On this page
The checks that read outside the working tree: the remote's refs, the branch, the CI publish credentials, and the follow-ups a conversion still owes.
#rlsbl.checks.release
#rlsbl.checks.release
Release checks (tag: release): the refs and the Releases hanging off them, the branch, the CI credentials, and the follow-ups a recorded conversion still owes the outside world.
Checks: unpublished-refs, branch-sync, ci-publish-secrets, old-repo-archived, go-deprecation-published.
Every check in this module reads something OUTSIDE the working tree -- the remote's refs, the GitHub API, the Go module proxy -- which is why they carry the release tag rather than project: the offline tags (project, changelog, quality, prepush) stay answerable with no network, and a networked check placed in one of them would make an offline run fail for a reason that has nothing to do with the repository.
All of them are fail-closed. A probe that cannot answer is a hard error, never a pass: "we could not ask" is not evidence that a ref is pushed, a secret exists, a repository is archived, or a module is deprecated.
#register_release_checks
def register_release_checks(app)Register release-tag checks on app.
#_transition_record_paths
def _transition_record_paths(ctx)Every transition record this project can reach, newest home first.
The three homes :func:rlsbl.transition_record.get_transition_record_path resolves: a standalone project's own record, the workspace-scoped record, and one per releasable. A monorepo carries facts in all three, and a conversion follow-up is owed whichever record recorded it.
#_read_transition_record
def _read_transition_record(ctx, reporter)(events, error_outcome) -- the events, or a finalized failure.
A malformed record is this check's finding, not a traceback: reading a record FOR USE is where :func:rlsbl.transition_record.read_events raises, and a check that consumes one has to report it.
#_followup_outcome
def _followup_outcome(verdict, reporter, *, passed)Report a :class:rlsbl.transition_record_followup.FollowupVerdict.
#register_networked_release_checks
def register_networked_release_checks(app)Register the probing release-tag checks on app.
#_same_commit
def _same_commit(a, b)Do two git object names denote the same commit, allowing abbreviation?
A release commit may be recorded abbreviated (the schema accepts 7 to 40 hex characters) while a resolved ref is always full, so the comparison is by common prefix -- the same rule the release record applies.