Skip to content

chore: reconcile published packages and infrastructure consumers - #567

Merged
ty-everett merged 3 commits into
mainfrom
automation/sync-published-versions
Sep 23, 2026
Merged

ty-everett merged 3 commits into
mainfrom
automation/sync-published-versions

Conversation

@github-actions

@github-actions github-actions Bot commented Sep 23, 2026

Copy link
Copy Markdown
Contributor

Program and scope

  • Tracker: protected release 35818166489, now fully green.
  • Reconcile infrastructure consumers and the release ledger with the 34 actually published, byte-verified npm artifacts. The bot sync commit is preserved; this follow-up refreshes the nested notifier lock omitted by the original workflow and advances documented published baselines.
  • Exact head: 6b5b0570131278509129ce60498b359b872ee466.

Impact

  • No public package source or manifest changed
  • Infrastructure source, dependency, image, or deployment configuration changed
  • Security-sensitive boundary changed
  • Documentation or examples changed

Intended OCI versions: Chaintracks 1.1.21; Message Box 1.1.44; Overlay 2.1.39; UHRP Basic 0.1.40; UHRP Cloud 0.2.41; WAB 1.8.4; Wallet Infra 2.0.43. The separately deployed private UHRP notifier becomes 1.0.1. Publication remains the protected infrastructure workflow after merge.

Verification

  • Required local workspace gates pass: pnpm health:check, pnpm lint, pnpm format:check, pnpm typecheck. Build and audit passed in preparation; no public package bytes changed.
  • All eight standalone consumers pass clean npm ci --ignore-scripts, explicitly allowlisted native rebuilds where needed, high/critical audit, build, lint and available tests.
  • Overlay runtime fixture now supplies a separate callback credential required by the newly published server. The regression checks presence, minimum length and independence from its ARC API key; production authentication stays enforced.
  • Published-ledger regression covers pending-to-published transition, rejection of stale release classification, and exact preservation of release summaries/migration notes. Documentation build and generated facts pass.
  • All 34 registry tarballs were independently downloaded and checked against the candidate's version/latest tag, SHA-512, SHA-256 and size. Protected post-release registry signatures/provenance verification passes.
  • Hosted acceptance passes on this exact head: CI 35826664644, CodeQL 35826664539 and all seven Linux runtime containers 35826664538. Direct Sonar API reconciliation reports quality OK, zero new findings and zero unreviewed hotspots. GitHub reports zero open CodeQL alerts on the PR and zero review threads. No source conformance behavior changed; release packed-consumer/browser/mobile evidence belongs to the unchanged published artifacts.
  • Complete diff reviewed for correctness, compatibility, artifacts, dependencies, documentation and operations
  • All applicable exact-head checks are terminal and successful

Security and dependency evidence

The lock delta is the coordinated first-party versions plus proxy-addr 2.0.7 → 2.0.8 under Overlay's Express dependency. The latter is the upstream GHSA-jqcg-44mw-7w3h security patch, retains the same Node/runtime contract and dependency versions, and passes the consumer audit/tests. No unrelated dependency cohort, new override, suppression, skipped test or advisory dismissal is introduced. Package release summaries and migration instructions are preserved exactly; releaseType: none now correctly records source/published parity.

  • Release necessity, runtime/peer compatibility, lockfile graph and audits reviewed
  • No new override, advisory dismissal, quality suppression or skipped test
  • Exact-head CodeQL has no new alert
  • Exact-head Sonar has zero new issues and unreviewed hotspots

Release and operations

  • No workstation npm publication
  • Correct infrastructure patch versions and generated facts included
  • Public package release ledger matches actual registry evidence
  • Existing migration and operator guides remain applicable

After accepted merge and green main, the protected infrastructure workflow must build Linux/amd64 images, reject high/critical findings, publish immutable GHCR tags, and verify signatures, provenance and SBOMs. Staging-first operators must follow the WAB/Message Box coordinated schema cutovers; these services are not eligible for image-only rollback after their schema advances. No live deployment is performed by this PR.

Completion evidence

  • One qualified maintainer review is sufficient; no last-pusher restriction is assumed
  • Exact-head hosted acceptance, security review and review-thread resolution complete

@github-actions
github-actions Bot requested a review from sirdeggen as a code owner September 23, 2026 06:11
@ty-everett
ty-everett marked this pull request as draft September 23, 2026 06:12
@ty-everett ty-everett changed the title chore: sync published workspace versions chore: reconcile published packages and infrastructure consumers Sep 23, 2026
@sonarqubecloud

Copy link
Copy Markdown

@ty-everett ty-everett left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Critical maintainer review of exact head 6b5b0570131278509129ce60498b359b872ee466: no remaining blocking finding.

The bot synchronization is preserved. Reviewed all eight standalone consumer graphs, integrity/lock changes, seven OCI patch versions, generated documentation and the published-ledger transition. The only third-party delta is the reviewed proxy-addr 2.0.8 security patch; all 34 public package trees are unchanged from the immutable npm release source. Release summaries and migration instructions remain intact. The Overlay runtime fixture now supplies an independent callback credential required by the actual published server, with a regression guard; authentication was not weakened.

Local required health/lint/format/typecheck, documentation, all standalone consumer installs/builds/audits/tests and publication reconciliation pass. Exact-head hosted CI 35826664644, CodeQL 35826664539 and all seven runtime containers 35826664538 pass. Direct Sonar gate reports quality OK, zero new findings and zero unreviewed hotspots. GitHub PR CodeQL alerts and review threads are empty. Expected scope skips were accepted by the strict final CI gate.

One qualified maintainer review is sufficient under repository policy; recording COMMENT because this account authored the follow-up commits. Ready for administrator-assisted merge. Main must pass before protected infrastructure publication; live migrations and deployments remain separate acceptance steps.

@ty-everett
ty-everett marked this pull request as ready for review September 23, 2026 06:31
@ty-everett
ty-everett merged commit 4bd9000 into main Sep 23, 2026
48 checks passed
@ty-everett
ty-everett deleted the automation/sync-published-versions branch September 23, 2026 06:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant