Title: Harden GitHub runner provider contracts and lifecycle by intel352 · Pull Request #50 · GoCodeAlone/workflow-plugin-github · GitHub
Open Graph Title: Harden GitHub runner provider contracts and lifecycle by intel352 · Pull Request #50 · GoCodeAlone/workflow-plugin-github
X Title: Harden GitHub runner provider contracts and lifecycle by intel352 · Pull Request #50 · GoCodeAlone/workflow-plugin-github
Description: Summary publish strict typed GitHub runner-provider contracts, schemas, catalog metadata, and hermetic release manifests harden exact org JIT ownership, workflow/run/job identity, pagination, cleanup, artifacts, process isolation, and failure handling package the provider for Linux, macOS, and Windows while keeping the runner workload Linux-only add native Windows CI for the native journal directory durability path Locked-plan placement This is fix-forward hardening required while executing Task 8 of 2026-06-26-github-provider-dogfood-agents.md. The original Task 1-2 branch merged as PR #28 and Task 3-4 branch merged as PR #29; this PR does not collapse or replace those manifest rows. The plugin repo is public, so native Windows package validation uses windows-latest; retained org-runner proof remains in the private workflow-compute STG phase because the org group intentionally denies public repositories. Adversarial review The final blocking review found and this branch fixes: provider-token deletion of organization runners not present in the exact JIT ownership journal an unbounded wait after graceful HTTP shutdown timed out readiness polling that retried permanent provider authentication failures as transient The local adversarial pass also fixed retained-runner Git credential persistence, online-but-busy JIT dispatch, and one-sided exact-runner status coverage. Verification GOWORK=off go test ./... -count=1 GOWORK=off go test -race ./internal ./cmd/github-actions-runner-job ./cmd/github-runner-provider -count=1 GOWORK=off go test ./cmd/github-actions-runner-job -count=5 GOWORK=off go vet ./... GOWORK=off golangci-lint run --new-from-rev=origin/main ./... (0 issues) actionlint .github/workflows/*.yml goreleaser check wfctl plugin validate-contract --for-publish --tag v1.0.29 . Windows amd64 test cross-build and provider build macOS arm64 provider build and Linux amd64 runner-job build GoReleaser snapshot: all six provider archives built; runner-job present only in Linux archives Runtime launch Built provider launched on loopback, GET /healthz returned {"status":"ok"}, signal shutdown exited 0, and the journal persisted as version 1 with an empty entries list. No failure signatures were observed. Doc-reconciliation: 1 item fixed - remove_org_runner now explicitly documents provider-owned journaled JIT runners only.
Open Graph Description: Summary publish strict typed GitHub runner-provider contracts, schemas, catalog metadata, and hermetic release manifests harden exact org JIT ownership, workflow/run/job identity, pagination, clea...
X Description: Summary publish strict typed GitHub runner-provider contracts, schemas, catalog metadata, and hermetic release manifests harden exact org JIT ownership, workflow/run/job identity, pagination, clea...
Opengraph URL: https://github.com/GoCodeAlone/workflow-plugin-github/pull/50
X: @github
Domain: github.com
| route-pattern | /:user_id/:repository/pull/:id/files(.:format) |
| route-controller | pull_requests |
| route-action | files |
| fetch-nonce | v2:52c4a613-fd7c-56fb-ff1a-491c25689545 |
| current-catalog-service-hash | ae870bc5e265a340912cde392f23dad3671a0a881730ffdadd82f2f57d81641b |
| request-id | 82F0:6E24C:666AF2:8E6F1F:6A62405F |
| html-safe-nonce | ff2d2d1f4c6ba88af874ff8d1fb481fa1a5206e1433251b694f197379d13aa8c |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiI4MkYwOjZFMjRDOjY2NkFGMjo4RTZGMUY6NkE2MjQwNUYiLCJ2aXNpdG9yX2lkIjoiMzMyODUxMDU5NDYyNjUxOTk5IiwicmVnaW9uX2VkZ2UiOiJpYWQiLCJyZWdpb25fcmVuZGVyIjoiaWFkIn0= |
| visitor-hmac | 33ca85cca9347291f864685e978b4d7789ddaa0d69a12d848963d44991be1f25 |
| hovercard-subject-tag | pull_request:4037022025 |
| github-keyboard-shortcuts | repository,pull-request-list,pull-request-conversation,pull-request-files-changed,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/GoCodeAlone/workflow-plugin-github/pull/50/files |
| twitter:image | https://avatars.githubusercontent.com/u/77607?s=400&v=4 |
| twitter:card | summary_large_image |
| og:image | https://avatars.githubusercontent.com/u/77607?s=400&v=4 |
| og:image:alt | Summary publish strict typed GitHub runner-provider contracts, schemas, catalog metadata, and hermetic release manifests harden exact org JIT ownership, workflow/run/job identity, pagination, clea... |
| og:site_name | GitHub |
| og:type | object |
| hostname | github.com |
| expected-hostname | github.com |
| None | 5d6ba65d73ecc4e3394fe318d2b2f98e6f8eed4878b5421b938e20d30bde267b |
| turbo-cache-control | no-preview |
| diff-view | unified |
| go-import | github.com/GoCodeAlone/workflow-plugin-github git https://github.com/GoCodeAlone/workflow-plugin-github.git |
| octolytics-dimension-user_id | 66024440 |
| octolytics-dimension-user_login | GoCodeAlone |
| octolytics-dimension-repository_id | 1166334892 |
| octolytics-dimension-repository_nwo | GoCodeAlone/workflow-plugin-github |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 1166334892 |
| octolytics-dimension-repository_network_root_nwo | GoCodeAlone/workflow-plugin-github |
| turbo-body-classes | logged-out env-production page-responsive full-width |
| disable-turbo | true |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | 2dadc56fd5989b76a8ae7304e3aa56d0b485e5dc |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width