Skip to content

chore: authorize v0.74.0 release source - #2762

Merged
steipete merged 1 commit into
mainfrom
release/0.74.0-source
Oct 11, 2026
Merged

steipete merged 1 commit into
mainfrom
release/0.74.0-source

Conversation

@steipete

Copy link
Copy Markdown
Contributor

Bind v0.74.0 to its signed tag object and frozen source commit. GitHub reports the tag signature verified against the registered maintainer signing key.

The source is the merged preparation PR #2761. Exact-source CI and coordinator deployment passed. The source-built AWS smoke passed run, attach, ordered events, retained logs, and cleanup: the lease is released and absent from the active inventory and local claims. Attribution and unchanged published-history audits passed.

Validation: source-record JSON and independent Codex review passed with no actionable P0–P2 findings. Required CI and the protected release check must pass before merge. No candidate or draft has been produced; signing, notarization, native verification, publication and channel smokes remain separate gates under the release authorization.

@steipete
steipete requested a review from a team as a code owner October 11, 2026 00:08
@clawsweeper

clawsweeper Bot commented Oct 11, 2026 •

Copy link
Copy Markdown
Contributor

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@clawsweeper clawsweeper Bot added P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. labels Oct 11, 2026
@clawsweeper

clawsweeper Bot commented Oct 11, 2026

Copy link
Copy Markdown
Contributor

Codex review: needs maintainer review before merge.

What this changes

This PR adds the v0.74.0 release record binding its signed tag object to the frozen source commit.

Example: An operator prepares the v0.74.0 release candidate.

  • Before: Source verification rejects the missing protected release record.
  • After: Once merged, the record supplies the pinned source identity while later release gates remain required.

Review scores

Measure Result What it means
Overall readiness 🐚 platinum hermit (4/6) A focused, source-verified administrative change with no findings; real runtime proof is outside this record-only change.
Proof confidence 🌊 off-meta tidepool Not applicable: This maintainer-authored release-record addition changes no runtime implementation; remote tag verification confirms its identity, while candidate and publication proof remain later release gates.
Patch quality 🦞 diamond lobster (5/6) No actionable review findings were identified.

Product

Kind: Maintenance · Worth it: Yes · Fix scope: Complete
User problem: The release operator needs the protected source record required to produce the v0.74.0 candidate.
Reason: Repository policy explicitly requires this record, and the maintainer-authored direction follows repeated prior merged release work.

Merge readiness

✅ Ready for maintainer review

Keep this PR open: the release-source record is absent from main, matches the verified signed tag, and introduces no actionable defect.

Priority: P3
Reviewed head: 86314e003a5442175aa8a36f904d56cf9958a2d5

Before merge

None.

Findings

None.

Agent review details

How this fits together

Release tooling consumes the protected JSON record, signed tag, signer policy, and source ancestry to validate candidate production and publication inputs.

flowchart TD
 A[Signed version tag] --> C[Source verification]
 B[Protected release record] --> C
 D[Signer policy and main ancestry] --> C
 C --> E[Candidate production]
 E --> F[Signing and native verification]
 F --> G[Explicit publication]
Loading

Technical review

Best possible solution:

Land the matching source record through the existing protected checks and continue the documented release sequence.

Do we have a high-confidence way to reproduce the issue?

This is release administration rather than a bug report; the pinned diff and live tag metadata establish the requested source binding.

Is this the best way to solve the issue?

The record follows the established schema and previous release pattern without replacing or weakening the existing verification owners.

AGENTS.md: found and applied where relevant.

Codex review notes: model internal, reasoning medium; reviewed against 338eb4a43620.

Security

None.

Evidence

What I checked:

  • Pinned introduced change: The complete introduced diff adds only the eight-line schema-1 release record; no executable tooling or existing record changes. (release/records/v0.74.0.json:1, 86314e003a54)
  • Verified remote source identity: GitHub reports tag object 6a6013fdb53c0837bb798e0f6633f76e4ecd6bf3 as validly signed, annotated v0.74.0, and pointing to the exact recorded source commit. (release/records/v0.74.0.json:5, 86314e003a54)
  • Merged preparation and current main: chore: prepare 0.74.0 release #2761 merged as the recorded source commit; the live default branch still points there, and the latest published release remains v0.73.0. (338eb4a43620)
  • Existing identity and publication gates: The existing source verifier requires matching record fields, an allowed signed annotated tag, and source ancestry; the publisher repeats protected-source validation with REQUIRE_PUBLISHABLE=1 before its publication sequence. (scripts/verify-release-source.sh:35, 338eb4a43620)
  • Applicable repository policy: The complete root AGENTS.md requires a merged source record before production and preserves separate signing, verification, publication, and cancellation gates; no release-subtree AGENTS.md or maintainer-notes directory was found. (AGENTS.md, 86314e003a54)
  • Release ownership history: Current-main history shows repeated release-record work and major release-trust refactors by Peter Steinberger; CODEOWNERS routes release records to openclaw-secops. (release/records/v0.73.0.json:5, 338eb4a43620)

Likely related people:

  • Peter Steinberger: Raw commit 7d597ef adds release/records/v0.73.0.json:5 relative to its recorded parents. This identifies author metadata, not feature responsibility or a PR merger. (role: source-line author; confidence: high; commits: 7d597efb297a; files: release/records/v0.73.0.json)

Labels

Label changes:

  • add P3: This is a focused release-administration record using existing tooling and policy.
  • add rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🌊 off-meta tidepool and patch quality is 🦞 diamond lobster.
  • add status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR.

Label justifications:

  • P3: This is a focused release-administration record using existing tooling and policy.
  • rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🌊 off-meta tidepool and patch quality is 🦞 diamond lobster.
  • status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR.

Rating scale

6/6 🦀 challenger crab · 5/6 🦞 diamond lobster · 4/6 🐚 platinum hermit · 3/6 🦐 gold shrimp · 2/6 🦪 silver shellfish · 1/6 🧂 unranked krab. Overall follows the weaker of proof and patch quality; ✨ marks media proof (a screenshot, video, or linked artifact) that directly shows the changed behavior.

Workflow

ClawSweeper edits this one comment on every review. Comment @clawsweeper re-review for a fresh review only; repair and merge need explicit maintainer commands such as @clawsweeper autofix or @clawsweeper automerge.

Reviewed October 10, 2026, 8:10 PM ET / October 11, 2026, 00:10 UTC.

@steipete
steipete merged commit 7529953 into main Oct 11, 2026
35 checks passed
@steipete
steipete deleted the release/0.74.0-source branch October 11, 2026 00:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant