Repository navigation
feat: version JSON, distribute CLI, and harden CI - #49
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR resolves the three remaining maintenance issues in dependency order:
zstdscope inspect --jsonfrom the public Rust model with a dedicated schema-version-1 DTO;zstdscope-clipublishable and select crates.io as the supported CLI release channel;Closes #38
Closes #39
Closes #41
TDD evidence
Issue #38 — versioned JSON contract
4885bb0added black-box schema tests only. CI run #137 failed exactly on the missingschema_versionandu64JSON-number representation.u64values became decimal strings and the existing inspector distinctions were preserved.Issues #39/#41 — distribution and CI policy
bab4bb5added package/publish/install smoke and cargo-deny gates before implementation. CI run #141 failed only becausezstdscope-clistill hadpublish = falseand no license allowlist existed.deny.toml, Dependabot, immutable action pins, timeouts, concurrency controls, and a WASM compile gate were added.Behavior and compatibility
schema_version: 1;u64values are decimal strings for exact JavaScript interoperability;u8,u32, andusizevalues remain JSON numbers;CLI distribution decision
zstdscope-clizstdscopecargo install zstdscope-cli --locked)cargo install --git https://github.com/tappe9/zstdscope zstdscope-cli --lockedCI and supply-chain policy
contents: read;wasm32-unknown-unknowncompile-only gate for the core crate;cargo-denyfor advisories, licenses, bans, and sources;Apache-2.0,MIT,Unicode-3.0;cargo-auditnot duplicated because cargo-deny already provides the RustSec advisory gate;cargo-semver-checksevaluated and deferred to release/API review, with mandatory-gate reconsideration before 1.0.Self-review
Reviewed the complete 14-file diff against Issues #38, #39, and #41. Two maintainability/policy findings were fixed before completion:
Unlicensewas initially allowlisted even though the relevant dependency expression can be accepted through its MIT option.No unresolved PR comments, reviews, or review threads remain.
Validation
cargo fmt --checkcargo clippy --workspace --all-targets --all-features --locked -- -D warningscargo test --workspace --all-features --lockedRUSTDOCFLAGS="-D warnings" cargo doc -p zstdscope --all-features --no-deps --lockedcargo test -p zstdscope --no-default-features --lockedcargo check -p zstdscope --target wasm32-unknown-unknown --no-default-features --lockedcargo package --listcargo publish --dry-runzstdscope-clipackageFinal evidence: CI run #144 passed all six jobs at head
aa0eaac8674ed316c3fa590ca808a3aa549c7de7.Documentation
Updated README/README.ja and ROADMAP, and added:
docs/SUPPLY-CHAIN.md— CI, advisory, license, source, compatibility, and exception policy.