chore(release): prepare 0.40.0-beta.5 - #636
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (3)
🚧 Files skipped from review as they are similar to previous changes (2)
📝 WalkthroughWalkthroughThe PR changes beta.5 publication from tag-triggered release creation to protected ChangesBeta.5 release flow
Estimated code review effort: 4 (Complex) | ~45 minutes Sequence Diagram(s)sequenceDiagram
participant NextPush
participant ReleaseWorkflow
participant ArtifactVerifier
participant Npm
NextPush->>ReleaseWorkflow: push package.json change to next
ReleaseWorkflow->>ArtifactVerifier: verify v0.40.0-beta.5 is absent
ArtifactVerifier-->>ReleaseWorkflow: Git tag and GitHub Release absent
ReleaseWorkflow->>Npm: publish with next tag and provenance
ReleaseWorkflow->>ArtifactVerifier: verify artifacts and package integrity
Possibly related issues
Possibly related PRs
Suggested labels: 🚥 Pre-merge checks | ✅ 3 | ❌ 2❌ Failed checks (2 warnings)
✅ Passed checks (3 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Comment |
Independent exact-head review receiptSubject head: Three independent read-only review axes pass with no P0/P1 blocker:
Pre-commit review caught and the final head fixes: a stale top-level package receipt, fail-open tag/Release probes, stale SBOM identity, an inconsistent source-delta base, and npm-init working-directory leakage. The corrected exact head has fail-closed probes, a fresh SBOM, exact source/package receipts, isolated temporary install verification, and version-only package metadata. Exact package: 102 files / 155157 packed / 653565 unpacked; shasum CI, CodeRabbit, and unresolved-thread gates remain pending and will be recorded separately before merge. |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@docs/core-reset/scorecard.md`:
- Line 48: Update docs/core-reset/scorecard.md lines 48-48 to replace active
beta.5 testing language with wording that publication and owner testing are
authorized but pending the protected-next release merge; update docs/roadmap.md
lines 184-186 to state that `#631` remains in progress while npm publication and
owner manual testing are pending that merge.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Pro Plus
Run ID: 262292d6-15da-45f0-92c9-27f957f970a6
📒 Files selected for processing (17)
.github/scripts/verify-forbidden-release-artifacts.mjs.github/workflows/release.ymlCHANGELOG.mdREADME.mddocs/claims-and-evidence.mddocs/core-reset/removal-manifest.ymldocs/core-reset/scorecard.mddocs/designs/2026-07-19-core-reset.mddocs/mcp-registry/server.jsondocs/release.mddocs/roadmap.mdpackage-lock.jsonpackage.jsonsbom.cdx.jsontests/unit/core-reset-governance.test.tstests/unit/release-docs.test.tstests/unit/release-hygiene.test.ts
Corrective exact-head independent review receiptSubject head: Three independent read-only review axes pass with no P0/P1 blocker:
Focused governance/release tests pass 31/31; release hygiene and Registry validation pass. The npm artifact remains exact and byte-identical: 102 files / 155,157 packed / 653,565 unpacked; shasum CI completion, CodeRabbit, protected-base freshness, and zero unresolved threads remain separate final merge gates. |
Final protected-
|
Publication completion receiptProtected squash merge: Published exactly An independent clean temporary install returned This publication enables owner manual testing only. It does not qualify or close #631 and makes no stable, comparative, or external-validation claim. |
Outcome
Prepare exactly
@lubab/madar@0.40.0-beta.5for npm dist-tagnextfrom protectednext, solely so the owner can manually test it before formal #631 qualification.Owner authorization receipts:
Exact scope
9703a7090fd3ef3600b4ab4e298b12f0faa05a1e5db67cbe19a9479409192558ea40b0ac8e3add78d424ab795cdb68be53dc81656b28e4a6582389b558afc08c8fcfe58e2ac99d430a0c9c78b032b76bnextsrc/**, graph/index/query behavior, CLI, MCP behavior, retrieval budgets, or TypeScript configuration changed.The release workflow now runs from the exact protected-
nextpackage-version merge through npm Trusted Publishing. It fails closed unless the livenexttip and protection match, the beta.5 git tag is absent, and the GitHub Releases API returns exactly authenticated HTTP 404. It publishes onlynpm nextand re-verifies immutable identity, provenance, signatures,next=0.40.0-beta.5, and unchangedlatest=0.32.0.This PR creates no git tag or GitHub Release, does not dispatch or publish MCP Registry metadata, does not publish stable/
latest, and never targetsmain. The checked-in Registry manifest is version-aligned only becauseregistry:validaterequires it; external Registry publication remains separate and forbidden.Exact package receipt
Generated with Node
22.22.3and npm12.0.1:102155157653565d637297412ec5b868586ba59142fbefdcfc0d5e0sha512-HorzqtIvp2v5xMaYVGDzPDYtFBMaEVBkGXHBdTSVwC1DkQgmZaFuTU1Ff+7YByWN9FTQaVLTJsV7zKhEgSKxXw==6e20a4edc6fb10ed3853f69e599676a723d2d771078810693f3cd13fc6e032dcVerification
31/3183 files / 899 tests5/5madar --versionprints0.40.0-beta.5Qualification boundary
This package is a manual-test candidate, not a #631 result. It makes no comparator, no-fallback, token, latency, cost, activation, retention, or external-user claim. #631 and #629 remain open.
Summary by CodeRabbit
Release
0.40.0-beta.5.nextchannel for manual testing.Documentation
Validation