Skip to content

[F00] Dogfood resource readiness #7

Description

@yunseo-kim

Scope

User selects the real public caller repository and established public npm package. Verify repository/package administration, caller workflow, npm Trusted Publisher, and protected-tag rules. Create docs/dogfood/npm-m1-readiness.md only after actual values are known.

Contracts

ADRs 0024, 0026, 0032, 0034, 0076; npm profile

Dependencies

None; user interaction required

Blocking issues: None.

Executable QA

`gh api "repos/$DOGFOOD_REPO" --jq '{admin:.permissions.admin,visibility:.visibility}'` must exit 0 with `admin:true` and `visibility:"public"`. `gh api "repos/$DOGFOOD_REPO/contents/.github/workflows/release.yml?ref=main" --jq .sha` must return a 40-hex blob SHA. `gh api "repos/$DOGFOOD_REPO/rulesets" --paginate --jq '.[] | select(.target=="tag" and .enforcement=="active")'` must show an active rule covering `refs/tags/v*`. `npm view "$DOGFOOD_PACKAGE" name version repository dist-tags --json` must exit 0 with the exact package name and public metadata. In npmjs UI, Package → Settings → Trusted Publisher must show GitHub Actions, exact owner/repository, workflow `release.yml`, and intended environment. Any failed check produces `NO-GO`; all checks produce `GO`.

Activity

  1. added
    implementationImplementation task from .omo/plans/implementation-plan.md
    dogfoodLive external proof against npmjs/GitHub
    user-action-requiredBlocked on user selection or authorization
    m1Part of the M1 npm-publish vertical slice
    on Aug 5, 2026
  2. yunseo-kim commented on Aug 12, 2026

    @yunseo-kim
    MemberAuthor

    F00 execution report — vers-js (selected caller)

    Executed while preparing windlasstech/vers-js as the M1 dogfood caller (caller PR: windlasstech/vers-js#40).

    Gate results

    Check Result Evidence
    Repo admin/visibility ✅ {"admin":true,"visibility":"public"}
    Caller workflow blob SHA ✅ .github/workflows/publish.yml on main: e85528f8323abb9eb14d778838494e6c7ced72e5 (re-fetch after the caller PR merges; the blob changes)
    Active tag rule covering release tags ✅ Two active org-level tag rulesets; details below
    npm package metadata ✅ @windlass/vers-js@0.1.1, repository URL correct, dist-tags.latest = 0.1.1
    npmjs Trusted Publisher values ✅ with action item publisher=GitHub Actions, organization=windlasstech, repository=vers-js, workflow filename=publish.yml (maintainer-confirmed in the UI). Environment field currently npm — must be blanked before the dogfood run (see spec note 3)

    Applied tag protection (verified via repos/windlasstech/vers-js/rulesets, includes_parents default):

    • Ensure immutable & signed tags (Organization, active, no bypass actors): rules deletion, update, non_fast_forward, required_linear_history, required_signatures; ref target ~ALL.
    • Restrict tag creation to admin (Organization, active): rule creation; bypass = OrganizationAdmin + RepositoryRole admin (always).

    Spec feedback for the F00 gate text

    1. Organization rulesets are a legitimate enforcement location. The QA text requires the repo rulesets query to "show an active rule covering refs/tags/v*", but enforcement may live in org rulesets. These surface through the same repo endpoint (includes_parents=true by default) with source_type: "Organization". Suggest the gate explicitly accept org-inherited rulesets.
    2. Ref-name inclusion patterns are plan-gated. On non-Enterprise plans, inclusion patterns like refs/tags/v* cannot be used, so exact-pattern coverage is impossible there. ~ALL coverage (a superset that includes refs/tags/v*) should be accepted as satisfying the gate on such plans.
    3. Trusted Publisher environment must be blank for reusable-workflow callers. The QA expects the npmjs Trusted Publisher entry to show an "intended environment". For a caller publishing through js-ts-npm-package-slsa3.yml there must be no environment: GitHub forbids environment: on reusable-workflow caller jobs (actionlint-verified), and the OIDC token is minted inside the reusable workflow's internal publish job, which declares no environment, so the token carries no environment claim. If the npmjs environment field is set (for example npm from a pre-slsa-builder configuration), publish authentication fails. Suggest the npmjs check read: "workflow filename matches the caller file; environment field blank".

    Status

    F00 for vers-js: GO (4/4; tag-rule coverage satisfied by org-inherited rulesets per notes 1–2). Remaining pre-dogfood items are on the vers-js side: blank the npmjs environment field, merge the caller PR, cut the 0.1.2 release PR, push the signed tag.

  3. yunseo-kim commented on Aug 12, 2026

    @yunseo-kim
    MemberAuthor

    GO — all readiness checks pass (verified 12026-08-13):

    • gh api repos/windlasstech/vers-js: admin:true, visibility:public
    • publish.yml on main: blob SHA e868d69c1e13ff5036cb20405bfdb25da438821d (thin caller of slsa-builder reusable workflow, OIDC-only, no NPM_TOKEN)
    • Active tag rulesets (2): 'Ensure immutable & signed tags', 'Restrict tag creation to admin' — no ref conditions (apply to all tags, covering refs/tags/v*)
    • npm view @windlass/vers-js: exact name, 0.1.1 published, dist-tags.latest=0.1.1, public metadata
    • npm Trusted Publisher: configured by maintainer (GitHub Actions, windlasstech/vers-js, publish.yml, environment npm)
    • packageManager selection: devEngines.packageManager pnpm@11.17.0 exact + onFail:download — accepted per ADR 0015/0017

    Note: first dogfood run (v0.1.2 tag) failed closed BEFORE OIDC exchange at build/package-resolution — see #30 for the finding. Readiness itself is confirmed; the failure is an slsa-builder spec gap, not a readiness gap.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    dogfoodLive external proof against npmjs/GitHubimplementationImplementation task from .omo/plans/implementation-plan.mdm1Part of the M1 npm-publish vertical sliceuser-action-requiredBlocked on user selection or authorization

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions