Goal
Close the correctness and coverage gaps identified after #375 merged, keeping the release provenance gate fail-closed and maintainable.
Findings from the #375 post-merge review
GITHUB_EVENT_PATH is parsed with type=Path and a string default, so an unset value becomes Path('.'); the intended missing-event guard is unreachable and produces a confusing directory-read error.
_git_output("rev-parse", "--is-shallow-repository") converts Git failures into an empty string that is interpreted as False, allowing the shallow-history check to pass on command failure.
- The tests exercise only
validate_release_provenance() and not the production main() entrypoint, event-payload parsing, or Git wrapper failure paths.
- The deleted-tag event branch lacks a direct regression test.
- The workflow test does not independently prove that both
publish and attest retain the provenance dependency.
- The
production_release expression contains an unnecessary disjunct that obscures the actual branch-publication rule.
- The v-prefixed-tag rule is duplicated between
validate_release_ref.py and validate_release_provenance.py; extract a shared helper in scripts/release_metadata_helpers.py.
References: #375 post-merge discussion, shallow-history comment, entrypoint coverage comment, deleted-tag test comment, workflow assertion comment, cleanup comment, and shared-helper finding.
Scope
- Make missing event-payload input explicit and test it through the real command entrypoint.
- Treat every Git inspection failure as a validation error; never coerce an unknown repository state into a safe boolean.
- Add deleted-tag coverage and Git-wrapper failure coverage.
- Assert the provenance dependency separately for publication, attestation, and GitHub Release jobs.
- Simplify the production-dispatch condition.
- Centralize the v-prefix tag validation and keep both validators on the shared helper.
Acceptance criteria
- Missing
GITHUB_EVENT_PATH fails with a clear validation error before attempting to read ..
- A failed shallow-state Git query fails closed.
- The deleted-tag negative path is covered.
- At least one test invokes the production validator entrypoint and exercises event-payload parsing.
- Workflow tests fail if either
publish, attest, or release loses the provenance dependency.
- Both release validators use one shared v-prefix helper.
- Full tests, Ruff, strict mypy, and workflow validation pass.
Project Fields
- Status: Backlog
- Priority: P1
- Area: Security
- Initiative: v1.0 Readiness
- Size: M
Ownership
Goal
Close the correctness and coverage gaps identified after #375 merged, keeping the release provenance gate fail-closed and maintainable.
Findings from the #375 post-merge review
GITHUB_EVENT_PATHis parsed withtype=Pathand a string default, so an unset value becomesPath('.'); the intended missing-event guard is unreachable and produces a confusing directory-read error._git_output("rev-parse", "--is-shallow-repository")converts Git failures into an empty string that is interpreted asFalse, allowing the shallow-history check to pass on command failure.validate_release_provenance()and not the productionmain()entrypoint, event-payload parsing, or Git wrapper failure paths.publishandattestretain the provenance dependency.production_releaseexpression contains an unnecessary disjunct that obscures the actual branch-publication rule.validate_release_ref.pyandvalidate_release_provenance.py; extract a shared helper inscripts/release_metadata_helpers.py.References: #375 post-merge discussion, shallow-history comment, entrypoint coverage comment, deleted-tag test comment, workflow assertion comment, cleanup comment, and shared-helper finding.
Scope
Acceptance criteria
GITHUB_EVENT_PATHfails with a clear validation error before attempting to read..publish,attest, orreleaseloses the provenance dependency.Project Fields
Ownership