Skip to content

feat: version JSON, distribute CLI, and harden CI - #49

Merged
tappe9 merged 8 commits into
mainfrom
feat/resolve-38-39-41
Aug 27, 2026
Merged

tappe9 merged 8 commits into
mainfrom
feat/resolve-38-39-41

Conversation

@tappe9

@tappe9 tappe9 commented Aug 27, 2026 •

Copy link
Copy Markdown
Owner

Summary

This PR resolves the three remaining maintenance issues in dependency order:

  1. decouple zstdscope inspect --json from the public Rust model with a dedicated schema-version-1 DTO;
  2. make zstdscope-cli publishable and select crates.io as the supported CLI release channel;
  3. harden CI and document the dependency/supply-chain policy.

Closes #38
Closes #39
Closes #41

TDD evidence

Issue #38 — versioned JSON contract

  • RED: commit 4885bb0 added black-box schema tests only. CI run #137 failed exactly on the missing schema_version and u64 JSON-number representation.
  • GREEN: a private CLI DTO layer was added; u64 values became decimal strings and the existing inspector distinctions were preserved.
  • REFACTOR: rustfmt output was applied and the large Standard-frame DTO variant was boxed without changing the wire format. CI run #140 passed.

Issues #39/#41 — distribution and CI policy

  • RED: commit bab4bb5 added package/publish/install smoke and cargo-deny gates before implementation. CI run #141 failed only because zstdscope-cli still had publish = false and no license allowlist existed.
  • GREEN: package metadata, a versioned crates.io dependency, deny.toml, Dependabot, immutable action pins, timeouts, concurrency controls, and a WASM compile gate were added.
  • REFACTOR: packaged-version detection now supports prerelease SemVer, and the license allowlist was narrowed to the minimum accepted set.

Behavior and compatibility

  • No Zstandard parsing, validation, bounds-checking, or human-readable rendering behavior changes.
  • No public Rust API change.
  • CLI JSON intentionally changes from the previous unversioned pre-1.0 representation:
    • top-level schema_version: 1;
    • Rust u64 values are decimal strings for exact JavaScript interoperability;
    • u8, u32, and usize values remain JSON numbers;
    • Standard/Skippable tags, Dictionary-ID presence, and RLE size semantics are preserved.
  • The core crate's optional Serde representation remains independent from the CLI JSON wire contract.

CLI distribution decision

  • Package: zstdscope-cli
  • Installed binary: zstdscope
  • Selected release channel: crates.io (cargo install zstdscope-cli --locked)
  • Transitional source install: cargo install --git https://github.com/tappe9/zstdscope zstdscope-cli --locked
  • Prebuilt GitHub Release binaries are deferred until target, checksum, signing/provenance, and release-automation policies are defined.
  • Actual crates.io publication is an explicit release operation and is not performed by pull-request CI.

CI and supply-chain policy

  • immutable action revisions and least-privilege contents: read;
  • superseded-PR concurrency cancellation and bounded job timeouts;
  • existing stable/MSRV and Ubuntu/Windows/macOS gates retained;
  • wasm32-unknown-unknown compile-only gate for the core crate;
  • cargo-deny for advisories, licenses, bans, and sources;
  • minimum license allowlist: Apache-2.0, MIT, Unicode-3.0;
  • weekly Dependabot updates for Cargo and GitHub Actions;
  • cargo-audit not duplicated because cargo-deny already provides the RustSec advisory gate;
  • cargo-semver-checks evaluated and deferred to release/API review, with mandatory-gate reconsideration before 1.0.

Self-review

Reviewed the complete 14-file diff against Issues #38, #39, and #41. Two maintainability/policy findings were fixed before completion:

  1. packaged CLI version extraction originally split at the last hyphen and would mishandle prerelease versions;
  2. Unlicense was initially allowlisted even though the relevant dependency expression can be accepted through its MIT option.

No unresolved PR comments, reviews, or review threads remain.

Validation

  • cargo fmt --check
  • cargo clippy --workspace --all-targets --all-features --locked -- -D warnings
  • cargo test --workspace --all-features --locked
  • RUSTDOCFLAGS="-D warnings" cargo doc -p zstdscope --all-features --no-deps --locked
  • cargo test -p zstdscope --no-default-features --locked
  • cargo check -p zstdscope --target wasm32-unknown-unknown --no-default-features --locked
  • core and CLI cargo package --list
  • core and CLI cargo publish --dry-run
  • install and smoke-test generated zstdscope-cli package
  • MSRV Rust 1.85.0 check/test
  • Ubuntu, Windows, and macOS tests
  • cargo-deny advisory/license/ban/source checks

Final evidence: CI run #144 passed all six jobs at head aa0eaac8674ed316c3fa590ca808a3aa549c7de7.

Documentation

Updated README/README.ja and ROADMAP, and added:

  • ADR 0005 — versioned CLI JSON DTO boundary;
  • ADR 0006 — crates.io CLI distribution decision;
  • docs/SUPPLY-CHAIN.md — CI, advisory, license, source, compatibility, and exception policy.

@tappe9
tappe9 marked this pull request as ready for review August 27, 2026 02:33
@tappe9
tappe9 merged commit 1aa4ac7 into main Aug 27, 2026
6 checks passed
@tappe9
tappe9 deleted the feat/resolve-38-39-41 branch August 27, 2026 02:34
@tappe9 tappe9 mentioned this pull request Aug 27, 2026
12 tasks done
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant