The exact-byte public package check superseded metadata-only chart inspection, but the broader deployment contract still required the removed command and failed deterministically. Require the consumer-path pull and byte comparison so the contract matches the stronger workflow guarantee.
Change-source: pulse-maintainer
Readable chart metadata does not prove that the public index serves the OCI-qualified package. Pull through the consumer repository and compare exact bytes before reporting convergence, with offline regression coverage for mismatched, missing and unavailable downloads. Activation and publication authority remain unchanged.
Change-source: pulse-maintainer
The scheduled reconciler can select a preview retry while silently excluding the mutable stable head. Report that concrete continuity debt in the existing log and job summary, without changing retry eligibility, credential containment or publication authority.
Validated with 37 reconciler and 47 release policy tests. New debt assertions fail against the original code; read-only live discovery reports v6.4.1 debt and preserves preview candidate 33674637446.
Change-source: pulse-maintainer
The open publication proposal exposed an earlier additive formatting correction that lacked a Contract-Neutral trailer and therefore could not pass per-commit governance without rewriting reviewed history. Infer neutrality only for immutable commits whose every governed runtime path is byte-for-byte the locked Prettier output of its parent; mixed, unreadable, added, deleted, or non-frontend changes continue to fail closed.
Change-source: pulse-maintainer
Reject mismatched image defaults before packaging; preserve equal and default versions. Reproduced four accepted mismatches before the fix. All 58 focused tests pass; no publication performed.
Change-source: pulse-maintainer
Reproduce draft and unknown publication states reaching the Pages index boundary. Require an explicitly non-draft existing release before uploading, editing or advertising its chart, without implicitly publishing operator drafts.
Exercise the actual publication shell with a fake GitHub CLI and wire its seven retry tests into canonical governance. Existing digest and maturity behaviour remains covered.
Change-source: pulse-maintainer
Fresh stable readback still shows mutable v6.4.1 alongside orphan v6.4.2. Explain forward supersession without deleting historical tags or treating frontier success as release admission. Cover that distinction with a focused recovery regression; publication authority and all existing gates remain unchanged.
Change-source: pulse-maintainer
Reproduce PR #1909 governance failures on the combined lane source. Derive reference positions from named content while retaining explicit section, ownership and verification assertions, so unrelated documentation insertions do not break CI.
Validation: all 163 subsystem lookup tests pass via pulse-heavy-run; both affected tests also pass with two documentation lines inserted in memory. No runtime or release-policy change.
Change-source: pulse-maintainer
Explain actions previously opened a blank conversation and discarded richer
finding context. Dispatch the selected explanation through shared chat
handling, retain evidence and drafts, and cancel pending work on tenant
switches. Keep unrelated workflow starters out of scoped conversations.
Record the remaining real-model and customer-outcome qualification gap
without treating scripted browser responses as proof of product value.
Close the missing third-organisation and real shell SIGTERM evidence without expanding product scope. Retain measured narrow-table clipping and accessible-name evidence so follow-up repairs preserve Android vertical gesture ownership rather than assuming horizontal scroll access.
Validation: eight Chromium admission cases, two local-backend narrow socket/access runs, real Compose/Playwright SIGTERM cleanup, twelve focused shell tests, and diff checks passed. No installed release or physical-device qualification.
Change-source: pulse-maintainer
Close the unfinished browser evidence gap without extending UI scope. Exercise admission races and subsequent current-organisation reconnect requests, and use 390x844 for populated socket recovery so retained screenshots expose the remaining table clipping rather than implying mobile layout acceptance.
Change-source: pulse-maintainer
Downstream release-note syndication repeats the asset check banner even when installed health or release convergence is not qualified. Report asset checks only and state the remaining evidence boundaries for both draft and post-publication banners.
Change-source: pulse-maintainer
Exercise real SSH signatures from an untrusted key and the trusted key under an unrelated namespace, for both manifest and installer. Keep checksum content valid so these regressions specifically protect signature trust selection.
Change-source: pulse-maintainer
The successful scheduled reconciliation at run 33972475922 retained a credential-containment hold and dispatched no retry. Put safe decision messages in the Actions summary so a green reconciler is not mistaken for delivered releases. Narrow empty-discovery wording because mutable channels and missing runs are not qualified. Preserve containment, retry budgets and dispatch behaviour; cover summary output and empty discovery with focused tests.
Change-source: pulse-maintainer
Count all activation marker names before validating their metadata so a malformed duplicate cannot pass the immutable packet boundary. Reproduced acceptance with a valid uploaded marker plus a zero-size pending duplicate; both valid and malformed duplicates now fail before attestation or download.
Validation: 13 focused integrity tests and 46 promotion policy tests pass; bash syntax and git diff checks pass. No publication or deployment performed.
Change-source: pulse-maintainer
Exercise all three reconciliation recovery paths through the mocked transport for accepted and rejected POSTs. Assert rejected submissions raise without emitting a success receipt.
Validation: 30 reconciliation tests and 46 release promotion policy tests pass. No remote mutations performed.
Change-source: pulse-maintainer
The dry-run receipt repair made submitted messages dynamic, hiding the literal
pre-commit renewal contract from canonical governance. Keep submitted and
non-mutating output distinct while spelling each receipt explicitly so the
existing release-policy guard continues to verify the recovery handoff.
Validation: 29 reconciliation tests and 46 release promotion policy tests
pass, including the check that failed on pull request 1904.
Change-source: pulse-maintainer
An outgoing admission refresh could restore platform navigation after an organisation switch. Accept only the latest request response, including when a newer request fails or is still pending. Preserve authoritative successful empty admission and subsequent navigation recovery.
Reproduced at 390px and 1440px; six repaired synthetic full-app browser cases and 59 focused tests pass. Typecheck passes. This does not qualify backend isolation, a released artifact or external alert delivery.
Change-source: pulse-maintainer
Contract-Neutral: Restore existing latest-organisation admission semantics only; no API, entitlement, navigation surface or subsystem contract changes. Focused ordering regressions and desktop/narrow browser proof cover the repair.
A read-only reconciliation of current release debt printed Dispatched despite suppressing the POST. Return submission status from the transport and qualify all three mutation receipts. Preserve retry and containment policy unchanged.
Verified 29 reconciliation and 41 workflow-trust tests; new dry-run regression rejects all three baseline paths. Live --latest --dry-run now reports Would dispatch without mutation.
Change-source: pulse-maintainer
The stable-install smoke body is intentionally workflow_call-only so its read-only continuity caller and draft-capable release caller can supply different explicit token budgets. Treat that exact no-override shape as an auditable permission boundary while continuing to reject independent triggers and job permission overrides.
Validation: 41 workflow-trust tests, repository workflow audit, focused install-smoke contract tests, Python compilation and diff checks pass.
Change-source: pulse-maintainer
Scheduled reconciliation fails when gh api refuses ANSI-bearing Actions logs. Use the dedicated sanitising log reader without disabling terminal protection, preserving private authentication and fail-closed evidence handling. Focused reconciliation and policy tests pass; a read-only live job probe retains failure evidence without ESC bytes.
Change-source: pulse-maintainer
Stable continuity run 33592377446 was rejected before any job ran: its read-only caller invoked a reusable job requesting contents:write. Extract the unchanged smoke execution into a body that inherits the caller budget, keeping the existing draft-capable entry point and its write-level draft GET access. Continuity now calls the shared body directly without broadening its token. Pin the permission boundary in regression coverage; do not relax immutable-release admission.
Change-source: pulse-maintainer
The isolated Coverage fixture cannot establish whether resource-provider and WebSocket replacement preserves application interaction in issue #1869. Exercise the actual shell, scoped paginated resources, windowed Coverage and By date, and the real PBS History drawer with synthetic snapshots. Retain desktop and narrow evidence without claiming a deployed-release or Brave fix.
Change-source: pulse-maintainer
Git tag creation can precede candidate publication, allowing stable promotion before the required observation period. Read the exact published prerelease and fail closed when publication evidence is unavailable. Cover repaired-candidate minor and patch boundaries.
Change-source: pulse-maintainer
Reconcile coverage rows by logical keys before windowing. Isolated Chromium checks at desktop and narrow widths preserve keyboard focus, expanded evidence, route and scroll across replacement HTTP snapshots. Include subsystem completion obligations and a content-bound browser receipt.
Does not qualify the full application scroll-jump report in #1869 or reporter resolution.
Change-source: pulse-maintainer
Issue #1890 reports macOS agent updates stopping because the root group does not exist. Use numeric superuser ownership in the two shared lifecycle writes without relaxing failure handling or the least-privilege group boundary. Add a regression fixture that rejects named root ownership and checks that chown failures still prevent replacement.
Change-source: pulse-maintainer
Reapply the reviewed Go 1.26.8, OCI Helm recovery, and non-login-shell test expectations that later upstream merges accidentally replaced while retaining the corresponding implementations.
Contract-Neutral: test-only reconciliation; no product or runtime behavior changed
Change-source: pulse-maintainer
A published release packet is a customer-visible surface in its own right. Deriving newer published versions only from matching Git refs lets that surface escape continuity validation when the corresponding ref is absent. Evaluate every stable-shaped release record independently and pin the detached-ref case with a regression test.
Change-source: pulse-maintainer
Update the retained canonical Python contract for the upstream wall-clock timeout mechanism and the single complete per-PR audit, while preserving the two-view scheduled audit expectations.\n\nChange-source: pulse-maintainer
Change-source: pulse-maintainer
A failed v6.4.2 release left newer stable-shaped source and public container tags behind after its GitHub Release packet was removed. Extend the scheduled continuity audit across the stable tag and public registry frontier so this partial publication cannot remain hidden behind an older latest release.
Change-source: pulse-maintainer
The security workflow moved to the scoped npm audit retry runner, but its
dependency-policy test still asserted the retired direct invocation. Assert the
checked-in all and production modes so the script suite tests the active
scheduled scan.
Contract-Neutral: test expectation only; scheduled audit behaviour is unchanged
Change-source: pulse-maintainer
The benchmark gate compared five-sample PR results with a cache produced on
another hosted VM. Two unrelated changes failed today while the same main code
passed, and benchstat reports infinite 95% confidence intervals for that sample
size.
Collect ten base and candidate samples on the PR runner in alternating order,
retain both inputs and the comparison, and reject under-sampled verdicts. Keep
non-PR benchmark evidence without the cross-run baseline cache.
Contract-Neutral: CI performance evidence collection only; no product or release contract changes
Change-source: pulse-maintainer
The retry hardening added in #1885 bounded attempts but not time. npm's own
fetch-timeout defaults to five minutes and it retries internally, so three
"attempts" against a hanging advisory endpoint ran for 10m56s on job
100986651307, and a second audit step added 3m36s. The Frontend job was
cancelled 31s into type-check with all 1183 test files already passing, and a
cancelled job reports as a failed required check, so a green run blocked every
pull request. #1888 raised the job timeout to 40 minutes to unblock delivery;
this decides the policy instead.
Each attempt now runs under a hard wall-clock bound and the sequence stops at
a total deadline (60s and 240s by default). npm's internal retry loop is
disabled in favour of this one, since it was the hidden multiplier. The bound
is enforced by a watchdog subshell rather than timeout(1), which is not
present on every developer machine.
What happens when the endpoint stays unreachable is unchanged, because that
split was already right: the run fails when the change touches the dependency
graph and the answer is genuinely unknown, and warns without failing when it
does not, because the graph is then identical to a base commit that already
produced a passing answer. Any advisory at any severity still fails.
Also drops the production-only audit from the per-pull-request path. It audits
a subset of the same packages, so it reports a subset of the same advisories,
and because the complete audit fails the job on any finding, the production
step could only ever execute in the cases where it was already guaranteed
clean. The dev-versus-production split still runs for every npm workspace in
the scheduled security-scan job, where it informs rather than blocks delivery,
and Dependabot security updates remain the route for advisories published
against unchanged dependencies.
With the audit bounded to 4 minutes against an ~11 minute baseline, the job
timeout returns to 30: a stalled endpoint should surface as a warning, not be
absorbed by a budget large enough to hide it.
Replace the remaining Node 20 action pins before GitHub removes that runtime, and make the reviewed Node 24 pins a workflow trust invariant.
Change-source: pulse-maintainer
Retire the unused self-hosted live qualification workflow and reject future secret- or write-capable jobs on persistent or dynamically selected runners. Keep live Patrol qualification as a disposable lab operation.
Change-source: pulse-maintainer
On 2026-09-03 registry.npmjs.org returned 503s and then timeouts from its
bulk advisory endpoint for over an hour. `npm audit` exits non-zero both
for a real advisory and for an endpoint it cannot reach, so the Frontend
job failed four times running and, because it is a required check, no
pull request could land at all - including Go-only ones that touch no
JavaScript. Every one of those failures was the outage. In two of the
runs the other audit call in the same job succeeded and reported zero
vulnerabilities.
The audits now run through scripts/npm-audit-retry.sh, which separates
the two cases and does nothing else. A conclusive result is acted on
immediately, and the gate stays exactly as strict as before: any
vulnerability at any severity still fails, and no severity threshold is
introduced. Only an unreachable endpoint is retried, with backoff.
When retries are exhausted the outcome depends on whether the answer is
actually unknown. A change that touches frontend-modern/package.json,
frontend-modern/package-lock.json, or the runner itself fails, because
the dependency graph moved and no result means no answer. A change that
touches none of them warns and continues, because the graph is then
identical to the base commit that already produced a passing answer.
Advisories published later against unchanged dependencies are what
Dependabot security updates are for, not a per-pull-request audit.
Deliberately not done: relaxing the severity threshold. That was my first
instinct, but the evidence does not support it. None of the four failures
was an advisory, the lockfile reports zero vulnerabilities at every
severity, and a threshold would have weakened the gate without fixing
anything. The contract's rule that audit suppression is not a valid
closure stands.
The pinning test now requires the runner's invocation and the dependency
detection wiring, and additionally asserts the runner carries no
--audit-level flag, so the strictness cannot be quietly traded away
later.
Go 1.26.8 supersedes the prior patch release, so every release builder and local toolchain guard must move together to prevent candidate artifacts from retaining an older compiler and runtime.
Contract-Neutral: toolchain-only patch update; no product or runtime contract changed
Change-source: pulse-maintainer
An unchanged control revision cannot repair release-convergence debt after its
bounded retry budget is spent. Continuing to raise from the scheduled
reconciler only creates a recurring controller failure while the original
failed run already preserves the actionable debt signal.
Treat that exhausted current revision as a stable no-op, but let a newer
control revision dispatch again so repaired controls are not stranded behind
stale attempts.
Contract-Neutral: release-control automation only; no runtime or public API contract changed
Change-source: pulse-maintainer
Move x/crypto to v0.56.0 after the upstream SSH connection deadlock advisories, and keep the local dependency-floor check from accepting a downgrade.
Contract-Neutral: dependency-only security floor update; no runtime contract changed
Change-source: pulse-maintainer