Skip to content

Replace the resolution record with a --json run log - #142

Open
nodeselector wants to merge 16 commits into
nodeselector-sticky-lock-parity-verifyfrom
nodeselector-drop-resolution-record
Open

nodeselector wants to merge 16 commits into
nodeselector-sticky-lock-parity-verifyfrom
nodeselector-drop-resolution-record

Conversation

@nodeselector

@nodeselector nodeselector commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

The resolution record only repeated the lockfile when a run succeeded, and it was wrong when a run failed (it logged rejected runs as valid), so this drops it. Instead, every run now saves its --json output to a run log in the user cache dir, plus a new pins field showing what happened to each pin, and failed runs print the path so folks can attach it to bug reports. The log is written once on every exit path, and a run that errors is never logged as valid.

@nodeselector nodeselector changed the title Drop the resolution record Replace the resolution record with a --json run log Oct 9, 2026
@nodeselector
nodeselector marked this pull request as ready for review October 9, 2026 21:25
@nodeselector
nodeselector requested a review from a team as a code owner October 9, 2026 21:25
Copilot AI balanced review requested due to automatic review settings October 9, 2026 21:25

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Run-log retention, permissions, failure coverage, and cross-host pin identity have unresolved correctness and security issues.

4 open findings
What changed in this PR

Replaces resolution records with retained run logs containing complete CLI JSON output.

Changes:

  • Adds pin outcomes to --json.
  • Moves run-log persistence into the CLI layer.
  • Removes obsolete record serialization and updates tests.
File Description
test/​scenarios/​catalog.yml Updates run-log scenario expectations.
internal/​pin/​resolution.go Removes custom JSON serialization.
internal/​pin/​resolution_test.go Removes obsolete serialization tests.
internal/​pin/​record.go Removes run-log schema and persistence.
internal/​pin/​record_test.go Removes migrated persistence tests.
internal/​pin/​plan.go Stops recording version and timestamp metadata.
cmd/​gh-actions-lock/​verify.go Adapts JSON formatting call.
cmd/​gh-actions-lock/​runlog.go Implements retained CLI run logs.
cmd/​gh-actions-lock/​runlog_test.go Tests logging and retention.
cmd/​gh-actions-lock/​run.go Integrates logs and pin JSON output.
cmd/​gh-actions-lock/​format/​json.go Adds JSON pin outcomes.
cmd/​gh-actions-lock/​format/​json_test.go Adapts formatter tests.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread cmd/gh-actions-lock/format/json.go Outdated
Comment thread cmd/gh-actions-lock/run.go Outdated
Comment thread cmd/gh-actions-lock/runlog.go Outdated
Comment thread cmd/gh-actions-lock/runlog.go
The run-record JSON written to the user cache dir had no reader, restated
the lockfile, and reported failed runs as valid. --json covers
machine-readable output.
Every run writes the full --json report, plus a new pins field with
per-action outcomes, to the user cache dir. Unlike the old record it
reflects workflows rejected before planning and the report's validity.
@nodeselector
nodeselector force-pushed the nodeselector-drop-resolution-record branch from 00d3e2c to 05db1ff Compare October 9, 2026 22:19
@nodeselector
nodeselector changed the base branch from nodeselector-reject-transferred-actions to nodeselector-sticky-lock-parity-verify October 9, 2026 22:19
@nodeselector

Copy link
Copy Markdown
Collaborator Author

Rebased onto #145, which supersedes #118.

@nodeselector
nodeselector added this pull request to stack #146 October 9, 2026 22:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants