Filed by the domain:spec seat 2 PM (session_014EJ1ED8X4MMrT18BhVx4tx) while writing the landing record for #20613 (PR #20625, merged as 73213a521d). Every reading below was taken at 14:10Z on 2026-09-29.
What was measured
PR #20625 added the stale-prompts job to .github/workflows/release.yml (Cancel publish prompts for versions already on npm). It runs node scripts/release-pending-publish.mjs sweep --workflow release.yml on every main push. Its purpose, in the job's own comment, is that run 36539819278 must not keep waiting after @objectstack/cli@17.5.0 reached npm.
Two main pushes have run the job since the merge. Both jobs were green, and both logs print the same verdict:
| Release run |
Head |
Job |
Log line |
| 36579512725 |
73213a521d (PR #20625's merge) |
109443658530 |
### Waiting approval prompts (0 waiting run(s) of release.yml) / - none waiting |
| 36579680181 |
9b402dbaed |
109444238812 |
### Waiting approval prompts (0 waiting run(s) of release.yml) / - none waiting |
At the same time, the same endpoint read without a token lists the run:
GET /repos/objectstack-ai/objectstack/actions/workflows/release.yml/runs?status=waiting&per_page=100 → total_count: 1, run 36539819278, status: waiting, event: push, head 422db788a2. The repo-wide GET /actions/runs?status=waiting gives the same single run.
GET .../actions/runs/36539819278/jobs?filter=latest → Publish 17.5.0 to npm (awaiting approval), waiting. This matches PUBLISH_JOB_NAME.
GET .../actions/runs/36539819278/pending_deployments → environment release.
npm view @objectstack/cli@17.5.0 version → 17.5.0, which classifyNpmView reads as present.
So every predicate judgeWaitingRuns checks would put this run in cancel. It never reaches the judge, because collectWaitingRuns' first read, the waiting-runs list made with the job's GITHUB_TOKEN, answered an empty list twice. Neither job carries an annotation other than the runner-image notice. That fits the runs.length === 0 path, which prints no ::warning::.
Reach (measured)
- The stale holder still holds the group. Run 36539819278 is still
waiting at the release environment, 6 hours after cli@17.5.0 reached npm (07:58:57Z). The job's own comment gives the harm: the waiting publish job holds release-publish-<ref>, so the next Version Packages merge's real prompt pends behind it and is hidden. That is the 17.4.0 → 17.5.0 misapproval shape the amendment (ADR-0125 D1, amended 2026-09-29) exists to stop.
- The failure is silent. A wrong-empty read ends green with
- none waiting. The job comment asks that "a failed read here must be loud (a red job on main)", but a read that answers 200 with nothing is not a failed read to this code, so nothing on main turns red or warns.
Hypotheses for the dev (unverified; measure first)
- The difference is the token, not the filter: the list endpoint's
status=waiting filter answers the workflow token with no runs while it answers an anonymous read with one. Measure it from inside a run: a --dry-run dispatch, or a temporary diagnostic that logs total_count for (a) ?status=waiting, (b) the unfiltered list, and (c) GET /actions/runs/36539819278.
- If (1) holds, reading the recent runs unfiltered and selecting
status === 'waiting' in the script removes the dependency on the server filter. The unfiltered list must still be read far enough back: this run was created at 07:58Z and many pushes have landed since.
- Either way, "0 waiting" should be cross-checked, or at least printed as a
::notice:: with the listed total_count, so the next wrong-empty read is visible in the run summary instead of reading as "nothing to do".
⛔ The seat did not reject, approve or cancel run 36539819278. Release deployments are the maintainer's alone (AGENTS.md). Until a fix lands, the maintainer can Reject that run's Publish 17.5.0 prompt at the release environment. A rejected run can publish nothing and releases the group.
Related: #20613 (the card PR #20625 closed), #20627 (release-integrity's in-flight publish read).
Generated by Claude Code
Filed by the
domain:specseat 2 PM (session_014EJ1ED8X4MMrT18BhVx4tx) while writing the landing record for #20613 (PR #20625, merged as73213a521d). Every reading below was taken at 14:10Z on 2026-09-29.What was measured
PR #20625 added the
stale-promptsjob to.github/workflows/release.yml(Cancel publish prompts for versions already on npm). It runsnode scripts/release-pending-publish.mjs sweep --workflow release.ymlon every main push. Its purpose, in the job's own comment, is that run 36539819278 must not keep waiting after@objectstack/cli@17.5.0reached npm.Two main pushes have run the job since the merge. Both jobs were green, and both logs print the same verdict:
73213a521d(PR #20625's merge)### Waiting approval prompts (0 waiting run(s) of release.yml)/- none waiting9b402dbaed### Waiting approval prompts (0 waiting run(s) of release.yml)/- none waitingAt the same time, the same endpoint read without a token lists the run:
GET /repos/objectstack-ai/objectstack/actions/workflows/release.yml/runs?status=waiting&per_page=100→total_count: 1, run36539819278,status: waiting,event: push, head422db788a2. The repo-wideGET /actions/runs?status=waitinggives the same single run.GET .../actions/runs/36539819278/jobs?filter=latest→Publish 17.5.0 to npm (awaiting approval),waiting. This matchesPUBLISH_JOB_NAME.GET .../actions/runs/36539819278/pending_deployments→ environmentrelease.npm view @objectstack/cli@17.5.0 version→17.5.0, whichclassifyNpmViewreads aspresent.So every predicate
judgeWaitingRunschecks would put this run incancel. It never reaches the judge, becausecollectWaitingRuns' first read, the waiting-runs list made with the job'sGITHUB_TOKEN, answered an empty list twice. Neither job carries an annotation other than the runner-image notice. That fits theruns.length === 0path, which prints no::warning::.Reach (measured)
waitingat thereleaseenvironment, 6 hours after cli@17.5.0 reached npm (07:58:57Z). The job's own comment gives the harm: the waiting publish job holdsrelease-publish-<ref>, so the next Version Packages merge's real prompt pends behind it and is hidden. That is the 17.4.0 → 17.5.0 misapproval shape the amendment (ADR-0125 D1, amended 2026-09-29) exists to stop.- none waiting. The job comment asks that "a failed read here must be loud (a red job on main)", but a read that answers 200 with nothing is not a failed read to this code, so nothing on main turns red or warns.Hypotheses for the dev (unverified; measure first)
status=waitingfilter answers the workflow token with no runs while it answers an anonymous read with one. Measure it from inside a run: a--dry-rundispatch, or a temporary diagnostic that logstotal_countfor (a)?status=waiting, (b) the unfiltered list, and (c)GET /actions/runs/36539819278.status === 'waiting'in the script removes the dependency on the server filter. The unfiltered list must still be read far enough back: this run was created at 07:58Z and many pushes have landed since.::notice::with the listedtotal_count, so the next wrong-empty read is visible in the run summary instead of reading as "nothing to do".⛔ The seat did not reject, approve or cancel run 36539819278. Release deployments are the maintainer's alone (AGENTS.md). Until a fix lands, the maintainer can Reject that run's
Publish 17.5.0prompt at thereleaseenvironment. A rejected run can publish nothing and releases the group.Related: #20613 (the card PR #20625 closed), #20627 (release-integrity's in-flight publish read).
Generated by Claude Code