Skip to content

fix(release): harden version sync pull requests - #416

Merged
ty-everett merged 1 commit into
mainfrom
codex/release-sync-pr-evidence
Jul 31, 2026
Merged

fix(release): harden version sync pull requests#416
ty-everett merged 1 commit into
mainfrom
codex/release-sync-pr-evidence

Conversation

@ty-everett

@ty-everett ty-everett commented Jul 31, 2026

Copy link
Copy Markdown
Collaborator

Program and scope

  • Tracker or issue: release automation follow-up to fix(auth): contain untrusted transport failures #413 and protected release run 30662244573
  • Program gate(s) advanced: protected version reconciliation; fail-fast repository health
  • Why this change is needed: generated version-sync PRs must include required dependency evidence and regenerate checked-in stack facts after service version bumps.
  • Explicitly out of scope: package or service runtime behavior.
  • Exact head SHA reviewed: 4e4ca8f

Impact

  • No public package source or manifest changed
  • Public package source or manifest changed; affected packages are listed below
  • Infrastructure source, dependency, image, or deployment configuration changed
  • Public API, exports, types, runtime targets, or browser/mobile behavior changed
  • Security-sensitive boundary changed
  • Documentation or examples changed

Verification

  • Local commands and results: Node 24.18.0; package-release-artifacts 12/12; repository health 126/126 plus all governance checks; lint, format, full build, and full typecheck passed.
  • Hosted CI runs: CI 30664596795 and CodeQL 30664596991 succeeded for this exact head; superseded fail-fast attempts are retained as evidence of the dependency-body gate.
  • Conformance evidence: not selected; no conformance input changed.
  • Coverage delta: no product source changed.
  • Lint/typecheck delta: zero local findings.
  • Browser/mobile/packed-consumer evidence: not selected; release orchestration only.
  • Performance or bundle-size delta: no runtime bundle changed.
  • I self-reviewed the complete diff for correctness, security, compatibility, public API, artifacts, dependencies, docs, and operations
  • All applicable checks are terminal and successful on the exact head; any scope-based skip is expected and validated by the merge gate

Security and dependencies

  • No dependency or lockfile change
  • Changelog, runtime relevance, peer compatibility, transitive graph, and audit results were reviewed
  • CodeQL/negative tests cover any changed trust boundary
  • The exact-head CodeQL analysis has no new alert
  • The exact-head repository quality gate reports zero new Sonar findings and zero unreviewed hotspots
  • No new override, advisory dismissal, quality suppression, or skipped test
  • Workflow permissions and lifecycle-script behavior remain least privilege

Dependency evidence

  • Release notes and necessity: Release-orchestration hardening only; no package dependency changed.
  • Runtime, build, and peer compatibility: No runtime, build dependency, or peer range changed.
  • Deduplicated lockfile: No lockfile changed.
  • Audit and CodeQL: Local repository governance passed; exact-head dependency review, CodeQL, Socket, and Sonar run on this PR.
  • Package and consumer tests: Release-workflow regression tests passed 12/12; package consumer scope is empty by the affected graph.
  • Bundle and performance impact: No runtime bundle or performance path changed.
  • Affected public package versions: The workflow changes no public package manifest; future sync PRs derive and enumerate published versions from the protected release.

Release and operations

  • No npm publication was performed from a workstation or from this PR
  • Required npm patch bumps are included or intentionally deferred by the controlling program
  • Image/SBOM/provenance/deployment/rollback impact is documented
  • Documentation, changelog, migration, and operational guidance are current

The release job now regenerates and stages stack facts, and its generated PR body supplies the evidence required by repository policy. The regression test fails if either behavior is removed.

Completion evidence

  • Documentation, changelog, migration notes, release notes, and operator guidance are current or concretely not applicable
  • One qualified maintainer approval is sufficient; no last-pusher restriction is assumed

@ty-everett
ty-everett requested a review from sirdeggen as a code owner July 31, 2026 20:42
@ty-everett ty-everett closed this Jul 31, 2026
@ty-everett ty-everett reopened this Jul 31, 2026
@ty-everett ty-everett closed this Jul 31, 2026
@ty-everett ty-everett reopened this Jul 31, 2026
@ty-everett ty-everett closed this Jul 31, 2026
@ty-everett ty-everett reopened this Jul 31, 2026
@sonarqubecloud

Copy link
Copy Markdown

@ty-everett
ty-everett merged commit 1a6b34c into main Jul 31, 2026
98 of 116 checks passed
@ty-everett
ty-everett deleted the codex/release-sync-pr-evidence branch July 31, 2026 20:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant