Skip to content

chore(release): prepare 0.7.0 - #187

Merged
clawsweeper[bot] merged 1 commit into
mainfrom
release/0.7.0
Aug 31, 2026
Merged

chore(release): prepare 0.7.0#187
clawsweeper[bot] merged 1 commit into
mainfrom
release/0.7.0

Conversation

@steipete

Copy link
Copy Markdown
Contributor

Summary

Prepare the user-requested 0.7.0 release. Update the root package, all seven platform packages, private native build workspace, Rust crate, exact optional-dependency pins, and generated locks together. Date the approved Highlights/upgrade notes as 0.7.0 — 2026-08-31, preserving their complete content and all historical notes.

This is release metadata only: no runtime changes or dependency upgrades. After this PR lands and its exact-head gates pass, the maintainer will push an annotated protected v0.7.0 tag on main. The existing release workflow will build all seven bindings, publish the eight packages through npm trusted publishing, verify artifacts/provenance, and promote the GitHub Release. Do not publish locally.

Executed candidate proof

On the candidate version, pnpm native:build, pnpm check, pnpm test:security, and pnpm package:smoke passed: 6,086 TypeScript tests, 65 Rust tests, and 78 security tests. The package smoke installed only the packed root into isolated npm/pnpm consumers; native require/auto/off produced the same SHA-256, omitted optionals retained the documented fallback, and missing binaries failed require with helper-unavailable. The local native target was macOS arm64; foreign fixtures proved installer filtering, not foreign execution. Hosted CI supplies the other execution lanes.

Version and approved-note verification emitted:

{"rootVersion":"0.7.0","platformPackages":7,"nativeVersion":"0.7.0","exactOptionalPins":true,"releaseNotesMatchApprovedHighlights":true,"releaseNoteBytes":9335}

The real compiled sidecar proof emitted:

{"proof":"sidecar-unlinked-snapshot","platform":"darwin","handoff":{"hookCalls":1,"waiterOwner":"waiter","payload":{"owner":"waiter","scenario":"handoff"},"verified":true,"openedHandleClosed":true,"finalMissing":true},"replacement":{"hookCalls":1,"error":{"name":"FsSafeError","code":"path-mismatch"},"openedHandleClosed":true,"replacementPreserved":true,"originalPreserved":true}}

Compiled temp quarantine/reparse-root proof preserved replacements and outside bytes with stable indeterminate results, and the append proof rejected raced async/sync targets while stable appends returned ab.

Codex autoreview is scoped-clean with no actionable findings. git diff --check passes. Lockfile diffs contain only seven platform version specifiers and the workspace crate version. The real release-note generator matches the previously approved Unreleased body byte-for-byte.

@steipete
steipete requested a review from a team as a code owner August 31, 2026 16:05
@clawsweeper

clawsweeper Bot commented Aug 31, 2026

Copy link
Copy Markdown
Contributor

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

@steipete

Copy link
Copy Markdown
Contributor Author

@clawsweeper automerge

Special instructions:
Review and land the 0.7.0 release-preparation metadata on exact head 413e15b2e8cc615bbd686cec028d9f8b70da5c9e after normal exact-head gates pass. The user explicitly requested release 0.7.0. All package/native versions and exact pins must agree; lockfile changes must remain version-only, approved Highlights/upgrade notes must remain byte-identical apart from the dated heading, and runtime code must not change. Executed packed-consumer and compiled runtime proof is in the main PR body; local full checks and Codex review pass.

Only land this preparation PR. The coordinating maintainer owns the annotated tag and publishing workflow afterward; do not create tags, publish npm packages, create/promote releases, rewrite runtime code, or start unrelated work.

@clawsweeper

clawsweeper Bot commented Aug 31, 2026

Copy link
Copy Markdown
Contributor

🦞🧹
ClawSweeper could not enable automerge for this PR.

Reason: target is no longer an open PR.

Draft PRs stay fix-only until GitHub marks them ready for review. Pause with /clawsweeper stop.

Automerge progress:

  • 2026-08-31 16:06:30 UTC active review reused 413e15b2e8cc (waiting)
  • 2026-08-31 16:09:57 UTC review passed 413e15b2e8cc (structured ClawSweeper verdict: pass (sha=413e15b2e8cc615bbd686cec028d9f8b70da5...)
  • 2026-08-31 16:14:32 UTC merged 413e15b2e8cc (merged by ClawSweeper automerge)

@clawsweeper clawsweeper Bot added clawsweeper:automerge Maintainer opted this ClawSweeper PR into bounded ClawSweeper-reviewed automerge P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. proof: sufficient Contributor real behavior proof is sufficient. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 🚀 automerge armed This PR is in ClawSweeper's automerge lane. labels Aug 31, 2026
@clawsweeper

clawsweeper Bot commented Aug 31, 2026

Copy link
Copy Markdown
Contributor

Codex review: passed. Reviewed August 31, 2026, 12:08 PM ET / 16:08 UTC.

ClawSweeper review

What this changes

The PR prepares version 0.7.0 by updating the changelog, root and native package versions, seven platform package versions, and matching workspace lock entries.

Merge readiness

⚠️ Ready for maintainer review - 1 item remains

Keep this PR open for landing: its introduced release metadata matches the repository’s tag-time version checks, and no correctness or security defect was found. The supplied candidate proof is sufficient; exact-head CI can finish through the normal merge gate.

Priority: P3
Reviewed head: 413e15b2e8cc615bbd686cec028d9f8b70da5c9e

Review scores

Measure Result What it means
Overall readiness 🐚 platinum hermit (4/6) This is a clean, narrowly scoped release-preparation patch with sufficient supplied package-behavior proof.
Proof confidence 🐚 platinum hermit (4/6) Sufficient (terminal): The changed production surface is package metadata that controls root-to-native binding resolution; the exact-head PR body records isolated packed-consumer smoke across npm/pnpm and compiled native-sidecar results, with matching native-mode SHA-256 output and observed fallback/error behavior.
Patch quality 🦞 diamond lobster (5/6) No actionable review findings were identified.

Verification

Check Result Evidence
Real behavior Verified Sufficient (terminal): The changed production surface is package metadata that controls root-to-native binding resolution; the exact-head PR body records isolated packed-consumer smoke across npm/pnpm and compiled native-sidecar results, with matching native-mode SHA-256 output and observed fallback/error behavior.
Evidence reviewed 6 items Complete introduced release delta: The verified merge-base-to-head diff changes 13 files with 26 additions and 26 deletions; it contains only the 0.6.0-to-0.7.0 version transition and the changelog heading.
Release validator matches the metadata layout: The tag workflow requires the root package, private native workspace, Rust crate, every one of seven platform packages, and root optional-dependency pins to use the tagged version; it also requires a dated changelog section and validates release notes.
Current metadata satisfies the release contract: The checked-out root declares 0.7.0, all seven optional native pins are exact 0.7.0 values, the native crate declares 0.7.0, and the changelog has a dated 0.7.0 section.
Findings None None.
Security None None.

How this fits together

The root npm package installs an optional platform-specific native binding. Release metadata must keep the root package, native workspace and crate, platform packages, lockfile, and dated release notes aligned before the tag-triggered publishing workflow runs.

flowchart LR
  Notes[Release notes] --> Root[Root npm package]
  Root --> Pins[Exact platform package pins]
  Native[Native workspace and crate] --> Validator[Tag-time release validation]
  Pins --> Validator
  Validator --> Packages[Published root and platform packages]
Loading

Before merge

  • Complete next step (P2) - No repair is needed; the requested automerge path can rely on normal exact-head checks and mergeability gates.
Agent review details

Security

None.

Review metrics

Metric Value Why it matters
Release metadata scope 13 files; 26 additions, 26 deletions The entire introduced delta is confined to version alignment, the dated changelog heading, and corresponding lock metadata.
Native package alignment 1 root package, 1 native workspace, 1 Rust crate, 7 platform packages This matches the version topology enforced by the tag-time release validator.

Technical review

Best possible solution:

Merge the synchronized metadata after the exact-head gates pass, then let the protected annotated tag and existing release workflow build, verify, and publish the packages.

Do we have a high-confidence way to reproduce the issue?

Not applicable: this PR changes release metadata, not a reported user-facing defect; its package behavior is covered by the supplied candidate smoke evidence.

Is this the best way to solve the issue?

Yes. Updating every release-version surface together is the narrowest maintainable path and directly matches the repository’s tag-time validator.

AGENTS.md: found and applied where relevant.

Codex review notes: model internal, reasoning high; reviewed against b83b339c0cb6.

Labels

Label changes:

  • add P3: This is a bounded release-preparation metadata update with no runtime implementation change.
  • add proof: sufficient: Contributor real behavior proof is sufficient. The changed production surface is package metadata that controls root-to-native binding resolution; the exact-head PR body records isolated packed-consumer smoke across npm/pnpm and compiled native-sidecar results, with matching native-mode SHA-256 output and observed fallback/error behavior.
  • add rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🐚 platinum hermit and patch quality is 🦞 diamond lobster.
  • add status: 🚀 automerge armed: This PR is in ClawSweeper's automerge lane. Sufficient (terminal): The changed production surface is package metadata that controls root-to-native binding resolution; the exact-head PR body records isolated packed-consumer smoke across npm/pnpm and compiled native-sidecar results, with matching native-mode SHA-256 output and observed fallback/error behavior.

Label justifications:

  • P3: This is a bounded release-preparation metadata update with no runtime implementation change.
  • rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🐚 platinum hermit and patch quality is 🦞 diamond lobster.
  • status: 🚀 automerge armed: This PR is in ClawSweeper's automerge lane. Sufficient (terminal): The changed production surface is package metadata that controls root-to-native binding resolution; the exact-head PR body records isolated packed-consumer smoke across npm/pnpm and compiled native-sidecar results, with matching native-mode SHA-256 output and observed fallback/error behavior.
  • proof: sufficient: Contributor real behavior proof is sufficient. The changed production surface is package metadata that controls root-to-native binding resolution; the exact-head PR body records isolated packed-consumer smoke across npm/pnpm and compiled native-sidecar results, with matching native-mode SHA-256 output and observed fallback/error behavior.

Evidence

What I checked:

  • Complete introduced release delta: The verified merge-base-to-head diff changes 13 files with 26 additions and 26 deletions; it contains only the 0.6.0-to-0.7.0 version transition and the changelog heading. (package.json:3, 413e15b2e8cc)
  • Release validator matches the metadata layout: The tag workflow requires the root package, private native workspace, Rust crate, every one of seven platform packages, and root optional-dependency pins to use the tagged version; it also requires a dated changelog section and validates release notes. (.github/workflows/release.yml:48, b83b339c0cb6)
  • Current metadata satisfies the release contract: The checked-out root declares 0.7.0, all seven optional native pins are exact 0.7.0 values, the native crate declares 0.7.0, and the changelog has a dated 0.7.0 section. (package.json:151, 413e15b2e8cc)
  • Release-note parser accepts this shape: The release-note generator finds a section beginning with the requested version, requires an ISO date, and emits its nonempty body; the new changelog heading follows that contract. (scripts/release-notes.mjs:7, b83b339c0cb6)
  • Established release preparation history: Repository history records the prior v0.6.0 finalization and subsequent opening of the Unreleased section, establishing the same dated-release/changelog lifecycle used here. (CHANGELOG.md:3, b7cc408)
  • Candidate real-behavior proof: The PR body for the exact head reports successful package smoke in isolated npm/pnpm consumers plus compiled sidecar proof, including matching native mode SHA-256 output and documented fallback behavior. (413e15b2e8cc)

Likely related people:

  • steipete: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

@clawsweeper
clawsweeper Bot merged commit 054b488 into main Aug 31, 2026
29 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

clawsweeper:automerge Maintainer opted this ClawSweeper PR into bounded ClawSweeper-reviewed automerge P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. proof: sufficient Contributor real behavior proof is sufficient. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 🚀 automerge armed This PR is in ClawSweeper's automerge lane.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant