b0b |
chore: bump taiki-e/install-action from 2.85.10 to 2.85.11 (#3801)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.85.10 to 2.85.11. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.85.11</h2> <ul> <li> <p>Update <code>zola@latest</code> to 0.23.2.</p> </li> <li> <p>Update <code>wasm-bindgen@latest</code> to 0.2.127.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.12.3.</p> </li> <li> <p>Update <code>osv-scanner@latest</code> to 2.5.0.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.3.</p> </li> <li> <p>Update <code>kingfisher@latest</code> to 1.112.0.</p> </li> <li> <p>Update <code>editorconfig-checker@latest</code> to 3.10.0.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.85.11] - 2026-08-09</h2> <ul> <li> <p>Update <code>zola@latest</code> to 0.23.2.</p> </li> <li> <p>Update <code>wasm-bindgen@latest</code> to 0.2.127.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.12.3.</p> </li> <li> <p>Update <code>osv-scanner@latest</code> to 2.5.0.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.3.</p> </li> <li> <p>Update <code>kingfisher@latest</code> to 1.112.0.</p> </li> <li> <p>Update <code>editorconfig-checker@latest</code> to 3.10.0.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/7f4eb899022d8fe70b20c4f3de697aa85c309026"><code>7f4eb89</code></a> Release 2.85.11</li> <li><a href="https://github.com/taiki-e/install-action/commit/c17da6245a7fe549cefa05b31e3614ce0b16c2af"><code>c17da62</code></a> Update <code>zola@latest</code> to 0.23.2</li> <li><a href="https://github.com/taiki-e/install-action/commit/97e8291c2ba440a7119c03ebe3ed1e584a1f9b7f"><code>97e8291</code></a> Update <code>wasm-bindgen@latest</code> to 0.2.127</li> <li><a href="https://github.com/taiki-e/install-action/commit/91f9e5c61a2dc7936a8f404d01b7c1551b9c581a"><code>91f9e5c</code></a> Update <code>uv@latest</code> to 0.12.3</li> <li><a href="https://github.com/taiki-e/install-action/commit/bd0cb00440414f36db2f79bca8e27971bb63b2a3"><code>bd0cb00</code></a> Update <code>osv-scanner@latest</code> to 2.5.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/4def957aa80c252e2d4c61387c6a429d377907d1"><code>4def957</code></a> Update <code>mise@latest</code> to 2026.8.3</li> <li><a href="https://github.com/taiki-e/install-action/commit/3d149dc3890afe4774d158d353b5a3e55fe90f60"><code>3d149dc</code></a> Update <code>kingfisher@latest</code> to 1.112.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/20d4381a5cf6917520fde30f9ff52387410bfb6e"><code>20d4381</code></a> Update <code>editorconfig-checker@latest</code> to 3.10.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/583939ec0c8ee9c523cc60342d3d979ce6730f38"><code>583939e</code></a> codegen: Ignore clippy::assert_is_empty lint</li> <li>See full diff in <a href="https://github.com/taiki-e/install-action/compare/v2.85.10...v2.85.11">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
ec2aa4d154 |
chore: bump taiki-e/install-action from 2.85.8 to 2.85.10 (#3793)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.85.8 to 2.85.10. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.85.10</h2> <ul> <li> <p>Update <code>uv@latest</code> to 0.12.2.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.2.7.</p> </li> <li> <p>Update <code>cosign@latest</code> to 3.1.3.</p> </li> <li> <p>Update <code>coreutils@latest</code> to 0.10.0.</p> </li> <li> <p>Update <code>cargo-rdme@latest</code> to 2.2.0.</p> </li> <li> <p>Update <code>cargo-crap@latest</code> to 0.4.3.</p> </li> </ul> <h2>2.85.9</h2> <ul> <li> <p>Update <code>zola@latest</code> to 0.23.1.</p> </li> <li> <p>Update <code>wild@latest</code> to 0.10.0.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.2.</p> </li> <li> <p>Update <code>just@latest</code> to 1.58.0.</p> </li> <li> <p>Update <code>jaq@latest</code> to 3.1.1.</p> </li> <li> <p>Update <code>cargo-nextest@latest</code> to 0.9.143.</p> </li> <li> <p>Update <code>cargo-crap@latest</code> to 0.4.2.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.7.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.85.10] - 2026-08-07</h2> <ul> <li> <p>Update <code>uv@latest</code> to 0.12.2.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.2.7.</p> </li> <li> <p>Update <code>cosign@latest</code> to 3.1.3.</p> </li> <li> <p>Update <code>coreutils@latest</code> to 0.10.0.</p> </li> <li> <p>Update <code>cargo-rdme@latest</code> to 2.2.0.</p> </li> <li> <p>Update <code>cargo-crap@latest</code> to 0.4.3.</p> </li> </ul> <h2>[2.85.9] - 2026-08-06</h2> <ul> <li> <p>Update <code>zola@latest</code> to 0.23.1.</p> </li> <li> <p>Update <code>wild@latest</code> to 0.10.0.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.2.</p> </li> <li> <p>Update <code>just@latest</code> to 1.58.0.</p> </li> <li> <p>Update <code>jaq@latest</code> to 3.1.1.</p> </li> <li> <p>Update <code>cargo-nextest@latest</code> to 0.9.143.</p> </li> <li> <p>Update <code>cargo-crap@latest</code> to 0.4.2.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.7.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/6c6fd71fe4fb72c3697d269963d0e15df8adedad"><code>6c6fd71</code></a> Release 2.85.10</li> <li><a href="https://github.com/taiki-e/install-action/commit/37cec23487191ef9aef8b1315865bd6dc584bef4"><code>37cec23</code></a> Update zola manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/4914ea4fea5759852f8cda51753420130b883d65"><code>4914ea4</code></a> Update <code>uv@latest</code> to 0.12.2</li> <li><a href="https://github.com/taiki-e/install-action/commit/0ce64163d455e35fedc5f5925221d4a71f05c990"><code>0ce6416</code></a> Update <code>tombi@latest</code> to 1.2.7</li> <li><a href="https://github.com/taiki-e/install-action/commit/1f89e2fb52c482b53fcf083bf64b5abd5d6563ab"><code>1f89e2f</code></a> Update osv-scanner manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/65ef13f21e6dd200e402682be3b1bc896f6aa862"><code>65ef13f</code></a> Update kingfisher manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/9f6a5a8ec701c59d62ac1013b92714e7410b2cae"><code>9f6a5a8</code></a> Update <code>cosign@latest</code> to 3.1.3</li> <li><a href="https://github.com/taiki-e/install-action/commit/df08c38f9c0580a749efefc712ba563ff2107db5"><code>df08c38</code></a> Update <code>coreutils@latest</code> to 0.10.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/dc7bb1f807a876bf372de55372b320860efe4019"><code>dc7bb1f</code></a> Update <code>cargo-rdme@latest</code> to 2.2.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/9970698e35256036b84ecfb8a70b90fe068a934b"><code>9970698</code></a> Update <code>cargo-crap@latest</code> to 0.4.3</li> <li>Additional commits viewable in <a href="https://github.com/taiki-e/install-action/compare/v2.85.8...v2.85.10">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
ec574b6c35 |
ci: bump pinned cargo-nextest 0.9.143 and worktrunk 0.72.0 (#3783)
## Summary Weekly CI pin check found the following drift (these inline `version:` strings are invisible to Dependabot — it follows `Cargo.toml` deps and `uses: foo@vN` refs, not pinned versions inside `with:` blocks): - `cargo-nextest`: 0.9.140 → 0.9.143 (MSRV 1.91, compatible with our 1.96) — pinned in `coverage.yaml`, `actions/test-setup`, and `actions/claude-setup`; all three moved together. - `worktrunk`: 0.71.0 → 0.72.0 (MSRV 1.96, compatible with our 1.96) — the CI-installed `wt` that runs `wt hook pre-merge`, bumped to the current release; pinned in `ci.yaml` (×2) and `nightly.yaml`. ## Already up to date - `cargo-affected`: 0.4.0, `cargo-insta`: 1.48.0, `cargo-llvm-cov`: 0.8.7, `cargo-msrv`: 0.19.3, `cargo-udeps`: 0.1.61, `lychee`: 0.24.2 - `hustcer/setup-nu` (nushell): 0.114.1 — matches the current nushell release across all four call sites - Runner images: ubuntu-24.04, windows-2022 ## Notes - windows-2022 stays pinned ([actions/runner-images#12677](https://github.com/actions/runner-images/issues/12677) — windows-2025 lacks the D: drive). - **cargo-nextest 0.9.143 has nothing config-facing to adjust.** The 0.9.140 → 0.9.143 range is dynamic-library-search-path fixes (build-dir layout v2, `build.build-dir`, `[[example]]` targets), archive filterset fixes, an opt-in `junit.report-skipped` setting we don't set, and a listing progress bar. The one behavior change — ordering the Cargo artifact directory ahead of `deps` on the dylib search path, matching Cargo since 1.93 — doesn't affect this repo, which links no `dylib` dependency. - **worktrunk 0.72.0 is only exercised through `wt hook pre-merge`** in these three jobs, so the release's `wt merge` / `wt step push` two-tree changes and the `branch_outcome` JSON rename don't reach CI. The relevant one is the opposite direction: 0.72.0 fixes `wt` writing ANSI to a pipe and exiting 101 on `Broken pipe`, which is exactly the non-tty shape these jobs run in. - **`zola` is deliberately left at 0.22.1** — see below. ## Deferred: zola 0.22.1 → 0.23.2 `taiki-e/install-action`'s `tool: zola@0.22.1` in `check-docs` (and the matching pin in `publish-docs.yaml`) is behind, but 0.23.0 is not a routine bump. Upstream calls it "probably the most breaking version of Zola that will happen" ([CHANGELOG](https://github.com/getzola/zola/blob/master/CHANGELOG.md)): **shortcodes are removed entirely** and Tera is updated to v2 with its own [migration guide](https://github.com/Keats/tera/blob/master/MIGRATION.md). `docs/templates/shortcodes/` and `docs/templates/macros.html` both exist, so this needs a real docs-site migration rather than a version-string change, and it would land in the same PR as the live-site publish pin. Left for a separate change; flagging it here so it isn't silently skipped each week. Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> |
||
|
|
00ab0ffa26 |
Canonicalize benchmark fixtures and variants (#3761)
Benchmark fixtures still encoded the benchmark that first needed each repository state, which left overlapping recipes and variants after the earlier harness consolidation. This change reduces the fixture catalog to two provenance-based bases: `Generated` builds an ordinary Git repository locally, while `Imported` copies the pinned `rust-lang/rust` corpus. Worktree, branch, and remote-ref populations remain parameters on `Generated`; prune candidates and backdrop are overlays that work with either base. The generated base deliberately combines heterogeneous worktree states, history-spread branches, and optional remote refs so ordinary list, completion, picker, first-output, alias, remove, and prune benchmarks can share it. Imported history-spread branches and clean base-tip worktrees carry their own commits, preserving the base populations without making them incidental prune candidates when overlays advance the default branch. The benchmark matrix now keeps single-factor contrasts: list scaling uses the 1- and 8-worktree endpoints; alias dispatch has a startup floor, two population endpoints, and one warm/cold variable-resolution pair; completion keeps one full-surface case; remove and prune vary cache or hook state only where the command exercises it. Historical recipes, redundant cache rows, and intermediate scaling points are removed. Manual setup paths live under `target/`, and the benchmark guide documents the resulting fixture and cache model. Tests: `cargo run -- hook pre-merge --yes` after merging current `main` (4,571 tests); targeted Criterion test-mode runs; `cargo test -p wt-perf`; benchmark check, clippy, formatting, and diff checks. > _This was written by Codex on behalf of max-sixty_ |
||
|
|
683bc9b91b |
docs(ci): record that the release/signing environments admit any tag (#3775)
The `release` and `signing` deployment branch policies were pinned to `v*` tags; they now admit any tag, and this records that. The "Tag operations" ruleset covers `~ALL` tags, so the `v*` pattern carried no part of the gate — tend's `_tags_admin_gated` credits a tag entry on that ruleset alone and never reads the pattern. What the pattern did do was duplicate `release.yaml`'s own tag filter, which is broader: `**[0-9]+.[0-9]+.[0-9]+*` matches an unprefixed `1.2.3`, which a `v*` policy would then refuse. A release cut under that name would have stopped at `build-local-artifacts` — it names `signing` and waits only on `plan`, so the refusal lands before an artifact is built, not at a publish job. Dropping the pattern removes the only place the two could drift. This also brings the repo onto the shape install-tend's §3 recipe documents (`-f name='*' -f type=tag`), which worktrunk had deviated from. `uvx tend check` still reports 8/8. Also updates a stale `v*` reference in the `signing` job's comment in `release.yaml`. > _This was written by Claude Code on behalf of max-sixty_ --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
2dc9380670 |
docs(ci): the tend environment-deployments gap closed with #3749 (#3764)
Nightly sweep finding: the last paragraph of "Environment protection" in `.github/CLAUDE.md` describes a gap that closed the same night it was written. #3748 added the paragraph saying the generated `tend-*.yaml` files "still carry the bare `environment: tend`" and that `tend check`'s `environment-deployments` "fails until a `uvx tend@latest init` regen lands them on tend ≥ 0.1.14". #3749 merged 3 hours later and did exactly that regen — every generated job now reads `{name: tend, deployment: false}`, and tonight's `tend check` reports `environment-deployments` as `PASS`. Left as-is, the file tells the next reader to expect a failure that no longer happens and a regen that already ran. The rewrite keeps the durable half — the generated files aren't hand-edited, because `uvx tend@latest init` overwrites them — and states the resolution instead of the pending action. <details><summary>Evidence</summary> Current state of the generated files (all eight are identical in shape): ``` $ grep -A2 'environment:' .github/workflows/tend-nightly.yaml environment: name: tend deployment: false ``` Tonight's `tend check`, run by the nightly sweep: ``` PASS environment-deployments — No job files a deployment for the 'tend' environment ``` The three checks still failing (`credential-environments`, `claude-auth`, `repo-secret-allowlist`) are tracked in #3729 and are repository-settings changes, unrelated to this file. #3760 edits the same section but not these lines, so the two don't conflict. </details> No test accompanies this — it's a documentation-only change to a file no test reads. Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> |
||
|
|
5d4d0e8407 |
docs(ci): record the model credential as environment-scoped (#3760)
Documents `CLAUDE_CODE_OAUTH_TOKEN` moving out of repo-level storage and into the `tend` environment — the last operational secret still sitting where any workflow the repo runs could read it, and the remaining `repo-secret-allowlist` failure after #3748. The environment copy is set; the repo-level copy is deleted once this PR's own `tend-review` run comes back green. That run is the verification. An environment secret outranks a repo-level one of the same name, so a job naming `environment: tend` already reads the new value while both exist — which means the credential is exercised end to end before anything is removed, rather than after. Nothing about who reads the token changes. All eight readers — `triage`, `handle`, `fix-ci`, `nightly`, `review-runs`, `notifications`, `weekly`, `review` — already declare `environment: tend`. The lead sentence of "Environment protection" claimed environments hold "credentials that grant write access". That was never the set — the model credential grants no write access to anything in this repo, and it now lives in one. It states the set directly instead, with the reason `CODECOV_TOKEN` stays outside it. The `tend` row's "Read by" cell also picks up semicolons. `every tend-*.yaml job but relay, append-gist, both create-issue-on-*-failure jobs` reads as one four-item exclusion list, which would say `append-gist` doesn't read the token — it does. > _This was written by Claude Code on behalf of max-sixty_ Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
02a8dc829c |
chore: bump taiki-e/install-action from 2.85.7 to 2.85.8 (#3758)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.85.7 to 2.85.8. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.85.8</h2> <ul> <li> <p>Update <code>zizmor@latest</code> to 1.29.0.</p> </li> <li> <p>Update <code>typos@latest</code> to 1.49.0.</p> </li> <li> <p>Update <code>trivy@latest</code> to 0.73.0.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.2.6.</p> </li> <li> <p>Update <code>prek@latest</code> to 0.4.12.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.1.</p> </li> <li> <p>Update <code>convco@latest</code> to 0.7.1.</p> </li> <li> <p>Update <code>cargo-semver-checks@latest</code> to 0.50.0.</p> </li> <li> <p>Update <code>cargo-crap@latest</code> to 0.4.1.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.85.8] - 2026-08-04</h2> <ul> <li> <p>Update <code>zizmor@latest</code> to 1.29.0.</p> </li> <li> <p>Update <code>typos@latest</code> to 1.49.0.</p> </li> <li> <p>Update <code>trivy@latest</code> to 0.73.0.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.2.6.</p> </li> <li> <p>Update <code>prek@latest</code> to 0.4.12.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.1.</p> </li> <li> <p>Update <code>convco@latest</code> to 0.7.1.</p> </li> <li> <p>Update <code>cargo-semver-checks@latest</code> to 0.50.0.</p> </li> <li> <p>Update <code>cargo-crap@latest</code> to 0.4.1.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/cb33e69fad06166ca28a42b2575e4dadabf62ee8"><code>cb33e69</code></a> Release 2.85.8</li> <li><a href="https://github.com/taiki-e/install-action/commit/205431a517a990dfa58a0f22a02abd8cbef31c11"><code>205431a</code></a> Update <code>zizmor@latest</code> to 1.29.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/e734f91b32f269a08deefc4ceb37d4aa4747a26b"><code>e734f91</code></a> Update wild manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/2596ecb10ea03dec655fc75e41a3b0f4dad7bc42"><code>2596ecb</code></a> Update <code>typos@latest</code> to 1.49.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/a44271eb2d867e7b1cf13602d4e4f0a93eec2f5e"><code>a44271e</code></a> Update <code>trivy@latest</code> to 0.73.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/9b100e5f66ebcc3ef6c9e7380611a923118c93bd"><code>9b100e5</code></a> Update <code>tombi@latest</code> to 1.2.6</li> <li><a href="https://github.com/taiki-e/install-action/commit/f28498427840d9dc2242c579fe43460aad78fb48"><code>f284984</code></a> Update <code>prek@latest</code> to 0.4.12</li> <li><a href="https://github.com/taiki-e/install-action/commit/3b86746a2ded65050e00646b310ebba2a15bdaf6"><code>3b86746</code></a> Update <code>mise@latest</code> to 2026.8.1</li> <li><a href="https://github.com/taiki-e/install-action/commit/9287d185066eec8a77c1f11905ac9727db063430"><code>9287d18</code></a> Update just manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/32702bef0f7f8c45b9b179686f51a0f2739378c3"><code>32702be</code></a> Update <code>convco@latest</code> to 0.7.1</li> <li>Additional commits viewable in <a href="https://github.com/taiki-e/install-action/compare/v2.85.7...v2.85.8">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
6ad0439d79 |
chore: update tend workflows (0.1.13 → 0.1.14) (#3749)
Automated nightly regeneration of tend's workflow files. **tend version:** 0.1.13 → 0.1.14 ## Notable changes - **Jobs now name the `tend` environment with `deployment: false`** (max-sixty/tend#852), so GitHub stops filing a deployment record per run and posting it on the pull request. This is what the current `tend check` flags as `environment-deployments` (#3729) — regenerating clears it, and max-sixty/tend#853 makes `check` refuse the old shape going forward. - **`id-token: write` dropped from every tend job** — a side effect of removing the claude-smoke workflow and its `tend-manual` environment (max-sixty/tend#820). None of the remaining jobs use OIDC, so the permission was unused. - **`tend-mention` counts bot engagement outside `jq`** (max-sixty/tend#840). `gh api --paginate` applies `--jq` once per page, so `| length` emitted one count per page; past 100 comments the shell variable held `100\n7`, the numeric test errored, and the bot fell through to `should_run=false` — going quiet on exactly its most-engaged threads. - **Review and triage skill fixes** — the review-record guards now ignore synthetic reply containers (max-sixty/tend#835), `/code-review` is ported into a tend-owned skill (max-sixty/tend#819), and triage substitutes the real issue number into its PR-body templates instead of leaving a placeholder (max-sixty/tend#844). - **Outage reporting is more robust** — a stranded outage row now names the trigger it points at (max-sixty/tend#823), and marking a notification read tolerates a transient run-metadata fetch failure (max-sixty/tend#843). Full compare: https://github.com/max-sixty/tend/compare/0.1.13...0.1.14 Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> |
||
|
|
59c7320a78 |
ci: read TEND_BOT_TOKEN from an environment in every job (#3748)
Closes worktrunk's half of the `tend` environment migration (tend's `TODO.md`, "Finish moving the operational secrets into the `tend` environment", item 2). The environment is a secret scope, not a deploy target: its deployment branch policy is what stops a workflow pushed to a feature branch from reading the bot's PAT. That gate closes only when the repo-level copy of the secret is gone, since a job naming an environment still reads repo-level secrets. worktrunk kept one because these hand-maintained workflows read `TEND_BOT_TOKEN` outside tend's generated set. ## What changed | Job | Environment | Why that one | |---|---|---| | `benchmarks.yaml` `append-gist` (new) | `tend` | `schedule`-gated, so it runs on `main` | | `benchmarks.yaml` `create-issue-on-benchmark-failure` | `tend` | already `schedule`-gated | | `nightly.yaml` `create-issue-on-nightly-failure` | `tend` | already `schedule`-gated | | `release.yaml` `publish-winget` | `release` | runs on a `v*` tag push | | `release.yaml` `publish-homebrew` | `release` | runs on a `v*` tag push | Every job reading `TEND_BOT_TOKEN` now names an environment, so deleting the repo-level copy breaks nothing. ### The gist append moved into its own job The `benchmarks` job has no `if` gate, so putting `tend` on it would refuse a `workflow_dispatch` against a non-`main` ref — on-demand runs against a chosen branch are what that trigger is documented for. A job GitHub skips never requests its environment, so moving the append into a `schedule`-gated `append-gist` job keeps the policy off the dispatch path entirely. It reads `target/criterion` back from the artifact the `benchmarks` job already uploads. `create-issue-on-benchmark-failure` now `needs` both jobs, so a failed append still files an issue — previously it failed the `benchmarks` job directly. ### Why the release jobs get `release`, not `tend` A tag push is not bot-steerable and tag creation and update are already restricted to admins by the "Tag operations" ruleset, so a tag policy is a real boundary. The tag entry cannot go on `tend`: `tend check`'s `check_environment` pins that policy to exactly the protected branches and its `--fix` deletes anything else. `release` already exists with a `v*` tag policy and already holds `AUR_SSH_PRIVATE_KEY`, so no new environment and no new credential — `TEND_BOT_TOKEN` is seeded into it as a second copy. ### `deployment: false` Jobs naming `tend` use the mapping form. GitHub files a deployment record for every job that names an environment, against whatever ref the run belongs to; under `pull_request_target` that is the PR's own head, which is why PR timelines grew a "worktrunk-bot deployed to tend" line on every push. `deployment: false` drops the record and keeps the gate. The release jobs keep their records, which land in no PR timeline. ## Follow-up: one step, after merge `TEND_BOT_TOKEN` is **already seeded into the `release` environment** (read from the local `worktrunk-bot` gh config dir at `~/.config/gh-bots/worktrunk-bot`, so no new credential was minted and nothing was pasted). Verified: the token resolves to `worktrunk-bot` and has push on both `max-sixty/winget-pkgs` and `max-sixty/homebrew-worktrunk`. That leaves one step, and it must come **after** this PR merges: ``` gh secret delete TEND_BOT_TOKEN --repo max-sixty/worktrunk ``` Not before. On `main` today the gist append, both `create-issue-on-*-failure` jobs, and the two publish jobs still read the token with no environment named, so deleting the repo-level copy first would break the next benchmarks cron (03:47 UTC daily). Merging this PR is what makes the deletion safe. ## What this does not fix - `repo-secret-allowlist` still fails on `CLAUDE_CODE_OAUTH_TOKEN`, also at repo level. It cannot be read back either; separate item. - `environment-deployments` still fails on the generated `tend-*.yaml`, which pin tend 0.1.13 and carry the bare `environment: tend`. Those are regenerated by the published tend, and a regen also carries an unrelated `gh api --paginate` fix in `tend-mention.yaml`, so it belongs in its own PR. ## Verification - The `append-gist` script was run end-to-end against a real `benchmark-results-*` artifact from run 30976221483. It emits 40 rows whose `bench` names match the live gist's existing rows exactly, confirming the artifact round-trip preserves paths relative to `target/criterion`. - That a skipped `if` short-circuits the environment gate is confirmed by run 31066000517: `publish-cargo`, which names `environment: release`, completed as *skipped* on a `pull_request` from a non-tag ref rather than failing on the policy. - `actionlint` reports the same eight pre-existing shellcheck notes as `main`; no new findings. `pre-commit` passes. > _This was written by Claude Code on behalf of max-sixty_ |
||
|
|
970976bd32 |
Consolidate benchmark recipes and cases (#3721)
Benchmark fixtures had accumulated around individual call sites, leaving the same repository shapes and command modes expressed several ways. This change makes repository state the organizing concept: benchmark groups select semantic `FixtureRecipe`s, share table-driven cases, and retain separate fixtures only when a controlled contrast, destructive precondition, or disproportionate setup cost requires one. The real-repository list benchmarks now share one pinned `rust-lang/rust` fixture with eight worktrees and fifty branches spread across history. The list matrix keeps default, branch, warm, and cold coverage without maintaining several “real” repository handles. Remove and prune cases share the same case machinery, while the destructive large-repository prune state remains separate. The scheduled workflow now converts Criterion estimates directly with `jq`, removing the one-off Python converter and its tests. The benchmark guide records the canonical-fixture principle and the remaining recipe-to-group mapping. Tests: `cargo run -- hook pre-merge --yes` (4,551 tests); `cargo bench --bench list large_repository -- --test`; `cargo test -p wt-perf`; benchmark check, clippy, formatting, and diff checks. > _This was written by Codex on behalf of max-sixty_. |
||
|
|
5a5f5795c9 |
chore: bump taiki-e/install-action from 2.85.5 to 2.85.7 (#3739)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.85.5 to 2.85.7. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.85.7</h2> <ul> <li> <p>Update <code>wasmtime@latest</code> to 47.0.3.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.12.1.</p> </li> <li> <p>Update <code>rclone@latest</code> to 1.75.0.</p> </li> <li> <p>Update <code>kingfisher@latest</code> to 1.110.0.</p> </li> </ul> <h2>2.85.6</h2> <ul> <li> <p>Update <code>wasm-tools@latest</code> to 1.255.0.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.2.5.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.18.</p> </li> <li> <p>Update <code>cargo-neat@latest</code> to 0.5.3.</p> </li> <li> <p>Update <code>cargo-crap@latest</code> to 0.4.0.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.85.7] - 2026-08-02</h2> <ul> <li> <p>Update <code>wasmtime@latest</code> to 47.0.3.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.12.1.</p> </li> <li> <p>Update <code>rclone@latest</code> to 1.75.0.</p> </li> <li> <p>Update <code>kingfisher@latest</code> to 1.110.0.</p> </li> </ul> <h2>[2.85.6] - 2026-08-01</h2> <ul> <li> <p>Update <code>wasm-tools@latest</code> to 1.255.0.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.2.5.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.18.</p> </li> <li> <p>Update <code>cargo-neat@latest</code> to 0.5.3.</p> </li> <li> <p>Update <code>cargo-crap@latest</code> to 0.4.0.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/67729d5c413db75907f0ad1e39bb04b9c868ff60"><code>67729d5</code></a> Release 2.85.7</li> <li><a href="https://github.com/taiki-e/install-action/commit/d247d7efe4dd236c2b4dee4c768ae8993e3df073"><code>d247d7e</code></a> Update wasmtime manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/9197a82bb72ccea72eb87ca9bcf8dfeebceecb4a"><code>9197a82</code></a> Update zizmor manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/68f6cd570d5902077df155f8ef44867ad5f57fe7"><code>68f6cd5</code></a> Update <code>wasmtime@latest</code> to 47.0.3</li> <li><a href="https://github.com/taiki-e/install-action/commit/377ee3f6a005506fab9f724afd7eae3134bc1154"><code>377ee3f</code></a> Update <code>uv@latest</code> to 0.12.1</li> <li><a href="https://github.com/taiki-e/install-action/commit/8724fbfce1efccf3c603dcdece7882571347b0c7"><code>8724fbf</code></a> Update <code>rclone@latest</code> to 1.75.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/8d0062e663b7476d094ab4bc20c4436abdefb289"><code>8d0062e</code></a> Update mise manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/28977a596b3205a34299d9607ece4eed2c6932eb"><code>28977a5</code></a> Update <code>kingfisher@latest</code> to 1.110.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/b951679bfc703a3cdad770a495203180e58aeb3d"><code>b951679</code></a> Update cargo-semver-checks manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/1beb33eee6d086258184383af9a538940be190ed"><code>1beb33e</code></a> Release 2.85.6</li> <li>Additional commits viewable in <a href="https://github.com/taiki-e/install-action/compare/v2.85.5...v2.85.7">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
ecde50eabe |
chore: bump taiki-e/install-action from 2.85.4 to 2.85.5 (#3716)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.85.4 to 2.85.5. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.85.5</h2> <ul> <li> <p>Update <code>uv@latest</code> to 0.12.0.</p> </li> <li> <p>Update <code>syft@latest</code> to 1.50.0.</p> </li> <li> <p>Update <code>sccache@latest</code> to 0.17.0.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.16.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.85.5] - 2026-07-30</h2> <ul> <li> <p>Update <code>uv@latest</code> to 0.12.0.</p> </li> <li> <p>Update <code>syft@latest</code> to 1.50.0.</p> </li> <li> <p>Update <code>sccache@latest</code> to 0.17.0.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.16.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/6a1bd70eaac3c8bdf093356838d7ee09fda951cf"><code>6a1bd70</code></a> Release 2.85.5</li> <li><a href="https://github.com/taiki-e/install-action/commit/e55bdcf1dbf7a2b65f2a51365635e9b42fc25b1b"><code>e55bdcf</code></a> Update <code>uv@latest</code> to 0.12.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/360695b5ac7cbf7052eb841633b06cd5e5cf73cd"><code>360695b</code></a> Update <code>syft@latest</code> to 1.50.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/9dfbbc2988d91169e4279461e8b23ade4a670b52"><code>9dfbbc2</code></a> Update <code>sccache@latest</code> to 0.17.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/acc58332f7353bf8d3e368d3838b46513a4a90cb"><code>acc5833</code></a> Update <code>mise@latest</code> to 2026.7.16</li> <li><a href="https://github.com/taiki-e/install-action/commit/deaa28d948b4684cf00f14feb5a9267ae3792577"><code>deaa28d</code></a> Update cargo-neat manifest</li> <li>See full diff in <a href="https://github.com/taiki-e/install-action/compare/v2.85.4...v2.85.5">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
1acfbeb7f4 |
chore: regenerate tend workflows with 0.1.13 (#3720)
Regenerates the `tend-*.yaml` workflows against [tend 0.1.13](https://github.com/max-sixty/tend/releases/tag/0.1.13). Generated output only — no hand edits. The change that matters is that every workflow now names `environment: tend`, so the bot token and the model credential can live in a deployment environment gated to `main` instead of as repo-level secrets, which any workflow on any branch can read. `tend-mention` gains a secretless `relay` job to go with it: a review or review-comment event runs on `refs/pull/N/merge`, a ref no deployment-branch policy can admit, so `relay` holds no secrets and re-posts only identifiers as a `repository_dispatch`, which `verify` then re-reads from the API. Merging this on its own changes nothing operationally. The `tend` environment already exists on this repo with `TEND_BOT_TOKEN` in it, and a job naming an environment can still read repo-level secrets, so the gate closes only when the repo-level copies are deleted — a follow-up once the model credential is in the environment too. > _This was written by Claude Code on behalf of max-sixty_ |
||
|
|
dd453304ed |
test: fold the mock stub into the wt binary (#3712)
`cargo test --test integration` neither built nor rebuilt `mock-stub`: a
target filter deselects the dummy test that pulled it in, so a fresh
tree panicked ("mock-stub binary not found") and a warm one could run a
stale stub. The chain that compensated — the separate helper package,
its dummy `builds.rs`, the `default-members` entry, nextest's
experimental `build-bins` setup script, `workspace_bin()` — existed only
because cargo-dist ships every `[[bin]]`, and carried a TODO to collapse
once that changed. dist 0.30.2 does support per-binary exclusion now
(`[dist.binaries]`, since 0.29.0; verified with `dist plan`), but the
TODO's plan has a hole it predates: `cargo install worktrunk` installs
every feature-satisfied `[[bin]]`, and dist config doesn't govern
crates.io installs.
So the mock commands are now the `wt` binary itself. `mock_commands`
links `wt` under the mock's name (`gh`, `glab`, …), and `main()`
dispatches to the ported playback (`testing::mock_stub`) when
`WORKTRUNK_TEST_MOCK_CONFIG_DIR` is set, argv[0] is a foreign name, and
the config dir holds `<argv0>.json` for it. The existence check keeps wt
under a foreign argv[0] *without* a config being wt — the
argv0-validation security test symlinks it as `wt;touch` and must reach
wt's own rejection. The shipped binary already compiles the whole
`testing` module unconditionally, so this adds no new category of test
code to it. Windows links `wt.exe` with `hard_link` (copy fallback for
cross-drive dirs); the debug binary is ~67 MB, so per-mock copies stay
the fallback.
Every runner is now safe by construction — cargo rebuilds a package's
own binaries whenever its integration tests build, so there is no
separate artifact to go missing or stale. Deleted: the helper package,
the setup script plus `experimental = ["setup-scripts"]`, the
`default-members` trick, `workspace_bin()`, and `wt_bin()`'s dead
compile-time branch (unit-test targets get neither the runtime variable
nor the `option_env!` value, so the runtime resolution is the one
mechanism).
Validated locally: the pre-merge gate's full suite passes (4542/4542;
its doc step also caught unescaped `argv[0]` intra-doc links in the new
comments, fixed and `cargo doc -Dwarnings` re-verified). With all stub
artifacts purged from `target/`, plain `cargo test --test integration`
on mock-dependent tests builds them and passes — the command that used
to hit the trap. Two integration tests pin the dispatch's argv[0] edges
(an empty argv[0], and a non-UTF8 one), alongside the existing
`wt;touch` carve-out test.
The first commit is the investigation that preceded the fix: it verified
the `wt` binary itself was never subject to the staleness the mock-stub
was, and documented that in `tests/CLAUDE.md`; the fix then narrows that
paragraph further, since the gap it scoped no longer exists.
A two-reviewer subagent round (one prosecuting the diff against the
failure modes documented in the repo's own mock history — the #401/#407
Windows era, #547, #654, #127, #2544, #2730, #2744 — the other
adversarial) then hardened the dispatch. The reserved-name guard is
case-insensitive, matching the config probe, which goes through a
filesystem that equates `WT.json` with `wt.json` on macOS and Windows;
`command_name()` reads `args_os` — `env::args()` panics on a non-Unicode
argument, and this runs inside `main()` on every invocation (caught by
the tend review) — and returns `None` for a degenerate argv[0] instead
of panicking; the `.exe` suffix is stripped explicitly rather than via
`file_stem`, so a dotted mock name (`python3.11`) resolves identically
on every platform; and `copy_mock_binary` is now private —
`MockConfig::write` writes `<name>.json` before linking and is the only
way to create a mock, so a link cannot exist without its config, and the
dispatch's missing-config fall-through can only mean "wt under a foreign
name" (the argv0-validation tests' `wt;touch`), never a half-configured
mock that silently runs real wt with the mocked tool's arguments. The
`Option<&str>` mock helpers whose `None` arm produced exactly such
configless links lost the arm (every caller passed `Some`), and 25
redundant standalone link calls went with it.
The review also surfaced the one remaining spawn-a-stale-binary path
outside the suite: `wt-perf timeline` resolved a sibling `wt` by path,
checked only existence, and told the user to build it manually — so
`cargo run -p wt-perf -- timeline` after a `src/` edit silently measured
stale code. It now builds `wt` first and takes the artifact path from
cargo's `--message-format=json` report rather than deriving a sibling
location, so target-dir and profile overrides can't divert the build
away from where it's resolved; a release wt-perf builds and measures a
release wt. The build runs before the timeline's wall-clock measurement
starts, cargo's progress streams on stderr, and stdout keeps the
`--chrome` JSON contract.
> _This was written by Claude Code on behalf of max-sixty_
---------
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
|
||
|
|
3c2b4e44bb |
docs(ci): widen the TEND_BOT_TOKEN row past the Claude workflows (#3711)
`WINGET_TOKEN` sat in the `release` environment with no reference anywhere in the repo. Its last use was removed in December 2025; the February 2026 environment migration carried it across anyway. `publish-winget` also declares no `environment:`, so it could not have read a `release`-scoped secret even if the workflow still named it. What actually publishes to winget is `TEND_BOT_TOKEN`: as `GH_TOKEN` for the fork-sync step, and as the `token:` input to `vedantmgoyal9/winget-releaser`. Submission to `microsoft/winget-pkgs` is a plain fork-and-PR — there is no separate winget publisher credential — and the v0.71.0 PR there was opened by `worktrunk-bot`, the account that token belongs to. The secret is deleted. This commit closes the documentation gap that made it look load-bearing: the Tokens table described `TEND_BOT_TOKEN` as covering "All Claude workflows", which left winget publishing with no credential named anywhere. > _This was written by Claude Code on behalf of max-sixty_ Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
1db305f32f |
ci: bump pinned cargo-affected 0.4.0 and worktrunk 0.71.0 (#3708)
## Summary Weekly CI pin check found the following drift (these `version:` strings are invisible to Dependabot — it follows `Cargo.toml` deps and `uses: foo@vN` refs, not inline pins): - `cargo-affected`: 0.3.2 → 0.4.0 (MSRV 1.94, compatible with our 1.96) — pinned twice in `affected.yaml` (`collect-affected` + `affected-tests`); both moved together. - `worktrunk`: 0.69.2 → 0.71.0 (MSRV 1.96, compatible with our 1.96) — the CI-installed `wt`, bumped to the current release; pinned in `ci.yaml` (×2) and `nightly.yaml`. ## Already up to date - `cargo-insta`: 1.48.0, `cargo-nextest`: 0.9.140, `cargo-llvm-cov`: 0.8.7, `cargo-msrv`: 0.19.3, `cargo-udeps`: 0.1.61, `lychee`: 0.24.2 - `hustcer/setup-nu` (nushell): 0.114.1 - `zola`: 0.22.1 (taiki-e/install-action) - Runner images: ubuntu-24.04, macos-15, windows-2022 ## Notes - windows-2022 stays pinned (actions/runner-images#12677 — windows-2025 lacks the D: drive). - Both bumped tools' latest MSRVs are ≤ 1.96, so they stay compatible with the current toolchain. - **cargo-affected 0.4.0 DB compatibility:** the `cargo-affected-db-v1-*` cache marker in `affected.yaml` does **not** need bumping. The v0.3.2→v0.4.0 diff (`perf(collect): export each binary's coverage map once`, `Make status predict what run does`) touches `src/db.rs` only with `pub` → `pub(crate)` visibility changes — no SQLite schema change to the `fingerprint_components` / coverage tables — so an existing main DB deserializes unchanged. Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> |
||
|
|
aa988b37bb |
ci(release): scope SIGNPATH_API_TOKEN to a dedicated signing environment (#3704)
`SIGNPATH_API_TOKEN` sits at repo level, where every workflow the repo
runs can read it. It is referenced once, by the "Submit SignPath signing
request" step in `build-local-artifacts`. This joins that job to a new
`signing` environment so the token can be held there instead.
The environment already exists, with a `v*` tag policy and no reviewer
rule. It holds no secret yet, and this PR is safe to merge before it
does: an environment secret *overrides* a repository one of the same
name rather than displacing access to it, so until `signing` holds a
token the job keeps reading the repo-level copy and signing behaves
exactly as it does today.
Two steps remain, and both need the token value, which is write-only and
so has to be set by hand — or re-issued from the SignPath console, which
rotates it at the same time:
```
gh secret set SIGNPATH_API_TOKEN --repo max-sixty/worktrunk --env signing
```
```
gh secret delete SIGNPATH_API_TOKEN --repo max-sixty/worktrunk
```
The delete is what clears the drift, and it is the one step with an
ordering constraint: run it after the environment secret exists, or the
next release signs with an empty token.
## Why a new environment rather than the existing `release`
Reusing `release` looks cheaper, and the usual objection to it turns out
to be false: `release` has no reviewer rule, so it would not have pulled
an approval gate into the build phase. Its only protection rule is a
`v*` tag policy, which is why `publish-cargo` and `publish-aur` deploy
to it unattended today.
The real problem is the other direction. A job that joins an environment
can read *every* secret in it, and `release` holds
`AUR_SSH_PRIVATE_KEY`. Putting `build-local-artifacts` there would give
the build phase the AUR deploy key, so the change would trade one
over-broad grant for another rather than removing one. `signing` holds
the single token its single consumer needs.
Allowlisting the secret in `.config/tend.yaml` was the third option. It
records "intentionally repo-wide", which is the wrong posture for a
credential that becomes a real code-signing key once the SignPath OSS
application clears. It is a self-signed test certificate today, which is
the argument for moving it now rather than after.
<details><summary>Verification</summary>
`.github/CLAUDE.md` claimed the `release` environment required
"deployment approval from `@max-sixty`". That was the source of the
approval-gate objection, and it was wrong:
```
$ gh api repos/max-sixty/worktrunk/environments/release
"protection_rules": [{"id": 48355233, "type": "branch_policy"}]
$ gh api repos/max-sixty/worktrunk/environments/release/deployment-branch-policies
{"branch_policies": [{"name": "v*", "type": "tag"}]}
```
No `required_reviewers` rule. The v0.71.0 deployment confirms it
behaviorally — `waiting` to `queued` in one second, with no approval in
between:
```
$ gh api repos/max-sixty/worktrunk/deployments/5682057674/statuses
success 2026-07-30T20:46:46Z
in_progress 2026-07-30T20:45:00Z
queued 2026-07-30T20:44:57Z
waiting 2026-07-30T20:44:56Z
```
That doc line is rewritten here, into a table of which environment holds
what and which job reads it.
Three other things worth confirming before touching a dist-generated
file:
- **Hand edits survive.** `dist-workspace.toml` sets `allow-dirty =
["ci"]`, and no job anywhere runs `dist generate --check`. The custom
`publish-cargo`, `publish-winget`, and `publish-aur` jobs already only
exist because of this.
- **The environment doesn't serialize the matrix.** `publish-cargo` and
`publish-aur` both target `release` and ran concurrently in the v0.71.0
release (started `20:44:58` and `20:44:59`), so the five matrix legs
won't queue behind each other.
- **tend only scans repo-level secrets.** `AUR_SSH_PRIVATE_KEY` and
`WINGET_TOKEN` sit in the `release` environment and `tend check` passes
them without complaint, so moving `SIGNPATH_API_TOKEN` to an environment
is what clears the check.
</details>
## Risk
Low. The repo-level token remains readable until it is deleted, so
signing is unaffected by the merge. Even with no token reachable at all,
the signing step is `continue-on-error: true` while the certificate is a
test one, so it would fail without blocking the crates.io, Homebrew,
winget, or AUR publishes — the one step that is deliberately not
`continue-on-error` just recomputes a checksum over whatever zip is in
place.
One coupling is now load-bearing and is noted in the workflow: the `v*`
tag policy means setting `pr-run-mode = "upload"` in
`dist-workspace.toml` would make GitHub reject this job on a PR ref.
Today `pr-run-mode` defaults to `plan`, so `build-local-artifacts` is
skipped on pull requests entirely — which also means this PR's own CI
does not exercise the change. The first real exercise is the next
release tag.
Ref #3572 — the issue closes once the repo-level secret is deleted.
> _This was written by Claude Code on behalf of max-sixty_
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
||
|
|
62cc0af7f8 |
chore: bump taiki-e/install-action from 2.85.3 to 2.85.4 (#3659)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.85.3 to 2.85.4. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.85.4</h2> <ul> <li> <p>Update <code>uv@latest</code> to 0.11.33.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.15.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.6.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.85.4] - 2026-07-29</h2> <ul> <li> <p>Update <code>uv@latest</code> to 0.11.33.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.15.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.6.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/065d6a08a14e61e89fb0a4c10eecdbdef39c7d8e"><code>065d6a0</code></a> Release 2.85.4</li> <li><a href="https://github.com/taiki-e/install-action/commit/971197ad86f8f6f161d7a8d91f1d711c4c21f628"><code>971197a</code></a> Update <code>uv@latest</code> to 0.11.33</li> <li><a href="https://github.com/taiki-e/install-action/commit/3fc72354cdfd0f85327736793faab9b90a6282bb"><code>3fc7235</code></a> Update syft manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/7e230c19cf947f65a34e4e6f737c5f594c6779ba"><code>7e230c1</code></a> Update sccache manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/51f77e860854ede202e22ff29a94094601feca62"><code>51f77e8</code></a> Update <code>mise@latest</code> to 2026.7.15</li> <li><a href="https://github.com/taiki-e/install-action/commit/87ddca437422cbc964934ac7b2d8423c1838090a"><code>87ddca4</code></a> Update <code>biome@latest</code> to 2.5.6</li> <li>See full diff in <a href="https://github.com/taiki-e/install-action/compare/v2.85.3...v2.85.4">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
f1923e9344 |
chore: bump taiki-e/install-action from 2.85.2 to 2.85.3 (#3649)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.85.2 to 2.85.3. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.85.3</h2> <ul> <li> <p>Update <code>xh@latest</code> to 0.26.2.</p> </li> <li> <p>Update <code>ubi@latest</code> to 0.10.0.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.14.</p> </li> <li> <p>Update <code>martin@latest</code> to 1.13.0.</p> </li> <li> <p>Update <code>cargo-shear@latest</code> to 1.13.3.</p> </li> <li> <p>Update <code>cargo-binstall@latest</code> to 1.21.1.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.85.3] - 2026-07-28</h2> <ul> <li> <p>Update <code>xh@latest</code> to 0.26.2.</p> </li> <li> <p>Update <code>ubi@latest</code> to 0.10.0.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.14.</p> </li> <li> <p>Update <code>martin@latest</code> to 1.13.0.</p> </li> <li> <p>Update <code>cargo-shear@latest</code> to 1.13.3.</p> </li> <li> <p>Update <code>cargo-binstall@latest</code> to 1.21.1.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/18b1216eba7f8039b0f8d131d5473787f0edce68"><code>18b1216</code></a> Release 2.85.3</li> <li><a href="https://github.com/taiki-e/install-action/commit/3a7eb9d7de04335647f871d88d8831485be842be"><code>3a7eb9d</code></a> Update <code>xh@latest</code> to 0.26.2</li> <li><a href="https://github.com/taiki-e/install-action/commit/3d4a0c1c709bc0f907c2a23b1a17cf6296b08298"><code>3d4a0c1</code></a> Update uv manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/9e4a53cd83bbbd84b17bc14008d4b067b9e99edb"><code>9e4a53c</code></a> Update <code>ubi@latest</code> to 0.10.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/9f2f6a3c937466e1abfae58f471a04b8835bc6de"><code>9f2f6a3</code></a> Update <code>mise@latest</code> to 2026.7.14</li> <li><a href="https://github.com/taiki-e/install-action/commit/e026bd26eeb6a9542c62d43e1f98ced8d56ac346"><code>e026bd2</code></a> Update <code>martin@latest</code> to 1.13.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/f72efa0e99d8d9c15bf7fa6f14f0d4eb369fd084"><code>f72efa0</code></a> Update <code>cargo-shear@latest</code> to 1.13.3</li> <li><a href="https://github.com/taiki-e/install-action/commit/d19664f75e59dd9c49e306b357f78fcb72cd2711"><code>d19664f</code></a> Update <code>cargo-binstall@latest</code> to 1.21.1</li> <li><a href="https://github.com/taiki-e/install-action/commit/4d9bbfb56af57e022493493eecb97d07bf4fddd5"><code>4d9bbfb</code></a> Update biome manifest</li> <li>See full diff in <a href="https://github.com/taiki-e/install-action/compare/v2.85.2...v2.85.3">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
1b35950a9c |
test: simplify the integration suite (#3657)
This reduces duplicated and false-confidence integration coverage while preserving the suite's semantic and user-facing contracts. ## What changed - Replaces three overlapping list-layout suites with two representative CLI integrations, leaving exhaustive geometry at the direct layout layer. - Groups Git error render variants into labeled family snapshots and removes command-by-shell wrapper cross-products while retaining shell-specific conformance and regression cases. - Updates test-authoring guidance around boundary choice, minimal contrasts, and PTY use, and runs local and CI coverage through Nextest isolation. ## Results - Test catalog: 4,642 to 4,562 - Snapshots: 1,193 to 1,131 - Warm all-feature runtime: 84.70s to 78.17-80.35s - Full coverage: 97.32% of lines ## Testing - `cargo run -- hook pre-merge --yes` - `cargo llvm-cov nextest --features shell-integration-tests --summary-only` > _This was written by Claude Code on behalf of max_. |
||
|
|
062cf57d8e |
ci(affected): pin cargo-affected to the published 0.3.2 (#3634)
Both `Install cargo-affected` steps in `affected.yaml` installed from git with no rev, so the tool version on any run was whatever had last merged to cargo-affected's default branch. That cut both ways today: an upstream regression made `cargo affected run` abort with `git diff stdout was not valid UTF-8: invalid utf-8 sequence of 1 bytes from index 136455` on all three OSes, turning the advisory legs red repo-wide, and the fix (cargo-affected #69) then arrived the same way. Neither change is visible in this repo's history. cargo-affected publishes to crates.io as of 0.3.1, so it can carry a `version: "=X.Y.Z"` pin like every other `baptiste0928/cargo-install` block here. `=0.3.2` is what the unpinned installs already resolve to, so nothing changes behaviorally today. Two things it buys: - The crate joins the weekly tend pin sweep, which reads `version:` strings and now covers `affected.yaml`. The `cargo-install` action's own drift annotation starts firing for it too. - The existing "bump the `db-v{N}` cache marker if cargo-affected ships an on-disk schema change" rule becomes enforceable. It was unfollowable against a floating version, since the schema could change with no diff to notice. The pin appears twice, once per job, which is a new way to be wrong. A drift between the two hits `migrate_legacy_tables`, which drops and rebuilds the coverage tables rather than erroring, so selection silently degrades while the advisory job stays green. That is recorded in the workflow's cache-contract comment and in the tend skill's bump list. `cargo-affected`'s `rust-version` is 1.94, against this repo's pinned 1.96.0 toolchain. ## Testing The `affected tests (…, advisory)` legs on this PR exercise the change directly: they resolve `=0.3.2` from crates.io rather than from git. > _This was written by Claude Code on behalf of max_ Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
e6ca358846 |
chore: bump clechasseur/rs-cargo from 5.0.6 to 5.0.7 (#3624)
Bumps [clechasseur/rs-cargo](https://github.com/clechasseur/rs-cargo) from 5.0.6 to 5.0.7. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/clechasseur/rs-cargo/releases">clechasseur/rs-cargo's releases</a>.</em></p> <blockquote> <h2>v5.0.7</h2> <p>Patch release with updates to vulnerable dependencies.</p> <h2>What's Changed</h2> <ul> <li>chore(deps): bump fast-xml-parser from 5.9.3 to 5.10.1 in the npm_and_yarn group across 1 directory by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/clechasseur/rs-cargo/pull/427">clechasseur/rs-cargo#427</a></li> <li>fix: update <code>@clechasseur/rs-actions-core</code> to 8.0.3, run <code>npm update</code> to get vulnerability fixes by <a href="https://github.com/clechasseur"><code>@clechasseur</code></a> in <a href="https://redirect.github.com/clechasseur/rs-cargo/pull/429">clechasseur/rs-cargo#429</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/clechasseur/rs-cargo/compare/v5.0.6...v5.0.7">https://github.com/clechasseur/rs-cargo/compare/v5.0.6...v5.0.7</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/clechasseur/rs-cargo/commit/8ccb6817fc46c9af3b058a5a7b31932edb82cf13"><code>8ccb681</code></a> Merge pull request <a href="https://redirect.github.com/clechasseur/rs-cargo/issues/429">#429</a> from clechasseur/fix/update-deps</li> <li><a href="https://github.com/clechasseur/rs-cargo/commit/a11eddeaaecf8997cf0bcc3c24becc1f09624173"><code>a11edde</code></a> fix: bump version to 5.0.7</li> <li><a href="https://github.com/clechasseur/rs-cargo/commit/76685bb9f52e212a4c00f3ddc44842dc5281ca3d"><code>76685bb</code></a> fix: <code>npm update</code></li> <li><a href="https://github.com/clechasseur/rs-cargo/commit/48ea33b367c4c1b8b6fe7fefc203bce3d4e7158a"><code>48ea33b</code></a> fix: update <code>@clechasseur/rs-actions-core</code> to 8.0.3</li> <li><a href="https://github.com/clechasseur/rs-cargo/commit/b5a8184fad32ef9f11f0e29418d46300fa1a1986"><code>b5a8184</code></a> chore(deps): bump fast-xml-parser (<a href="https://redirect.github.com/clechasseur/rs-cargo/issues/427">#427</a>)</li> <li><a href="https://github.com/clechasseur/rs-cargo/commit/5b3bb18517d1d95a02ac4aa47ff2a192c63da94a"><code>5b3bb18</code></a> chore(deps): update dependency prettier to ^3.9.6 (<a href="https://redirect.github.com/clechasseur/rs-cargo/issues/422">#422</a>)</li> <li><a href="https://github.com/clechasseur/rs-cargo/commit/95bd32da1610f3c33ea573b0248b59d5416eefee"><code>95bd32d</code></a> chore(deps): update dependency oxlint to ^1.74.0 (<a href="https://redirect.github.com/clechasseur/rs-cargo/issues/420">#420</a>)</li> <li><a href="https://github.com/clechasseur/rs-cargo/commit/de86f7e954c523dbb840a840196e75d2b3f5a56c"><code>de86f7e</code></a> chore(deps): update actions-rust-lang/setup-rust-toolchain action to v1.17.0 ...</li> <li><a href="https://github.com/clechasseur/rs-cargo/commit/24b0f4bdb30da53e2b0bd096f5936f516c683c38"><code>24b0f4b</code></a> chore(deps): update dependency <code>@types/node</code> to ^24.13.3 (<a href="https://redirect.github.com/clechasseur/rs-cargo/issues/423">#423</a>)</li> <li><a href="https://github.com/clechasseur/rs-cargo/commit/3ad8301e71b20505890be273a34f0840a9f7701b"><code>3ad8301</code></a> chore(deps): update actions/setup-node action to v7 (<a href="https://redirect.github.com/clechasseur/rs-cargo/issues/426">#426</a>)</li> <li>See full diff in <a href="https://github.com/clechasseur/rs-cargo/compare/v5.0.6...v5.0.7">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
8ef63150b6 |
chore: bump taiki-e/install-action from 2.85.0 to 2.85.2 (#3623)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.85.0 to 2.85.2. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.85.2</h2> <ul> <li> <p>Update <code>prek@latest</code> to 0.4.11.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.13.</p> </li> <li> <p>Update <code>kingfisher@latest</code> to 1.109.0.</p> </li> </ul> <h2>2.85.1</h2> <ul> <li> <p>Update <code>vacuum@latest</code> to 0.30.0.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.11.32.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.12.</p> </li> <li> <p>Update <code>cyclonedx@latest</code> to 0.33.1.</p> </li> <li> <p>Update <code>cargo-neat@latest</code> to 0.5.2.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.85.2] - 2026-07-26</h2> <ul> <li> <p>Update <code>prek@latest</code> to 0.4.11.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.13.</p> </li> <li> <p>Update <code>kingfisher@latest</code> to 1.109.0.</p> </li> </ul> <h2>[2.85.1] - 2026-07-25</h2> <ul> <li> <p>Update <code>vacuum@latest</code> to 0.30.0.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.11.32.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.12.</p> </li> <li> <p>Update <code>cyclonedx@latest</code> to 0.33.1.</p> </li> <li> <p>Update <code>cargo-neat@latest</code> to 0.5.2.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/41049aa56687c35e0afa74eed4f09cec4f9afabf"><code>41049aa</code></a> Release 2.85.2</li> <li><a href="https://github.com/taiki-e/install-action/commit/dfcf36552b1b743e910b9b9b6b114a08e56a1e5e"><code>dfcf365</code></a> Update <code>prek@latest</code> to 0.4.11</li> <li><a href="https://github.com/taiki-e/install-action/commit/eea03ccfa855b965a301aa52424915fddc32f855"><code>eea03cc</code></a> Update <code>mise@latest</code> to 2026.7.13</li> <li><a href="https://github.com/taiki-e/install-action/commit/81ca2feb84748ed3fa514707ee1004f4f3ad715a"><code>81ca2fe</code></a> Update martin manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/cc90ed04bc1a258ea90a83789f24b759a77c9671"><code>cc90ed0</code></a> Update <code>kingfisher@latest</code> to 1.109.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/55639a3362f508fda5154d3451072205f5c32ca6"><code>55639a3</code></a> Update cargo-shear manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/3d7d7cd5ac7f994c1892ae0c06165095b9139094"><code>3d7d7cd</code></a> Release 2.85.1</li> <li><a href="https://github.com/taiki-e/install-action/commit/d09ccb4fe2105ac9ead6376f7a423ff88defeb57"><code>d09ccb4</code></a> Update <code>vacuum@latest</code> to 0.30.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/ac43dee1a92e482c0e244bdb0bb126908159e245"><code>ac43dee</code></a> Update <code>uv@latest</code> to 0.11.32</li> <li><a href="https://github.com/taiki-e/install-action/commit/49b16979f38f30e44b1f68af9115be9a6ffc5215"><code>49b1697</code></a> Update prek manifest</li> <li>Additional commits viewable in <a href="https://github.com/taiki-e/install-action/compare/v2.85.0...v2.85.2">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
4202cffe61 |
fix(ci): split ci by cadence so coverage uploads on every main commit (#3608)
## What prompted this Getting #3605 green ran into codecov reporting a `base_commit` three commits older than the real merge-base. This audits whether our config causes that. ## The cause Codecov picks a PR's base by walking back to the newest ancestor that has a coverage report. It used the real merge-base for PRs #3480, #3532 and #3602, and a stale one for #3603 and #3605. The difference is whether the merge-base uploaded a report. **29 of the last 40 main commits did not.** `ci` had one concurrency group for main pushes, and GitHub cancels the *pending* run in a group whenever a newer one joins, even with `cancel-in-progress: false`. So the question is how long a run holds the group, and a run isn't done until its slowest job is: | job | duration on main | |-----|------------------| | `fast-checks` | 2 min | | `code-coverage` | 3-4 min | | `test (windows)` | 11 min | | `collect affected coverage (windows)` | 110-129 min | Each main run held the group for ~2 hours, so nearly every subsequent main push was cancelled while queued, taking the 4-minute coverage job with it. Every cancelled main run's `updated_at` lands within a second of the next push's `created_at`. The 2 hours is real work, not queue: 2-5s from `created_at` to `started_at`, then 108 minutes inside `cargo affected collect` — 4181 tests under `-C instrument-coverage` with a per-test LLVM profile, ~5 GB of profraw. ## The fix: one workflow per cadence The three groups of jobs have incompatible needs, and one group was serving all of them. | workflow | cadence on main | why | |----------|-----------------|-----| | `ci` | every commit, ~11 min | required gate + fast checks | | `coverage` | every commit, keyed per-sha | a skipped upload leaves later PRs on a stale base | | `affected` | sampled, ~2 h | a DB a few commits old still anchors a correct superset | `affected` keeps exactly the grouping it has today, so its sampling is unchanged and deliberate. It just no longer drags the other two along. ### Scope of the impact The posted `codecov/patch` check scopes to the PR's own GitHub diff, so a stale base did **not** score PRs against other people's lines. On #3605 the posted 91.66% is exactly `github.rs`'s 11/12, while the stale-base compare object reported 64/65 across 13 files. What a stale base costs: - `codecov/project` reports "compared to \<stale sha\>" - the patch `auto` target is the stale base's project coverage (0.02pp here) - the compare API object widens to `base..head`, which is what made the investigation look like silence Separately, `test`/`lint`/`fast-checks` also stopped completing on main. Nothing load-bearing rode on that (they already ran on the PR), but it left `tend-ci-fix` with nothing to watch, since it doesn't fire on cancelled runs. ## Two smaller fixes - `ignore: "**/tests/**"` compiles to `.*/tests/.*` (confirmed against codecov's validator), which needs a leading directory and so never matched `tests/` itself. Inert today since `cargo llvm-cov` reports only `src/` (verified against a downloaded `cobertura.xml`), but now correct if that changes. Now `tests/**`. - `fail_ci_if_error` gated on `github.repository_owner`, which is the *base* repo's owner on a fork PR too, so the soft-fail its comment describes never applied. It keys off the head repo now. ## Docs The API behaviour was ours to misuse, not codecov's to explain. Three traps, all confirmed against the live API: - `file_report/<path>/` 404s with `coverage info not found` because the route swallows the trailing slash into the path. Without it the endpoint returns `line_coverage`. - `?pullid=N` always compares the PR's **current** head. `?base=&head=` asks about an earlier commit. - the compare response has no `patch_totals` key, and `.name` is `{base, head}` rather than a string, so a filename lookup silently matches nothing. A working recipe already existed in `running-tend`, but that skill is scoped to CI. `tests/CLAUDE.md` owns coverage investigation, so the queries go there and `running-tend` points at them instead of keeping a second copy. Re-running the corrected query against #3605's failing commit reproduces the miss exactly: `src/git/remote_ref/github.rs:164`, the `gh repo set-default` hint, matching what the session eventually found by hand. ## This PR demonstrates it It changes no Rust at all, only YAML and markdown. Codecov still reported a **10-file, 111-line patch** on its first commit, because it based the comparison on `203603909` rather than the real merge-base `32f380a27`. Every main commit in between has no report: | commit | ci run | report | |--------|--------|--------| | `32f380a27` | queued | no | | `9645e3e13` | cancelled | no | | `bcd1ffdfd` | cancelled | no | | `8865f20ab` | cancelled | no | Every one of those 111 patch lines belongs to somebody else's merged commit. It passed at 100% only because those commits are well covered. > _This was written by Claude Code on behalf of @max-sixty_ --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> |
||
|
|
901b79ab52 |
ci: bump pinned worktrunk to 0.69.2 (#3612)
Weekly CI pin bump. Only `worktrunk` drifted since last week — every other `baptiste0928/cargo-install` pin (cargo-msrv `0.19.3`, cargo-llvm-cov `0.8.7`, cargo-insta `1.48.0`, cargo-nextest `0.9.140`, cargo-udeps `0.1.61`, lychee `0.24.2`), plus `setup-nu` `0.114.1` and `zola@0.22.1`, is already at the latest upstream release. - **worktrunk** `=0.68.0` → `=0.69.2` (3 sites: `ci.yaml` ×2, `nightly.yaml`) Compatibility: worktrunk `0.69.2` declares `rust-version = 1.96`, matching the pinned toolchain (`rust-toolchain.toml` channel `1.96.0`), so it builds under `baptiste0928/cargo-install`. MSRV/toolchain needed no bump this week: current stable is `1.97.1`, so latest−1 is `1.96`, which is already what `Cargo.toml`, `tests/helpers/wt-perf/Cargo.toml`, and `rust-toolchain.toml` pin. Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> |
||
|
|
f1f1b50d85 |
docs(release): trim the signing archaeology now the path is proven (#3593)
Follow-up to #3590, now that v0.69.2 has shipped a signed Windows binary — verified against the published asset rather than the logs: ``` git-wt.exe: certificate table 8480 bytes wt.exe: certificate table 8472 bytes c4343fb5…1a43 *worktrunk-x86_64-pc-windows-msvc.zip (published .sha256 matches) ``` Comments only; no behavior change. The signing comments were written while the mechanism was still being guessed at, so they carried the failed attempts — a ten-line account of the zip-of-a-zip failure, a six-line account of the `…zip.zip` collision. The path is proven and the workflow now verifies itself, so what a reader needs is the current mechanism. Trimmed to that. One thing added rather than removed. `Recompute checksum` sits between two `continue-on-error` steps and looks like it should fold into the replace step above it. It must not: the signing steps are tolerant because publishing can't depend on a self-signed test certificate, while a checksum that doesn't match the shipped zip has to fail the release. That asymmetry is invisible in the YAML, so it's now stated — the next person to simplify this shouldn't have to rediscover it. > _This was written by Claude Code on behalf of max_ |
||
|
|
5e03e2863c |
docs(changelog): document the v0.69.2 drift (#3592)
Eleven commits landed on `main` while #3590 sat in CI, so they ship in v0.69.2 with no changelog entry. Most are user-facing, and three are data-loss fixes — exactly the drift the release skill's step-12 check exists to catch. The tag is held until this lands. Entries added, most-impactful first: - **#3589** — two ways shell integration deleted user data on a substring guess: an rc line that only *quotes* the init command, and a user's own `conf.d/wt.fish` deleted outright by `install`'s legacy cleanup. Plus forge detection moving from `host.contains("github")` to label-wise matching. - **#3585 + #3591** — truncate-in-place rc writes replaced by write-temp-then-rename, then generalized to every user-file write. - **#3578** — despite its `docs(step):` subject this carries three behavior fixes, including `wt step push` succeeding mid-rebase and moving the target branch onto a half-replayed history. - **#3588 + #3587** — conflict markers can no longer reach a commit via `wt step relocate --commit`, and `wt merge` refuses in its own name. - **#3554** — OpenCode marker writes could land in another session's worktree (thanks @4i3n6, who both reported and fixed it). Not documented, per convention: #3574 (doc comments only, no runtime or docs-site surface) and the three dependency bumps. Also corrects `.github/CLAUDE.md`, which lists three required status checks; there are four — `fast-checks` is required too, confirmed against the branch-protection API. Entries verified against the diffs by subagent. Two corrections came back and are folded in: the #3589 entry originally promised "two of them deleted" and described only one, and the #3578 entry mis-quoted the success line as `✓ Pushed to main` when it carries a commit count. > _This was written by Claude Code on behalf of max_ |
||
|
|
6b29c2802b |
Release v0.69.2 (#3590)
Cuts v0.69.2, and fixes the Windows code-signing path it depends on. ## The signing fix v0.69.1 shipped an unsigned `wt.exe` under a green run and a **Completed** SignPath signing request. `archive: false` (#3566) had already made the GitHub artifact name `worktrunk-x86_64-pc-windows-msvc.zip`, and SignPath names its download after the artifact — so with `output-artifact-directory: target/distrib` the signed zip landed at `worktrunk-x86_64-pc-windows-msvc.zip.zip`, beside the untouched unsigned build. The checksum step and the release upload both kept reading the original. Confirmed by parsing the published asset's PE certificate table: `size=0`. The download now goes to a scratch directory and whatever single file lands there replaces the built zip, so SignPath's naming isn't load-bearing. ## Verification, because this failure is invisible Signing is `continue-on-error` by design (self-signed test certificate pending SignPath's OSS review), so nothing in the logs distinguishes "signed" from "silently unsigned" — which is how it slipped through twice, two different ways. `.github/verify-windows-signature.py` reads the zip's PE certificate tables directly, and runs at two points with distinct jobs: - **before the overwrite** — an unsigned release is tolerable while the certificate is a test one; a corrupt one never is, so the replacement has to verify before it can clobber a good build. - **after** — reports what the release actually ships, which is the question the logs never answered. ## Rehearsed before landing The signing path only runs on a tag, so each question about it used to cost a release. This chain was instead run on a Windows runner against the already-published v0.69.1 zip (identical bytes, no build): ``` saved to …\target\signpath\worktrunk-x86_64-pc-windows-msvc.zip.zip git-wt.exe: certificate table 8480 bytes wt.exe: certificate table 8472 bytes → mv → target/distrib/worktrunk-x86_64-pc-windows-msvc.zip target/distrib/worktrunk-x86_64-pc-windows-msvc.zip: all 2 executables signed worktrunk-x86_64-pc-windows-msvc.zip: OK (checksum matches) ``` That also settled the open question behind #3556: SignPath returns the signed zip itself, not a wrapper, so `skip-decompress: true` is correct — the extract mode does explode it into loose files. ## Release contents `wt remove`'s fsmonitor sweep (#3581), the troubleshooting doc trim, and this fix. The two refactors in range (#3582, #3584) are behavior-preserving and omitted per convention. Local gate green (4547 passed). Changelog entries verified against the diffs by subagent; two claims corrected (the doc entry's rationale, and an overclaim attributing v0.69.0's unsigned binary to this bug rather than the separate upload failure #3566 fixed). Data-loss surface reviewed across the cumulative diff. > _This was written by Claude Code on behalf of max_ |
||
|
|
eda641546f |
chore: update tend workflows (0.1.11 → 0.1.12) (#3573)
Automated nightly regeneration of tend's workflow files via `uvx tend@latest init`, picking up the tend release since the last regen. **tend version:** 0.1.11 → 0.1.12 **Notable changes:** - **Notifications workflow tolerates transient `gh api` blips** — the notifications fetch now retries on non-JSON responses (e.g. an HTML error page returned with a 200 during an API blip) and skips the cycle cleanly instead of aborting the step red (max-sixty/tend#780). - **`review-runs` fails loud on transient `gh` errors** — a failed run enumeration no longer reports a false all-clear; it surfaces the error so the run isn't silently treated as clean (max-sixty/tend#784). - **`running-in-ci` guidance** — the bot no longer asks outside contributors to do work it can't do itself (max-sixty/tend#789). - **Harness bumps** — Claude harness version bumped to 2.1.215 (max-sixty/tend#782) and the default harness timeout raised to 5h50m (max-sixty/tend#790). Compare: https://github.com/max-sixty/tend/compare/0.1.11...0.1.12 Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> |
||
|
|
4ea2fe46a3 |
chore: bump taiki-e/install-action from 2.84.0 to 2.85.0 (#3570)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.84.0 to 2.85.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.85.0</h2> <ul> <li> <p>Support <code>wild</code> (alias: <code>wild-linker</code>). (<a href="https://redirect.github.com/taiki-e/install-action/pull/1949">#1949</a>)</p> </li> <li> <p>Support <code>bpf-linker</code>. (<a href="https://redirect.github.com/taiki-e/install-action/pull/1950">#1950</a>)</p> </li> <li> <p>Support <code>rafn</code>. (<a href="https://redirect.github.com/taiki-e/install-action/pull/1935">#1935</a>, thanks <a href="https://github.com/DarkWanderer"><code>@DarkWanderer</code></a>)</p> </li> <li> <p>Update <code>cargo-neat@latest</code> to 0.5.1.</p> </li> <li> <p>Update <code>zizmor@latest</code> to 1.28.0.</p> </li> <li> <p>Update <code>wasmtime@latest</code> to 47.0.2.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.11.31.</p> </li> <li> <p>Update <code>syft@latest</code> to 1.49.0.</p> </li> </ul> <h2>2.84.1</h2> <ul> <li> <p>Update <code>wasmtime@latest</code> to 47.0.1.</p> </li> <li> <p>Update <code>wasm-tools@latest</code> to 1.254.0.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.11.30.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.11.</p> </li> <li> <p>Update <code>cargo-neat@latest</code> to 0.5.0.</p> </li> <li> <p>Update <code>cargo-crap@latest</code> to 0.3.1.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.5.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.85.0] - 2026-07-23</h2> <ul> <li> <p>Support <code>wild</code> (alias: <code>wild-linker</code>). (<a href="https://redirect.github.com/taiki-e/install-action/pull/1949">#1949</a>)</p> </li> <li> <p>Support <code>bpf-linker</code>. (<a href="https://redirect.github.com/taiki-e/install-action/pull/1950">#1950</a>)</p> </li> <li> <p>Support <code>rafn</code>. (<a href="https://redirect.github.com/taiki-e/install-action/pull/1935">#1935</a>, thanks <a href="https://github.com/DarkWanderer"><code>@DarkWanderer</code></a>)</p> </li> <li> <p>Update <code>cargo-neat@latest</code> to 0.5.1.</p> </li> <li> <p>Update <code>zizmor@latest</code> to 1.28.0.</p> </li> <li> <p>Update <code>wasmtime@latest</code> to 47.0.2.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.11.31.</p> </li> <li> <p>Update <code>syft@latest</code> to 1.49.0.</p> </li> </ul> <h2>[2.84.1] - 2026-07-22</h2> <ul> <li> <p>Update <code>wasmtime@latest</code> to 47.0.1.</p> </li> <li> <p>Update <code>wasm-tools@latest</code> to 1.254.0.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.11.30.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.11.</p> </li> <li> <p>Update <code>cargo-neat@latest</code> to 0.5.0.</p> </li> <li> <p>Update <code>cargo-crap@latest</code> to 0.3.1.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.5.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/7572810d7dd469b651bb7793945692cf78da5dd7"><code>7572810</code></a> Release 2.85.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/d73fed906d8b5a8fbe1165c7635ef41dbf5e6ccd"><code>d73fed9</code></a> Update changelog</li> <li><a href="https://github.com/taiki-e/install-action/commit/20d0440ac8346c2da5bfa9bc79b6d50c30ee7658"><code>20d0440</code></a> Support bpf-linker (<a href="https://redirect.github.com/taiki-e/install-action/issues/1950">#1950</a>)</li> <li><a href="https://github.com/taiki-e/install-action/commit/05a01b63a23569d0bf6dde483954e312dce7d417"><code>05a01b6</code></a> Update vacuum manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/23a3cce147f42d0975d244f68a4af961ccd8fd53"><code>23a3cce</code></a> Update <code>cargo-neat@latest</code> to 0.5.1</li> <li><a href="https://github.com/taiki-e/install-action/commit/54ede987e296f0fc0b43f3f75d496577fad36a9c"><code>54ede98</code></a> Support rafn (<a href="https://redirect.github.com/taiki-e/install-action/issues/1935">#1935</a>)</li> <li><a href="https://github.com/taiki-e/install-action/commit/411aa4ba3c7fb6ad60a7421c46e881a3a1ceb8ad"><code>411aa4b</code></a> Support wild (<a href="https://redirect.github.com/taiki-e/install-action/issues/1949">#1949</a>)</li> <li><a href="https://github.com/taiki-e/install-action/commit/4427ee328dd40578670ed6724b4a766207e21f0e"><code>4427ee3</code></a> Update <code>zizmor@latest</code> to 1.28.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/68a5a96ea71119471050840e296140c66135d7b8"><code>68a5a96</code></a> Update <code>wasmtime@latest</code> to 47.0.2</li> <li><a href="https://github.com/taiki-e/install-action/commit/f276a80345c4641da04f6613887cc496c332c232"><code>f276a80</code></a> Update <code>uv@latest</code> to 0.11.31</li> <li>Additional commits viewable in <a href="https://github.com/taiki-e/install-action/compare/v2.84.0...v2.85.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
b636ae1a11 |
chore: bump max-sixty/tend from 0.1.11 to 0.1.12 (#3569)
Bumps [max-sixty/tend](https://github.com/max-sixty/tend) from 0.1.11 to 0.1.12. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/max-sixty/tend/releases">max-sixty/tend's releases</a>.</em></p> <blockquote> <h2>0.1.12</h2> <h3>Improved</h3> <ul> <li><strong>The default harness timeout rises from 3 hours (10800s) to 5h50m (21000s)</strong> in both Claude harnesses (<code>claude/action.yaml</code> headless, <code>claude-interactive/action.yaml</code> PTY), leaving a 10-minute buffer under GitHub Actions' hard 6-hour job cap instead of cutting long sessions off at 3 hours. (<a href="https://redirect.github.com/max-sixty/tend/pull/790">#790</a>)</li> </ul> <h3>Fixed</h3> <ul> <li><strong>The bot no longer asks an upstream maintainer to do verification work it couldn't do itself.</strong> When a check needs hardware or an environment CI doesn't have, the <code>running-in-ci</code> skill now escalates in order — do it yourself, add the capability to your own repo, ask a contributor, ask your own maintainer — and never hands the ask outward to someone reviewing the bot's change as a favor. (<a href="https://redirect.github.com/max-sixty/tend/pull/789">#789</a>)</li> <li><strong><code>list-recent-runs.sh</code> fails loud on a transient <code>gh</code> API error instead of silently reporting zero runs.</strong> A dropped <code>gh workflow list</code>/<code>gh run list</code> call previously read as a false all-clear that permanently skipped that window; it now retries with backoff and exits non-zero if every attempt fails. (<a href="https://redirect.github.com/max-sixty/tend/pull/784">#784</a>)</li> <li><strong>The notifications workflow tolerates a transient non-JSON response from the GitHub API</strong> instead of failing the step outright. (<a href="https://redirect.github.com/max-sixty/tend/pull/780">#780</a>)</li> </ul> <h3>Internal</h3> <ul> <li>Bumped pinned <code>claude_version</code> to 2.1.215. (<a href="https://redirect.github.com/max-sixty/tend/pull/782">#782</a>)</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/max-sixty/tend/blob/main/CHANGELOG.md">max-sixty/tend's changelog</a>.</em></p> <blockquote> <h2>0.1.12</h2> <h3>Improved</h3> <ul> <li><strong>The default harness timeout rises from 3 hours (10800s) to 5h50m (21000s)</strong> in both Claude harnesses (<code>claude/action.yaml</code> headless, <code>claude-interactive/action.yaml</code> PTY), leaving a 10-minute buffer under GitHub Actions' hard 6-hour job cap instead of cutting long sessions off at 3 hours. (<a href="https://redirect.github.com/max-sixty/tend/pull/790">#790</a>)</li> </ul> <h3>Fixed</h3> <ul> <li><strong>The bot no longer asks an upstream maintainer to do verification work it couldn't do itself.</strong> When a check needs hardware or an environment CI doesn't have, the <code>running-in-ci</code> skill now escalates in order — do it yourself, add the capability to your own repo, ask a contributor, ask your own maintainer — and never hands the ask outward to someone reviewing the bot's change as a favor. (<a href="https://redirect.github.com/max-sixty/tend/pull/789">#789</a>)</li> <li><strong><code>list-recent-runs.sh</code> fails loud on a transient <code>gh</code> API error instead of silently reporting zero runs.</strong> A dropped <code>gh workflow list</code>/<code>gh run list</code> call previously read as a false all-clear that permanently skipped that window; it now retries with backoff and exits non-zero if every attempt fails. (<a href="https://redirect.github.com/max-sixty/tend/pull/784">#784</a>)</li> <li><strong>The notifications workflow tolerates a transient non-JSON response from the GitHub API</strong> instead of failing the step outright. (<a href="https://redirect.github.com/max-sixty/tend/pull/780">#780</a>)</li> </ul> <h3>Internal</h3> <ul> <li>Bumped pinned <code>claude_version</code> to 2.1.215. (<a href="https://redirect.github.com/max-sixty/tend/pull/782">#782</a>)</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/max-sixty/tend/commit/f90bacaf61dc655fa6331ff558006cb730501772"><code>f90baca</code></a> chore: release 0.1.12 (<a href="https://redirect.github.com/max-sixty/tend/issues/791">#791</a>)</li> <li><a href="https://github.com/max-sixty/tend/commit/a843719b8c32b66a5e2c4408b7512dccb93771d7"><code>a843719</code></a> chore: bump harness timeout default to 5h50m (<a href="https://redirect.github.com/max-sixty/tend/issues/790">#790</a>)</li> <li><a href="https://github.com/max-sixty/tend/commit/ba5a7dee5fe23776255a5c759137269bd5a09c0a"><code>ba5a7de</code></a> fix(running-in-ci): don't ask outsiders to do work the bot can't do itself (#...</li> <li><a href="https://github.com/max-sixty/tend/commit/bbeb9d2cc5df849ed3cc517c8f5ce59ef38f7066"><code>bbeb9d2</code></a> fix(list-recent-runs): fail loud on transient gh errors instead of a false al...</li> <li><a href="https://github.com/max-sixty/tend/commit/8d217418307c9365e2a8e1d67c8e3435c6c675e6"><code>8d21741</code></a> chore: bump claude_version to 2.1.215 (<a href="https://redirect.github.com/max-sixty/tend/issues/782">#782</a>)</li> <li><a href="https://github.com/max-sixty/tend/commit/c3fd0c46d5f9bf4d202ffe7991b56e042f2b0348"><code>c3fd0c4</code></a> fix(notifications): tolerate transient non-JSON gh api responses (<a href="https://redirect.github.com/max-sixty/tend/issues/780">#780</a>)</li> <li><a href="https://github.com/max-sixty/tend/commit/44beffddf7930a82932ab7d7f70a9697b5d1200b"><code>44beffd</code></a> chore: regenerate workflows with tend 0.1.11 (<a href="https://redirect.github.com/max-sixty/tend/issues/778">#778</a>)</li> <li>See full diff in <a href="https://github.com/max-sixty/tend/compare/0.1.11...0.1.12">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
7b741d0791 |
fix(release): stop double-zipping the SignPath upload artifact (#3566)
## Summary - `actions/upload-artifact` wraps every upload in its own GitHub storage zip unless `archive: false`. The uploaded file here is already a zip (`worktrunk-x86_64-pc-windows-msvc.zip`), so the default produced a zip-of-a-zip — SignPath treated the outer storage wrapper as "the artifact" and the configured `<pe-file path="wt.exe">` never matched anything inside it. - Root-caused this against the real v0.69.0 release run: the SignPath dashboard shows the failed request's unsigned artifact as `unsigned-windows-zip.zip` (16.8MB, matching GitHub's storage-wrapper name, not the real filename) with error `Expected path to match exactly 1 item, but found 0` for `wt.exe`. - `archive: false` uploads the file as-is (single-file only, which is what we have), so SignPath receives the real zip directly, one level shallower — matching the artifact configuration as originally written. - Also fixes the v0.69.0 CHANGELOG's SignPath entry, which read "Signed with a test certificate" — overclaiming, since the actual signing attempt on that release failed. Reworded to describe the pipeline's intent rather than a specific run's result. v0.69.0 shipped with an unsigned Windows binary as a result (signing failure was masked by the intentional `continue-on-error`, so the release itself succeeded — this is exactly the non-blocking behavior that was designed in). This fix should make the next release's signing attempt succeed for real. ## Test plan - [x] `actionlint .github/workflows/release.yaml` — no new warnings - [x] Root cause confirmed directly against the SignPath dashboard's error details and artifact tab for the failed v0.69.0 signing request - [x] Verified `archive: false` semantics against `actions/upload-artifact@v7`'s own `action.yml` (single-file upload, uploaded as-is) > _This was written by Claude Code on behalf of Max_ |
||
|
|
481125801f |
ci: publish to crates.io via trusted publishing (#3564)
## What `publish-cargo` now mints its crates.io credential per run through `rust-lang/crates-io-auth-action` (GitHub Actions OIDC) instead of reading the `CARGO_REGISTRY_TOKEN` environment secret. The job gains `id-token: write` for the OIDC exchange and `contents: read` for checkout, narrowing it from the workflow-level `contents: write`. The token lives for about 30 minutes and the action's post step revokes it, so no long-lived publish credential exists anywhere. ## Why The stored token expires on a schedule, and each expiry is a silent trap: nothing breaks until the next release tag, which is exactly when you don't want to discover it. ## Prerequisite, already in place A Trusted Publisher is configured for `worktrunk` on crates.io — repository `max-sixty/worktrunk`, workflow `release.yaml`, environment `release`. It had to land before this merge, since otherwise `publish-cargo` would fail at the auth step on the next release tag. `CARGO_REGISTRY_TOKEN` can be deleted from the `release` environment once a release has gone out this way. `AUR_SSH_PRIVATE_KEY` stays. > _This was written by Claude Code on behalf of max_ |
||
|
|
8f55d15301 |
fix(release): preserve signed Windows zip filename, match checksum format (#3556)
## Summary - The SignPath action's `skip-decompress` defaults to `false`, so it would have extracted the returned zip's contents as loose files into `target/distrib/` instead of saving back a signed `worktrunk-x86_64-pc-windows-msvc.zip`. The checksum step would have silently hashed the still-unsigned zip, and the release would have shipped unsigned Windows binaries with no CI failure to flag it. - `sha256sum` without `-b` omits the `*` binary-mode marker; cargo-dist's own checksums use `<hash> *<filename>` (confirmed against a real release asset). Added `-b` to match. Confirmed via `gh run view` on #3553's own CI run that `build-local-artifacts` is skipped on PRs in this repo, so this code path has never actually executed — this is the first real fix before it runs for real on a tagged release. ## Test plan - [x] `actionlint .github/workflows/release.yaml` — no new warnings (same pre-existing shellcheck style notes as before) - [x] Verified `skip-decompress` behavior against the action's own `action.yml` input spec - [x] Verified checksum format against a real downloaded release asset (`v0.68.0`) > _This was written by Claude Code on behalf of Max_ |
||
|
|
5f8c301dec |
feat(release): sign Windows binaries via SignPath (#3553)
## Summary - Signs the Windows release zip (`wt.exe` + `git-wt.exe`) via [SignPath](https://signpath.io)'s free OSS code-signing program, using the `test-signing` policy (self-signed test certificate) while the project's Foundation-program application is under review. - Non-blocking (`continue-on-error`) so a signing hiccup can't take down crates.io/homebrew/winget/AUR publishing. - Recomputes the `.sha256` checksum after signing, since the signed zip's bytes differ from the unsigned one. - Uses a dedicated low-privilege `CI builds` SignPath identity (submitter-only), not an admin account. ## Test plan - [x] `actionlint` clean (only pre-existing shellcheck style warnings elsewhere in the file) - [x] Artifact configuration (zip containing `wt.exe` + `git-wt.exe`) validated against SignPath's own XML parser and against the real file layout inside a downloaded `v0.68.0` Windows release zip - [ ] First real Windows build after merge will be the first live signing round-trip through GitHub Actions — watch that release's CI run > _This was written by Claude Code on behalf of Max_ --------- Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> |
||
|
|
a7c4a7a120 |
refactor(wt-perf): place fixtures under target/wt-perf, not the cache dir (#3547)
## What Move every `wt-perf` on-disk fixture out of the per-user cache dir and under the cargo target dir at `<target>/wt-perf/`, resolved by a renamed `wt_perf_fixture_dir()`: - `setup <config>` fixtures → `<target>/wt-perf/<config>` (was `~/.cache/wt-perf/<config>`). - The rust-lang/rust clone and `prune-real` fixtures → `<target>/wt-perf/bench-repos/` (was `~/.cache/wt-perf/bench-repos/`). - `wt_perf_cache_dir()` → `wt_perf_fixture_dir()`. The target dir is derived from the **running executable's own path** (it lives inside whichever dir cargo built into — `<target>/debug/wt-perf`, `<target>/release/deps/<bench>`), so it honors `CARGO_TARGET_DIR`, a config-file `build.target-dir`, and cargo-llvm-cov's `target/llvm-cov-target/` — none of which a bare `CARGO_TARGET_DIR` env read covers. Falls back to `<workspace>/target` if the binary isn't under a recognizable profile dir. The `etcetera` dependency is dropped. - The `WT_PERF_CACHE_DIR` env override (and the empty-value guard it required) is removed; the benchmarks workflow now caches the deterministic `target/wt-perf/bench-repos` path directly. - In-process throwaway fixtures (`create_repo`) are unchanged — they keep using `tempfile::TempDir`. This reverses the location decision from #3542, which had moved these into `~/.cache/wt-perf`. ## Why `target/` is the conventional home for build/test-generated artifacts — gitignored, reaped by `cargo clean`, and already where criterion writes (`target/criterion`). Keeping every wt-perf fixture there gives one predictable location under the repo that `cargo clean` fully resets. Deriving the target dir from the running binary (rather than assuming `<workspace>/target`) keeps that property intact even when the target dir is relocated. ## Tradeoff (accepted) `target/` is **not** shared across git worktrees (worktrees don't share it) and is wiped by `cargo clean`. So the ~15 GiB `prune-real` rust clone re-clones per worktree and after every `cargo clean` — the cost #3542 avoided by using the cache dir. This is deliberate and documented on `wt_perf_fixture_dir`; it's cheap for the synthetic `setup` fixtures, which rebuild in seconds. ## Testing - `cargo build -p wt-perf --all-targets`, `cargo test -p wt-perf` — clean. - New unit test `target_dir_from_exe_finds_cargo_target` covers the resolution logic (relocated `CARGO_TARGET_DIR`, bench binary under `release/deps/`, cargo-llvm-cov's nested target, closest-profile-wins, and the outside-any-target fallback). - `pre-commit run --all-files` (fmt, clippy, yaml, typos, cargo-lock, custom hooks) — clean. - Smoke-tested end-to-end: `setup branches-2` lands at `<worktree>/target/wt-perf/branches-2` and writes nothing to `~/.cache/`; a copy of the binary run from a fake `<dir>/debug/wt-perf` correctly resolves fixtures to `<dir>/wt-perf/`, proving a relocated target dir is honored. > _This was written by Claude Code on behalf of Maximilian_ --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> |
||
|
|
4121dc979c |
refactor(wt-perf): cache fixtures in the platform cache dir, not /tmp or target/ (#3542)
## What Move `wt-perf`'s benchmark/debug fixture repos out of `std::env::temp_dir()` and `target/bench-repos/` into the per-user cache dir, resolved by a new `wt_perf_cache_dir()`: - `$WT_PERF_CACHE_DIR` if set, else `<cache>/wt-perf` via `etcetera::choose_base_strategy().cache_dir()` — `~/.cache/wt-perf` (or `$XDG_CACHE_HOME/wt-perf`) on Linux **and** macOS. This matches worktrunk's own base-dir convention (`src/config/user/path.rs` resolves user config through the same XDG-on-macOS strategy). - `setup <config>` fixtures → `<cache>/<config>` (was `temp_dir()/wt-perf-<config>`). `--path` still overrides. - Real cloned fixtures (`prune-real`, the rust-lang/rust clone) → `<cache>/bench-repos/` (was `target/bench-repos/`). - In-process throwaway fixtures (`create_repo`) are unchanged — they keep using `tempfile::TempDir`. ## Why Both old homes were wrong for a *reused* fixture (these are given stable names, persist between runs, and are referenced from docs and `-C <path>` — that's a cache, not a temp file): - **A fixed name in a shared `/tmp` (Linux)** collides across users: `/tmp` is sticky (`1777`), so a second user's `setup` hits `remove_dir_all().unwrap()` on a dir they don't own → `EPERM` → panic. It's also a predictable-path/TOCTOU hazard, and `systemd-tmpfiles` reaps `/tmp` per-file at 10 days by `max(atime,mtime,ctime)` — on a `noatime` mount an actively-*read* fixture still loses cold `.git/objects/pack/*.pack` mid-use → silent git corruption. - **On macOS**, `temp_dir()` is already `/var/folders/.../T` (per-user, `0700`), so the docs' `/tmp/wt-perf-*` paths were simply wrong there. - **`target/`** is per-worktree (git worktrees don't share it) and wiped by `cargo clean`, so the ~15 GiB rust clone was re-cloned per worktree — worst for the most expensive fixture, in a worktree-heavy workflow. The cache dir is per-user (no collision, no TOCTOU), stable and discoverable (docs/`-C` references still work), shared across worktrees (clone once per machine), and survives `cargo clean` — matching sccache, cargo, rustup, Go, Bazel, and Hugging Face, which all place large reusable caches there rather than in `/tmp`. ## Migration notes - First bench/setup run after this rebuilds the cache under the new location (the old `target/bench-repos/` is no longer read). Existing fixtures can be dropped with `rm -rf target/bench-repos`. - `.github/workflows/benchmarks.yaml` sets `WT_PERF_CACHE_DIR` and caches `$WT_PERF_CACHE_DIR/bench-repos`, so the cached path and the path wt-perf writes stay pinned together (no drift if a runner sets `$XDG_CACHE_HOME`); key unchanged. - Docs (`benches/CLAUDE.md`, `src/commands/CLAUDE.md`) updated to the new paths, noting that `wt-perf setup` prints the exact path. ## Testing - `cargo build --workspace --all-targets`, `cargo clippy --workspace --all-targets --features shell-integration-tests -- -D warnings` — clean. - `cargo test -p wt-perf` — passes. - Smoke-tested default resolution (`~/.cache/wt-perf/…` on macOS), `$WT_PERF_CACHE_DIR` override, and the `prune-real --path` rejection (now names the resolved cache path). > _This was written by Claude Code on behalf of Maximilian_ --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> |
||
|
|
89b58e2522 |
chore: bump taiki-e/install-action from 2.83.3 to 2.84.0 (#3529)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.83.3 to 2.84.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.84.0</h2> <ul> <li> <p>Support <code>d2</code>. (<a href="https://redirect.github.com/taiki-e/install-action/pull/1944">#1944</a>)</p> </li> <li> <p>Support <code>protoc-gen-connect-openapi</code>. (<a href="https://redirect.github.com/taiki-e/install-action/pull/1922">#1922</a>, thanks <a href="https://github.com/JasterV"><code>@JasterV</code></a>)</p> </li> <li> <p>Update <code>convco@latest</code> to 0.7.0. (<a href="https://redirect.github.com/taiki-e/install-action/pull/1941">#1941</a>, thanks <a href="https://github.com/graelo"><code>@graelo</code></a>)</p> </li> <li> <p>Update <code>just@latest</code> to 1.57.0.</p> </li> <li> <p>Update <code>cargo-semver-checks@latest</code> to 0.49.0.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.2.4.</p> </li> <li> <p>Update <code>cosign@latest</code> to 3.1.2.</p> </li> </ul> <h2>2.83.4</h2> <ul> <li> <p>Update <code>vacuum@latest</code> to 0.29.10.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.11.29.</p> </li> <li> <p>Update <code>syft@latest</code> to 1.48.0.</p> </li> <li> <p>Update <code>prek@latest</code> to 0.4.10.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.7.</p> </li> <li> <p>Update <code>cargo-shear@latest</code> to 1.13.2.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.84.0] - 2026-07-20</h2> <ul> <li> <p>Support <code>d2</code>. (<a href="https://redirect.github.com/taiki-e/install-action/pull/1944">#1944</a>)</p> </li> <li> <p>Support <code>protoc-gen-connect-openapi</code>. (<a href="https://redirect.github.com/taiki-e/install-action/pull/1922">#1922</a>, thanks <a href="https://github.com/JasterV"><code>@JasterV</code></a>)</p> </li> <li> <p>Update <code>convco@latest</code> to 0.7.0. (<a href="https://redirect.github.com/taiki-e/install-action/pull/1941">#1941</a>, thanks <a href="https://github.com/graelo"><code>@graelo</code></a>)</p> </li> <li> <p>Update <code>just@latest</code> to 1.57.0.</p> </li> <li> <p>Update <code>cargo-semver-checks@latest</code> to 0.49.0.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.2.4.</p> </li> <li> <p>Update <code>cosign@latest</code> to 3.1.2.</p> </li> </ul> <h2>[2.83.4] - 2026-07-17</h2> <ul> <li> <p>Update <code>vacuum@latest</code> to 0.29.10.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.11.29.</p> </li> <li> <p>Update <code>syft@latest</code> to 1.48.0.</p> </li> <li> <p>Update <code>prek@latest</code> to 0.4.10.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.7.</p> </li> <li> <p>Update <code>cargo-shear@latest</code> to 1.13.2.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/a6b2e2dcd845ddd7f509ce4f3ed3d922b80cc5d9"><code>a6b2e2d</code></a> Release 2.84.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/fbdd9c50c029b1f2d5667c090563e4a31cc3f43c"><code>fbdd9c5</code></a> Update cargo-neat manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/424c5f90440984601897d473b7936cc3fd52bda8"><code>424c5f9</code></a> Update changelog</li> <li><a href="https://github.com/taiki-e/install-action/commit/a1fa02c1f9b8ef65d443ad6b3f0b99f5863b6f4f"><code>a1fa02c</code></a> Support <code>protoc-gen-connect-openapi</code> (<a href="https://redirect.github.com/taiki-e/install-action/issues/1922">#1922</a>)</li> <li><a href="https://github.com/taiki-e/install-action/commit/9e22773f98774c41688b7cc39a5f7f7eaa4ca97d"><code>9e22773</code></a> Update DEVELOPMENT.md</li> <li><a href="https://github.com/taiki-e/install-action/commit/8d5009fee2da9de26fee96bb727c2df318ffce42"><code>8d5009f</code></a> Support d2</li> <li><a href="https://github.com/taiki-e/install-action/commit/5193316cc852ca0f37d4819875e939522c4f7c47"><code>5193316</code></a> Update <code>tombi@latest</code> to 1.2.4</li> <li><a href="https://github.com/taiki-e/install-action/commit/4c740c71c8320819d812216022c3ff178e1a3394"><code>4c740c7</code></a> Update <code>tombi@latest</code> to 1.2.3</li> <li><a href="https://github.com/taiki-e/install-action/commit/de240ff26f6e8b33bacd85a1a7c621c92d8d7c70"><code>de240ff</code></a> Update <code>just@latest</code> to 1.57.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/dfca8548668aebabd66da598ea31d87a03819d43"><code>dfca854</code></a> Update <code>cargo-semver-checks@latest</code> to 0.49.0</li> <li>Additional commits viewable in <a href="https://github.com/taiki-e/install-action/compare/v2.83.3...v2.84.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
013d1cc221 |
chore: bump KSXGitHub/github-actions-deploy-aur from 4.1.3 to 4.2.0 (#3472)
Bumps [KSXGitHub/github-actions-deploy-aur](https://github.com/ksxgithub/github-actions-deploy-aur) from 4.1.3 to 4.2.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/ksxgithub/github-actions-deploy-aur/releases">KSXGitHub/github-actions-deploy-aur's releases</a>.</em></p> <blockquote> <h2>v4.2.0</h2> <p>Add a feature to sync AUR repo (<a href="https://redirect.github.com/KSXGitHub/github-actions-deploy-aur/pull/52">KSXGitHub/github-actions-deploy-aur#52</a>).</p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/KSXGitHub/github-actions-deploy-aur/commit/084b0d9b15415bf9cdb65d44dad1efe37a354050"><code>084b0d9</code></a> style: consistency (<a href="https://redirect.github.com/ksxgithub/github-actions-deploy-aur/issues/55">#55</a>)</li> <li><a href="https://github.com/KSXGitHub/github-actions-deploy-aur/commit/9e2f21095c586521806151200746082d8e02bb90"><code>9e2f210</code></a> fix: force-add <code>PKGBUILD</code> and <code>.SRCINFO</code> in the asset_dir/assets path (<a href="https://redirect.github.com/ksxgithub/github-actions-deploy-aur/issues/53">#53</a>)</li> <li><a href="https://github.com/KSXGitHub/github-actions-deploy-aur/commit/7acb32fe8c43848121eee16dd39d8294ec2bf25b"><code>7acb32f</code></a> feat: full asset sync (<a href="https://redirect.github.com/ksxgithub/github-actions-deploy-aur/issues/52">#52</a>)</li> <li>See full diff in <a href="https://github.com/ksxgithub/github-actions-deploy-aur/compare/v4.1.3...v4.2.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
99704db62f |
chore: bump taiki-e/install-action from 2.83.2 to 2.83.3 (#3497)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.83.2 to 2.83.3. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.83.3</h2> <ul> <li> <p>Update <code>release-plz@latest</code> to 0.3.160.</p> </li> <li> <p>Update <code>prek@latest</code> to 0.4.9.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.6.</p> </li> <li> <p>Update <code>dprint@latest</code> to 0.55.2.</p> </li> <li> <p>Update <code>cargo-dinghy@latest</code> to 0.8.5.</p> </li> <li> <p>Update <code>cargo-binstall@latest</code> to 1.21.0.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.4.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.83.3] - 2026-07-16</h2> <ul> <li> <p>Update <code>release-plz@latest</code> to 0.3.160.</p> </li> <li> <p>Update <code>prek@latest</code> to 0.4.9.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.6.</p> </li> <li> <p>Update <code>dprint@latest</code> to 0.55.2.</p> </li> <li> <p>Update <code>cargo-dinghy@latest</code> to 0.8.5.</p> </li> <li> <p>Update <code>cargo-binstall@latest</code> to 1.21.0.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.4.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/ed67fa35ac944f3a9b33f12c4dd43b6f31a47e20"><code>ed67fa3</code></a> Release 2.83.3</li> <li><a href="https://github.com/taiki-e/install-action/commit/618fa5589cc587c869ec39ae0606a6cf6ef03c0b"><code>618fa55</code></a> Update prek manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/47579092c792f14738b668ee240d199bcad0d8e2"><code>4757909</code></a> Update zizmor manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/f1fa00538cc2e7231cb60e4d47c24597e0c387b7"><code>f1fa005</code></a> Update uv manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/aa8dc906017e56077bc125256c4d9301b1cde72a"><code>aa8dc90</code></a> Update <code>release-plz@latest</code> to 0.3.160</li> <li><a href="https://github.com/taiki-e/install-action/commit/b9654978ff643e657a453245addf012127caa2c5"><code>b965497</code></a> Update <code>prek@latest</code> to 0.4.9</li> <li><a href="https://github.com/taiki-e/install-action/commit/7aab3a9c373d60a23a5b89c212174c0baa6a0fa0"><code>7aab3a9</code></a> Update <code>mise@latest</code> to 2026.7.6</li> <li><a href="https://github.com/taiki-e/install-action/commit/bfee8d1ca4d6f82a5c3f7151f046e75e6c202ff5"><code>bfee8d1</code></a> Update kingfisher manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/b65771b2e228b44f33eb596fbf78979075cd8aa7"><code>b65771b</code></a> Update <code>dprint@latest</code> to 0.55.2</li> <li><a href="https://github.com/taiki-e/install-action/commit/20468927b3c1d5f14e6c4c1379ced0c6cc1ed103"><code>2046892</code></a> Update <code>cargo-dinghy@latest</code> to 0.8.5</li> <li>Additional commits viewable in <a href="https://github.com/taiki-e/install-action/compare/v2.83.2...v2.83.3">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
5967df2dfc | chore(ci): weekly renovation 2026-07-19 (#3518) | ||
|
|
a1332d46bd |
chore: update tend workflows (0.1.10 → 0.1.11) (#3500)
Automated nightly regeneration of tend's workflow files, picking up the upstream release. **tend version:** 0.1.10 → 0.1.11 **Notable changes** (consumer-relevant): - Skip no-op `tend-mention` sessions triggered by the bot's own comments — a new pre-mention guard in the generated `tend-mention.yaml` short-circuits before the engagement heuristics (max-sixty/tend#751). - Respond to actionable bot self-reviews instead of exiting as a self-loop: a review the review workflow leaves on its own PR is the bot's reviewer role, so it gets actioned rather than silently skipped (max-sixty/tend#762). - Sandbox: adopter levers to reach inside the Claude-family sandbox, and derive the sandbox `PATH` from the runner's `PATH` (max-sixty/tend#768, max-sixty/tend#767). - `running-in-ci`: permit maintainer-invited upstream contributions, and prohibit self-authored attribution sign-offs (max-sixty/tend#770, max-sixty/tend#773). - Action reliability: self-heal duplicate `tend-outage` issues from concurrent leg failures, and recover dropped cron ticks in list-recent-runs via a previous-run anchor (max-sixty/tend#744, max-sixty/tend#753). Compare: https://github.com/max-sixty/tend/compare/0.1.10...0.1.11 Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> |
||
|
|
8ab797f595 | chore: bump max-sixty/tend from 0.1.10 to 0.1.11 (#3496) |