release: v2.0.0 and signed TypeScript 0.2.0 artifacts - #111
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What & why
Publish the approved integrity upgrade as CLI 2.0.0 and TypeScript verifier 0.2.0. Schema level 4 changes every fresh tool commitment, so existing approvals require review/re-pin; the major CLI release makes that compatibility boundary explicit.
The existing GitHub Release workflow keeps PyPI's Python artifacts isolated and adds an npm-installable TypeScript tarball plus SHA-256 checksums to the same Sigstore signing/asset path. Permissions, trusted publisher, certificate identity, action pins and publication trigger remain unchanged. No npm registry identity or credential is introduced.
Validation
1de0d8809619df6d98a5a0f34d46559db5b716ff, with 1218 tests and deterministic fuzz green.025b2dcea61bca1defc40fa3545963f614180db3; 19 packaged files checked, 123 consumer tests and 90 workflow tests pass.Migration and publication
Review old locks and re-pin/re-sign for v4; old signatures do not approve the new fields. The broader Warden checkpoints remain proposal-only.
TypeScript 0.2.0 will be available from the GitHub v2.0.0 release assets; this PR makes no npm registry publication claim. CLI package name stays
mcp-warden-cliand the command staysmcp-warden.Ernest explicitly approved PR #110's final head in authenticated chat and instructed 'proceed. publish all the way.' This PR completes that stated publication scope.