release: prepare 0.40.0-beta.6 for npm next - #638
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (17)
📝 WalkthroughWalkthroughThis PR advances the authorized corrective prerelease from ChangesBeta.6 corrective release
Estimated code review effort: 3 (Moderate) | ~20 minutes Possibly related issues
Possibly related PRs
Suggested labels: 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Comment |
|
Independent exact-head release-safety review — PASS, no content or implementation blocker Reviewed candidate head Verified:
This review does not waive any merge gate. Merge remains forbidden until all six exact-head CI jobs are green, CodeRabbit reaches a final honest disposition with no actionable blocker, zero review threads remain, and the final live collision/branch/exclusion checks are repeated. |
|
CodeRabbit exact-head disposition CodeRabbit completed on Its summary includes one non-blocking docstring-coverage warning. That warning does not identify a correctness, security, release, or contract defect: this release-only PR adds no production API or production source, and adding docstrings to governance/test/release helpers would widen the exact authorized release diff without product value. No code change is warranted. Review-thread query at this head reports 0 total / 0 unresolved threads. CI remains independently gated; merge still waits for all six required jobs. |
|
Independent exact-head packed-runtime review — PASS, no blocker Reviewed
No files were edited during review. This is a content review only; the protected merge still requires the separate CI, CodeRabbit, exact-head, and zero-thread gates. |
Publication complete
The release workflow is fully green on attempt 2: https://github.com/mohanagy/madar/actions/runs/30746816714. Attempt 1 published once with Trusted Publishing/provenance, then encountered a temporary npm attestation-endpoint propagation 404. Attempt 2 explicitly detected the immutable version as already public, did not republish, and passed final artifact, dist-tag, provenance, and signature verification. Exact tarball SHA-256: Durable tracking receipts: #631 and #629 remain open; this publication does not claim final qualification. |
Summary
@lubab/madar@0.40.0-beta.6from authorized protected-nextbase68729161699b7592bea6984e1aa22c7b4b0833e8.4c98dd99cd321e741cabd689f0803d99e519f389, integritysha512-o6L/BiJ1wrTWCaK537p60pGUC5i8zY0Zqz7NqD1zW4fJl/ewjF3cgysf4dbOkY4y49DkYDTG2qoUh1DGvq2Q0Q==, and tarball SHA-25612d8abe1ac3d0945c654f4df2582ac1de63f2aeee55d82d4bf5b053d92036074.nexttrusted-publishing workflow under npm dist-tagnext.latest, create a GitHub Release, publish Registry metadata, create a tag, or targetmain.Owner authorization: #631 receipt, #629 receipt.
Testing
npm run test:coverage— 83 files / 914 tests; thresholds passednpm run typecheck— Node 22 and Node 20npm run buildandnpm run build:eval— Node 22 and Node 20npm run release:verifynpm run registry:validatenode tools/eval/core-reset/benchmark.mjs— 14/14 ready, all four handoffs and terminal persistence, 100 warm samplesnpx vitest run tests/unit/core-reset-baseline.test.tsnpm run verify:pack-parity— installed package and checkout matchnode tools/eval/core-reset/verify-isolation.mjs— exact package metrics, zero evaluation leakagenpm audit --audit-level=high— zero vulnerabilitiesnpm audit signatures— 75 signatures / 27 attestations verifiedmadar --version, andmadar generatesmokenpm packis stronger thannpm pack --dry-run; exact artifact identity matches the sealed receiptCore Reset contract
no-fallback-qualification-631Reset scope checks
src/Checklist
Related issues
Tracks #631 and #629. Formal #631 qualification remains open.
Summary by CodeRabbit
Release
0.40.0-beta.6.nextchannel for corrective manual testing.Documentation
Testing