Repository navigation
Release v0.3.5 - #31
Conversation
The version bump the release workflow normally makes, routed through a PR
because it can no longer push it directly.
The `Protect Main` ruleset (created today 09:06 UTC) requires the `Rust` status
check on `main` with no bypass actors, and the workflow's `Prepare release` job
pushes the bump straight to `main` as `github-actions[bot]`. A direct push
carries no check, so the ruleset rejects it:
[main 6df9add] Release v0.3.5
remote: error: GH013: Repository rule violations found for refs/heads/main.
remote: - Required status check "Rust" is expected.
! [remote rejected] HEAD -> main (push declined due to repository rule violations)
Every gate passed before that point — fmt, clippy `-D warnings`, build, test, the
90%-per-file coverage check, docs — so this is a release-path/ruleset conflict
rather than anything wrong with the tree. v0.3.4 released cleanly on 2026-09-28,
before the ruleset existed.
Going through a PR satisfies the rule on its own terms: `Rust` runs here, so the
bump lands on `main` checked rather than around the check. Afterwards the tag is
pushed (the ruleset targets branches, not tags) and the release workflow is run
with `bump=current`, which skips the version edit and the push and goes straight
to bundling and `gh release create --verify-tag`.
Contents are exactly what the workflow's own step produces: the
`[workspace.package]` version and the two workspace members' entries in
`Cargo.lock` via `cargo update --workspace`. Both members inherit with
`version.workspace = true`, so nothing else needs editing.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Tiny Sweeper reviewThis pull request bumps the workspace package version from 0.3.4 to 0.3.5 and updates Cargo.lock accordingly. The change is minimal and follows the established release pattern. No problems are introduced. State: Incomplete Review snapshot
Completeness: Incomplete What changedversion bump from 0.3.4 to 0.3.5 in workspace.package, plus Cargo.lock update FeaturesNone identified with supported citations. TestsNo supported feature-to-test mapping was produced. Test execution is not inferred. FindingsNo active actionable findings. Could not review: Cargo.toml Before merge
Agent review detailscritique
security
tests
commits
description
e2e
Evidence and run details
|
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: Comment |
There was a problem hiding this comment.
tinysweeper found nothing blocking, but could not review everything, so this is not an approval: Cargo.toml.
$0.0006 · 5,092 in / 1,377 out · 1,024 cached (20%) · ladder/vectors, deepseek/deepseek-v4-flash · 27 embedded
description: $0.0005 · 3,861 in / 1,268 out · 1,024 cached (27%) · deepseek/deepseek-v4-flash
Version bump for v0.3.5, routed through a PR because the release workflow can no longer push it directly.
Why this is a PR and not the workflow's own commit
The
Protect Mainruleset (id24168751, created today 09:06 UTC) requires theRuststatus check onmainand has no bypass actors. The workflow'sPrepare releasejob pushes the bump straight tomainasgithub-actions[bot], and a direct push carries no check, so the ruleset rejects it — run 36555489654:Every gate passed before that point — fmt, clippy
-D warnings, build, test, the 90%-per-file coverage check, docs. It is a release-path/ruleset conflict, not a problem with the tree. v0.3.4 released cleanly on 2026-09-28, before the ruleset existed, which is why this is the first release to hit it.Going through a PR satisfies the rule on its own terms:
Rustruns here, so the bump lands onmainchecked rather than around the check.Contents
Exactly what the workflow's
Update crate versionstep produces:[workspace.package] version→0.3.5Cargo.lockviacargo update --workspace(the two workspace members; both inherit withversion.workspace = true)2 files changed, 3 insertions(+), 3 deletions(-)— the same shape as418f9c0 Release v0.3.4.After this merges
v0.3.5tag at the merge commit — the ruleset targets branches, so tags are unaffected.bump=current, which skips the version edit and the push (if: inputs.bump != 'current') and goes to bundling plusgh release create --verify-tag.What v0.3.5 carries
npx,uvx) start at allWorth a separate decision
The release workflow is currently unable to complete for anyone, not just this release. A permanent fix is either a bypass actor for the Actions token, or reshaping the workflow to bump via PR by default. Whoever added the ruleset this morning is best placed to choose; this PR only unblocks v0.3.5.
🤖 Generated with Claude Code