Skip to content

chore(release): v0.29.0 - #346

Merged
wmadden merged 4 commits into
mainfrom
chore/release-v0.29.0
Oct 8, 2026
Merged

wmadden merged 4 commits into
mainfrom
chore/release-v0.29.0

Conversation

@kristof-siket

@kristof-siket kristof-siket commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Composer 0.29.0, on Prisma ORM 8.0.0-rc.17 and CLI engine 0.7.0. Merging this PR ships 0.29.0.

What's in it

Checks

  • The branch merges main after chore(deps): move Composer to Prisma ORM 8.0.0-rc.17 and CLI engine 0.7.0 #345. The merge commit is a fresh pnpm bump-minor run on top of main, not hand-resolved conflicts.
  • pnpm bump-minor changed only versions: 41 manifests from 0.28.0 to 0.29.0, the skill's library_version, and pnpm-lock.yaml. pnpm install --frozen-lockfile passes on the result.
  • After the bump and a rebuild, examples/auth is emitted again, so its contract records auth extension 0.29.0. Only the version lines change.
  • pnpm check:publish-deps: no workspace: or catalog: leaks in the 3 publishable packages.

Signed-off-by: Kristof Siket <siket@prisma.io>
@prisma-gizmo

prisma-gizmo Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

✅ Gizmo reviewed 1a9f984 — posted 0 inline comment(s) this pass.

Open findings: none

Change walkthrough

This PR ships Composer 0.29.0 — a release bump on top of main after the merge of #345, so the delta since the last reviewed commit is the fresh pnpm bump-minor run plus the merged dependency-policy changes it now releases.

Version bump. Every touched manifest moves to 0.29.0 with workspace:0.29.0 cross-references: the three publishable packages (packages/9-public/composer, composer-cli, composer-prisma-cloud), the framework and prisma-cloud internals, the examples (including the store and storefront-auth module graphs), test/integration, the website, and the root. The skill's library_version matches. Repo-wide greps found no stale 0.28.0 workspace refs and no leftover old pins.

Engine/ORM alignment (#345). @prisma/cli-engine moves 0.6.3 → 0.7.0 in the root pnpm.overrides, the internal CLI, composer-cli's peer/devDependencies, and the target package; @prisma/orm-postgres and @prisma/orm-toolchain go to 8.0.0-rc.17 (peer and dev in the publishables, direct deps in target and the auth module), and @distilled.cloud/prisma follows alchemy to rc.13. The auth pack's regenerated contract names its foreign-key backing indexes, flipping the storage hash 310f206d → 0df0ef09; the pack migrations, the auth example's migrations and snapshots, and the example contract's recorded extension version (0.29.0) are all consistent with one another.

Effect range policy (#348). The exact effect pin becomes ^4.0.0 everywhere, @effect/platform-bun/platform-node adopt the same range, and the floater pins (@effect/sql-d1, sql-sqlite-do, vitest, platform-node-shared) are dropped — no source imports of them remain. check-npm-effect-resolution.mjs was reworked to assert "exactly one effect, whatever the range resolves" instead of a specific pin, and both skill documents describe the new policy, so tooling, docs, and manifests agree. Alchemy lands at 2.0.0-beta.81, which the core-concepts skill also cites.

@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Essentials
  • Run ID: 5d8d0835-4033-4106-bdf8-1f3dae3195e3
📥 Commits

Reviewing files that changed from the base of the PR and between e8ae0b3 and 1a9f984.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (9)
  • examples/auth/contract.d.ts
  • examples/auth/contract.json
  • examples/auth/package.json
  • examples/orm-demo/package.json
  • examples/store/modules/orders/package.json
  • packages/0-framework/3-tooling/cli/package.json
  • packages/1-prisma-cloud/1-extensions/target/package.json
  • packages/9-public/composer-cli/package.json
  • packages/9-public/composer-prisma-cloud/package.json

Included review availability: This review used your included allowance. 2 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 4 reviews per hour.


Summary by CodeRabbit

  • Chores
    • Updated Composer and related packages, examples, and workspace dependencies from version 0.28.0 to 0.29.0, keeping the release versions aligned across the project.
  • Documentation
    • Updated the documented Composer version and the authentication example’s extension version to 0.29.0.

Walkthrough

Package versions and workspace dependency references were updated from 0.28.0 to 0.29.0 across the root package, framework and Prisma Cloud packages, public packages, examples, integration tests, and website. The core concepts skill documentation and auth extension contract were also updated to name version 0.29.0.

Priority: ⬆️ High

Merge Risk: ⚪ Minimal · up to 1a9f9

The reviewed release changes show no actionable merge-blocking behavior; the documented node migration is not introduced by this change.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 1…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly identifies this pull request as the release of Composer version 0.29.0, which matches the main change across the manifests and release files.
Description check ✅ Passed The description directly explains the Composer 0.29.0 release, its dependency updates, breaking changes, auth migration requirement, and validation checks.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
✨ Simplify code
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@pkg-pr-new

pkg-pr-new Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/@prisma/composer@346
npm i https://pkg.pr.new/@prisma/composer-cli@346
npm i https://pkg.pr.new/@prisma/composer-prisma-cloud@346

commit: 1a9f984

@prisma-gizmo prisma-gizmo Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

New findings: 🟡 1 minor · trace

Findings outside the diff

  • 🟡 Minor · consistency examples/auth/contract.json — Auth example contract still records extension 0.28.0 after the workspace bumped to 0.29.0
    This release stamps every workspace manifest to 0.29.0, including the auth extension pack at packages/1-prisma-cloud/2-shared-modules/auth/package.json, but the auth example's committed contract still embeds the extension version as 0.28.0 (examples/auth/contract.json:59 and the mirror at examples/auth/contract.d.ts:311). The previous release cycle handled exactly this: after the 0.28.0 bump, the contract was re-emitted in a follow-up ("Re-emitted after the bump, so the version the example contract embeds matches the release"), which is what the release notes refer to as "the auth example records auth extension 0.28.0 (#343)". So as merged, 0.29.0 ships an example whose recorded extension version does not match the extension actually shipped. If the #343-style re-emit is planned as a separate post-merge PR this is a known follow-up; otherwise run prisma contract emit for examples/auth so the embedded version tracks the release (the commit message notes hashes do not change).
    Recommended fix: After the version bump lands, re-emit the example contract (prisma contract emit in examples/auth) so extensions.auth.version reads 0.29.0, matching the lockstep version of packages/1-prisma-cloud/2-shared-modules/auth.

@prisma-gizmo prisma-gizmo Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No critical or major Gizmo finding is open and the head commit has been reviewed. Approving.

Re-runs pnpm bump-minor on top of main to resolve the version conflicts with #348.

Signed-off-by: Kristof Siket <siket@prisma.io>
Re-runs pnpm bump-minor on top of main to resolve the version conflicts with #345.

Signed-off-by: Kristof Siket <siket@prisma.io>
The auth example's contract emitted again after the 0.29.0 bump and a rebuild, so the version it embeds matches the release. Storage, execution and profile hashes do not change.

Signed-off-by: Kristof Siket <siket@prisma.io>
@kristof-siket

Copy link
Copy Markdown
Contributor Author

Fixed in 1a9f984: examples/auth is emitted again after the bump, so its contract records auth extension 0.29.0. Only the two version lines change; no hash changes.

@prisma-gizmo prisma-gizmo Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

New findings: none · trace

@prisma-gizmo prisma-gizmo Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No critical or major Gizmo finding is open and the head commit has been reviewed. Approving.

@wmadden
wmadden merged commit b8e44e1 into main Oct 8, 2026
26 checks passed
@wmadden
wmadden deleted the chore/release-v0.29.0 branch October 8, 2026 16:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants