Skip to content

fix(ci): verify exact triggering commit in Windows build and package - #376

Merged
masarray merged 2 commits into
mainfrom
fix/ci-exact-trigger-revision-v1640
Sep 24, 2026
Merged

masarray merged 2 commits into
mainfrom
fix/ci-exact-trigger-revision-v1640

Conversation

@masarray

Copy link
Copy Markdown
Owner

Root cause

The canonical Windows build cloned a moving PR/branch tip (git clone --branch), which may differ from GitHub's triggering SHA after a concurrent push. A green check could therefore attest a different source revision than its displayed commit.

Change

  • Use actions/checkout@v4 with exact ${{ github.sha }} under the same application sibling path.
  • Fail closed unless checked-out HEAD equals GITHUB_SHA, and record ARSAS_SOURCE_COMMIT in job environment.
  • Add regression contract ensuring the moving-branch clone cannot return.

No engine lock, runtime, Smart Discovery, SCL, reporting, release version, or published binary changes. This secures the source of the same existing build/test/portable smoke job. CI must pass before merge.

@masarray
masarray merged commit 5757fa5 into main Sep 24, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant