Skip to content

Provision Whitaker through install-whitaker - #372

Merged
leynos merged 2 commits into
mainfrom
jm5/whitaker-install-action
Oct 1, 2026
Merged

leynos merged 2 commits into
mainfrom
jm5/whitaker-install-action

Conversation

@leynos

@leynos leynos commented Oct 1, 2026 •

Copy link
Copy Markdown
Owner

Provision Whitaker only through the shared-actions install-whitaker action, so the repository passes concordat's QG-002 rule.

  • Replaces the hand-rolled cache and install steps with leynos/shared-actions/.github/actions/install-whitaker pinned to 6cec89bac47a21cf756d68d638a9a510998e57f8 (shared-actions #546; QG-002 accepts it because install-whitaker is content-identical to the reviewed 6dea5677, #522, at that commit, per concordat Update reqwest requirement from 0.11.27 to 0.13.4 #249).
  • The action pins whitaker-installer 0.2.9, verifies the release archive against a pinned digest, passes --no-source-fallback, and takes github.token itself. The lint suite stays a rolling release.
  • The repository's lint invocation is unchanged.

More than a pin (review-gated)

  • The installer-version input stays (tests/contracts/supply_chain.rs asserts it) and is raised from 0.2.7 to the action's 0.2.9 floor; the test follows.
  • every_shared_action_reference_is_pinned holds each action to a reviewed commit with named exceptions in tests/support/workflow_estate.rs. install-whitaker now sits at 6cec89ba, so it joins that table as its own exception (WHITAKER_ACTION_SHA) rather than moving the estate-wide constant, which would repin every other action. 6cec89ba is a shared-actions main commit that leaves install-whitaker content-identical to the reviewed 6dea5677, the set concordat's QG-002 accepts.
  • Proved by mutation: pointing the step back at c5a54701 fails every_shared_action_reference_is_pinned. cargo test --test workflow_contracts passes (185); the rest of the suite is untouched.

QG-002 proof

$ concordat artefact rule run whitaker-provisioning --repo .
whitaker-provisioning: compliant
rule rc=0
$ actionlint
.github/workflows/ci.yml 
actionlint rc=0

Summary by Sourcery

Use the reviewed shared install-whitaker action to provision Whitaker and satisfy the repository’s workflow supply-chain requirements.

Enhancements:

  • Provision Whitaker through the reviewed shared install-whitaker action with its pinned installer version and release verification.
  • Track the Whitaker action as an independently reviewed workflow pin to satisfy supply-chain and QG-002 requirements.

Documentation:

  • Document the independent Whitaker action pin and required installer version in the developer guide.

Tests:

  • Update the supply-chain contract and shared-action pin exceptions for Whitaker 0.2.9 and its reviewed action revision.

Replace the hand-rolled Whitaker provisioning with the shared-actions
install-whitaker action, pinned to 6dea5677 (shared-actions #522), the
revision the concordat QG-002 rule lists as compliant. The action
installs the exact installer version it pins from a digest-verified
release archive, never builds from source, and leaves the lint suite a
rolling release. The lint invocation is unchanged.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @leynos, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 6 minutes by commenting @sourcery-ai review. Upgrade to get a review now.

@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Team

Run ID: 7270cc59-4067-4142-93e9-d8c0a3af0904

📥 Commits

Reviewing files that changed from the base of the PR and between 79d5ef4 and 46313e0.

📒 Files selected for processing (3)
  • .github/workflows/ci.yml
  • tests/contracts/supply_chain.rs
  • tests/support/workflow_estate.rs
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour.


Summary

  • Replace the Whitaker installation step’s shared-action revision c5a54701 with 6cec89ba and update installer-version from 0.2.7 to 0.2.9. Keep cache-provider: github unchanged.
  • Add WHITAKER_ACTION_SHA and register install-whitaker as an exception to the shared-action pin in SHARED_ACTION_PIN_EXCEPTIONS. Keep the estate-wide pin unchanged.
  • Update the supply-chain contract to expect installer version 0.2.9.

Walkthrough

The CI workflow now installs Whitaker version 0.2.9 through an updated pinned shared action. Test support and the supply-chain contract reflect the new version and pin.

Changes

Whitaker installer update

Layer / File(s) Summary
Update the installer pin and checks
.github/workflows/ci.yml, tests/support/workflow_estate.rs, tests/contracts/supply_chain.rs
The CI workflow uses the new shared-action revision and installer version 0.2.9. Test support records the action pin exception, and the supply-chain contract expects version 0.2.9.

Priority: ⬇️ Low

Change: Other

Merge Risk: ⚪ Minimal · up to 46313

The Whitaker update is mergeable with no concrete current-head risk identified.


Caution

Pre-merge checks failed

Please resolve all errors before merging. Addressing warnings is optional.

  • Ignore

❌ Failed checks (1 error, 1 warning)

Check name Status Explanation Resolution
Testing (Unit And Behavioural) ❌ Error The pull request changes the externally observable GitHub Actions workflow and the Whitaker installation network boundary, but it adds no end-to-end or execution-level test. The updated `whitaker_is_i… Add a workflow-level smoke or end-to-end test that invokes the pinned install-whitaker action at the supported boundary and verifies that Whitaker is installed with the requested version and expected failure-safe behaviour. Extend the sha…
Developer Documentation ⚠️ Warning The pull request changes the Whitaker CI tooling: it raises installer-version to 0.2.9 and adds install-whitaker at 6cec89ba... as a shared-action pin exception. The pull request does not chan… Update docs/developers-guide.md to document the Whitaker installer version 0.2.9, the reviewed install-whitaker commit 6cec89bac47a21cf756d68d638a9a510998e57f8, and its separate entry in SHARED_ACTION_PIN_EXCEPTIONS. Correct the s…
✅ Passed checks (13 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files. (1 skipped: 1 …
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Testing (Overall) ✅ Passed Accept the testing coverage. The authoritative diff changes only the Whitaker shared-action revision and installer version; the workflow already used install-whitaker at the base revision. `whitaker…
User-Facing Documentation ✅ Passed Pass. Treat this change as CI-only tooling maintenance, not user-facing functionality. The PR changes only the GitHub Actions Whitaker installer reference/version and workflow contract constants; it c…
Module-Level Documentation ✅ Passed Pass the module-level documentation check. The pull request changes no module declarations. The changed Rust modules already have //! documentation that states their purpose, utility, and relationsh…
Testing (Property / Proof) ✅ Passed No property test or exhaustive proof is required. The PR changes a fixed workflow action coordinate and a fixed installer version. The relevant invariant is finite and repository-owned: `every_shared_…
Testing (Compile-Time / Ui) ✅ Passed Pass this check. The pull request changes GitHub Actions provisioning and Rust workflow-contract test data. It introduces no Rust or TypeScript compile-time behaviour, so a trybuild or equivalent test…
Unit Architecture ✅ Passed PASS. Restrict the review to the three changed files: the pull request updates a pinned GitHub Action revision and installer version, updates the matching workflow contract, and adds the reviewed revi…
Domain Architecture ✅ Passed Pass this check. The pull request changes only the GitHub Actions workflow and workflow-contract test support. It does not change domain logic, adapters, repositories, transport code, persistence code…
Observability ✅ Passed Pass. The diff changes only the CI Whitaker installation action, its installer version, and workflow contract tests. It does not change production service behaviour, process boundaries, request handli…
Title check ✅ Passed The title clearly identifies the main change: provisioning Whitaker through the shared install-whitaker action. No roadmap item or issue reference is required by the provided context.
Description check ✅ Passed The description directly explains the replacement of the hand-rolled Whitaker provisioning with the pinned shared action and documents the related tests and policy checks.
Full details: Developer Documentation

Explanation

The pull request changes the Whitaker CI tooling: it raises installer-version to 0.2.9 and adds install-whitaker at 6cec89ba... as a shared-action pin exception. The pull request does not change docs/developers-guide.md. Its Tool installation section still states that the exceptions are only the two coverage actions, so the developer documentation is inaccurate.

Resolution

Update docs/developers-guide.md to document the Whitaker installer version 0.2.9, the reviewed install-whitaker commit 6cec89bac47a21cf756d68d638a9a510998e57f8, and its separate entry in SHARED_ACTION_PIN_EXCEPTIONS. Correct the statement that only the two coverage actions are exceptions.

Full details: Testing (Unit And Behavioural)

Explanation

The pull request changes the externally observable GitHub Actions workflow and the Whitaker installation network boundary, but it adds no end-to-end or execution-level test. The updated whitaker_is_installed_from_a_pinned_prebuilt_release test only parses .github/workflows/ci.yml and checks two input values. The generic pin contract checks the configured reference, but it does not execute install-whitaker or verify installation, digest validation, --no-source-fallback, token handling, or cache behaviour. The new install-whitaker exception also has no direct case in a_shared_action_reference_resolves_to_its_reviewed_commit; that test still covers only the two existing exceptions and default/lookalike paths.

Resolution

Add a workflow-level smoke or end-to-end test that invokes the pinned install-whitaker action at the supported boundary and verifies that Whitaker is installed with the requested version and expected failure-safe behaviour. Extend the shared-action resolution cases with install-whitaker, plus a negative pin case, so the new exception and its edge path are independently tested.

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Whitaker’s pin moves on,
The installer steps to nine,
The workflow marks the change,
Contract checks keep pace in line,
Three pins sit in the ledger,
CI starts the newer run.

Comment @coderabbitai help to get the list of available commands.

@sourcery-ai

sourcery-ai Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

Whitaker provisioning now uses the shared install-whitaker action at a reviewed, content-approved commit, with the installer floor updated to 0.2.9 and workflow pinning tests explicitly recognizing its independent revision. The lint invocation remains unchanged; the described QG-002 and actionlint checks pass.

Flow diagram for reviewed Whitaker action pinning

flowchart TD
    Workflow["CI workflow"] --> ActionRef["install-whitaker@6cec89ba"]
    ActionRef --> PinCheck["every_shared_action_reference_is_pinned"]
    PinCheck --> Exception["WHITAKER_ACTION_SHA reviewed exception"]
    ActionRef --> Contract["installer-version 0.2.9"]
    Contract --> Tests["cargo test --test workflow_contracts"]
Loading

File-Level Changes

Change Details Files
Replaced the repository-owned Whitaker installation and cache setup with the reviewed shared install action.
  • Pinned the action to the reviewed 6cec89ba commit, whose content satisfies QG-002.
  • Kept GitHub cache provisioning while delegating installer, archive verification, cache ownership, token handling, and no-source-fallback behavior to the action.
  • Preserved the existing lint command and workflow behavior after installation.
.github/workflows/ci.yml
Updated supply-chain contract expectations for the action-managed installer version.
  • Raised the required installer-version from 0.2.7 to 0.2.9.
  • Continued asserting GitHub cache usage and the action-based installation contract.
tests/contracts/supply_chain.rs
Added an explicit workflow-estate exception for the independently reviewed Whitaker action pin.
  • Defined WHITAKER_ACTION_SHA for 6cec89ba.
  • Registered install-whitaker as a named exception without repinning the estate-wide shared-actions revision.
tests/support/workflow_estate.rs

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-01T14:15:00.601663Z 46313e0 PR opened
🔒 Security Review ✅ Completed 2026-10-01T14:18:09.051546Z 46313e0 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

codescene-access[bot]

This comment was marked as outdated.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 46313e0837

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread tests/support/workflow_estate.rs

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pre-merge checks failed. Please resolve the failing checks before merging.

The developers' guide named only the two coverage actions as shared-action
pin exceptions. install-whitaker is a third, held to WHITAKER_ACTION_SHA
because QG-002 accepts a later main commit that leaves the action
unchanged, and its installer-version input is asserted at 0.2.9.
@leynos

leynos commented Oct 1, 2026

Copy link
Copy Markdown
Owner Author

Answering the Testing (Unit And Behavioural) error row: it asks for a test that executes the install-whitaker action. That execution is covered where the action lives: shared-actions' own contract and test suite install Whitaker through the action (digest verification, --no-source-fallback, the Windows and no-prebuilt-release cases), and the QG-002 rule in concordat audits every consumer's use of it. This pull request changes only the pin and the installer-version input, and the repository's own contract (supply_chain.rs) asserts both and was mutation-proved: pointing the step back at the old commit fails every_shared_action_reference_is_pinned. An act-style run of the workflow is waived across the estate for the same reason (rust-prover-tools #132, hecate #113, ghillie #149), because it would rebuild the action's coverage inside every consumer. The Developer Documentation warning is fixed at 4a31cff.

@leynos
leynos merged commit 5995441 into main Oct 1, 2026
9 checks passed
@leynos
leynos deleted the jm5/whitaker-install-action branch October 1, 2026 18:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant