Skip to content

docs: reconcile published SDK 2.8.1 baseline - #576

Merged
ty-everett merged 1 commit into
mainfrom
codex/sdk-2-8-1-published-baseline
Sep 23, 2026
Merged

ty-everett merged 1 commit into
mainfrom
codex/sdk-2-8-1-published-baseline

Conversation

@ty-everett

@ty-everett ty-everett commented Sep 23, 2026 •

Copy link
Copy Markdown
Collaborator

SDK 2.8.1 is now published, but its release ledger still describes an unpublished candidate. Reconcile the SDK baseline and generated migration ledger with the verified protected release; link the source and publication evidence in the SDK documentation.

Program and scope

Impact

  • No public package source or manifest changed
  • Documentation or examples changed
  • Registry baseline only: SDK 2.8.1, release type none; no new version or publication is requested.

Verification

  • Local pnpm health:check, pnpm lint, pnpm format:check, pnpm build, pnpm typecheck, pnpm audit:security pass; generated ledger uses pnpm docs:packages.
  • Registry latest=2.8.1, integrity matches the immutable candidate; GitHub provenance verifies against e09515508bf5bf22d7b56085170debc2b0803b2a and release.yaml. Protected preparation, publication and post-release verification all pass; cascade-only sync was correctly skipped.
  • Published tarball SHA-256: bca1215604443f320f628e1e933f7c55c61953faa3c14f8818d7ecd92e46e788.
  • Conformance, coverage, browser/mobile and bundle behavior: unchanged from fix(sdk): authenticate empty AES-GCM payloads in portable runtimes #574; protected release reran package and platform consumer gates.
  • Complete three-file diff self-reviewed for correctness, compatibility, artifacts, documentation and operations
  • All applicable hosted checks are terminal and successful on the exact head; documentation-only skips are validated by the successful merge gate

Security and dependencies

  • No dependency or lockfile change
  • No new override, advisory dismissal, quality suppression or skipped test
  • No trust-boundary/runtime/workflow-permission change
  • Exact-head CodeQL and repository zero-new-findings/merge gates pass; no open CodeQL alerts or review threads

Release and operations

  • No npm publication from a workstation or this PR
  • No additional patch bump is required: all changed files are repository documentation/governance outside the published package
  • Published source, registry digest, SBOM and provenance are linked through the protected release; no image or deployment changes
  • Release/migration guidance is current; no ciphertext, account-data or API migration

Completion evidence

  • SDK publication claims are supported by verified registry and workflow evidence
  • One qualified maintainer approval is sufficient under repository policy
  • All exact-head hosted checks pass, with scope skips validated by the merge gate. This is maintainer self-review plus automated analysis; no independent human review is claimed.

@sonarqubecloud

Copy link
Copy Markdown

@ty-everett
ty-everett marked this pull request as ready for review September 23, 2026 16:56
@ty-everett
ty-everett merged commit d98117b into main Sep 23, 2026
33 checks passed
@ty-everett
ty-everett deleted the codex/sdk-2-8-1-published-baseline branch September 23, 2026 16:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant