fix(release): verify root consumers from packed tarball - #292
fix(release): verify root consumers from packed tarball#292seonghobae wants to merge 19 commits into
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Signed-off-by: Seongho Bae <me@seonghobae.me>
Signed-off-by: Seongho Bae <me@seonghobae.me>
|
Protected-main synchronization completed without force push. Exact head: Local exact-head evidence:
@codex review |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Remove the duplicated Python support contract changes from this package isolation branch. PR #405 remains the single writer while this branch keeps its packed root consumer boundary. Signed-off-by: Seongho Bae <seonghobae@users.noreply.github.com> Commit-Message-Assisted-by: Claude (via Claude Code)
Closes #291.
Current authoritative boundary
Protected shipped truth is exact
main@3b38ead2d00f44eb578d0689087b9293b3dabe1e. This Draft remains the canonical single writer fortests/package/verify-package.mjsplussrc/packedRootConsumerIsolation.test.ts. Current exact head is147f317ca07d8fccf6b69ff220aba0bf971837ceonfix/packed-root-consumer-isolation-291. Earlier body claims namingbfdd218caf41575cf750dcb03172a6896c4ee567,e0da9e3fa6a3f8dca13fa929532ba4dd6afa1ffa, older protected main, or their workflow generations as current are predecessor evidence.This is release-evidence integrity only. It adds no registry install, workspace link, lifecycle-script execution, network, credential, database, model/provider, transport, persistence, authorization, tenancy, deployment or durable-audit authority.
Test-first lineage
1e6705ed39b18161cf874bffec5e0d3bd88710c9failed in test setup and is rejected as product evidence.065346eb01a7ee4740ce4086c6cc15e8d91a7114, CI31653280023, proved the verifier usednpm pack --dry-runplus repository self-reference instead of an extracted package.e9cf52a92ec14acd1f9330de04503fbd3d4f9dd3, CI31654244618, exposed a second real defect: a temporary consumer nested under the repository package scope still resolved the package name back to the checkout.npm pack --json --ignore-scripts --pack-destinationtarball, validates inventory from that exact archive, extracts those bytes beneath an isolated consumernode_modules, gives the consumer a distinct nearest package scope, and proves ESM/CommonJS/subpath/strict-TypeScript consumers resolve from the extracted package rather than the checkout.Exact-current-head evidence
For exact head
147f317ca07d8fccf6b69ff220aba0bf971837ceagainst live protectedmain@3b38ead2d00f44eb578d0689087b9293b3dabe1e, at the latest fresh refetch:32445567032: completed / success; build/test checked out the exact head, the packed-entry contract passed, 145 files / 834 tests passed at 100% aggregate statement/branch/function/line coverage, andverify:packageexecuted the changed verifier successfully;32445566914: completed / success;32445566963: completed / success;All observed repository-owned exact-head workflows are terminal success. Repository exact-head technical success is not qualifying independent approval and does not replace separately applicable central workflows or protected integration. No predecessor evidence transfers; absent review remains non-passing.
Integration boundary
Keep Draft/unmerged while #118 owns the exact protected
v0.6.0release/publication boundary. Before any lifecycle transition refetch exact head/live base, rules/permissions, reviews/threads and all applicable repository/central workflows. Do not self-approve, weaken gates, transfer predecessor evidence, move protected main or represent this active-PR verifier as shipped release evidence.