Repository navigation
feat(release): prepare reviewed Rust crate artifacts - #44
Conversation
|
@codex review |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Codex Review: Didn't find any major issues. 👍 Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
|
🎉 This PR is included in version 2.7.0 🎉 The release is available on:
Your semantic-release bot 📦🚀 |
Summary
Prepare the unpublished Rust 0.2.0 crate for a separately reviewed registry activation, and fix the release download layout exposed by v2.6.0.
The published v2.6.0 assets remain unchanged. Its 33 downloaded assets match their GitHub digests and all 32 flat checksum entries pass, but its checksum manifest also names 30 nested fixtures absent from the GitHub asset list. Those fixtures are present in the source archive.
Implementation / behavior
Validation
At
fec06675d996c41e2802a3c8e71d6239733773b2:tools/validate.shpassed in the pinned Atrinik Linux build imagesha256:7904a1802054662b0ede5b55de72e4c92b0112a3c211125f994ed6c62e9ec9d8, with Go 1.26.6 and Rust 1.97.1.Protocol validationandConventional PR titlepassed on this exact head and accepted base.Limitations / follow-up
This is the preparation source change, not registry activation. v2.6.0 still has Cargo publication disabled and cannot supply publishable bytes without changing them. Actual released-tag preparation therefore follows a separately approved source merge/release and manual preparation dispatch.
The next activation PR must use the real prepared source release, revision, asset and checksum, and add the reviewed Trusted Publishing upload job. Exact release-asset attachment, environment/Trusted Publisher setup and publication dispatch each retain their authorization boundary. Governance preparation is tracked in atrinik/github-settings#86; access-token consumer coordination remains in #43.
No release asset, environment, registry configuration or package was changed. No merge, dispatch or publication is authorized by this PR. Consumers still need the actual registry release and normal dependency-lock validation.