Skip to content

fix(ci): stop the seal check and the auto-tag blocking releases - #52

Merged
easel merged 3 commits into
mainfrom
fix/release-tag-title-parsing
Sep 22, 2026
Merged

easel merged 3 commits into
mainfrom
fix/release-tag-title-parsing

Conversation

@easel

@easel easel commented Sep 22, 2026 •

Copy link
Copy Markdown
Collaborator

Three release-plumbing fixes found while cutting v0.14.0.

The seal check blocked the deploy on content that passed review

pages.yml called innsigle verify --all raw, which fails on STALE.
tests/validate-innsigle.sh — the gate the website workflow runs, and the one
a contributor sees on a pull request — treats an unsigned or stale page as a
warning and fails only on a broken or wrong-key signature. #42 made that
choice deliberately: sealing a curated page needs the human key from 1Password,
which CI does not have.

So a page could pass review and then break the deploy, and it did twice: #50
edited use/anti-slop.md without resealing, and v0.14.0 bumped the version
string in use/claude-code-recipe.md. The Pages deploy has failed on every
push to main since #50 merged. Neither case is a signature failure — a stale
seal costs that page its rendered seal and nothing else.

The deploy now runs the same gate, so one file defines the policy.

Both pages are also resealed here, which is worth doing on its own but is no
longer what unblocks the deploy.

The release auto-tag has never tagged anything

release-tag.yml interpolated the PR title into the shell as
TITLE=${{ toJSON(...) }}. Bash consumed the JSON quotes, so json.loads
received a bare string:

json.decoder.JSONDecodeError: Expecting value: line 1 column 1 (char 0)

Both runs to date failed this way: v0.13.3 (which is why that version was
never tagged) and v0.14.0. The v0.14.0 tag was pushed by hand at the merge
commit 33a43087 and verified by release-version-guard.yml, which passed.

The title now reaches the script as an environment variable and is read
directly, which also keeps a title containing shell metacharacters out of the
script text.

🤖 Generated with Claude Code

easel and others added 3 commits September 22, 2026 15:21
The Pages deploy has failed since #50 merged: its seal-and-verify step
fails the build on any claim that is not VALID, and `use/anti-slop.md`
was edited in #50 without resealing. The v0.14.0 release added a second
stale page, `use/claude-code-recipe.md`, whose sample `claude plugin
list` output carries the version.

Reseal both with the house key so the site can publish the release.

Note the asymmetry this exposes: tests/validate-innsigle.sh only warns
on STALE (so PR checks stay green without 1Password), while pages.yml
still fails on it. A stale seal therefore passes review and breaks the
deploy.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The auto-tag workflow has never tagged a release. It interpolated the PR
title into the shell as `TITLE=${{ toJSON(...) }}`, so bash consumed the
JSON quotes and `json.loads` got a bare string:

    json.decoder.JSONDecodeError: Expecting value: line 1 column 1

Both runs to date failed this way — v0.13.3 (which is why that version
was never tagged) and v0.14.0, whose tag was pushed by hand and verified
by release-version-guard.yml instead.

Pass the title as an environment variable and read it directly. This
also keeps a title with shell metacharacters out of the script text.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The deploy called `innsigle verify --all` raw, which fails on STALE.
tests/validate-innsigle.sh — the gate the website workflow runs, and the
one contributors see on a pull request — treats an unsigned or stale page
as a warning and fails only on a broken or wrong-key signature, because
sealing a curated page needs the human key from 1Password and CI does not
have it.

So a page could pass review and then break the deploy. It did twice: #50
edited use/anti-slop.md without resealing, and v0.14.0 bumped the version
string in the recipe page. Neither is a signature failure; a stale seal
simply does not render.

Run the gate here instead of a second, stricter policy nobody reviews.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@easel easel changed the title fix(ci): unbreak the Pages deploy and the release auto-tag fix(ci): stop the seal check and the auto-tag blocking releases Sep 22, 2026
@easel
easel merged commit 191d0d7 into main Sep 22, 2026
3 checks passed
@easel
easel deleted the fix/release-tag-title-parsing branch September 22, 2026 22:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant