Repository navigation
test(coven): pin the Automations v1 canary to the v0.4.7 release producer - #337
Merged
Merged
Conversation
…ucer The exact-artifact canary was still bound to Coven 8a796807, a pre-release CI artifact with the 17-file contract (content 3c145eb9), while every release since v0.4.4 ships content ef266d16 (19 files). Coven's release runbook requires the SDK canary to consume the released archive and its recorded SHA-256. The lock, the exact-runtime CI reproduction and the pinned test values now name the producer of the released v0.4.7 bundle: source c93a8a93, CI run 37077748408 job 111071346442, artifact 11257472104, bundle fcb084bd (byte-identical to the GitHub release asset and to a local reproduction from the tag), manifest 976c9b70, content ef266d16. The canary already supports the 19-file contract, so no SDK source changes. Refs #80 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The README still incorrectly describes the replaced artifact pin as unchanged.
Review effort: Balanced
Findings: 1
What changed in this PR
Rebinds the Automations v1 canary to Coven v0.4.7’s released 19-file contract.
Changes:
- Updates producer, artifact, manifest, and contract pins.
- Rebinds CI reproduction and verification.
- Refreshes documentation and pin tests.
| File | Description |
|---|---|
.github/workflows/ci.yml |
Reproduces and verifies the v0.4.7 bundle. |
conformance/automations-v1-artifact-lock.json |
Records the new artifact identities. |
README.md |
Updates artifact ID and file count. |
tests/automations-v1-artifact-evidence.spec.ts |
Updates evidence expectations. |
tests/workflow-pins.spec.ts |
Updates the Coven checkout pin. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
The README still called the lock the unchanged historical pin that does not certify coven#991/#999; it now names the v0.4.7 release producer, whose contract includes them. The roadmap records the rebinding and corrects two statements this program has since overtaken: individual run lookup and per-automation history landed in SDK #330, #331 and #333, and Coven persists rich definitions (coven#1185) that SDK #336 sends. Refs #80 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Refs #80. This rebinds the exact-artifact Automations v1 canary from Coven
8a796807, a pre-release CI artifact with the 17-file contract, to the producer of the released Coven v0.4.7 bundle,c93a8a93.Why
Coven's release runbook requires the SDK canary to consume the released archive and its recorded SHA-256. The SDK was still pinned to contract content
3c145eb9…(17 files). Every release from v0.4.4 through v0.4.7 shipsef266d16…(19 files): the definition timezone and retry semantics, and the conformance-result schema and vectors.The new producer (all from Coven's exact-commit
mainCI)c93a8a936f9b7f1bd070a1cbb608d38d4e13c92a/c735abce27f7e72a797e392d7d08db43b3ee9f9e267192017, run37077748408attempt 1 (push,main);ci.yml35,497 bytes,5266844a…111071346442, "Automations v1 protocol bundle",ubuntu-latest11257472104, archive 43,604 bytes,89d96098…fcb084bd4f1755d49ccfe91c6f461e7d30be2154c9b51c0333b65fd7f59f01ca976c9b70…ef266d16d76d7380f5cd2b30a110b2e84f1310b154b262e0ade9aa6bf60b3445, 19 filesThree sources agree on the bundle bytes:
coven-automations-v1-contract-c93a8a93….tar.gz;v0.4.7tag with Coven's deterministic packager.Changes
conformance/automations-v1-artifact-lock.json: the new producer, artifact, bundle, manifest and contract..github/workflows/ci.yml: the exact-runtime job checks out Coven atc93a8a93, reproduces the bundle, checks the new manifest digest and size, and runs the canary with the new digests.README.md: the artifact ID and the 19-file count, and the pin is described as the v0.4.7 producer, which includes coven#991 and #999, rather than as an unchanged historical pin.docs/ROADMAP.md: records this rebinding. It also corrects two statements that are no longer true: run lookup and per-automation history landed in feat(coven): read one automation run by id and filter occurrences by automation #330, feat(coven): page one automation's occurrence history #331 and feat(coven): page one automation's run history #333, and Coven persists rich definitions (coven#1185) that feat(coven): create and revise rich automation definitions #336 sends.tests/automations-v1-artifact-evidence.spec.tsandtests/workflow-pins.spec.ts: the pinned values. The canary spec's synthetic 17-file layout test is unchanged, because the canary still accepts that layout.No SDK source changes. The canary already supports the 19-file contract.
Verification
pnpm verify:automations-v1-evidencepassed against GitHub's live repository, workflow, run, job and artifact metadata, withartifactId=11257472104 … manifestFiles=19.c93a8a93, the step rebuilds the bundle, the manifest digest and size match, and the canary reportssourceCommit=c93a8a93… bundleSha256=fcb084bd… contractContentSha256=ef266d16…. All of these pass: fixture integrity, receipt binding, declaration typecheck, duplicate delivery, out-of-order refusal and reconnect replay.pnpm typecheckandpnpm lint(zero warnings) are clean, andpnpm testpasses: 91 files, 3,124 passed, 2 skipped.🤖 Generated with Claude Code