CI: fetch full history for release-gate (shallow clone broke commit-e… #11
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: release-gate | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| branches: [main] | |
| workflow_dispatch: | |
| jobs: | |
| validate: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| with: | |
| # Full history: the release seal validates that the bundle's recorded | |
| # evidence commit (e.g. 9062b07) exists in git history. A shallow | |
| # depth-1 clone only has the tip commit, which fails that check. | |
| fetch-depth: 0 | |
| - uses: actions/setup-python@v5 | |
| with: | |
| python-version: "3.11" | |
| - name: Install deps | |
| run: pip install pyyaml | |
| - name: Release integrity gate | |
| run: python3 scripts/validate.py --repo . | |
| - name: Regeneration idempotence (drift check) | |
| run: | | |
| # NOTE: drafts/ is NOT committed (maintainer-private). The drift | |
| # check runs against the committed generated content only: convert | |
| # must be a no-op on a clean release tree. | |
| set -euo pipefail | |
| if [ -d ./drafts ]; then | |
| python3 scripts/convert.py --repo . --drafts ./drafts | |
| fi | |
| if ! git diff --exit-code -- skills references templates persona.md evals; then | |
| echo "::error::Generated content drift detected — regenerate and commit." | |
| exit 1 | |
| fi |