Repository navigation
test(coven): pin the daemon canary to v0.4.8 and require revision digests - #339
Merged
Merged
Conversation
…ests Re-pins the daemon canary to the published @opencoven/cli@0.4.8, at the integrity npm serves, and makes the digest check a requirement now that the pinned release has the fix (coven#1200). The created and revised events must carry exactly the integrity create and revise returned, revise's stored integrity must match computeDefinitionDigest(), and the paused revisions 2 and 4, which share a body, must publish different digests. Against v0.4.7 the canary now fails on the created event. Refs #80, OpenCoven/coven#1054. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Missing or incorrect transition digests can still pass despite the reported integrity guarantee.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Updates the SDK’s released-daemon canary to Coven v0.4.8 and makes definition-digest checks mandatory.
Changes:
- Updates CLI package pins, lockfile integrity values, and CI invocation.
- Adds digest assertions and regression cases.
- Documents the new checks and v0.4.7 compatibility limitation.
| File | Description |
|---|---|
| tests/automations-v1-daemon-canary.spec.ts | Models revision digests and adds failure cases. |
| scripts/verify-automations-v1-daemon.mjs | Enforces digest checks. |
| scripts/verify-automations-v1-daemon.d.mts | Removes the informational digest result field. |
| README.md | Updates usage and digest guarantees. |
| docs/ROADMAP.md | Records the canary upgrade. |
| conformance/automations-v1-daemon/package.json | Pins CLI v0.4.8. |
| conformance/automations-v1-daemon/package-lock.json | Updates platform packages and integrity hashes. |
| .github/workflows/ci.yml | Runs the v0.4.8 canary. |
Files not reviewed (1)
- conformance/automations-v1-daemon/package-lock.json: Generated file
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Copilot noted the canary checked only the created and revised event digests, and that two paused digests differed, while reporting that every event matched. An activation, pause or disable event with no digest or an unrelated one would have passed. Compute the integrity of every revision the scenario commits. Revisions 1 and 2 are what create and revise returned. Revisions 3-5 are the revised document regenerated at that revision and lifecycle state, as Coven's stored view does. Require each of the five events to carry exactly its revision's value. The published v0.4.8 daemon matches all five. New negative cases cover a missing activation digest and an unrelated disable digest. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This was referenced Oct 3, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Refs #80, OpenCoven/coven#1054. This re-pins the Automations v1 daemon canary (#338) from
@opencoven/cli@0.4.7to the published0.4.8. Now that the pinned release has the fix, it also makes the definition digest a requirement.Why
#338 found that v0.4.7's lifecycle events, occurrences, runs and receipts published a digest of the legacy routine projection rather than the definition document's
integrity. Coven v0.4.8 fixes that (OpenCoven/coven#1200). Until now the canary only reported the digest; now it fails closed if the behaviour regresses.Changes
conformance/automations-v1-daemon/:@opencoven/cli0.4.8and a regenerated npm lockfile coveringcli,cli-macos,cli-macos-x64,cli-linux-x64andcli-windows, at thesha512integrity npm serves..github/workflows/ci.yml: the step is now "Drive the released Coven v0.4.8 daemon through the SDK" with--expect-version 0.4.8. The pin test keeps the lock,package.jsonand the workflow in step.scripts/verify-automations-v1-daemon.mjs: revise's stored integrity must now equalcomputeDefinitionDigest(), as create's already did. Each of the five lifecycle events must carry exactly its revision's definition integrity:Revisions 2 and 4 share a body, so a digest that ignored the revision could not match both. A missing or unrelated digest on any event fails. The summary still prints
eventDefinitionDigest=matches-definition-integrity. That is now a requirement, so the scenario result no longer carries the field.tests/automations-v1-daemon-canary.spec.ts: the in-memory daemon now publishes each revision's document digest. Four new deviations must fail closed:The suite has 30 tests.
README.md,docs/ROADMAP.md: the pin moves to v0.4.8. The README records that v0.4.7 published the projection digest, and that v0.4.7 events, being immutable, keep it.Verification
npm ci, thennpm audit signatures("2 packages have verified registry signatures", "2 packages have verified attestations"), then the canary:events: definition.created publishes 59af64ce…, not the created definition's integrity cca43536….pnpm typecheckandpnpm lintare clean.pnpm testrun passed 3,150 tests and failed 2, with 2 skipped. The two failures were the shared-deadline timing test incoven-automations-platforms.spec.tsand the annotated-tag test inrelease-readiness.spec.ts, neither of which this change touches. Re-run on their own, both files pass, 153/153, which fits load-dependent timing.The second commit addresses Copilot's finding. The first version checked only the created and revised digests, so a transition event with no digest or an unrelated one would have passed.
🤖 Generated with Claude Code