Repository navigation
[F00] Dogfood resource readiness #7
Copy link
Copy link
Closed
Labels
dogfoodLive external proof against npmjs/GitHubLive external proof against npmjs/GitHubimplementationImplementation task from .omo/plans/implementation-plan.mdImplementation task from .omo/plans/implementation-plan.mdm1Part of the M1 npm-publish vertical slicePart of the M1 npm-publish vertical sliceuser-action-requiredBlocked on user selection or authorizationBlocked on user selection or authorization
Description
Activity
- added this to the Wave 0: External readiness, feasibility, and guardrails milestone
on Aug 5, 2026 - addedimplementationImplementation task from .omo/plans/implementation-plan.mdImplementation task from .omo/plans/implementation-plan.mddogfoodLive external proof against npmjs/GitHubLive external proof against npmjs/GitHubuser-action-requiredBlocked on user selection or authorizationBlocked on user selection or authorizationm1Part of the M1 npm-publish vertical slicePart of the M1 npm-publish vertical slice
on Aug 5, 2026 - added a commit that references this issue
on Aug 7, 2026 F00 execution report — vers-js (selected caller)
Executed while preparing
windlasstech/vers-jsas the M1 dogfood caller (caller PR: windlasstech/vers-js#40).Gate results
Check Result Evidence Repo admin/visibility ✅ {"admin":true,"visibility":"public"}Caller workflow blob SHA ✅ .github/workflows/publish.ymlonmain:e85528f8323abb9eb14d778838494e6c7ced72e5(re-fetch after the caller PR merges; the blob changes)Active tag rule covering release tags ✅ Two active org-level tag rulesets; details below npm package metadata ✅ @windlass/vers-js@0.1.1, repository URL correct,dist-tags.latest = 0.1.1npmjs Trusted Publisher values ✅ with action item publisher=GitHub Actions, organization= windlasstech, repository=vers-js, workflow filename=publish.yml(maintainer-confirmed in the UI). Environment field currentlynpm— must be blanked before the dogfood run (see spec note 3)Applied tag protection (verified via
repos/windlasstech/vers-js/rulesets,includes_parentsdefault):Ensure immutable & signed tags(Organization, active, no bypass actors): rulesdeletion,update,non_fast_forward,required_linear_history,required_signatures; ref target~ALL.Restrict tag creation to admin(Organization, active): rulecreation; bypass = OrganizationAdmin + RepositoryRole admin (always).
Spec feedback for the F00 gate text
- Organization rulesets are a legitimate enforcement location. The QA text requires the repo rulesets query to "show an active rule covering
refs/tags/v*", but enforcement may live in org rulesets. These surface through the same repo endpoint (includes_parents=trueby default) withsource_type: "Organization". Suggest the gate explicitly accept org-inherited rulesets. - Ref-name inclusion patterns are plan-gated. On non-Enterprise plans, inclusion patterns like
refs/tags/v*cannot be used, so exact-pattern coverage is impossible there.~ALLcoverage (a superset that includesrefs/tags/v*) should be accepted as satisfying the gate on such plans. - Trusted Publisher environment must be blank for reusable-workflow callers. The QA expects the npmjs Trusted Publisher entry to show an "intended environment". For a caller publishing through
js-ts-npm-package-slsa3.ymlthere must be no environment: GitHub forbidsenvironment:on reusable-workflow caller jobs (actionlint-verified), and the OIDC token is minted inside the reusable workflow's internal publish job, which declares no environment, so the token carries no environment claim. If the npmjs environment field is set (for examplenpmfrom a pre-slsa-builder configuration), publish authentication fails. Suggest the npmjs check read: "workflow filename matches the caller file; environment field blank".
Status
F00 for vers-js: GO (4/4; tag-rule coverage satisfied by org-inherited rulesets per notes 1–2). Remaining pre-dogfood items are on the vers-js side: blank the npmjs environment field, merge the caller PR, cut the 0.1.2 release PR, push the signed tag.
- added 2 commits that reference this issue
on Aug 12, 2026 GO — all readiness checks pass (verified 12026-08-13):
- gh api repos/windlasstech/vers-js: admin:true, visibility:public
- publish.yml on main: blob SHA e868d69c1e13ff5036cb20405bfdb25da438821d (thin caller of slsa-builder reusable workflow, OIDC-only, no NPM_TOKEN)
- Active tag rulesets (2): 'Ensure immutable & signed tags', 'Restrict tag creation to admin' — no ref conditions (apply to all tags, covering refs/tags/v*)
- npm view @windlass/vers-js: exact name, 0.1.1 published, dist-tags.latest=0.1.1, public metadata
- npm Trusted Publisher: configured by maintainer (GitHub Actions, windlasstech/vers-js, publish.yml, environment npm)
- packageManager selection: devEngines.packageManager pnpm@11.17.0 exact + onFail:download — accepted per ADR 0015/0017
Note: first dogfood run (v0.1.2 tag) failed closed BEFORE OIDC exchange at build/package-resolution — see #30 for the finding. Readiness itself is confirmed; the failure is an slsa-builder spec gap, not a readiness gap.
Metadata
Metadata
Assignees
Labels
dogfoodLive external proof against npmjs/GitHubLive external proof against npmjs/GitHubimplementationImplementation task from .omo/plans/implementation-plan.mdImplementation task from .omo/plans/implementation-plan.mdm1Part of the M1 npm-publish vertical slicePart of the M1 npm-publish vertical sliceuser-action-requiredBlocked on user selection or authorizationBlocked on user selection or authorization
Scope
User selects the real public caller repository and established public npm package. Verify repository/package administration, caller workflow, npm Trusted Publisher, and protected-tag rules. Create
docs/dogfood/npm-m1-readiness.mdonly after actual values are known.Contracts
ADRs 0024, 0026, 0032, 0034, 0076; npm profile
Dependencies
None; user interaction required
Blocking issues: None.
Executable QA