Skip to content

ci: publish with verified provenance - #91

Merged
martinfrancois merged 1 commit into
mainfrom
ci/publish-provenance
Sep 21, 2026
Merged

martinfrancois merged 1 commit into
mainfrom
ci/publish-provenance

Conversation

@martinfrancois

@martinfrancois martinfrancois commented Sep 21, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Problem: tessl plugin publish in the java-functional-style-skill 0.1.0 release run (GitHub Actions run 35557635462 in that repository) warned "This job cannot read a GitHub OIDC token. This publish will go out without verified provenance."
  • Why it matters: the warning names the fix; with the permission, Tessl publishes with verified provenance.
  • What changed: the workflow-level permissions: block in .github/workflows/publish-tessl.yml gains id-token: write next to contents: read. The workflow has one job, so the grant reaches the step that runs tessl plugin publish .. No action input is needed; the CLI reads the token itself, and the setup-tessl README's publish example uses exactly these two permissions.
  • What did not change: anything else in the workflow, the runtime bundle, evals, or the other workflows (their dry-run jobs printed no such warning, and ci.yml runs on pull requests, where widening permissions is not wanted).

Change Type

  • Skill behavior
  • Evals or scoring
  • Documentation
  • CI, release, or dependency automation
  • Repository metadata or contribution process
  • Other maintenance

Linked Issue

  • No issue. Source: the warning in run 35557635462 of java-functional-style-skill; this repository's publish workflow has the byte-identical permissions block, so it will print the same warning on its next release.

User-Visible Behavior

None. Future releases publish with verified provenance.

Bug Fix Details

  • Root cause: the workflow-level permissions: block replaces GitHub's defaults and did not include id-token.
  • Test, eval, or guardrail added: none; the next release run shows whether the warning is gone.
  • If no test or eval was added, why not: a permission line has no local test.

Validation

Checks most contributors can run:

  • bash -n scripts/*.sh -> passed
  • python3 -m py_compile scripts/*.py -> passed
  • python3 scripts/validate_json_files.py -> passed
  • python3 scripts/validate_openai_agent_yaml.py -> passed
  • python3 scripts/validate_skill.py skills/java-streams -> passed
  • python3 scripts/validate_eval_criteria.py evals evals-reference evals-regression -> passed, 29 scenarios
  • tessl plugin lint . -> passed
  • npx js-yaml .github/workflows/publish-tessl.yml -> parses; permissions is {contents: read, id-token: write}

Tessl-authenticated checks:

  • Skipped on purpose: docs/agents/workflow.md lists the publish dry-runs for CI changes; a permission line changes no package content, so they would show nothing new.

Details:

The only diff is one added line at workflow level. Review checked that the job still has contents: read for both checkouts and that the environment gate does not affect OIDC issuance.

Human Verification

Read the warning text in the publish log and the tesslio/setup-tessl README publish example; the fix is the permission the warning names.

Review Checklist

  • The change is scoped to the sections, skill files, evals, or workflows described above.
  • Validation that applies to this change is checked above, or any unavailable check is explained.
  • If Java stream guidance changed, Java baseline compatibility plus ordering, null handling, and parallelism were considered. (Not changed.)
  • If evals or benchmark claims changed, the eval scenarios remain fair and do not leak answer keys, run IDs, or fixed score claims into runtime references. (Not changed.)
  • If runtime skill text or references changed, hosted checks were widened as described in docs/agents/workflow.md, or any Tessl blocker is documented. (Not changed.)
  • If a runtime skill/reference change was released, the final report includes the published main eval run plus post-change reference and regression run IDs, or a blocker issue for missing broad suites. (Not applicable.)
  • Main and reference evals were run with both variants when hosted evals were needed; regression evals were run with context only unless reclassification back to reference was being checked. (Not needed.)
  • New or moved eval scenarios follow the classifier recommendation, or the PR explains the maintainer-approved override. (None.)
  • Every retained eval scenario has a 100% with-context result, or any below-100 result is documented as blocking follow-up rather than classified/reportable coverage. (Unchanged suite.)
  • PR title or squash title uses Conventional Commits.
  • Redaction checked: no tokens, private links, private eval artifacts, local host paths, or proprietary Java source.

AI Assistance (if used)

  • AI-assisted PR
  • I confirm I understand and reviewed the change
AI prompts / session logs (optional)
AI assistance drafted the change and the description and ran a two-axis code review; the local checks listed above were run on this branch before the description was written.

The java-functional-style 0.1.0 publish run warned that the job cannot
read a GitHub OIDC token, so plugins go out without verified provenance;
this workflow has the same permissions block. The publish job now
requests id-token: write.
@martinfrancois
martinfrancois merged commit 886dc0b into main Sep 21, 2026
7 checks passed
@martinfrancois
martinfrancois deleted the ci/publish-provenance branch September 21, 2026 04:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant