Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
164 commits
Select commit Hold shift + click to select a range
5cfc84b
chore: update agent instructions
guyghost Jul 1, 2026
5f4edb4
fix(perf-report): use readiness metric for extension hard-load
guyghost Jul 1, 2026
a68a6aa
docs(product): add canonical PRODUCT.md and impeccable critique snapshot
guyghost Jul 1, 2026
2ebbb56
docs: reflect six platforms including Malt
guyghost Jul 5, 2026
b426a99
fix(extension): production hardening pass (overflow, lint, dead code)…
guyghost Jul 6, 2026
f137118
docs: update pulse workflow instructions
guyghost Jul 7, 2026
b077be8
Save uncommitted changes
guyghost Jul 8, 2026
18c33eb
fix(lint): resolve eslint-plugin-svelte v3 warnings — phase A (85)
guyghost Jul 12, 2026
b548819
fix(lint): resolve eslint-plugin-svelte v3 warnings — phase B (85)
guyghost Jul 12, 2026
7528521
fix(feed-controller): keep SvelteMap/SvelteSet instances stable
Copilot Jul 12, 2026
b4eaa47
fix(ui): replace self-closing option tags with explicit closing tags
guyghost Jul 12, 2026
37fc253
feat(feed): add stable mission arrival stack (#229)
guyghost Jul 13, 2026
6c772c6
fix(e2e): wait for initial scan to settle before testing empty feed s…
Copilot Jul 13, 2026
5f5da67
feat(ui): improve keyboard shortcuts modal accessibility
guyghost Jul 13, 2026
1e1255d
chore: initial plan for merge conflict resolution
Copilot Jul 13, 2026
e4b43fb
chore(extension): format keyboard shortcuts help
guyghost Jul 13, 2026
3dec170
Merge pull request #230 from guyghost/codex/amliorer-lisibilit-cran-r…
guyghost Jul 13, 2026
b1b37fb
fix(merge): resolve conflicts with develop and fix lint errors from n…
Copilot Jul 13, 2026
9c84748
fix(merge): resolve conflicts with develop (keyboard shortcuts access…
Copilot Jul 13, 2026
0161903
fix(linkedin): sync owner-view experience identities
guyghost Jul 13, 2026
e9413da
Merge pull request #228 from guyghost/fix/lint-svelte-v3-all-warnings
guyghost Jul 13, 2026
b308290
Merge pull request #232 from guyghost/codex/rparer-sync-linkedin
guyghost Jul 13, 2026
24fb98d
perf(scoring): use Schwartzian transform in sortMissions
guyghost Jul 15, 2026
5407d48
docs(plan): define extension production readiness work
guyghost Jul 15, 2026
69a98ab
docs(models): define production readiness workflows
guyghost Jul 15, 2026
2bcb6ae
docs(models): resolve workflow review findings
guyghost Jul 15, 2026
91c9b20
docs(models): close remaining review gaps
guyghost Jul 15, 2026
476a67b
docs(models): close audited action on success
guyghost Jul 15, 2026
7629723
fix(release): validate the filtered production artifact
guyghost Jul 15, 2026
63ecd2e
fix(shell): recover from bootstrap and page load failures
guyghost Jul 15, 2026
b1f798e
fix(shell): dispose pending shell operations
guyghost Jul 15, 2026
e565a7a
fix(scan): make cancellation a terminal state
guyghost Jul 15, 2026
3616277
fix(scan): enforce quiescent terminal settlement
guyghost Jul 15, 2026
065b0de
fix(scan): recover interrupted worker operations
guyghost Jul 15, 2026
9b14f08
fix(scan): serialize provisional admission
guyghost Jul 15, 2026
32db1b2
docs(models): define tracking failure contract
guyghost Jul 15, 2026
d32d76b
fix(tracking): report persistence failures truthfully
guyghost Jul 15, 2026
690f509
Merge pull request #235 from guyghost/guyghost-perf-analysis-2026-07
guyghost Jul 15, 2026
33c3ee9
feat(tracking): add revisioned transaction core
guyghost Jul 15, 2026
1b45059
feat(storage): model transactional dataset startup
guyghost Jul 16, 2026
91ee3a4
feat(storage): add reset-safe database handle registry
guyghost Jul 16, 2026
2c6f5c6
feat(storage): add dataset epoch authority
guyghost Jul 16, 2026
d956be5
feat(onboarding): model source selection workflow
guyghost Jul 16, 2026
74254b8
fix(storage): make database opening reset-safe
guyghost Jul 16, 2026
3c23745
feat(storage): add reset-safe startup barrier
guyghost Jul 16, 2026
e132896
test(extension): add packaged mv3 production gate
guyghost Jul 16, 2026
fc39270
feat(release): align production surfaces
guyghost Jul 16, 2026
6b729d1
feat(extension): harden production readiness flows and tracking model
guyghost Jul 16, 2026
3f65d52
fix(models): format dataset-write-capability.model.md with prettier
Copilot Jul 16, 2026
8682bc9
fix(tests): update branch count and timezone-proof next-action assertion
Copilot Jul 16, 2026
a5dade5
fix(feed): polish compact action card
guyghost Jul 16, 2026
5d9bb39
docs(models): harden extension workflow contracts
guyghost Jul 16, 2026
2eb4993
fix(settings): keep confirmed values on save failure
guyghost Jul 16, 2026
3940953
docs(models): simplify feed and modal workflows
guyghost Jul 16, 2026
133e399
docs(models): simplify release evidence workflow
guyghost Jul 16, 2026
b11abed
feat(connectors): share shipped source catalogue
guyghost Jul 16, 2026
859ff98
fix(extension): harden feed arrivals and modal focus
guyghost Jul 16, 2026
905a390
docs(models): close reset handoff contracts
guyghost Jul 16, 2026
250ae11
fix(extension): harden scheduled workflows and reset gates
guyghost Jul 16, 2026
f1987cf
feat(settings): add dormant persistence authority
guyghost Jul 16, 2026
133cb0b
docs(models): approve settings release compatibility
guyghost Jul 16, 2026
842dc65
docs(models): approve content-authorized release gate
guyghost Jul 16, 2026
6400c8c
docs(models): bind settings catalogue history
guyghost Jul 16, 2026
3043669
test(mv3): harden packaged runtime ownership
guyghost Jul 17, 2026
d2fa606
fix(accessibility): keep feedback inside active modal
guyghost Jul 17, 2026
e842c72
docs(models): approve cv experience accessibility
guyghost Jul 17, 2026
3d917cc
docs(models): guarantee cv focus cleanup
guyghost Jul 17, 2026
947a307
docs(models): approve connector health workflow
guyghost Jul 17, 2026
ff9164c
docs(models): approve packaged tab scenarios
guyghost Jul 17, 2026
c229b90
feat(cv): enforce accessible experience workflow
guyghost Jul 17, 2026
1bf3ba3
refactor(pulse): align workflow and state handling with models
guyghost Jul 17, 2026
96b9162
style(extension): apply prettier to release policies, model specs, an…
guyghost Jul 18, 2026
c08a144
Merge remote-tracking branch 'origin/codex/production-readiness' into…
guyghost Jul 18, 2026
bfed526
fix(release): validate diagnostic artifact policy
guyghost Jul 18, 2026
cf7087c
fix(feed): expose stable mission card anchors
guyghost Jul 18, 2026
409be03
fix(tjm): expose semantic region insights
guyghost Jul 18, 2026
f91227d
fix(settings): expose confirmed theme controls
guyghost Jul 18, 2026
ff3eda6
fix(mv3): confirm storage seeding result
guyghost Jul 18, 2026
fd52f79
test(e2e): target semantic mission articles
guyghost Jul 18, 2026
70adebc
fix(ci): preserve canonical release policies
guyghost Jul 19, 2026
b0b4ab2
fix(ci): keep release policies canonical
guyghost Jul 19, 2026
7574bd5
fix(ci): provision pinned Python and Chromium in quality job
Copilot Jul 19, 2026
24734a4
fix(ci): pin actions/setup-python to full SHA40
Copilot Jul 19, 2026
18a893b
fix(ci): pin setup-python to SHA40 and align Python version to 3.14.5
Copilot Jul 19, 2026
cc3c1bc
fix(ci): add pinned Python setup to Packaged MV3 gate job
Copilot Jul 20, 2026
c7ae576
test(e2e): remove legacy onboarding_completed seed from navigation test
Copilot Jul 20, 2026
71a37d0
fix(mv3): raise Playwright transport inbound CDP cap to 16 MiB
Copilot Jul 20, 2026
5ffa2ca
Merge pull request #248 from guyghost/copilot/fix-failing-packaged-mv…
guyghost Jul 20, 2026
690347e
Merge pull request #237 from guyghost/codex/production-readiness
guyghost Jul 20, 2026
05f88f2
chore(deps): bump turbo to 2.10.5
guyghost Jul 21, 2026
02de911
feat(extension): enhance mission discovery workflows
guyghost Jul 21, 2026
764df19
Merge pull request #251 from guyghost/codex/proposer-le-premium-avec-…
guyghost Jul 21, 2026
ed6f5c4
fix(design): ensure WCAG AA contrast in dark mode
guyghost Jul 21, 2026
278bb23
fix(design): keep strong-blue token on hover/border/translucent fills
guyghost Jul 21, 2026
60f9caa
fix(design): AA-grade grade badges + register strong-blue token in de…
guyghost Jul 21, 2026
94f3b7b
Merge pull request #252 from guyghost/guyghost-polish-light-dark-cont…
guyghost Jul 21, 2026
5bce331
perf(semantic-cache): compute profile fingerprint once per call
guyghost Jul 22, 2026
f548aa8
test(semantic-cache): isolate fingerprint by stripping known prefix/s…
guyghost Jul 22, 2026
e0a2f6f
Merge pull request #253 from guyghost/guyghost-perf-improvements-scan
guyghost Jul 22, 2026
90bc4bb
fix(extension): badge icon count from notifiable missions only
cursoragent Jul 26, 2026
4694702
Merge branch 'main' into cursor/fix-extension-badge-count-a7e8
guyghost Jul 26, 2026
8b2f641
merge: integrate origin/develop into badge count fix branch
cursoragent Jul 26, 2026
e85d157
Merge remote-tracking branch 'origin/cursor/fix-extension-badge-count…
cursoragent Jul 26, 2026
66c1cb6
fix(mv3): restore newline-free JCS for scenarios.v1.json
cursoragent Jul 26, 2026
e43488e
refactor(design): rem-based type scale + brand font wiring
guyghost Jul 27, 2026
2c901ce
fix(design): sync all token sources + address review feedback
guyghost Jul 27, 2026
596bad1
Merge pull request #262 from guyghost/guyghost-automatic-tribble
guyghost Jul 27, 2026
949067b
feat(delight): add quiet scan completion summary
guyghost Jul 27, 2026
377a5de
refactor(format): consolidate TJM/date formatting into pure core module
guyghost Jul 27, 2026
904add2
fix(delight): address scan summary review feedback
guyghost Jul 27, 2026
7311dda
Merge pull request #263 from guyghost/guyghost-solid-parakeet
guyghost Jul 27, 2026
659b834
fix(format): address PR #264 review feedback
guyghost Jul 27, 2026
7bb54fa
Merge pull request #264 from guyghost/guyghost-harden-ui
guyghost Jul 27, 2026
fe3b347
fix(landing): align feature positioning with extension launch reality
guyghost Jul 27, 2026
55fe677
test(landing): align privacy-copy assertions with corrected positioning
guyghost Jul 27, 2026
a776f79
fix(scan): move semantic scoring to post-terminal enrichment
guyghost Jul 27, 2026
04c6351
docs(landing): use repo-relative paths in positioning model
guyghost Jul 27, 2026
fce0daf
fix(landing): mark cross-device sync as forthcoming, drop 100%-local …
guyghost Jul 27, 2026
37a1e43
Initial plan
Copilot Jul 27, 2026
5a8e96b
fix(landing): shorten sync list item so 'via Supabase' stays on one line
Copilot Jul 27, 2026
da74cc9
fix(landing): make 'via Supabase' test whitespace-tolerant
guyghost Jul 27, 2026
99117f7
fix(scan): address PR review feedback for enrichment routing
guyghost Jul 27, 2026
987ac13
Merge pull request #265 from guyghost/guyghost-expert-carnival
guyghost Jul 27, 2026
9c7712d
fix(e2e): remove delayed MISSIONS_UPDATED broadcast from dev stub
guyghost Jul 27, 2026
5e26444
fix(scan): run high-score notifications after semantic enrichment
guyghost Jul 27, 2026
2ff348e
style(scan): prettier-wrap notifyHighScoreMissions call
guyghost Jul 27, 2026
73457bd
Merge pull request #266 from guyghost/guyghost-fix-scan-collecte-state
guyghost Jul 27, 2026
1300346
refactor(ui): extract shared Toggle atom and unify source switches
guyghost Jul 27, 2026
e622d4c
Merge pull request #268 from guyghost/guyghost-potential-fiesta
guyghost Jul 27, 2026
0ae8321
fix(feed): resolve P0 empty-state ambiguity by extracting buildFeedSt…
guyghost Jul 28, 2026
e24e17a
refactor(comparison): distill MissionComparison modal to decision-fir…
guyghost Jul 28, 2026
cb0dc3f
feat(filters): constrain FilterBar tech chips to top-8 with overflow …
guyghost Jul 28, 2026
dea9ab0
docs(design): add side-panel impeccable critique record
guyghost Jul 28, 2026
a26022f
fix(ui): address review — overflow count, toggle a11y, stack dict safety
guyghost Jul 28, 2026
5732b99
fix(feed): distinguish filtered-empty from scanned-empty feed story
guyghost Jul 28, 2026
412704c
fix(e2e): import buildFeedStory into FeedPage instance script
guyghost Jul 28, 2026
062620d
Merge pull request #270 from guyghost/guyghost-animated-telegram
guyghost Jul 28, 2026
b093fbf
Merge pull request #267 from guyghost/copilot/fix-copilot-issues
guyghost Jul 28, 2026
13fb673
merge: resolve conflict with origin/develop in background/index.ts
Copilot Jul 28, 2026
ac68696
Merge pull request #273 from guyghost/guyghost-expert-carnival
guyghost Jul 28, 2026
2541361
Merge pull request #259 from guyghost/cursor/fix-extension-badge-coun…
guyghost Jul 28, 2026
0b9ab7a
feat(onboarding): redesign flow with machine-driven model
guyghost Jul 28, 2026
e1e0bd2
fix(onboarding): address code review feedback
guyghost Jul 28, 2026
6ceb5f7
fix(onboarding): address second round of review feedback
guyghost Jul 28, 2026
0022fcf
fix(feed): decouple and persist checklist pill nudge
guyghost Jul 28, 2026
5015bbe
fix(background): remove leftover merge-conflict markers in index.ts
guyghost Jul 28, 2026
e2c0cc5
fix(background): add settingsSnapshot param to persistPostCommitEffects
Copilot Jul 28, 2026
7f36507
Merge pull request #274 from guyghost/guyghost-feat-onboarding-ios-re…
guyghost Jul 29, 2026
62ef0b4
fix(qa): apply QA hardening fixes from 29 July Chrome review
guyghost Jul 29, 2026
7ae7421
fix(ui): polish Suivi tab spacing, contrast, and readability
guyghost Jul 29, 2026
b314700
Merge pull request #276 from guyghost/guyghost-upgraded-umbrella
guyghost Jul 29, 2026
5258eea
feat(form-assistant): add local Grammarly-like field assistant (Phase 1)
guyghost Jul 29, 2026
aafc73e
fix(form-assistant): address Copilot code review feedback
guyghost Jul 29, 2026
c67b846
fix(form-assistant): address second round of code review feedback
guyghost Jul 29, 2026
9cb5e92
Merge pull request #277 from guyghost/guyghost-feat-form-assistant-local
guyghost Jul 29, 2026
f6185b3
feat(scoring): display mission ratings as letter grades
guyghost Jul 29, 2026
f717607
feat(form-assistant): wire activation toggle in Settings UI
guyghost Jul 29, 2026
9dcdc29
feat(form-assistant): extend activation to all shipped connectors
guyghost Jul 29, 2026
c60d5bb
fix(layout): resolve overflow in Suivi section mission list
guyghost Jul 29, 2026
59a73af
Merge pull request #279 from guyghost/guyghost-super-barnacle
guyghost Jul 29, 2026
41d4f78
Merge pull request #278 from guyghost/guyghost-crispy-lamp
guyghost Jul 29, 2026
5c47054
fix(mv3): tolerate empty DevToolsActivePort and correct stale onboard…
guyghost Jul 29, 2026
a7d6fb7
ci: harden MV3 gate retry and SHA-pin release workflow actions
guyghost Jul 29, 2026
6829696
Merge pull request #280 from guyghost/guyghost-fix-ci-and-harden-work…
guyghost Jul 29, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
182 changes: 93 additions & 89 deletions .github/workflows/README.md
Original file line number Diff line number Diff line change
@@ -1,119 +1,123 @@
# GitHub Workflows
# GitHub workflows

This directory contains all GitHub Actions workflows for MissionPulse.
The workflows enforce two distinct boundaries:

## Workflows Overview
- CI may build and exercise an unpacked MV3 directory, but that directory is explicitly **unsealed** and is never presented as a Store package.
- Release automation consumes an already archived `TestedDistSealV1` plus the exact tested `dist/`, runs the package-only protocol, and stops at `package_validated`.

| File | Name | Trigger | Purpose |
| ------------- | ------- | --------- | ------------------------ |
| `ci.yml` | CI | Push, PR | Continuous integration |
| `release.yml` | Release | Tags `v*` | Build & publish releases |
No workflow bumps a version, creates an ad hoc archive, submits to Chrome Web Store, claims a monitored rollout, or promotes a release. Those later transitions require their modeled signed receipts and explicit authorization.

## Detailed Documentation
## `ci.yml`

See [docs/CI-CD.md](../../docs/CI-CD.md) for complete documentation.
Triggers on pushes and pull requests to `develop`/`main`, and by manual dispatch.

## Quick Reference
The workflow runs format, lint, TypeScript, unit, build, browser E2E, and packaged-MV3 gates. The build job uploads `chrome-extension-dist-unsealed` for short-lived inspection only. It does not emit a ZIP.

### Trigger CI manually
The complete packaged-MV3 gate must use the committed scenario inventory at `apps/extension/tests/mv3/scenarios.v1.json`. A later local sealer is responsible for binding that exact nonempty inventory, the aggregate result, zero skips/failures/diagnostics, and identical pre/post canonical trees.

```bash
gh workflow run ci.yml
```

### Create a release

```bash
git tag v1.0.0
git push origin v1.0.0
```

### Create a dry-run release (manual dispatch)

```bash
gh workflow run release.yml -f version=1.0.0 -f dry_run=true
```
## `connector-health.yml`

## Workflow Files
Ce workflow planifié ou manuel exécute uniquement les fixtures committées des six connecteurs. Il
n'a accès à aucune session navigateur, aucun cookie, aucun identifiant de production et aucun
endpoint authentifié de plateforme connecteur. Seul `issue-writer` utilise ensuite l'API GitHub
authentifiée, après admission d'un échec vérifié. Le registre de santé reste égal au catalogue
complet, y compris Malt, même si une configuration de build exclut un connecteur.

### ci.yml
Permissions exactes :

**Triggers:**
- `health-capture`: `contents: read` ;
- `issue-writer`: `actions: read`, `contents: read`, `issues: write` ;
- `conclusion`: `contents: read`.

- Push to `develop` and `main`
- Pull requests targeting `develop` and `main`
- Manual dispatch
Les permissions globales sont `{}`. Le vérificateur local de source et `conclusion` ne reçoivent
aucun `GITHUB_TOKEN` dans leur environnement. Seul l'acteur admis de `issue-writer` reçoit le token
pour les lectures d'étiquettes/issues et l'unique POST éventuel. Les actions d'artifact transfèrent
uniquement l'evidence du run courant : artifact `connector-health-report`, fichier unique
`connector-health-evidence.v1.json`, conservation 14 jours, sans overwrite.

**Jobs:**
Chaque job utilise `ubuntu-24.04`, Node `22.23.1`, pnpm `10.32.1`, admet le checkout exact avant
toute installation, puis vérifie l'identité `packageManager` avec intégrité et exécute
`pnpm install --frozen-lockfile`. Les entrées principales committées sont :

1. `setup` - Compute cache paths
2. `lint` - ESLint
3. `format` - Prettier check
4. `typecheck` - TypeScript
5. `test` - Vitest with coverage
6. `build` - Vite build, built manifest verification, ZIP artifact
7. `test-e2e` - Playwright (PRs only)

**Concurrency:** Previous runs on same branch are cancelled.

---

### release.yml

**Triggers:**
```text
pnpm --filter @pulse/extension exec tsx scripts/connector-health/capture.ts
pnpm --filter @pulse/extension exec tsx scripts/connector-health/issue-writer.ts
pnpm --filter @pulse/extension exec tsx scripts/connector-health/conclusion-cli.ts
```

- Tags matching `v*.*.*` (e.g., `v1.0.0`, `v2.1.0-beta.1`)
- Manual dispatch with `version` and `dry_run` inputs
Pins revus : `actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd`,
`pnpm/action-setup@0e279bb959325dab635dd2c09392533439d90093`,
`actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e`,
`actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a` et
`actions/download-artifact@70fc10c6e5e1ce46ad2ea6f2b72d43f7d47b13c3`.

**Inputs (manual dispatch):**
L'admission lie exactement dépôt, branche par défaut, ref, SHA, workflow, event et checkout propre.
Avec `contents: read`, elle ne peut pas vérifier la protection de branche : revues obligatoires,
protection et checks requis restent des contrôles administrateur hors bande. Le périmètre exécutable
fait confiance aux scripts/tests/dépendances revus. Les fixtures sont des données hostiles mais non
exécutables. Le PGID prouve seulement que le groupe contrôlé est vide ; il ne prétend pas contenir
du code committé malveillant qui ferait `setsid` ou se daemoniserait.

- `version` - Version to release (required)
- `dry_run` - Build and verify but skip GitHub Release and CWS publish (default: false)
Les terminaux enfants sont `capture_passed`, `capture_failed`,
`capture_infrastructure_failed`, `issue_settled` et `issue_failed`. Après le marqueur
`CONCLUSION_ACTOR_STARTED`, les trois seules conclusions sont `passed`, `failed_recorded` et
`failed_unreported`; les deux dernières sont rouges. Une panne de checkout/setup/install/module ou
d'input avant le marqueur est `pre_actor_bootstrap_interrupted` : GitHub reste rouge, aucun terminal
XState n'est fabriqué et aucune conclusion de santé n'est revendiquée.

**Jobs:**
## `release.yml`

1. `build-and-release` - Typecheck, test, bump version, build, verify manifest version match, reproducible ZIP, GitHub Release
2. `publish-to-chrome-store` - CWS publish (stable, non-dry-run, secrets configured only)
3. `publish-skip-notice` - Explains why CWS publish was skipped
This workflow is manual and local-first. It accepts:

**Version Validation Gates:**
- `source_commit`: exact clean commit recorded by the seal;
- `expected_version`: committed extension version;
- `evidence_run_id`: Actions run that archived the sealed candidate;
- `evidence_artifact`: artifact containing exactly `tested-dist-seal.json` and its tested `dist/`.

- Tag version format validated (`X.Y.Z` or `X.Y.Z-prerelease`)
- Root `package.json` `version` must match the release version after bump (hard error)
- Built manifest `version` must match tag version (hard error)
- Source manifest `version` must match tag version after bump (hard error)
- Root `package.json`, extension `package.json`, and `manifest.json` are bumped in lockstep
The job installs the committed verifier before ingesting the seal. From `Download sealed candidate evidence` onward, it performs no install, build, version bump, connector resolution, or `dist` rewrite. It calls only the shared `package:sealed` and `verify:release-artifact` boundaries, uploads the ZIP, checksum sidecar, validation record, seal and package receipt together, then downloads them in a second job and recomputes every digest.

**Pre-releases:** Tags with `-` (e.g., `v1.0.0-beta.1`) skip CWS publish.
The workflow's maximum claim is `package_validated`. Store readiness, submission, observation, promotion and rollback remain separate modeled events.

**Dry Run:** Manual dispatch with `dry_run: true` builds and verifies but skips release/publish.
## Local commands

**Required Secrets (for CWS publish):**
The worktree must be clean at the exact candidate commit before producing a seal. The sealer consumes complete gate input; it does not manufacture missing evidence.

- `CHROME_EXTENSION_ID`
- `CHROME_CLIENT_ID`
- `CHROME_CLIENT_SECRET`
- `CHROME_REFRESH_TOKEN`
```bash
pnpm --filter @pulse/extension release:seal-candidate -- \
--input output/playwright/mv3-evidence/final-gate-input.json \
--dist apps/extension/dist \
--output output/playwright/mv3-evidence/tested-dist-seal.json

pnpm --filter @pulse/extension package:sealed -- \
--seal output/playwright/mv3-evidence/tested-dist-seal.json \
--dist apps/extension/dist \
--releases apps/extension/releases \
--artifact-id artifact-0.2.2-<commit> \
--journal-id journal-0.2.2-<commit>
```

When secrets are not configured, the workflow succeeds with a warning.
The package command never installs, builds, bumps, or deletes `dist`. Run the consumer verifier against the exact published bundle and a fresh absent extraction path:

## Permissions
```bash
pnpm --filter @pulse/extension verify:release-artifact -- \
--bundle apps/extension/releases/v0.2.2 \
--zip apps/extension/releases/v0.2.2/missionpulse.zip \
--checksum apps/extension/releases/v0.2.2/missionpulse.zip.sha256 \
--validation apps/extension/releases/v0.2.2/validation.json \
--extract-fresh /tmp/missionpulse-0.2.2-consumer-check
```

| Workflow | Permissions |
| ----------- | ----------------- |
| ci.yml | `contents: read` |
| release.yml | `contents: write` |
## Actions in use

## Actions Used
| Action | Version | Purpose |
| --------------------------- | ------- | --------------------------------- |
| `actions/checkout` | v6.0.2 | Exact source checkout |
| `actions/setup-node` | v6 | Node toolchain |
| `pnpm/action-setup` | v6 | pnpm toolchain |
| `actions/cache` | v6 | Dependency and browser cache |
| `actions/upload-artifact` | v7 | Immutable evidence transfer |
| `actions/download-artifact` | v8 | Sealed input and consumer recheck |
| `codecov/codecov-action` | v7 | Non-blocking coverage upload |

| Action | Version | Purpose |
| --------------------------------- | ------- | ----------------- |
| `actions/checkout` | v7 | Git checkout |
| `actions/setup-node` | v6 | Node.js setup |
| `pnpm/action-setup` | v6 | pnpm setup |
| `actions/cache` | v6 | Dependency cache |
| `actions/upload-artifact` | v4 | Artifact upload |
| `actions/download-artifact` | v4 | Artifact download |
| `codecov/codecov-action` | v7 | Coverage upload |
| `softprops/action-gh-release` | v2 | GitHub releases |
| `mnao305/chrome-extension-upload` | v5.0.0 | CWS publish |
Les permissions du workflow de release restent en lecture seule. Son `GITHUB_TOKEN` sert uniquement
à télécharger l'artifact de preuve explicitement nommé depuis le run explicitement nommé.
Loading
Loading