Repository navigation
Replace the resolution record with a --json run log - #142
Open
nodeselector wants to merge 16 commits into
Open
nodeselector wants to merge 16 commits into
nodeselector wants to merge 16 commits into
Conversation
nodeselector
marked this pull request as ready for review
October 9, 2026 21:25
There was a problem hiding this comment.
🟡 Changes recommended
Run-log retention, permissions, failure coverage, and cross-host pin identity have unresolved correctness and security issues.
4 open findings
What changed in this PR
Replaces resolution records with retained run logs containing complete CLI JSON output.
Changes:
- Adds pin outcomes to
--json. - Moves run-log persistence into the CLI layer.
- Removes obsolete record serialization and updates tests.
| File | Description |
|---|---|
test/scenarios/catalog.yml |
Updates run-log scenario expectations. |
internal/pin/resolution.go |
Removes custom JSON serialization. |
internal/pin/resolution_test.go |
Removes obsolete serialization tests. |
internal/pin/record.go |
Removes run-log schema and persistence. |
internal/pin/record_test.go |
Removes migrated persistence tests. |
internal/pin/plan.go |
Stops recording version and timestamp metadata. |
cmd/gh-actions-lock/verify.go |
Adapts JSON formatting call. |
cmd/gh-actions-lock/runlog.go |
Implements retained CLI run logs. |
cmd/gh-actions-lock/runlog_test.go |
Tests logging and retention. |
cmd/gh-actions-lock/run.go |
Integrates logs and pin JSON output. |
cmd/gh-actions-lock/format/json.go |
Adds JSON pin outcomes. |
cmd/gh-actions-lock/format/json_test.go |
Adapts formatter tests. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
The run-record JSON written to the user cache dir had no reader, restated the lockfile, and reported failed runs as valid. --json covers machine-readable output.
Every run writes the full --json report, plus a new pins field with per-action outcomes, to the user cache dir. Unlike the old record it reflects workflows rejected before planning and the report's validity.
nodeselector
force-pushed
the
nodeselector-drop-resolution-record
branch
from
October 9, 2026 22:19
00d3e2c to
05db1ff
Compare
nodeselector
changed the base branch from
nodeselector-reject-transferred-actions
to
nodeselector-sticky-lock-parity-verify
October 9, 2026 22:19
Collaborator
Author
nodeselector
added this pull request to stack #146
October 9, 2026 22:30
# Conflicts: # internal/pin/record.go
…or-drop-resolution-record
…or-drop-resolution-record
…or-drop-resolution-record
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

The resolution record only repeated the lockfile when a run succeeded, and it was wrong when a run failed (it logged rejected runs as valid), so this drops it. Instead, every run now saves its
--jsonoutput to a run log in the user cache dir, plus a newpinsfield showing what happened to each pin, and failed runs print the path so folks can attach it to bug reports. The log is written once on every exit path, and a run that errors is never logged as valid.