Version Packages - #938
Conversation
77d81a8 to
e796adc
Compare
e796adc to
935828a
Compare
freshtonic
left a comment
There was a problem hiding this comment.
Requesting changes — not because the generated diff is wrong (mechanically it's correct, see below), but because merging it in the repo's current state produces a fully blocked release, and one required pre-merge step for the FFI half hasn't happened. This review is the checklist for whoever drives the release.
Why merge-now fails
-
@cipherstash/eqlis bumped to 3.0.6, but it is still a frozen publisher.scripts/release-gate.mjson live main still carries the@cipherstash/eqlentry inFROZEN_PUBLISHERS, npm has only up to 3.0.5, and the gate exits non-zero when a frozen package's committed version is missing from the registry. Merging this PR therefore fails thegatejob and skipsreleaseentirely — nothing ships, including@cipherstash/protect-ffi0.32.1 and@cipherstash/stack-prisma1.2.0. Note that no CI ran onchangeset-release/mainat all ("no checks reported"), so nothing surfaced this on the PR; the failure would arrive post-merge.Two ways out, both preceding the merge:
- Do the Phase-5 cutover first: delete the
@cipherstash/eqlentries fromFROZEN_PUBLISHERSandFROZEN_ARTEFACT_DIGESTS(they must go together —release-gate.test.mjspins that), update the three documentsfrozen-publisher-docs.test.mjsholds (AGENTS.md, SECURITY.md's publishing note, the gate map itself), and confirm the two cutover prerequisites AGENTS.md says no workflow can assert: theGPG_PRIVATE_KEYsecret for release-plz, and write access toghcr.io/cipherstash/postgres-eql. That arms the whole five-artefact EQL pipeline, which is presumably the intent given.changeset/eql-repoint-manifests-to-stack.mdis in this release. - Or defer the EQL release: pull the EQL changesets from main and let the bot regenerate this PR without the 3.0.6 bump.
- Do the Phase-5 cutover first: delete the
-
Seven FFI packages move to 0.32.1, and
ffi-preflight.ymlhas not been dispatched against this branch. AGENTS.md requires the preflight dry run against the Version Packages branch before merging a release that moves an FFI version (there is no--dry-runonchangeset publish; the preflight is the only rehearsal). The last preflight runs are from 19 Aug on other branches — and the most recent one on main failed. Dispatch it againstchangeset-release/mainand get it green before merging.
What I verified is right in the diff
- The EQL lockstep held: crate
eql-bindings→ 3.0.6,COMMENT ON SCHEMA eql_v3 IS '3.0.6'stamped in both copies of the install bundle, bothrelease-manifest.jsonfiles, andsrc/generated/release-manifest.tsall move together —sync-lockstep-versions.mjsran as designed, and theeql-sql-asset-freshnessinvariants hold in this tree. - All seven protect-ffi packages move in lockstep to 0.32.1; the platform packages match the wrapper.
- No parked
.md.deferredchangesets are being consumed; the changesets folded in match what was pending on main.
Once the frozen-publisher question is resolved one way or the other and a green ffi-preflight exists for this branch, I'm happy to re-review — the generated content itself is sound.
f54b74a to
543943a
Compare
freshtonic
left a comment
There was a problem hiding this comment.
Re-reviewed after the bot regenerated the branch (543943a, now folding in the changesets from #948/#951-family merges). Both blockers from my previous review are unchanged and still stand: (1) @cipherstash/eql is still bumped to 3.0.6 while live main's FROZEN_PUBLISHERS still freezes it and npm stops at 3.0.5 — merging fails the release gate and ships nothing; do the Phase-5 cutover first or defer the EQL changesets. (2) Seven FFI packages still move with no ffi-preflight.yml run against this branch (latest preflight runs are 19 Aug, and the last one on main failed). The generated lockstep content itself remains mechanically correct. Full checklist in my previous review.
8cddd8a to
8741d7a
Compare
freshtonic
left a comment
There was a problem hiding this comment.
Refreshing the block over the latest regeneration (8741d7a): both conditions are still unchanged — @cipherstash/eql is still in FROZEN_PUBLISHERS on live main while this PR bumps it to 3.0.6 (npm still stops at 3.0.5, so merge fails the release gate and nothing ships), and ffi-preflight.yml has still never run against this branch while seven FFI packages move. Checklist in my first review on this PR stands verbatim.
748a145 to
b4d25b9
Compare
freshtonic
left a comment
There was a problem hiding this comment.
Covering the latest regeneration: conditions unchanged — @cipherstash/eql still frozen in FROZEN_PUBLISHERS on live main while this PR bumps it to 3.0.6 (npm latest is still 3.0.5), and ffi-preflight.yml has still never run against this branch. My original checklist on this PR stands.
b4d25b9 to
03f2df2
Compare
This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.
Releases
stash@1.2.0
@cipherstash/nextjs@4.2.0
@cipherstash/protect-ffi@0.33.0
@cipherstash/stack@1.2.0
@cipherstash/stack-prisma@1.2.0
@cipherstash/eql@3.0.6
@cipherstash/stack-drizzle@1.2.0
@cipherstash/stack-supabase@1.2.0
@cipherstash/wizard@1.2.0
@cipherstash/protect-ffi-darwin-arm64@0.33.0
@cipherstash/protect-ffi-darwin-x64@0.33.0
@cipherstash/protect-ffi-linux-arm64-gnu@0.33.0
@cipherstash/protect-ffi-linux-x64-gnu@0.33.0
@cipherstash/protect-ffi-linux-x64-musl@0.33.0
@cipherstash/protect-ffi-win32-x64-msvc@0.33.0
@cipherstash/e2e@0.0.6
@cipherstash/basic-example@1.2.17
@cipherstash/prisma-example@0.1.3
@cipherstash/bench@0.0.8
@cipherstash/ffi-integration-tests@1.0.1
@cipherstash/test-kit@0.0.4