Skip to content

Task: Publish the verified Kida Report Action on GitHub Marketplace #322

Description

@lbliii

Parent: #318
Blocked by: owner authorization and #321

Goal

Publish the existing Kida Report composite Action to GitHub Marketplace only after its evidence cards, listing assets, release provenance, and owner approval are ready.

Preconditions

  • Owner explicitly authorizes the public release and Marketplace submission.
  • action.yml remains the unique root Action metadata file and Marketplace name availability is verified.
  • The listing’s quick-start YAML, input/output documentation, screenshots, and supported runner/platform constraints reflect the released revision.
  • Release, package, action, report-template, and least-privilege checks pass on the candidate revision.
  • The Marketplace developer agreement and 2FA/account prerequisites are satisfied by the authorized owner.

Scope

  • Create the release/tag through the owner-authorized release process.
  • Publish under Code quality, with Continuous integration as the secondary category if still appropriate.
  • Verify discoverability, rendered Marketplace copy, source links, version reference, and installation from a clean public workflow.
  • Record the exact listing URL, tag, publication timestamp, and verification result in this issue.

Acceptance and proof

  • The listing is live and uniquely resolves to the intended Kida Action.
  • A clean public Linux workflow can install the pinned release and render a built-in report successfully.
  • Raw failure output and least-privilege workflow requirements remain visible; report rendering does not hide underlying failures.
  • Supported/unsupported runner and shell conditions are stated explicitly.

Boundaries

  • No change to Action behavior, permissions, inputs, default Python version, runtime dependencies, or report schemas is implied by publication.
  • No floating tag update, release body, or public claim is altered without recording its exact provenance.
  • Do not describe the Action as a replacement for every reporting Action.

Stewards and collateral

  • Stewards: github, action, templates, markdown, schemas, utils, docs/site, public, tests.
  • Collateral: Marketplace listing, release notes, screenshot assets, Action usage docs, and appropriate changelog/release records.
  • Downstream pilot: Marketplace publication alone is not a consumer pilot. The follow-up pilot task owns target-repository evidence.

Blocking decision

This task must remain blocked until the repository owner authorizes the external release. An issue plan is not release authority.

Metadata

Metadata

Assignees

No one assigned

    Labels

    priority/P1Important for Kida and downstream confidencestatus/blockedCannot proceed until a named gate, date, or dependency clearstaskConcrete work itemtheme/releaseArea: release and evidence artifactstheme/testing-ciArea: tests and continuous integrationtype/ciCI or release pipeline

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions