Skip to content

chore: sync published workspace versions - #499

Merged
ty-everett merged 3 commits into
mainfrom
automation/sync-published-versions
Aug 27, 2026
Merged

chore: sync published workspace versions#499
ty-everett merged 3 commits into
mainfrom
automation/sync-published-versions

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Program and scope

  • Tracker or issue: protected release run 33098795348
  • Program gate(s) advanced: published-version reconciliation and reproducible OCI release inputs
  • Why this change is needed: synchronize first-party package floors and standalone infrastructure locks after protected npm publication.
  • Explicitly out of scope: product behavior beyond consuming the already-reviewed package artifacts.
  • Exact head SHA reviewed: generated sync commit; hosted checks bind validation to the PR head.

Impact

  • No public package source or manifest changed
  • Infrastructure source, dependency, image, or deployment configuration changed
  • Security-sensitive boundary changed

Affected services and intended patch versions are the changed infra package manifests in this PR.

Verification

  • Local commands and results: generated by protected release run 33098795348 after successful npm publication.
  • Hosted CI run: pending for this exact head.
  • Conformance evidence: Not selected because no conformance input changed.
  • Coverage delta: No product source changed.
  • Lint/typecheck delta: Pending hosted affected-graph validation.
  • Browser/mobile/packed-consumer evidence: The protected release passed package, clean-consumer, browser, and mobile verification before publication.
  • Performance or bundle-size delta: No product source or bundle composition changed.
  • I self-reviewed the complete diff for correctness, security, compatibility, public API, artifacts, dependencies, docs, and operations
  • All applicable checks are terminal and successful on the exact head; any scope-based skip is expected and validated by the merge gate

Security and dependencies

  • Changelog, runtime relevance, peer compatibility, transitive graph, and audit results were reviewed by the protected release
  • No new override, advisory dismissal, quality suppression, or skipped test
  • Workflow permissions and lifecycle-script behavior remain least privilege

Dependency evidence

  • Release notes and necessity: The protected release already validated the coordinated package release notes and migration guidance.
  • Runtime, build, and peer compatibility: The release verified the governed Node, browser, mobile, runtime, and peer-dependency contracts.
  • Deduplicated lockfile: Workspace and standalone npm locks were regenerated once from the published first-party versions without lifecycle scripts.
  • Audit and CodeQL: The release rejected high and critical package findings; exact-head CodeQL runs on this PR.
  • Package and consumer tests: The release passed full builds, typecheck, package artifacts, clean consumers, browser, mobile, registry signatures, provenance, and reconciliation.
  • Bundle and performance impact: No bundle composition changed; affected releases retain their documented compatibility contracts.
  • Affected public package versions: Derived from the published workspace manifests synchronized by this exact commit.

Release and operations

  • No npm publication was performed from a workstation or from this PR
  • Required npm patch bumps are included or intentionally deferred by the controlling program
  • Image/SBOM/provenance/deployment/rollback impact is documented by the protected infrastructure release
  • Documentation, changelog, migration, and operational guidance are current

The protected infrastructure release builds Linux/amd64 images, rejects high and critical findings, publishes immutable GHCR tags, and attaches SBOM, provenance, and signature evidence after merge. Existing immutable tags remain the rollback path.

Completion evidence

  • Documentation, changelog, migration notes, release notes, and operator guidance are current or concretely not applicable
  • One qualified maintainer approval is sufficient; no last-pusher restriction is assumed

@github-actions
github-actions Bot requested a review from sirdeggen as a code owner August 27, 2026 17:53
@socket-security

socket-security Bot commented Aug 27, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​@​bsv/​wallet-toolbox@​2.10.2 ⏵ 2.10.373 +11001009980
Updatednpm/​@​bsv/​wallet-toolbox-client@​2.10.2 ⏵ 2.10.384 -21001009980

View full report

@ty-everett

Copy link
Copy Markdown
Collaborator

Reopening to trigger exact-head hosted validation because GitHub suppresses workflow recursion for PRs created by the release workflow token.

@ty-everett ty-everett closed this Aug 27, 2026
@ty-everett ty-everett reopened this Aug 27, 2026
@ty-everett

Copy link
Copy Markdown
Collaborator

Follow-up on exact-head CI: the first hosted image scan detected CVE-2026-14456 in the pinned Alpine runtime (OpenSSL 3.5.7-r0; fixed in 3.5.8-r0). Commit 2cad81c installs the reviewed fixed libcrypto3/libssl3 packages in the affected Chaintracks, Message Box, WAB, and Wallet Infrastructure runtime stages. UHRP Basic and Cloud already carry the same fix.

Local validation on this head passed: pnpm health:check, pnpm lint, pnpm format:check, pnpm typecheck, pnpm audit:security, and git diff --check. The exact-head Linux/amd64 build, runtime contract, and Trivy matrix is authoritative for the image change.

@sonarqubecloud

Copy link
Copy Markdown

@ty-everett ty-everett left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved after exact-head review: version reconciliation is coherent; the Alpine OpenSSL remediation removes CVE-2026-14456 without suppressions; local governance/lint/format/typecheck/audit checks pass; hosted Linux/amd64 runtime, Trivy, CodeQL, Sonar zero-findings, dependency, conformance, and merge gates are green at a2c84c1.

@ty-everett
ty-everett merged commit 3f13263 into main Aug 27, 2026
46 checks passed
@ty-everett
ty-everett deleted the automation/sync-published-versions branch August 27, 2026 18:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant