chore: refuse hand-built libs/ jars in pull requests - #89
Closed
hal-eisen-adfa wants to merge 1 commit into
Closed
Conversation
libs/ holds build outputs. The "Update libs from CodeOnTheGo" workflow builds them on JDK 17, the JDK every runner here uses, and pushes to main with an admin PAT that bypasses the main ruleset. A laptop on JDK 21 writes class file version 65 into gradle-plugin.jar instead; a JDK 17 runner reads only up to 61. PR #87 shipped such a jar, so "Publish addons" failed with UnsupportedClassVersionError on a tree that built fine on the machine that produced it. Every human change reaches main through a pull request, so a PR-level check closes the laptop path without touching the CI path. Claude-Session: https://claude.ai/code/session_01XWXk1HTqbD46eYmnfAMPNv
There was a problem hiding this comment.
Claude Code Review
This repository is configured for manual code reviews. Comment @claude review for a one-time review, or @claude review always to subscribe this PR to a review on every future push.
Tip: disable this comment in your organization's Code Review settings.
Contributor
Author
|
Claude went wild and opened this without a ticket or me asking for it |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Publish addonsfailed ond09f05awith:PR #87 committed
libs/jars built on a laptop running JDK 21, which emits class file version 65. Every workflow here runs JDK 17, which reads up to 61. The tree built fine on the machine that produced it, so nothing caught it until publish time.Update libs from CodeOnTheGo(run 34164643060) has already restored a class-61 jar in055e6dc. This PR stops it happening again.What
Check toolchain— the only workflow that runs automatically on pull requests — now fails any PR that changes a file underlibs/.CLAUDE.mdrecords the policy: runscripts/update-libs.shlocally to test a CoGo change, then throw the diff away.Update libs from CodeOnTheGopushes straight tomainwith an admin PAT that bypasses themainruleset, so it never runs this check. Themainruleset requires pull requests, so every human path is covered.Note
The
mainruleset has norequired_status_checksrule, soCheck toolchainis advisory — a red PR can still be merged. Adding it as a required check would make this guard binding.https://claude.ai/code/session_01XWXk1HTqbD46eYmnfAMPNv