Skip to content

chore: sync published workspace versions - #484

Merged
ty-everett merged 1 commit into
mainfrom
automation/sync-published-versions
Aug 15, 2026
Merged

chore: sync published workspace versions#484
ty-everett merged 1 commit into
mainfrom
automation/sync-published-versions

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Program and scope

  • Tracker or issue: protected release run 31863397449
  • Program gate(s) advanced: published-version reconciliation and reproducible OCI release inputs
  • Why this change is needed: synchronize first-party package floors and standalone infrastructure locks after protected npm publication.
  • Explicitly out of scope: product behavior beyond consuming the already-reviewed package artifacts.
  • Exact head SHA reviewed: generated sync commit; hosted checks bind validation to the PR head.

Impact

  • No public package source or manifest changed
  • Infrastructure source, dependency, image, or deployment configuration changed
  • Security-sensitive boundary changed

Affected services and intended patch versions are the changed infra package manifests in this PR.

Verification

  • Local commands and results: generated by protected release run 31863397449 after successful npm publication.
  • Hosted CI run: pending for this exact head.
  • Conformance evidence: Not selected because no conformance input changed.
  • Coverage delta: No product source changed.
  • Lint/typecheck delta: Pending hosted affected-graph validation.
  • Browser/mobile/packed-consumer evidence: The protected release passed package, clean-consumer, browser, and mobile verification before publication.
  • Performance or bundle-size delta: No product source or bundle composition changed.
  • I self-reviewed the complete diff for correctness, security, compatibility, public API, artifacts, dependencies, docs, and operations
  • All applicable checks are terminal and successful on the exact head; any scope-based skip is expected and validated by the merge gate

Security and dependencies

  • Changelog, runtime relevance, peer compatibility, transitive graph, and audit results were reviewed by the protected release
  • No new override, advisory dismissal, quality suppression, or skipped test
  • Workflow permissions and lifecycle-script behavior remain least privilege

Dependency evidence

  • Release notes and necessity: The protected release already validated the coordinated package release notes and migration guidance.
  • Runtime, build, and peer compatibility: The release verified the governed Node, browser, mobile, runtime, and peer-dependency contracts.
  • Deduplicated lockfile: Workspace and standalone npm locks were regenerated once from the published first-party versions without lifecycle scripts.
  • Audit and CodeQL: The release rejected high and critical package findings; exact-head CodeQL runs on this PR.
  • Package and consumer tests: The release passed full builds, typecheck, package artifacts, clean consumers, browser, mobile, registry signatures, provenance, and reconciliation.
  • Bundle and performance impact: No bundle composition changed; affected releases retain their documented compatibility contracts.
  • Affected public package versions: Derived from the published workspace manifests synchronized by this exact commit.

Release and operations

  • No npm publication was performed from a workstation or from this PR
  • Required npm patch bumps are included or intentionally deferred by the controlling program
  • Image/SBOM/provenance/deployment/rollback impact is documented by the protected infrastructure release
  • Documentation, changelog, migration, and operational guidance are current

The protected infrastructure release builds Linux/amd64 images, rejects high and critical findings, publishes immutable GHCR tags, and attaches SBOM, provenance, and signature evidence after merge. Existing immutable tags remain the rollback path.

Completion evidence

  • Documentation, changelog, migration notes, release notes, and operator guidance are current or concretely not applicable
  • One qualified maintainer approval is sufficient; no last-pusher restriction is assumed

@github-actions
github-actions Bot requested a review from sirdeggen as a code owner August 15, 2026 04:22
@socket-security

Copy link
Copy Markdown

@sonarqubecloud

Copy link
Copy Markdown

@ty-everett
ty-everett merged commit 8b074a0 into main Aug 15, 2026
47 checks passed
@ty-everett
ty-everett deleted the automation/sync-published-versions branch August 15, 2026 04:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant