Skip to content

ci(repo): publish the evidence a borrowed-device Expo session hands off - #10163

Draft
mikepitre wants to merge 1 commit into
mike/expo-verify-borrowed-devicefrom
mike/expo-verify-attach
Draft

mikepitre wants to merge 1 commit into
mike/expo-verify-borrowed-devicefrom
mike/expo-verify-attach

Conversation

@mikepitre

Copy link
Copy Markdown
Contributor

Description

A cloud agent cannot put a run's video and screenshots on its pull request. Its sandbox refuses the upload, and the Actions token cannot attach files. So attach in #10131 hands the files to the session's runner, which keeps them as the artifact verify-evidence. This PR adds the workflow that reads that artifact and puts the evidence in the pull request description, with a bot token.

It is the fifth PR of the stack and sits on #10131, which sits on #10090, #10087, and #10052. GitHub starts the workflow only when it and verify-remote.yml are both on main. So it does nothing until the whole stack has merged.

One commit.

File Lines added What it does
.github/workflows/verify-attach.yml 83 Runs on workflow_run when a verify-remote session ends, from the default branch.
scripts/verify-attach.mjs 813 Downloads the artifact, validates it, and edits one block of the description with gh pr edit --attach.
scripts/verify-attach.test.mjs 1,460 143 tests of the script and of the workflow file.
.github/workflows/ci.yml 4 Runs those tests in the Unit Tests job, on its Node 24 leg.
.github/actionlint.yaml 5 Lets concurrency.queue through in this one workflow, because actionlint 1.7 does not know the key.
.changeset/expo-verify-attach.md 2 An empty changeset. No package changes.

The script is the same file, byte for byte, in clerk/clerk-ios and clerk/clerk-android. Review it once.

  • The artifact was written by branch code, so the job treats it as data. It never checks out, installs, or runs anything from the branch or from the artifact. The script reads the zip itself and refuses anything outside a fixed manifest, file names, sizes, counts, and leading bytes.
  • It publishes only to the open pull request of the session's branch, in this repository, and only when the commit the session started on and the commit the run was made at are both commits of that pull request. GitHub lists only the first 250 commits of a pull request, and when a longer one has either commit past them the workflow says so and publishes nothing.
  • The line it writes says that the session reported the result, links the session's run, and names the commit and the account that started the session, as GitHub records it. When the pull request has newer commits, the line says so. A later run and attach replaces the block.
  • The description gets one block per platform, between the comments <!-- verify-evidence:ios --> and <!-- /verify-evidence:ios -->, or the same two with android. Everything outside a block is kept as it was, with the line endings the description has. The workflow refuses a description that has neither comment and ends inside a code fence that never closes.
  • The runs for one branch take turns, and queue: max keeps every run that waits.
  • The workflow has actions: read and contents: read, and only the step that runs gh holds the token. It starts after every verify-remote session, with or without evidence, and each start shows as a deployment to verify-evidence.

A repository admin has to set this up before the workflow can publish:

  1. Create an environment named verify-evidence, and limit its deployment branches to main.
  2. Give a machine account write access to the repository.
  3. Create a fine-grained personal access token for it, limited to this repository, with "Pull requests: read and write".
  4. Store it as the secret VERIFY_EVIDENCE_TOKEN of that environment.
  5. Do not create a repository secret of that name.

A repository secret can be read by a workflow that anyone with write access adds on any branch. A secret of an environment that allows only main cannot. Without the environment or its secret the job prints a notice and publishes nothing.

Not proven, and not provable before the stack is on main:

  • That a real session's end starts the workflow, and that the job gets the environment's secret.
  • That a fine-grained token with only "Pull requests: read and write" can attach files with gh pr edit --attach.
  • A real verify-evidence artifact. The script was run against zips made on a Mac.
  • That queue: max keeps every waiting run in this workflow.
  • A real hand-off from a cloud sandbox through the tunnel, which is test(expo): borrow a device on a CI runner when the machine cannot run one #10131's part.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other: test tooling

🤖 Generated with Claude Code

@vercel

vercel Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
clerk-js-sandbox Ready Ready Preview Oct 9, 2026 7:20pm UTC
swingset Ready Ready Preview Oct 9, 2026 7:20pm UTC

Request Review

@changeset-bot

changeset-bot Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: da81537

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 0 packages

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@pkg-pr-new

pkg-pr-new Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@10163

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@10163

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@10163

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@10163

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@10163

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@10163

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@10163

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@10163

@clerk/expo-biometrics

npm i https://pkg.pr.new/@clerk/expo-biometrics@10163

@clerk/expo-google-signin

npm i https://pkg.pr.new/@clerk/expo-google-signin@10163

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@10163

@clerk/express

npm i https://pkg.pr.new/@clerk/express@10163

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@10163

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@10163

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@10163

@clerk/mosaic

npm i https://pkg.pr.new/@clerk/mosaic@10163

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@10163

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@10163

@clerk/react

npm i https://pkg.pr.new/@clerk/react@10163

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@10163

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@10163

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@10163

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@10163

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@10163

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@10163

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@10163

commit: da81537

A cloud agent cannot attach a run's video and screenshots to its pull
request: its sandbox refuses the upload, and the Actions token cannot
attach. `verify-attach.yml` does it instead. It runs on `workflow_run`
when a `verify-remote` session ends, so GitHub always runs the copy on
the default branch.

The job downloads the session's `verify-evidence` artifact and treats
it as data. `scripts/verify-attach.mjs` reads the zip itself,
refuses anything outside a fixed manifest schema, file names, sizes,
counts, and leading bytes, and writes only files it validated. It then
edits one marked block in the description with `gh pr edit --attach`.
The line it writes says that the session reported the result and links
the session's run.

It publishes only to the open pull request of the session's branch, in
this repository, and only when the commit the session started on and
the commit the run was made at are both commits of that pull request.
When the pull request has moved on, the line says so.

The bot token is the secret `VERIFY_EVIDENCE_TOKEN` of the environment
`verify-evidence`, which allows only the default branch. A repository
secret could be read by a workflow on any branch. Only the step that
runs `gh` holds the token. Without the secret the job prints a notice.
GitHub starts this workflow only when it and `verify-remote.yml` are
both on the default branch.

The runs for one branch take turns at the description, and
`queue: max` keeps every run that waits.

The `Unit Tests` job of `ci.yml` runs the script's tests on its
Node 24 leg. `.github/actionlint.yaml` ignores the `queue` key in this
workflow, which actionlint 1.7 does not know.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

This branch was successfully deployed

2 active deployments
Preview – swingset — da815370 Deployed Oct 9, 2026 by vercel[bot]
Preview – clerk-js-sandbox — da815370 Deployed Oct 9, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant