Skip to content

chore: sync published workspace versions - #415

Merged
ty-everett merged 2 commits into
mainfrom
automation/sync-published-versions
Jul 31, 2026
Merged

chore: sync published workspace versions#415
ty-everett merged 2 commits into
mainfrom
automation/sync-published-versions

Conversation

@github-actions

@github-actions github-actions Bot commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

Program and scope

  • Tracker or issue: release follow-up to fix(auth): contain untrusted transport failures #413
  • Program gate(s) advanced: published-version reconciliation; reproducible OCI release inputs
  • Why this change is needed: synchronize first-party package floors and standalone infrastructure locks to the four protected npm releases.
  • Explicitly out of scope: product behavior beyond consuming the already-reviewed package artifacts.
  • Exact head SHA reviewed: 79da638

Impact

  • No public package source or manifest changed
  • Public package source or manifest changed; affected packages are listed below
  • Infrastructure source, dependency, image, or deployment configuration changed
  • Public API, exports, types, runtime targets, or browser/mobile behavior changed
  • Security-sensitive boundary changed
  • Documentation or examples changed

Affected services and intended patch versions: Message Box 1.1.21; Overlay Server 2.1.24; UHRP Basic 0.1.17; UHRP Cloud Bucket 0.2.19; WAB 1.4.18; Wallet Infra 2.0.20.

Verification

  • Local commands and results: generated by protected release run 30662244573 after npm publication; exact lockfile integrity values match the reconciled registry artifacts.
  • Hosted CI runs: CI 30663885685, container runtime 30663885673, and CodeQL 30663886052 all succeeded for this exact head.
  • Conformance evidence: not selected; no conformance input changed.
  • Coverage delta: no product source changed.
  • Lint/typecheck delta: pending hosted affected-graph validation.
  • Browser/mobile/packed-consumer evidence: protected npm release run 30662244573 passed package, clean-consumer, browser, and mobile verification before publication.
  • Performance or bundle-size delta: no product source or bundle composition changed.
  • I self-reviewed the complete diff for correctness, security, compatibility, public API, artifacts, dependencies, docs, and operations
  • All applicable checks are terminal and successful on the exact head; any scope-based skip is expected and validated by the merge gate

Security and dependencies

  • No dependency or lockfile change
  • Changelog, runtime relevance, peer compatibility, transitive graph, and audit results were reviewed
  • CodeQL/negative tests cover any changed trust boundary
  • The exact-head CodeQL analysis has no new alert
  • The exact-head repository quality gate reports zero new Sonar findings and zero unreviewed hotspots
  • No new override, advisory dismissal, quality suppression, or skipped test
  • Workflow permissions and lifecycle-script behavior remain least privilege

Dependency evidence

  • Release notes and necessity: AuthSocket server/client, SDK Peer, and Express transport now contain synchronous and asynchronous callback failures so hostile payloads cannot escape their owning transport.
  • Runtime, build, and peer compatibility: all four packages require Node 22 or newer; the six infrastructure contexts use the governed Node 24 runtime and compatible 2.x peer ranges.
  • Deduplicated lockfile: npm lockfile v3 refresh changed only the intended first-party package versions, integrity hashes, service versions, and direct floors.
  • Audit and CodeQL: protected release rejected high and critical package findings; exact-head CodeQL is pending.
  • Package and consumer tests: protected release run 30662244573 passed full builds, typecheck, package artifacts, clean consumers, browser, mobile, registry signatures, provenance, and reconciliation.
  • Bundle and performance impact: no bundle composition change; patch releases preserve public and wire contracts.
  • Affected public package versions: @bsv/authsocket 2.1.5; @bsv/authsocket-client 2.1.4; @bsv/sdk 2.2.16; @bsv/auth-express-middleware 2.1.6.

Release and operations

  • No npm publication was performed from a workstation or from this PR
  • Required npm patch bumps are included or intentionally deferred by the controlling program
  • Image/SBOM/provenance/deployment/rollback impact is documented
  • Documentation, changelog, migration, and operational guidance are current

The protected infrastructure release will build Linux/amd64 images, reject high and critical findings, publish immutable GHCR tags, and attach SBOM, provenance, and signature evidence after merge. Existing immutable tags remain the rollback path.

Completion evidence

  • Documentation, changelog, migration notes, release notes, and operator guidance are current or concretely not applicable
  • One qualified maintainer approval is sufficient; no last-pusher restriction is assumed

@github-actions
github-actions Bot requested a review from sirdeggen as a code owner July 31, 2026 20:36
@ty-everett ty-everett closed this Jul 31, 2026
@ty-everett ty-everett reopened this Jul 31, 2026
@socket-security

socket-security Bot commented Jul 31, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addednpm/​@​bsv/​sdk@​2.2.16741001009980
Updatednpm/​@​bsv/​authsocket@​2.1.4 ⏵ 2.1.575 +1100100 +195 +180
Addednpm/​@​bsv/​auth-express-middleware@​2.1.6771001009780

View full report

@sonarqubecloud

Copy link
Copy Markdown

@ty-everett
ty-everett merged commit 730e645 into main Jul 31, 2026
44 checks passed
@ty-everett
ty-everett deleted the automation/sync-published-versions branch July 31, 2026 20:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant