Skip to content

test(coven): pin the Automations v1 canary to the v0.4.7 release producer - #337

Merged
BunsDev merged 2 commits into
mainfrom
chore/80-pin-automations-v0.4.7
Oct 3, 2026
Merged

BunsDev merged 2 commits into
mainfrom
chore/80-pin-automations-v0.4.7

Conversation

@BunsDev

@BunsDev BunsDev commented Oct 3, 2026 •

Copy link
Copy Markdown
Member

Refs #80. This rebinds the exact-artifact Automations v1 canary from Coven 8a796807, a pre-release CI artifact with the 17-file contract, to the producer of the released Coven v0.4.7 bundle, c93a8a93.

Why

Coven's release runbook requires the SDK canary to consume the released archive and its recorded SHA-256. The SDK was still pinned to contract content 3c145eb9… (17 files). Every release from v0.4.4 through v0.4.7 ships ef266d16… (19 files): the definition timezone and retry semantics, and the conformance-result schema and vectors.

The new producer (all from Coven's exact-commit main CI)

Field Value
Source commit / tree c93a8a936f9b7f1bd070a1cbb608d38d4e13c92a / c735abce27f7e72a797e392d7d08db43b3ee9f9e
Workflow CI 267192017, run 37077748408 attempt 1 (push, main); ci.yml 35,497 bytes, 5266844a…
Job 111071346442, "Automations v1 protocol bundle", ubuntu-latest
Artifact 11257472104, archive 43,604 bytes, 89d96098…
Bundle 42,034 bytes, fcb084bd4f1755d49ccfe91c6f461e7d30be2154c9b51c0333b65fd7f59f01ca
Manifest 3,296 bytes, 976c9b70…
Contract ef266d16d76d7380f5cd2b30a110b2e84f1310b154b262e0ade9aa6bf60b3445, 19 files

Three sources agree on the bundle bytes:

  • the CI artifact;
  • the released GitHub asset coven-automations-v1-contract-c93a8a93….tar.gz;
  • a local reproduction from the v0.4.7 tag with Coven's deterministic packager.

Changes

No SDK source changes. The canary already supports the 19-file contract.

Verification

  • Live evidence: pnpm verify:automations-v1-evidence passed against GitHub's live repository, workflow, run, job and artifact metadata, with artifactId=11257472104 … manifestFiles=19.
  • CI step, run literally: against a clean Coven checkout at c93a8a93, the step rebuilds the bundle, the manifest digest and size match, and the canary reports sourceCommit=c93a8a93… bundleSha256=fcb084bd… contractContentSha256=ef266d16…. All of these pass: fixture integrity, receipt binding, declaration typecheck, duplicate delivery, out-of-order refusal and reconnect replay.
  • Affected specs: 60/60 pass.
  • Suite: pnpm typecheck and pnpm lint (zero warnings) are clean, and pnpm test passes: 91 files, 3,124 passed, 2 skipped.

🤖 Generated with Claude Code

…ucer

The exact-artifact canary was still bound to Coven 8a796807, a
pre-release CI artifact with the 17-file contract (content 3c145eb9),
while every release since v0.4.4 ships content ef266d16 (19 files).
Coven's release runbook requires the SDK canary to consume the released
archive and its recorded SHA-256.

The lock, the exact-runtime CI reproduction and the pinned test values
now name the producer of the released v0.4.7 bundle: source c93a8a93,
CI run 37077748408 job 111071346442, artifact 11257472104, bundle
fcb084bd (byte-identical to the GitHub release asset and to a local
reproduction from the tag), manifest 976c9b70, content ef266d16. The
canary already supports the 19-file contract, so no SDK source changes.

Refs #80

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings October 3, 2026 05:41

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The README still incorrectly describes the replaced artifact pin as unchanged.

Review effort: Balanced
Findings: 1 Low severity

Open (1)
What changed in this PR

Rebinds the Automations v1 canary to Coven v0.4.7’s released 19-file contract.

Changes:

  • Updates producer, artifact, manifest, and contract pins.
  • Rebinds CI reproduction and verification.
  • Refreshes documentation and pin tests.
File Description
.github/​workflows/​ci.yml Reproduces and verifies the v0.4.7 bundle.
conformance/​automations-v1-artifact-lock.json Records the new artifact identities.
README.md Updates artifact ID and file count.
tests/​automations-v1-artifact-evidence.spec.ts Updates evidence expectations.
tests/​workflow-pins.spec.ts Updates the Coven checkout pin.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread README.md
The README still called the lock the unchanged historical pin that does
not certify coven#991/#999; it now names the v0.4.7 release producer,
whose contract includes them. The roadmap records the rebinding and
corrects two statements this program has since overtaken: individual
run lookup and per-automation history landed in SDK #330, #331 and
#333, and Coven persists rich definitions (coven#1185) that SDK #336
sends.

Refs #80

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@BunsDev
BunsDev merged commit cc41f28 into main Oct 3, 2026
8 checks passed
@BunsDev
BunsDev deleted the chore/80-pin-automations-v0.4.7 branch October 3, 2026 06:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants