Skip to content

chore(release): prepare v0.2.0 - #60

Merged
steipete merged 1 commit into
mainfrom
sweep3/release
Sep 22, 2026
Merged

steipete merged 1 commit into
mainfrom
sweep3/release

Conversation

@steipete

Copy link
Copy Markdown
Contributor

Prepare v0.2.0 for the accumulated scan-evidence, benchmark-memory, and retry fixes, plus worker container labels, platform-specific npm builds, and updated runtime tooling. A minor release reflects the added capabilities and Go 1.27.1 source-build requirement. Preserve contributor credit and leave an empty Unreleased section for the next cycle.

The release workflow now waits for npm publication and uses the finalized changelog section with verified npm version, tarball, and integrity metadata. Missing notes or mismatched package metadata stop publication. README badges now show live CI and release state. Focused release-note tests cover section boundaries and rejected metadata; workflow lint and independent Codex review through P2 passed.

AWS Crabbox validation passed on the final candidate: full Go tests and vet, all 32 npm/script tests, all six release archives, npm pack/install/CLI smoke for v0.2.0, and docs generation. Two unreachable leases were replaced. The first packaging run lacked Git metadata because the candidate had not yet been pushed; a full resync of the published candidate and packaging rerun passed with the actual commit recorded.

@steipete
steipete requested review from a team and Patrick-Erichsen as code owners September 22, 2026 09:54
@clawsweeper

clawsweeper Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@clawsweeper clawsweeper Bot added P2 Normal priority bug or improvement with limited blast radius. rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. status: 📣 needs proof The PR needs real behavior proof before ClawSweeper can clear the contributor ask. labels Sep 22, 2026
@clawsweeper

clawsweeper Bot commented Sep 22, 2026

Copy link
Copy Markdown

Codex review: needs real behavior proof before merge. Reviewed September 22, 2026, 5:57 AM ET / 09:57 UTC.

ClawSweeper review

What this changes

Prepares the v0.2.0 changelog, adds live README badges, and makes GitHub releases wait for npm publication and use validated changelog-backed notes.

Merge readiness

⛔ Blocked before merge - 2 items remain

Keep open: the release preparation is not implemented on main, and no concrete patch defect was found. The reported packaging validation is useful, but does not demonstrate the new release-note generation path.

Priority: P2
Reviewed head: f136a82029bbbfa2dbb31f49dc4a9b3e9e3a3f79

Review scores

Measure Result What it means
Overall readiness 🦐 gold shrimp (3/6) The patch is focused and source review found no blocking defect, but the available validation does not demonstrate its new release-note entrypoint.
Proof confidence 🦐 gold shrimp (3/6) Needs stronger real behavior proof before merge: The body reports successful Crabbox packaging and CLI smoke, but does not show scripts/release-notes.mjs consuming registry metadata and producing the intended release notes. Add redacted terminal output or an artifact from that changed path; a public release is not needed to demonstrate rendering. No stored-data contract changes. After adding proof, update the PR body; ClawSweeper should re-review automatically. If it does not, the PR author or someone with repository write access can comment @clawsweeper re-review.
Patch quality 🐚 platinum hermit (4/6) No actionable review findings were identified.

Verification

Check Result Evidence
Real behavior Needs proof Needs stronger real behavior proof before merge: The body reports successful Crabbox packaging and CLI smoke, but does not show scripts/release-notes.mjs consuming registry metadata and producing the intended release notes. Add redacted terminal output or an artifact from that changed path; a public release is not needed to demonstrate rendering. No stored-data contract changes. After adding proof, update the PR body; ClawSweeper should re-review automatically. If it does not, the PR author or someone with repository write access can comment @clawsweeper re-review.
Evidence reviewed 8 items Introduced scope: The pinned main-to-head delta changes six files: two workflows, the changelog, README, and a new release-note helper with tests. Runtime and scanner changes mentioned in the changelog are not introduced by this PR.
Publication boundary: GitHub publication now depends on successful npm publication, checks out the release reference, retrieves package metadata, and invokes the note generator before creating the GitHub release. Existing action pins and publishing permissions are retained.
Release-note validation: The helper selects the requested changelog section and rejects empty notes, a different package/version, an unexpected registry tarball URL, or malformed integrity syntax. It reuses the existing package-version normalizer; tests cover section boundaries and rejected metadata.
Findings None None.
Security None None.

How this fits together

ClawScan’s release workflow builds downloadable CLI archives and publishes its npm package. The changed publication step combines the tagged changelog with npm registry metadata to produce GitHub release notes.

flowchart TD
  A[Release tag] --> B[Build CLI archives]
  A --> C[Publish npm package]
  C --> D[Read registry metadata]
  E[Tagged changelog] --> F[Validate and render notes]
  D --> F
  B --> G[Publish GitHub release]
  F --> G
Loading

Before merge

  • Add real behavior proof - Needs stronger real behavior proof before merge: The body reports successful Crabbox packaging and CLI smoke, but does not show scripts/release-notes.mjs consuming registry metadata and producing the intended release notes. Add redacted terminal output or an artifact from that changed path; a public release is not needed to demonstrate rendering. No stored-data contract changes. After adding proof, update the PR body; ClawSweeper should re-review automatically. If it does not, the PR author or someone with repository write access can comment @clawsweeper re-review.
  • Complete next step (P2) - Add real release-note command output or a generated artifact before merge; terminal screenshots or recordings are welcome, and logs also count. Redact credentials and private details. Updating the PR body should trigger review; otherwise ask a maintainer to comment @clawsweeper re-review.
Agent review details

Security

None.

Review metrics

Metric Value Why it matters
Executable LOC delta Production helper +33; tests +29; workflows +8 net The small production addition has a stated purpose: generate release notes and reject mismatched package metadata.

Technical review

Best possible solution:

Keep release notes derived from the tagged changelog and validated registry metadata, with publication following successful package delivery.

Do we have a high-confidence way to reproduce the issue?

Not applicable: this PR prepares a release and changes publication automation; it does not report an existing runtime bug.

Is this the best way to solve the issue?

Yes: reusing the package-version normalizer and rendering one changelog section is a focused solution; the remaining gap is evidence exercising the new command.

AGENTS.md: found and applied where relevant.

Codex review notes: model internal, reasoning medium; reviewed against 37f74167237e.

Labels

Label changes:

  • add P2: This is a bounded release-publication improvement with no demonstrated urgent user-facing regression.
  • add rating: 🦐 gold shrimp: Overall readiness is 🦐 gold shrimp; proof is 🦐 gold shrimp and patch quality is 🐚 platinum hermit.
  • add status: 📣 needs proof: The PR needs real behavior proof before ClawSweeper can clear the contributor ask. Needs stronger real behavior proof before merge: The body reports successful Crabbox packaging and CLI smoke, but does not show scripts/release-notes.mjs consuming registry metadata and producing the intended release notes. Add redacted terminal output or an artifact from that changed path; a public release is not needed to demonstrate rendering. No stored-data contract changes. After adding proof, update the PR body; ClawSweeper should re-review automatically. If it does not, the PR author or someone with repository write access can comment @clawsweeper re-review.

Label justifications:

  • P2: This is a bounded release-publication improvement with no demonstrated urgent user-facing regression.
  • rating: 🦐 gold shrimp: Overall readiness is 🦐 gold shrimp; proof is 🦐 gold shrimp and patch quality is 🐚 platinum hermit.
  • status: 📣 needs proof: The PR needs real behavior proof before ClawSweeper can clear the contributor ask. Needs stronger real behavior proof before merge: The body reports successful Crabbox packaging and CLI smoke, but does not show scripts/release-notes.mjs consuming registry metadata and producing the intended release notes. Add redacted terminal output or an artifact from that changed path; a public release is not needed to demonstrate rendering. No stored-data contract changes. After adding proof, update the PR body; ClawSweeper should re-review automatically. If it does not, the PR author or someone with repository write access can comment @clawsweeper re-review.

Evidence

What I checked:

  • Introduced scope: The pinned main-to-head delta changes six files: two workflows, the changelog, README, and a new release-note helper with tests. Runtime and scanner changes mentioned in the changelog are not introduced by this PR. (f136a82029bb)
  • Publication boundary: GitHub publication now depends on successful npm publication, checks out the release reference, retrieves package metadata, and invokes the note generator before creating the GitHub release. Existing action pins and publishing permissions are retained. (.github/workflows/release.yml:83, f136a82029bb)
  • Release-note validation: The helper selects the requested changelog section and rejects empty notes, a different package/version, an unexpected registry tarball URL, or malformed integrity syntax. It reuses the existing package-version normalizer; tests cover section boundaries and rejected metadata. (scripts/release-notes.mjs:5, f136a82029bb)
  • Contributor validation and coverage gap: The complete supplied body, also confirmed through the pull endpoint, reports final-candidate Crabbox Go tests/vet, 32 npm/script tests, six archives, npm pack/install/CLI smoke, and docs generation. It supplies no generated release-note output or transcript exercising the new CLI helper with registry metadata. Packaging proof therefore does not establish the changed publication behavior. (f136a82029bb)
  • Current main and release status: Current main remains at the pinned base, whose changelog has only an Unreleased section. GitHub reports v0.1.8, published September 10, as the latest release. The recent pull listing contains the merged component changes, but no merged replacement for this release preparation. (CHANGELOG.md:3, 37f74167237e)
  • Release verification: The latest published release is v0.1.8; v0.2.0 is not the current published release.

Likely related people:

  • Patrick-Erichsen: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)
  • steipete: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)

Rank-up moves

Optional improvements that raise the rating; they are not merge blockers.

  • Provide a redacted transcript or generated artifact showing the release-note command processing registry metadata and emitting the selected changelog section.

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

@steipete
steipete merged commit ef02eb6 into main Sep 22, 2026
10 checks passed
@vincentkoc
vincentkoc deleted the sweep3/release branch September 25, 2026 11:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

P2 Normal priority bug or improvement with limited blast radius. rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. status: 📣 needs proof The PR needs real behavior proof before ClawSweeper can clear the contributor ask.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant