Skip to content

chore: sync published workspace versions - #582

Merged
ty-everett merged 2 commits into
mainfrom
automation/sync-published-versions
Sep 23, 2026
Merged

ty-everett merged 2 commits into
mainfrom
automation/sync-published-versions

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Program and scope

  • Tracker or issue: protected release run 35909323275
  • Program gate(s) advanced: published-version reconciliation and reproducible OCI release inputs
  • Why this change is needed: synchronize first-party package floors and standalone infrastructure locks after protected npm publication.
  • Explicitly out of scope: product behavior beyond consuming the already-reviewed package artifacts.
  • Exact head SHA reviewed: generated sync commit; hosted checks bind validation to the PR head.

Impact

  • No public package source or manifest changed
  • Infrastructure source, dependency, image, or deployment configuration changed
  • Security-sensitive boundary changed

Affected services and intended patch versions are the changed infra package manifests in this PR.

Verification

  • Local commands and results: generated by protected release run 35909323275 after successful npm publication.
  • Hosted CI run: pending for this exact head.
  • Conformance evidence: Not selected because no conformance input changed.
  • Coverage delta: No product source changed.
  • Lint/typecheck delta: Pending hosted affected-graph validation.
  • Browser/mobile/packed-consumer evidence: The protected release passed package, clean-consumer, browser, and mobile verification before publication.
  • Performance or bundle-size delta: No product source or bundle composition changed.
  • I self-reviewed the complete diff for correctness, security, compatibility, public API, artifacts, dependencies, docs, and operations
  • All applicable checks are terminal and successful on the exact head; any scope-based skip is expected and validated by the merge gate

Security and dependencies

  • Changelog, runtime relevance, peer compatibility, transitive graph, and audit results were reviewed by the protected release
  • No new override, advisory dismissal, quality suppression, or skipped test
  • Workflow permissions and lifecycle-script behavior remain least privilege

Dependency evidence

  • Release notes and necessity: The protected release already validated the coordinated package release notes and migration guidance.
  • Runtime, build, and peer compatibility: The release verified the governed Node, browser, mobile, runtime, and peer-dependency contracts.
  • Deduplicated lockfile: Workspace and standalone npm locks were regenerated once from the published first-party versions without lifecycle scripts.
  • Audit and CodeQL: The release rejected high and critical package findings; exact-head CodeQL runs on this PR.
  • Package and consumer tests: The release passed full builds, typecheck, package artifacts, clean consumers, browser, mobile, registry signatures, provenance, and reconciliation.
  • Bundle and performance impact: No bundle composition changed; affected releases retain their documented compatibility contracts.
  • Affected public package versions: Derived from the published workspace manifests synchronized by this exact commit.

Release and operations

  • No npm publication was performed from a workstation or from this PR
  • Required npm patch bumps are included or intentionally deferred by the controlling program
  • Image/SBOM/provenance/deployment/rollback impact is documented by the protected infrastructure release
  • Documentation, changelog, migration, and operational guidance are current

The protected infrastructure release builds Linux/amd64 images, rejects high and critical findings, publishes immutable GHCR tags, and attaches SBOM, provenance, and signature evidence after merge. Existing immutable tags remain the rollback path.

Completion evidence

  • Documentation, changelog, migration notes, release notes, and operator guidance are current or concretely not applicable
  • One qualified maintainer approval is sufficient; no last-pusher restriction is assumed

@github-actions
github-actions Bot requested a review from sirdeggen as a code owner September 23, 2026 20:33
@socket-security

socket-security Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​@​bsv/​message-box-client@​2.5.2 ⏵ 2.5.38010010099 +160
Updatednpm/​@​bsv/​wallet-toolbox@​2.13.2 ⏵ 2.14.06610010099 +180
Addednpm/​@​bsv/​sdk@​2.8.2741001009980
Addednpm/​@​bsv/​wallet-toolbox-client@​2.14.0831001009980

View full report

@ty-everett

Copy link
Copy Markdown
Collaborator

Temporarily closing and immediately reopening this generated PR to trigger the normal pull-request CI with the maintainer account. The workflow-created PR currently has external checks only; integration will wait for the required repository and infrastructure checks on this exact head.

@ty-everett ty-everett closed this Sep 23, 2026
@ty-everett ty-everett reopened this Sep 23, 2026
@sonarqubecloud

Copy link
Copy Markdown

@ty-everett ty-everett left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved after complete review of 7515cf2d605228966d83f5dd217649ddf7df0798, including the clean merge of SDK publication record #583. The PR updates eight infrastructure manifests/locks and generated service-version documentation. All 15 changed locked BSV artifacts exactly match the version and SHA-512 integrity of the independently verified protected releases 35909323275 and 35912232040; no other transitive package entry or runtime source is changed. Service versions receive patch bumps; SDK/Toolbox compatible ranges resolve to already published artifacts. Local generated facts, dependency-release governance and repository health pass. Exact-head CI, eight infrastructure lanes, seven runtime image/security lanes, CodeQL, the zero-new-Sonar gate and merge gate pass. Review threads and CodeQL alerts are empty; no exception or suppression was added. This source integration does not publish container images or deploy any operator workload; those remain distinct qualified steps.

@ty-everett

Copy link
Copy Markdown
Collaborator

Exact-head approval and every applicable check are now complete on 7515cf2, with base 4fb7f3e. The remaining normal-merge blocker is the required codecov/patch status, which is absent for this manifest/lock/generated-documentation-only change. Using the maintainer-authorized administrative merge after the full infrastructure/runtime gates passed; no failed test, vulnerability finding or unresolved review is bypassed.

@ty-everett
ty-everett merged commit 110aae4 into main Sep 23, 2026
48 checks passed
@ty-everett
ty-everett deleted the automation/sync-published-versions branch September 23, 2026 20:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant