Skip to content

release: promote v0.5.8 to main - #354

Merged
mohanagy merged 10 commits into
mainfrom
development
Aug 9, 2026
Merged

release: promote v0.5.8 to main#354
mohanagy merged 10 commits into
mainfrom
development

Conversation

@mohanagy

@mohanagy mohanagy commented Aug 9, 2026

Copy link
Copy Markdown
Owner

Refs #350.

Promotes protected development commit e2f08fa to main for v0.5.8.

Release gate

Security impact

  • actionable startup details remain bounded and pass through the configured runtime redactor before stderr
  • dynamic config paths and profile names remain literal shell arguments, including expansion syntax and apostrophes
  • production ACL behavior, credential handling, fail-closed boundaries, and publishing workflows are unchanged
  • no registry token or workstation publish is used

Publishing boundary

This PR does not publish. After merge, GitHub Release v0.5.8 must target the exact current main commit. The protected Publish workflow will verify tag, package version, main identity, tests, and package contents, then publish with provenance; registry provenance is verified afterward.

@coderabbitai

coderabbitai Bot commented Aug 9, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 859eb905-4206-4c84-bfde-2dd3ebce8cd8

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

chore: sync main ancestry before v0.5.8 promotion
* fix(cli): preserve retry command arguments

* fix(cli): label PowerShell retry commands
* test(cli): run diagnostic output contracts on Windows

* test(release): enforce CLI gate order
@mohanagy

mohanagy commented Aug 9, 2026

Copy link
Copy Markdown
Owner Author

Independent exact-head release review: PASS

Reviewed promotion head e2f08fa against main b076110 on 2026-08-09.

  • Standards review: PASS. No material code, release-process, security, or claim defect.
  • Spec review: PASS. Package and lockfile are 0.5.8; changelog and patch rationale match Release v0.5.8 #350; npm latest remains 0.5.7; Release v0.5.8 #350 remains open for post-publication evidence.
  • Cross-platform contract: test(cli): run diagnostic output contracts on Windows #360 places the real argv suite in protected test:cli, with PowerShell execution passing on Windows Node 20, 22, and 24.
  • Exact-head CI: runs 31323766935 and 31323768983 both completed successfully, including Linux quality, the full Ubuntu/macOS/Windows Node 20/22/24 matrix, and Verify.
  • Publishing boundary: the corrected exact-main/tag and post-publish provenance wording matches the protected trusted-publishing workflow.

Verdict: approved for the development-to-main release promotion. No material blockers remain.

This comment records the independent agent review evidence required by the release protocol. GitHub cannot accept a formal Approve review submitted by the pull-request author account.

@mohanagy
mohanagy merged commit 11aa48e into main Aug 9, 2026
23 checks passed
@mohanagy mohanagy mentioned this pull request Aug 9, 2026
10 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant