Skip to content

release: promote v1.1.0 to main - #395

Merged
mohanagy merged 37 commits into
mainfrom
development
Aug 11, 2026
Merged

release: promote v1.1.0 to main#395
mohanagy merged 37 commits into
mainfrom
development

Conversation

@mohanagy

Copy link
Copy Markdown
Owner

Summary

Promote the exact protected development release head 7b3bc866b08c367700827c5b7f358640775f5d58 to main for @lubab/miftah@1.1.0.

This is the release-promotion exception required by the repository protocol. It contains the completed MCP 2026-07-28 dual-era serving, stateless authenticated profile-context boundary, MRTR confirmation flow, OAuth/gateway hardening, v1 library-host compatibility bridge, compatibility evidence, and finalized v1.1.0 version/changelog metadata.

Tracks #393 and parent #362. These issues remain open until protected publication and post-publication verification complete.

Exact-source evidence

Validation

  • npm ci
  • npm run lint
  • npm run typecheck
  • npm test — 1,947 passed, 34 skipped across 158 files
  • npm run test:coverage — 96.04% statements, 92.17% branches
  • npm run build
  • CLI schema/version smoke
  • npm run check:pack
  • npm run check:test-fixture
  • npm run test:package — 31 packaged-consumer checks
  • npm run test:inspector — packaged Inspector 2.1.0 STDIO and modern HTTP interoperability
  • production and full dependency audits — 0 vulnerabilities

Claim boundary

Runtime interoperability claims cover the locked MCP TypeScript client and pinned MCP Inspector operations in docs/mcp-compatibility.md. Claude Desktop, Claude Code, Cursor, and VS Code remain configuration-shape destinations unless a separate exact packaged-host transcript is recorded.

Publication gates after merge

  • Current-head promotion CI and required CodeRabbit review pass.
  • Merge commit becomes the exact current main commit and exact-main push CI passes.
  • GitHub Release v1.1.0 targets that exact main commit.
  • Protected OIDC trusted publishing succeeds; no workstation publish or NPM_TOKEN is used.
  • npm latest, provenance, clean install, CLI version, and package signatures verify.

* docs(mcp): decide stateless profile context (#364)

* test(mcp): harden stateless context prototype
* feat(profiles): add stateless profile context handles (#377)

* fix(profiles): address stateless context review (#377)

* test(profiles): assert prototype remains clean (#377)
[Protocol] Upgrade to MCP TypeScript SDK v2 and negotiate the 2026-07-28 era
feat: harden MCP 2026 OAuth registration
[Gateway] Validate MCP headers and deterministic private catalogs
feat: harden MRTR workflows and defer Tasks
docs: define MCP compatibility contract
test: make local stdio fixture path independent
@coderabbitai

coderabbitai Bot commented Aug 11, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 3cf5067c-03fb-456b-bee8-7e1bba95b92e

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

chore: sync main release ancestry into development
@mohanagy

Copy link
Copy Markdown
Owner Author

Exact-head CI note for b5dc8d7cbcb5cc70b5982a3ef82d2815a68db9e5:

@mohanagy
mohanagy merged commit bb9c9c6 into main Aug 11, 2026
32 of 34 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant