Repository navigation
ci: close verification and Central publication gaps - #42
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
AI-assisted independent reviewConclusion: no confirmed actionable defects introduced by the assessed change. I recommend merge subject to human review. This is an advisory review, with human_review_required; it is not a release approval or a formal GitHub approval. Publication remains a separate operational decision. Reviewed identity and method
The PR identity was re-read before posting and still matches this assessment. The review covered the immutable diff, surrounding code and base behavior, workflow/job dependencies, packaging contracts, publication/recovery paths, and existing CI evidence. Potential issues were checked against their prerequisites and counterexamples, including whether the behavior was already present in the base. I did not execute the project locally or perform a live Central publication. The main question was whether the proposed checks actually enforce the intended release boundaries: complete verification, one identified candidate, credential isolation, and proof of public publication before declaring a release successful. Findings and rationale1. Runtime dependency correction is justified. 2. The aggregate CI gate is meaningfully fail-closed. 3. Candidate provenance is preserved across the credential boundary. 4. Publication and recovery have appropriate terminal-state checks. The Portal interaction is consistent with the official Sonatype Publisher API documentation. Simulated responses and temporary-key signing tests support the implementation's control flow, but they cannot establish that this repository's live credentials, namespace permissions, or first recovery attempt will work. 5. Suspected issues were checked against existing behavior. CI and dependency evidenceRun 37633304945 completed with all 11 jobs green. The reviewed evidence includes:
The actual checked-out CI commit was The dependency gate reported no newly introduced HIGH-or-higher issues. The OSV evidence covered 153 packages and contained 80 existing advisory records, with zero new high/unknown entries under the gate's classification. Existing advisory records remain relevant; this result does not establish that the dependency graph is vulnerability-free. Risk assessment and recovery
A merge itself does not publish the artifact. For an interrupted publication, inspect the existing deployment and use the bound recovery path; do not assume a failed client request means nothing was uploaded. Reverting repository files cannot retract an already consumed public artifact. Remaining pre-release checks
On the evidence above, I found no substantiated introduced defect that should block this head from merging. The remaining items define the limits of the evidence and the separate release-readiness work; they do not justify automatic merge or unsupervised publication. |
Summary
Unify CI checks and fail closed on invalid results or missing test evidence. Reuse one verified artifact, add real Sentinel/TLS smoke and dependency security gates, and publish/recover through the Central Portal without rebuilding in credential-bearing jobs.
Declare Boot-managed Micrometer Core as a runtime dependency: a minimal packaged Boot application previously failed to load
MeterRegistrywithout optional Actuator. Actuator and Redisson remain optional; metrics publishing remains opt-in and no registry is created in the minimal consumer. Public Java APIs and coverage thresholds are unchanged.Evidence
8e48b3cafac9442ff9ffc30377703c2aa37e6db6. Full verification executed 992 tests, zero skipped, and coverage passed. Unit, Checkstyle, docs, actionlint/ShellCheck, 14 pipeline regressions, all three packaged Boot consumers, JMH and dependency security passed. Publication regressions use temporary GPG keys and simulated Central responses.ci-ok(app 15368), strict up-to-date checks, administrator enforcement, no force push/deletion, zero required reviewers. Dependabot alerts/security updates are enabled; maven-central permits onlyv*tag deployments.0.0.2coordinates are occupied; maintainers must configure Portal/GPG access and push a new unused version tag matching the POM and Changelog. Post-merge main CI and manual weekly verification/security, including CodeQL, passed at450a874e9bb943cba3cc8e49e4fb355a48ea2b1c. Qodana remains optional and its scan was not enabled. Live publication/recovery remains unverified.Merge Danger
Door: two-way for repository files and protection settings; public Central publication is a separate irreversible tag-triggered operation.
Blast Radius: CI/CD and dependency packaging
Local Maven publication now requires explicit
-Prelease. CI publishes the exact verified bundle, confirms PUBLISHED and public repository hashes before creating a GitHub Release, and can resume an existing deployment without uploading again. The explicit Micrometer Core dependency fixes the packaged runtime classpath while retaining optional observability/locking behavior.