Repository navigation
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
🦋 Changeset detectedLatest commit: da81537 The changes in this PR will be included in the next version bump. This PR includes changesets to release 0 packagesWhen changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
Contributor
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: true
Comment |
mikepitre
added this pull request to stack #10100
October 9, 2026 02:05
3 of 9 tasks
mikepitre
force-pushed
the
mike/expo-verify-attach
branch
from
October 9, 2026 04:58
fcf1e27 to
a99c47a
Compare
@clerk/astro
@clerk/backend
@clerk/chrome-extension
@clerk/clerk-js
@clerk/electron
@clerk/electron-passkeys
@clerk/eslint-plugin
@clerk/expo
@clerk/expo-biometrics
@clerk/expo-google-signin
@clerk/expo-passkeys
@clerk/express
@clerk/fastify
@clerk/hono
@clerk/localizations
@clerk/mosaic
@clerk/nextjs
@clerk/nuxt
@clerk/react
@clerk/react-router
@clerk/shared
@clerk/tanstack-react-start
@clerk/testing
@clerk/ui
@clerk/upgrade
@clerk/vue
commit: |
mikepitre
force-pushed
the
mike/expo-verify-attach
branch
from
October 9, 2026 14:52
a99c47a to
55f48b3
Compare
A cloud agent cannot attach a run's video and screenshots to its pull request: its sandbox refuses the upload, and the Actions token cannot attach. `verify-attach.yml` does it instead. It runs on `workflow_run` when a `verify-remote` session ends, so GitHub always runs the copy on the default branch. The job downloads the session's `verify-evidence` artifact and treats it as data. `scripts/verify-attach.mjs` reads the zip itself, refuses anything outside a fixed manifest schema, file names, sizes, counts, and leading bytes, and writes only files it validated. It then edits one marked block in the description with `gh pr edit --attach`. The line it writes says that the session reported the result and links the session's run. It publishes only to the open pull request of the session's branch, in this repository, and only when the commit the session started on and the commit the run was made at are both commits of that pull request. When the pull request has moved on, the line says so. The bot token is the secret `VERIFY_EVIDENCE_TOKEN` of the environment `verify-evidence`, which allows only the default branch. A repository secret could be read by a workflow on any branch. Only the step that runs `gh` holds the token. Without the secret the job prints a notice. GitHub starts this workflow only when it and `verify-remote.yml` are both on the default branch. The runs for one branch take turns at the description, and `queue: max` keeps every run that waits. The `Unit Tests` job of `ci.yml` runs the script's tests on its Node 24 leg. `.github/actionlint.yaml` ignores the `queue` key in this workflow, which actionlint 1.7 does not know. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
mikepitre
force-pushed
the
mike/expo-verify-attach
branch
from
October 9, 2026 19:17
55f48b3 to
da81537
Compare
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
A cloud agent cannot put a run's video and screenshots on its pull request. Its sandbox refuses the upload, and the Actions token cannot attach files. So
attachin #10131 hands the files to the session's runner, which keeps them as the artifactverify-evidence. This PR adds the workflow that reads that artifact and puts the evidence in the pull request description, with a bot token.It is the fifth PR of the stack and sits on #10131, which sits on #10090, #10087, and #10052. GitHub starts the workflow only when it and
verify-remote.ymlare both onmain. So it does nothing until the whole stack has merged.One commit.
.github/workflows/verify-attach.ymlworkflow_runwhen averify-remotesession ends, from the default branch.scripts/verify-attach.mjsgh pr edit --attach.scripts/verify-attach.test.mjs.github/workflows/ci.ymlUnit Testsjob, on its Node 24 leg..github/actionlint.yamlconcurrency.queuethrough in this one workflow, because actionlint 1.7 does not know the key..changeset/expo-verify-attach.mdThe script is the same file, byte for byte, in clerk/clerk-ios and clerk/clerk-android. Review it once.
runandattachreplaces the block.<!-- verify-evidence:ios -->and<!-- /verify-evidence:ios -->, or the same two withandroid. Everything outside a block is kept as it was, with the line endings the description has. The workflow refuses a description that has neither comment and ends inside a code fence that never closes.queue: maxkeeps every run that waits.actions: readandcontents: read, and only the step that runsghholds the token. It starts after everyverify-remotesession, with or without evidence, and each start shows as a deployment toverify-evidence.A repository admin has to set this up before the workflow can publish:
verify-evidence, and limit its deployment branches tomain.VERIFY_EVIDENCE_TOKENof that environment.A repository secret can be read by a workflow that anyone with write access adds on any branch. A secret of an environment that allows only
maincannot. Without the environment or its secret the job prints a notice and publishes nothing.Not proven, and not provable before the stack is on
main:gh pr edit --attach.verify-evidenceartifact. The script was run against zips made on a Mac.queue: maxkeeps every waiting run in this workflow.Checklist
pnpm testruns as expected.pnpm buildruns as expected.Type of change
🤖 Generated with Claude Code