It would be good to run the "validating patches..." at build time as well as run time so that CI tools can validate patches and you know that the build artefact is good to run.
I realise that this can essentially be achieved by running the run command with -noexec as build time.