Skip to content

Fix hidden consumer verification artifact upload - #28

Merged
fraware merged 2 commits into
mainfrom
fix/consumer-pin-artifact-upload
Aug 26, 2026
Merged

fraware merged 2 commits into
mainfrom
fix/consumer-pin-artifact-upload

Conversation

@fraware

@fraware fraware commented Aug 26, 2026 •

Copy link
Copy Markdown
Owner

Final closure fix for Consumer Pin Verification evidence capture.

The fresh merged-consumer verification proved both consumer repositories pin the exact release candidate SHA and successfully generated ledger-ready evidence, but the workflow failed at artifact upload because the evidence is written under the hidden .verification/ directory and actions/upload-artifact excludes hidden files by default.

This PR makes the minimal correction:

  • sets include-hidden-files: true on the consumer evidence upload step;
  • adds a regression test in tests/test_workflow_dispatch_contracts.py requiring hidden evidence inclusion, if-no-files-found: error, and the .verification/ evidence path.

No candidate identity, consumer pin, verifier semantics, benchmark logic, package logic, or release claim is changed. The release evidence candidate remains b8d734f4a6a92a534aed87db91e12df16b718a9e.

Exact-head validation on fca749bc53fb96255787388cc49da0d169fb4cd4 is complete: CI run 33013596104 succeeded and Repro baseline run 33013596347 succeeded across its full matrix.

@fraware
fraware merged commit 0a429f1 into main Aug 26, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant