You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
SDK 2.8.2 is published, but the package guide still describes it as an unpublished candidate. Reconcile only the SDK baseline and regenerate its documentation from the verified registry result.
Gate advanced: accurate published-version and migration documentation.
Out of scope: all runtime code, package manifests, non-SDK baselines, infrastructure ranges and other maintainer work.
Exact reviewed head: 313c0fa58.
Impact
No public package source or manifest changed
Documentation or examples changed
SDK 2.8.2's registry tarball SHA-256 is 60f756bdb56869a7b6636da51aa147bba1bf5c2f2babc1f75971b7ab307c1a2c. It matches the immutable candidate from reviewed main cc1256c4d81b0f64de89a0df7a5af6efbe3b3983; GitHub attestation verification, npm provenance source/run and registry SHA-512 integrity were independently checked. The protected publish and post-release verification jobs passed.
Verification
Local: frozen install, generated package docs, complete health checks, lint, full formatting, workspace build and typecheck pass on Node 24.18.0 / pnpm 10.33.2.
Hosted: CI 35916929253, CodeQL 35916929255 and Conformance 35916929283 pass on 313c0fa5892b7b669fba0148c06eea71045a343c. Repository-owned Sonar zero-findings and merge gates pass; the pull-request CodeQL alert API is empty. Runtime-specific tests are correctly unselected for these two metadata/documentation files.
Coverage, conformance, browser/mobile behavior and bundle size: unchanged by these metadata-only edits. The protected release independently passed packed, clean, browser and mobile consumer gates.
I self-reviewed the complete diff for correctness, security, compatibility, artifacts, dependencies, docs and operations
All applicable checks are terminal and successful on the exact head
Security and dependencies
No dependency or lockfile change
No new override, advisory dismissal, quality suppression or skipped test
Workflow permissions and lifecycle behavior are unchanged
CodeQL/Sonar: both analyses and the repository zero-new-finding gate pass; no trust boundary changed.
Dependency evidence
Not applicable: existing package bytes and locks are unchanged. This records the already published version and preserves its consumer migration guidance.
Release and operations
No npm publication was performed from a workstation or from this PR
No further package bump is needed for release bookkeeping
SBOM/provenance evidence is retained by the linked protected release
SDK migration and published-version guidance are current
Completion evidence
No unrelated work or non-SDK baseline is claimed complete
Hosted checks and review conversations are complete
One qualified maintainer approval is sufficient; no last-pusher restriction is assumed
Maintainer review of exact head 313c0fa5892b7b669fba0148c06eea71045a343c: approved for integration. The only semantic changes record the independently verified SDK 2.8.2 publication and regenerate its package guide. Other release entries, package bytes, dependencies and runtime behavior are unchanged. Registry SHA-256/SHA-512, npm provenance source/run and GitHub attestation match protected release 35912232040 from cc1256c. Local health, lint, formatting, workspace build and typecheck pass. All applicable hosted checks, the exact-head zero-new-Sonar gate, CodeQL and merge gate pass; CodeQL alerts and review threads are empty. No findings were waived. This is the author-maintainer self-review allowed by CONTRIBUTING; GitHub does not permit a formal self-approval.
The remaining normal-merge blockers are the organization review requirement on this author-maintainer PR and an absent codecov/patch status for a change with no executable lines. All applicable checks, including the repository merge gate, are green. Applying the maintainer-authorized administrative merge for this two-file publication record; no failed check, finding, runtime test or review conversation is bypassed.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
SDK 2.8.2 is published, but the package guide still describes it as an unpublished candidate. Reconcile only the SDK baseline and regenerate its documentation from the verified registry result.
Program and scope
313c0fa58.Impact
SDK 2.8.2's registry tarball SHA-256 is
60f756bdb56869a7b6636da51aa147bba1bf5c2f2babc1f75971b7ab307c1a2c. It matches the immutable candidate from reviewed maincc1256c4d81b0f64de89a0df7a5af6efbe3b3983; GitHub attestation verification, npm provenance source/run and registry SHA-512 integrity were independently checked. The protected publish and post-release verification jobs passed.Verification
313c0fa5892b7b669fba0148c06eea71045a343c. Repository-owned Sonar zero-findings and merge gates pass; the pull-request CodeQL alert API is empty. Runtime-specific tests are correctly unselected for these two metadata/documentation files.Security and dependencies
Dependency evidence
Not applicable: existing package bytes and locks are unchanged. This records the already published version and preserves its consumer migration guidance.
Release and operations
Completion evidence