Skip to content

ci: mandatory work report and PR-specific blog pipeline - #997

Merged
gHashTag merged 1 commit into
mainfrom
fix/pr-work-report-blog
Sep 13, 2026
Merged

gHashTag merged 1 commit into
mainfrom
fix/pr-work-report-blog

Conversation

@gHashTag

@gHashTag gHashTag commented Sep 13, 2026 •

Copy link
Copy Markdown
Owner

Outcome

Implement the owner's request for mandatory agent work reports and an automatic PR-specific blog pipeline. Preserve the existing daily media schedule and unrelated workflows.

The report gate and draft generation are deterministic; publication is a separate verified outcome. No claim of live publication is made by this bootstrap PR.

{
  "version": 1,
  "head_sha": "9950e959873ee67a8eb46486a8430afd7c43f6f9",
  "summary": "Every Trinity PR now has a current-head work report and a source-linked unpublished blog draft; merged PRs start a dedicated article author with durable duplicate control.",
  "changes": [
    "Added a trusted pull_request_target validator that never executes PR source or reported commands and records the required status on the actual PR head commit.",
    "Added deterministic unpublished blog artifacts with source receipts, reported test evidence, mandatory topic tags and explicit limitations.",
    "Added a bot-owned durable publication issue and an exact-PR author workflow using the existing Claude Code and agent credentials, without the generic Inngest event that ignores PR context.",
    "Documented the mandatory report in AGENTS.md and the PR template, plus truthful publication and whole-triptych gates."
  ],
  "tests": [
    {
      "command": "python3 -m unittest discover -s scripts -p 'test_pr_blog*.py' -v",
      "status": "passed",
      "result": "All 45 offline report, dispatch and author-guard tests passed; network and publication boundaries were mocked.",
      "evidence": "Local run and GitHub Actions both passed 45 tests: https://github.com/gHashTag/trinity/actions/runs/34746157437 on 2026-09-13."
    },
    {
      "command": "python3 YAML parsing of .github/workflows/pr-blog-*.yml and git diff --check",
      "status": "passed",
      "result": "All three new workflow YAML files parsed and the staged diff had no whitespace errors.",
      "evidence": "Local PyYAML and git diff --check execution on 2026-09-13."
    },
    {
      "command": "Run PR work report and dedicated author on GitHub after installation",
      "status": "not_run",
      "result": "The workflows must exist on main before the trusted default-branch runtime can be exercised; live merge enforcement and article publication are not yet verified.",
      "evidence": "GitHub workflow lookup returned not found before installation on 2026-09-13."
    }
  ],
  "limitations": [
    "A structurally valid report does not prove that its author-reported tests actually passed; engineering CI and review remain separate.",
    "The existing Claude OAuth and agent token names are present but their live author runtime has not yet been verified in this change.",
    "The article remains unpublished if the author cannot generate and inspect the required img2img triptych; no placeholder cover is allowed.",
    "Repository merge enforcement requires activating the required GitHub Actions status rule after the installed workflow is observed."
  ],
  "tags": [
    "Automation",
    "Verification",
    "Engineering"
  ],
  "blog": {
    "title": "A work report needs a merge gate and a delivery receipt",
    "summary": "A PR-linked draft separates reported engineering evidence, author dispatch and verified publication instead of treating them as one successful event.",
    "outline": [
      "The existing repository instructions asked agents for evidence, but no branch rule required a report. The media schedule dispatched a generic skill event whose consumer ignored PR-specific payloads and watched another repository, so an accepted event could not demonstrate that a given PR became an article.",
      "The change validates a structured report against the exact PR head, preserving failures and unrun tests rather than forcing an artificial green result. It generates deterministic draft artifacts and creates one durable publication task per merged PR before dispatching an author with explicit source identifiers.",
      "The important boundary remains visible: a validated report is not independent verification, and an author workflow acknowledgement is not a live article. Publication requires a real body, checkable receipts, the complete T27 img2img triptych, meaningful hashtags and an existing service offer, with the canonical page checked after deployment."
    ]
  }
}

@gHashTag

Copy link
Copy Markdown
Owner Author

Verification: the new PR blog pipeline test run passed all 45 tests: https://github.com/gHashTag/trinity/actions/runs/34746157437 . Format and GitGuardian passed. Existing failures were compared with baseline: missing docs tjepa.zig (main run 34278860677), project-status 401 credentials (prior run 34743660169), and Claude review is_error:true with zero model usage (prior run 34743660232). These workflows are not changed here. The dedicated author runtime is still unverified; installing this bootstrap enables a real current-head report status and then the required merge rule. Draft creation and final live publication remain separate states.

@gHashTag
gHashTag merged commit 307383c into main Sep 13, 2026
33 of 43 checks passed
github-actions Bot added a commit that referenced this pull request Sep 13, 2026
ci: require work reports and PR-specific blog pipeline (#997)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant