Skip to content

release: v2.0.0 and signed TypeScript 0.2.0 artifacts - #111

Merged
ernestprovo23 merged 1 commit into
mainfrom
codex/release-v2.0.0
Oct 2, 2026
Merged

ernestprovo23 merged 1 commit into
mainfrom
codex/release-v2.0.0

Conversation

@ernestprovo23

@ernestprovo23 ernestprovo23 commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

What & why

Publish the approved integrity upgrade as CLI 2.0.0 and TypeScript verifier 0.2.0. Schema level 4 changes every fresh tool commitment, so existing approvals require review/re-pin; the major CLI release makes that compatibility boundary explicit.

The existing GitHub Release workflow keeps PyPI's Python artifacts isolated and adds an npm-installable TypeScript tarball plus SHA-256 checksums to the same Sigstore signing/asset path. Permissions, trusted publisher, certificate identity, action pins and publication trigger remain unchanged. No npm registry identity or credential is introduced.

Validation

  • Feature PR feat: lock complete tool annotations and output schemas (v4) #110 merged at 1de0d8809619df6d98a5a0f34d46559db5b716ff, with 1218 tests and deterministic fuzz green.
  • Release metadata: 211 focused Python tests pass (version, workflow pins, real pin/check and vectors).
  • TypeScript: 123 tests pass; the exact npm-packed tarball installs into a fresh consumer and passes all 123 public API/conformance tests.
  • Python sdist/wheel build, strict documentation build, Ruff, complete diff check and three-core-document links pass.
  • Independent CSO review: APPROVE at exact head 025b2dcea61bca1defc40fa3545963f614180db3; 19 packaged files checked, 123 consumer tests and 90 workflow tests pass.
  • Rendered docs pass at desktop 1440px and mobile 390px, with no horizontal overflow. All GitHub CI checks pass, including the full Python suite and deterministic fuzz.

Migration and publication

Review old locks and re-pin/re-sign for v4; old signatures do not approve the new fields. The broader Warden checkpoints remain proposal-only.

TypeScript 0.2.0 will be available from the GitHub v2.0.0 release assets; this PR makes no npm registry publication claim. CLI package name stays mcp-warden-cli and the command stays mcp-warden.

Ernest explicitly approved PR #110's final head in authenticated chat and instructed 'proceed. publish all the way.' This PR completes that stated publication scope.

@ernestprovo23
ernestprovo23 merged commit 350d5cc into main Oct 2, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant