Skip to content

ci: add clean-room gate CI + release workflows#403

Open
noahgift wants to merge 1 commit intomainfrom
ci/deploy-workflows
Open

ci: add clean-room gate CI + release workflows#403
noahgift wants to merge 1 commit intomainfrom
ci/deploy-workflows

Conversation

@noahgift
Copy link
Contributor

@noahgift noahgift commented Mar 4, 2026

Summary

  • Adds ci.yml — merge gate via centralized clean-room verification
  • Adds release.yml — tagged releases with crates.io Trusted Publishing (OIDC)
  • All actions pinned to commit SHAs (CVE-2025-30066 mitigation)

Spec

docs/specifications/sovereign-stack-protected-branch-strategy.md in paiml/infra

Test Plan

  • PR triggers CI and "clean-room / gate" check appears
  • Merge is blocked until CI passes
  • Tag push triggers release workflow (test with v-test-0.0.0 tag)

Generated with Claude Code

Generated by machines/clean-room/deploy-workflows.sh
Spec: sovereign-stack-protected-branch-strategy.md
Infra SHA: ca7db13be6a320dcd2f5b5b3ca9b29483abe2648

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant