Skip to content

docs(sdk): reconcile verified 2.8.2 publication - #583

Merged
ty-everett merged 1 commit into
mainfrom
codex/sdk-2-8-2-published-baseline
Sep 23, 2026
Merged

ty-everett merged 1 commit into
mainfrom
codex/sdk-2-8-2-published-baseline

Conversation

@ty-everett

@ty-everett ty-everett commented Sep 23, 2026 •

Copy link
Copy Markdown
Collaborator

SDK 2.8.2 is published, but the package guide still describes it as an unpublished candidate. Reconcile only the SDK baseline and regenerate its documentation from the verified registry result.

Program and scope

Impact

  • No public package source or manifest changed
  • Documentation or examples changed

SDK 2.8.2's registry tarball SHA-256 is 60f756bdb56869a7b6636da51aa147bba1bf5c2f2babc1f75971b7ab307c1a2c. It matches the immutable candidate from reviewed main cc1256c4d81b0f64de89a0df7a5af6efbe3b3983; GitHub attestation verification, npm provenance source/run and registry SHA-512 integrity were independently checked. The protected publish and post-release verification jobs passed.

Verification

  • Local: frozen install, generated package docs, complete health checks, lint, full formatting, workspace build and typecheck pass on Node 24.18.0 / pnpm 10.33.2.
  • Hosted: CI 35916929253, CodeQL 35916929255 and Conformance 35916929283 pass on 313c0fa5892b7b669fba0148c06eea71045a343c. Repository-owned Sonar zero-findings and merge gates pass; the pull-request CodeQL alert API is empty. Runtime-specific tests are correctly unselected for these two metadata/documentation files.
  • Coverage, conformance, browser/mobile behavior and bundle size: unchanged by these metadata-only edits. The protected release independently passed packed, clean, browser and mobile consumer gates.
  • I self-reviewed the complete diff for correctness, security, compatibility, artifacts, dependencies, docs and operations
  • All applicable checks are terminal and successful on the exact head

Security and dependencies

  • No dependency or lockfile change
  • No new override, advisory dismissal, quality suppression or skipped test
  • Workflow permissions and lifecycle behavior are unchanged
  • CodeQL/Sonar: both analyses and the repository zero-new-finding gate pass; no trust boundary changed.

Dependency evidence

Not applicable: existing package bytes and locks are unchanged. This records the already published version and preserves its consumer migration guidance.

Release and operations

  • No npm publication was performed from a workstation or from this PR
  • No further package bump is needed for release bookkeeping
  • SBOM/provenance evidence is retained by the linked protected release
  • SDK migration and published-version guidance are current

Completion evidence

  • No unrelated work or non-SDK baseline is claimed complete
  • Hosted checks and review conversations are complete
  • One qualified maintainer approval is sufficient; no last-pusher restriction is assumed

@sonarqubecloud

Copy link
Copy Markdown

@ty-everett
ty-everett marked this pull request as ready for review September 23, 2026 20:43
@ty-everett

Copy link
Copy Markdown
Collaborator Author

Maintainer review of exact head 313c0fa5892b7b669fba0148c06eea71045a343c: approved for integration. The only semantic changes record the independently verified SDK 2.8.2 publication and regenerate its package guide. Other release entries, package bytes, dependencies and runtime behavior are unchanged. Registry SHA-256/SHA-512, npm provenance source/run and GitHub attestation match protected release 35912232040 from cc1256c. Local health, lint, formatting, workspace build and typecheck pass. All applicable hosted checks, the exact-head zero-new-Sonar gate, CodeQL and merge gate pass; CodeQL alerts and review threads are empty. No findings were waived. This is the author-maintainer self-review allowed by CONTRIBUTING; GitHub does not permit a formal self-approval.

@ty-everett

Copy link
Copy Markdown
Collaborator Author

The remaining normal-merge blockers are the organization review requirement on this author-maintainer PR and an absent codecov/patch status for a change with no executable lines. All applicable checks, including the repository merge gate, are green. Applying the maintainer-authorized administrative merge for this two-file publication record; no failed check, finding, runtime test or review conversation is bypassed.

@ty-everett
ty-everett merged commit 4fb7f3e into main Sep 23, 2026
33 checks passed
@ty-everett
ty-everett deleted the codex/sdk-2-8-2-published-baseline branch September 23, 2026 20:44
@ty-everett ty-everett mentioned this pull request Sep 23, 2026
13 of 14 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant