Commit Graph

417 Commits

Author SHA1 Message Date
pulse-triage[bot] 0d32dac16e Keep release toolchains within support 2026-08-30 06:40:25 +01:00
pulse-triage[bot] e66f6a26f7 Fail closed when installing MCP binaries
Verify the signed release checksum manifest against Pulse's pinned SSH key before either MCP installer accepts a downloaded binary. Remove the unsigned bypass and require one exact digest entry.

Include bare Unix MCP executables in release checksum/signature assembly, cover unavailable, invalid, ambiguous, mismatched, and successful evidence paths with executable regression tests, and enforce MCP installer pins against the configured release key.
2026-08-30 05:11:55 +01:00
pulse-triage[bot] d8986c139a Enforce workflow data trust boundaries
Contract-Neutral: Moves workflow expressions into environment data flow without changing deployment interfaces or behavior.
2026-08-30 04:56:34 +01:00
pulse-triage[bot] a2bfadba7b Enforce workflow execution trust boundaries 2026-08-30 04:44:25 +01:00
pulse-triage[bot] 560c2de026 Automate dependency trust maintenance 2026-08-30 04:02:27 +01:00
Pulse Test d607d5cf46 Separate agent remediation runtime 2026-08-29 23:48:28 +01:00
pulse-triage[bot] e67e4a7c5f Bind container promotion to attested digests 2026-08-29 22:56:12 +01:00
Pulse Test 6d4ee48000 Add typed agent privilege helper 2026-08-29 22:51:58 +01:00
pulse-triage[bot] 7e7fb53911 Gate release publication on immutable setting 2026-08-29 22:41:04 +01:00
pulse-triage[bot] 1d170de364 Require immutable attested releases 2026-08-29 19:59:04 +01:00
pulse-triage[bot] 61a58758b2 Stabilize telemetry candidate validation
Fail schema-version drift in the fast E2E preflight before starting the browser matrix, and align the stable telemetry preview proof with schema 15.

Change-source: pulse-maintainer
2026-08-29 18:21:50 +01:00
pulse-triage[bot] 6cb5d3046b Preserve secondary issue feedback
Contract-Neutral: issue-triage intake only; no product, deployment, or release contract change
Change-source: pulse-maintainer
2026-08-29 12:24:03 +01:00
pulse-triage[bot] f83541061e Qualify embedded agent executable mode 2026-08-29 11:01:59 +01:00
pulse-triage[bot] ba73a5474e Keep published release validation non-destructive 2026-08-29 10:27:08 +01:00
Richard Courtman db0145b2b9 Bound legacy demo history startup 2026-08-29 03:47:09 +01:00
pulse-triage[bot] 2bf37a58c7 Capture blocked demo startup stack 2026-08-29 03:46:48 +01:00
pulse-triage[bot] 0d5b1202b5 Disable dev metrics backfill on stable demo 2026-08-29 03:41:44 +01:00
Richard Courtman 7255e44f57 Retain demo recovery diagnostics 2026-08-29 03:33:03 +01:00
Richard Courtman cb0e55671f Enforce exact release visual assets 2026-08-29 02:59:47 +01:00
Richard Courtman 58b07ef36c Serialize Docker staging after draft recovery 2026-08-29 01:29:17 +01:00
Pulse Test 0dc2c8c16d Require prerelease observation windows 2026-08-28 20:39:32 +01:00
Pulse Test a1ae0fa07f fix(release): require visual selection evidence 2026-08-28 20:11:04 +01:00
pulse-triage[bot] 1d15ab60a3 Defer generic retest guidance to maintainers 2026-08-28 16:25:05 +01:00
Pulse Test 354c1e6ffd feat(release): add visual changelog comparisons 2026-08-28 11:29:44 +01:00
pulse-triage[bot] 0ba57b5a68 Bound non-gating E2E probation failures 2026-08-28 04:26:34 +01:00
pulse-triage[bot] 94ccf96bad Accept qualified recovered release activation 2026-08-28 03:51:26 +01:00
Richard Courtman 7324867556 Harden release backend cold-run qualification 2026-08-28 03:36:33 +01:00
Richard Courtman 827017e196 Prepare v6.4.0-rc.10 release 2026-08-28 02:23:24 +01:00
pulse-triage[bot] 99a4ea45cb Govern rc.9 release timeout recovery 2026-08-28 02:10:07 +01:00
pulse-triage[bot] a65cd94c53 Give release backend tests timeout headroom 2026-08-28 02:07:19 +01:00
pulse-triage[bot] 8d573cd0ac Make formatting-only governance deterministic in CI
Change-source: pulse-maintainer
2026-08-26 16:03:27 +01:00
Richard Courtman 55192bf835 Clarify continuous maintenance provenance 2026-08-26 11:23:05 +01:00
rcourtman a8e84b4011 Bound legacy demo bootstrap workload 2026-08-26 10:27:58 +01:00
Richard Courtman af370a8dda Route triage comments through dedicated identity 2026-08-26 09:59:10 +01:00
rcourtman ee22a969d3 Bind container qualification to caller commit
Change-source: pulse-maintainer
2026-08-26 03:36:46 +01:00
rcourtman b34a3d8164 Fix stable demo runtime profile convergence 2026-08-26 00:20:50 +01:00
rcourtman 9ff5dfb4d4 Disable Windows signing until SignPath is ready 2026-08-25 22:24:07 +01:00
Richard Courtman 1c76a7cbdc Enforce customer-facing release notes 2026-08-25 17:13:07 +01:00
rcourtman 814f700883 Fix main CI fallout from the 50-node demo estate
The larger demo estate overflowed the rollups mock test's single
500-row page and pushed internal/api past the 25m -race budget, and
the alert history tests raced TempDir cleanup by never joining the
periodic save worker.

Walk every rollups page in the integration test, raise the shard
budget to 50m, and stop history managers through Stop() so the save
worker is joined before cleanup.

Contract-Neutral: test-only CI fix: paginate rollups mock test, join history save worker in test teardown, raise shard go test timeout for the 50-node demo estate; no runtime or contract delta
2026-08-24 08:56:07 +01:00
rcourtman 3bc613c915 Scale large-estate workload and Proxmox demo performance 2026-08-23 15:09:32 +01:00
rcourtman 6869612c66 Isolate PC compilation from SignPath workflow 2026-08-23 15:02:33 +01:00
rcourtman 32d7b22996 Use trusted PC for release compilation 2026-08-23 14:41:11 +01:00
rcourtman c7c42f87e4 Add a weekly scheduled dependency vulnerability scan
Build and Test audits npm dependencies on every push, but nothing scans the
Go module for known vulnerabilities and neither surface is re-checked when
no pushes happen — which is exactly when a newly disclosed advisory against
unchanged code goes unnoticed. Run govulncheck and both npm audits weekly on
a schedule so a failed run emails the maintainer.
2026-08-23 14:40:01 +01:00
rcourtman 567eca2572 Harden stable release convergence 2026-08-23 14:21:09 +01:00
rcourtman 2f3d224997 Use hosted container qualification for stable releases 2026-08-23 12:43:18 +01:00
rcourtman 0f369a4b0d Use hosted compilation for stable releases 2026-08-23 12:16:14 +01:00
rcourtman c1d0aaa0d5 Approve v6.3.1 unsigned Windows exception 2026-08-23 12:02:53 +01:00
rcourtman 34ae5c98f9 Fix SignPath release provenance 2026-08-23 11:39:21 +01:00
rcourtman b88e05d1ce Prepare v6.3.0 stable release 2026-08-22 10:35:27 +01:00
rcourtman b92893351d Make release dry-run diagnostics fail closed (#1758)
* Make release dry-run diagnostics fail closed

Select the installed Chromium project with retries disabled, replace the unconditional pass with fail-closed API and rendered-UI readiness assertions, retain actionable runtime evidence, and guard the release workflow contract against regression.

Contract-Neutral: Release diagnostic and workflow verification hardening only; no product runtime contract changes.

* Expose stable E2E failure identities

Project Playwright JUnit failures into bounded GitHub annotations so repeated stable-tier failures can be diagnosed without rerunning or weakening the gate. Keep the full reports and runtime logs as the forensic record, and cover annotation parsing and escaping with deterministic tests.

Contract-Neutral: This changes CI failure observability only and does not alter product runtime behavior, stable-tier membership, retries, or verdict semantics.

---------

Co-authored-by: rcourtman <rcourtman@users.noreply.github.com>
2026-08-22 07:28:29 +01:00