Skip to content

ci: add manual verified M0 publisher - #314

Merged
Pigbibi merged 2 commits into
mainfrom
codex/manual-m0-publisher-workflow
Aug 29, 2026
Merged

ci: add manual verified M0 publisher#314
Pigbibi merged 2 commits into
mainfrom
codex/manual-m0-publisher-workflow

Conversation

@Pigbibi

@Pigbibi Pigbibi commented Aug 29, 2026

Copy link
Copy Markdown
Contributor

Summary

  • add a workflow-dispatch-only M0 publisher that verifies one explicit successful QAR weekly run, its immutable artifact, source snapshot, and hashes before delivery
  • bind publisher execution to the protected m0-research-publisher Environment and QRS main
  • keep QAR artifact-read and M0 publish credentials separated by step

Safety

  • QAR run must be the fixed repository/workflow, main branch, successful, and schedule or workflow_dispatch triggered
  • no latest-run lookup, schedule, downstream dispatch, runtime, strategy, platform, broker, or order path
  • default contents permission remains read-only; output never prints URL or tokens
  • required Environment branch policy and secrets are documented as a fail-closed external prerequisite

Validation

  • python -m unittest tests.test_manual_m0_research_publisher_workflow tests.test_build_m0_research_publisher_envelope passed locally: 10 tests
  • independent Sol audit passed
  • GitHub CI will run workflow, Python, and JS checks

Pigbibi and others added 2 commits August 29, 2026 15:52
Co-Authored-By: Codex <noreply@openai.com>
Co-Authored-By: Codex <noreply@openai.com>
@Pigbibi
Pigbibi merged commit 8c920cc into main Aug 29, 2026
6 checks passed
@Pigbibi
Pigbibi deleted the codex/manual-m0-publisher-workflow branch August 29, 2026 08:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant