diff --git a/STATUS.md b/STATUS.md index f86e0fb..7c2567e 100644 --- a/STATUS.md +++ b/STATUS.md @@ -1,8 +1,8 @@ # STATUS -**Last tagged release:** `v6.5.0` (`2026-07-18`) -**Current release state:** `v6.5.1` release candidate; tag, npm publication, and GitHub Release remain pending the reviewed tag workflow. -**Latest verification:** the versioned `v6.5.1` candidate passed 14/14 release-verifier steps with 6,676 observed tests across Node, Bun, Deno, and all three real-Git integration suites; tag and publication verification remain pending. +**Last tagged release:** `v6.5.1` (`2026-07-18`) +**Current release state:** `v6.5.1` is published to npm with provenance and to GitHub Releases. +**Latest verification:** the reviewed release tree passed 14/14 release-verifier steps with 6,676 observed tests; release workflow `29666480492` then passed validation, tests, trusted npm publication, and final GitHub Release creation from merge `49b7d5cb`. **Playback truth:** `main` **Runtimes:** Node.js 22.x, Bun, Deno **Current planning method:** [WORKFLOW.md](./WORKFLOW.md) @@ -18,10 +18,11 @@ - The machine-facing `git cas agent` surface exists and now supports OS-keychain passphrase sources for vault-derived key flows, but parity and portability are still partial. -- **v6.5.1 candidate posture** — bounded immutable page payload reuse is merged - through reviewed commit `ad5b91b2`; npm, JSR, and runtime version metadata - identify `6.5.1`, while the tag and registry artifacts remain deliberately - absent until release-candidate review completes. +- **v6.5.1 artifact posture** — signed tag `v6.5.1` resolves to reviewed merge + `49b7d5cb`; npm reports `@git-stunts/git-cas@6.5.1` as `latest` with SLSA + provenance, and the final GitHub Release is published. Bounded immutable page + payload reuse is shipped. JSR dry-run validation is healthy, but JSR + publication is not part of the release workflow. - **v6.5.0 artifact posture** — signed tag `v6.5.0` resolves to reviewed merge `f464b929`; npm reports `@git-stunts/git-cas@6.5.0` as `latest` with SLSA provenance, and the final GitHub Release is published. Bounded direct bundle @@ -115,9 +116,11 @@ - GitHub Issues are canonical. If this section and GitHub disagree, GitHub wins and this section should be corrected. - Current release goalpost: - [#85 Bounded immutable page payload reuse](https://github.com/git-stunts/git-cas/issues/85) + [#39 v6.6.0: Operator TUI](https://github.com/git-stunts/git-cas/issues/39) + and + [#40 v6.6.0: Agent automation follow-through](https://github.com/git-stunts/git-cas/issues/40) under the - [`v6.5.1` milestone](https://github.com/git-stunts/git-cas/milestone/11). + [`v6.6.0` milestone](https://github.com/git-stunts/git-cas/milestone/9). - The latest landed design record is [0051-bounded-page-payload-reuse](./docs/design/0051-bounded-page-payload-reuse/bounded-page-payload-reuse.md). diff --git a/docs/design/0051-bounded-page-payload-reuse/witness/release-publication.md b/docs/design/0051-bounded-page-payload-reuse/witness/release-publication.md new file mode 100644 index 0000000..ea4d13e --- /dev/null +++ b/docs/design/0051-bounded-page-payload-reuse/witness/release-publication.md @@ -0,0 +1,80 @@ +# PERF-0051 v6.5.1 Publication Witness + +Date: 2026-07-18 + +Issue: #85 + +## Immutable Release Identity + +- Feature PR: [#87](https://github.com/git-stunts/git-cas/pull/87) +- Release PR: [#88](https://github.com/git-stunts/git-cas/pull/88) +- Reviewed merge commit: `49b7d5cb9d589d73fa17d393e48d40bd6f139e57` +- Signed annotated tag: `v6.5.1` +- Tag object: `ed905f8f8cde55ffae08f607dc02f545f9e0565b` +- Peeled tag target: `49b7d5cb9d589d73fa17d393e48d40bd6f139e57` +- Signing key: `01A63D8E9DBEEDE32918AF9C39560E0406CA9135` +- GitHub Release: + [v6.5.1](https://github.com/git-stunts/git-cas/releases/tag/v6.5.1) + (final, not a draft or prerelease; published `2026-07-19T00:14:32Z`) + +Local `git tag -v v6.5.1` reported a good signature. The remote tag object and +peeled target match the local tag and reviewed merge commit exactly. + +## Release Workflow + +[Release run 29666480492](https://github.com/git-stunts/git-cas/actions/runs/29666480492) +completed successfully against `v6.5.1`: + +| Job | Result | Evidence | +| -------------- | ------ | ---------------------------------------------- | +| Validate | pass | Tag version matched `package.json` | +| Test | pass | Lint, unit, Node/Bun/Deno real-Git integration | +| Publish npm | pass | OIDC trusted publication completed | +| GitHub Release | pass | Final release created after npm publication | + +Before tagging, `pnpm run release:verify` passed all 14 steps against PR head +`b73ee15a610dbb4a19b265d884c4a232ffdb5808`, observing 6,676 tests and +completing public type compatibility, npm package inspection, and the JSR +publication dry-run. That head and reviewed merge `49b7d5cb` share exact tree +`afe3b71ac88c1bed3220e578956a271a8d848dc2`. The tag push also passed the +local pre-push lint and 2,036-test Node unit gate. + +## npm Registry Evidence + +Independent registry queries after the workflow completed reported: + +| Field | Value | +| ------------- | ------------------------------------------------------------------------------------------------- | +| Package | `@git-stunts/git-cas@6.5.1` | +| Published | `2026-07-19T00:14:20.719Z` | +| Dist-tag | `latest` -> `6.5.1` | +| Integrity | `sha512-rRPDuuMUsy1KpysIDlQ0oclUxnECAN+b7TNGOBZdE+c7inqaj3Mv4dHuZ2Bb4I/jKwQ+e13wSSG+IaWfkrmOXw==` | +| Shasum | `3811131c703a0ccea5f4fdbb906778a6bdd06eb0` | +| File count | `250` | +| Unpacked size | `2,158,035` bytes | +| Tarball | `https://registry.npmjs.org/@git-stunts/git-cas/-/git-cas-6.5.1.tgz` | + +The registry exposes the package-version +[attestation endpoint](https://registry.npmjs.org/-/npm/v1/attestations/@git-stunts%2fgit-cas@6.5.1) +with npm publish and `https://slsa.dev/provenance/v1` predicates. The SLSA +statement resolves the build to Git commit +`49b7d5cb9d589d73fa17d393e48d40bd6f139e57` from tag `v6.5.1` and release +workflow run `29666480492`. + +## Downstream Gate + +The registry artifact now satisfies the dependency gate for git-warp. The +git-cas v6.5.1 goalpost can close on this publication evidence, while +[git-stunts/git-warp#738](https://github.com/git-stunts/git-warp/issues/738) +and +[git-stunts/git-warp#758](https://github.com/git-stunts/git-warp/issues/758) +remain open until git-warp consumes published version `6.5.1` and records +executable compatibility, CPU, wall-clock, Git-command, and bounded-memory +evidence. A local path override is not acceptable proof of the released +contract. + +Publication does not prove path-local retained-page derivation or eliminate +git-warp's remaining structural root-rebuild cost. That follow-up remains +[git-cas#86](https://github.com/git-stunts/git-cas/issues/86). JSR publication +was not claimed or attempted; its dry-run is healthy, but npm and GitHub +Releases are the v6.5.1 publication surfaces. diff --git a/test/unit/docs/release-state.test.js b/test/unit/docs/release-state.test.js index 242a8ef..e4eb1dd 100644 --- a/test/unit/docs/release-state.test.js +++ b/test/unit/docs/release-state.test.js @@ -1,9 +1,9 @@ import { describe, expect, it } from 'vitest'; -import { existsSync, readFileSync } from 'node:fs'; +import { readFileSync } from 'node:fs'; import path from 'node:path'; const repoRoot = process.cwd(); -const v651CandidateMarker = '**Current release state:** `v6.5.1` release candidate'; +const v651PublishedMarker = '**Current release state:** `v6.5.1` is published'; const v651CandidatePath = 'docs/design/0051-bounded-page-payload-reuse/witness/release-candidate.md'; const v651PublicationPath = @@ -17,10 +17,6 @@ function read(relPath) { return readFileSync(path.join(repoRoot, relPath), 'utf8'); } -function readOptional(relPath) { - return existsSync(path.join(repoRoot, relPath)) ? read(relPath) : null; -} - function v6Heading(changelog) { return changelog.match(/^## \[6\.0\.0\] — (.+)$/m)?.[1]; } @@ -48,14 +44,7 @@ function expectNoV651PublicationEvidence(...documents) { } } -function expectV651CandidateState(status, candidate, publication) { - expect(status).toContain('**Last tagged release:** `v6.5.0` (`2026-07-18`)'); - expect(status).toContain(v651CandidateMarker); - expect(status).toContain('remain pending the reviewed tag workflow'); - expect(status).toContain( - 'passed 14/14 release-verifier steps with 6,676 observed tests' - ); - expect(status).toContain('#85 Bounded immutable page payload reuse'); +function expectV651CandidateEvidence(candidate) { expect(candidate).toContain('# PERF-0051 v6.5.1 Release Candidate Witness'); expect(candidate).toContain('Implementation review: #87'); expect(candidate).toContain('Release review: #88'); @@ -63,8 +52,31 @@ function expectV651CandidateState(status, candidate, publication) { expect(candidate).toContain('**PASS (14/14)**'); expect(candidate).toContain('**6,676**'); expect(candidate).toMatch(/explicitly\s+unpublished candidate/); - expect(publication).toBeNull(); - expectNoV651PublicationEvidence(status, candidate); + expectNoV651PublicationEvidence(candidate); +} + +function expectV651PublishedEvidence(status, publication) { + expect(status).toContain('**Last tagged release:** `v6.5.1` (`2026-07-18`)'); + expect(status).toContain(v651PublishedMarker); + expect(status).toContain('49b7d5cb'); + expect(status).toContain('29666480492'); + expect(status).toContain('#39 v6.6.0: Operator TUI'); + expect(status).toContain('#40 v6.6.0: Agent automation follow-through'); + expect(publication).toContain('# PERF-0051 v6.5.1 Publication Witness'); + expect(publication).toContain('49b7d5cb9d589d73fa17d393e48d40bd6f139e57'); + expect(publication).toContain('ed905f8f8cde55ffae08f607dc02f545f9e0565b'); + expect(publication).toContain('01A63D8E9DBEEDE32918AF9C39560E0406CA9135'); + expect(publication).toContain('- Signed annotated tag: `v6.5.1`'); + expect(publication).toContain('https://github.com/git-stunts/git-cas/releases/tag/v6.5.1'); + expect(publication).toContain('actions/runs/29666480492'); + expect(publication).toMatch(/\| Package\s+\| `@git-stunts\/git-cas@6\.5\.1`\s+\|/); + expect(publication).toMatch(/\| Dist-tag\s+\| `latest` -> `6\.5\.1`\s+\|/); + expect(publication).toContain( + 'sha512-rRPDuuMUsy1KpysIDlQ0oclUxnECAN+b7TNGOBZdE+c7inqaj3Mv4dHuZ2Bb4I/jKwQ+e13wSSG+IaWfkrmOXw==' + ); + expect(publication).toContain('3811131c703a0ccea5f4fdbb906778a6bdd06eb0'); + expect(publication).toContain('2,158,035'); + expect(publication).toContain('attestations/@git-stunts%2fgit-cas@6.5.1'); } function expectV650PublishedEvidence(status, publication) { @@ -100,15 +112,16 @@ function expectCurrentV640PublicationEvidence(publication) { } describe('release state docs', () => { - it('enforces the v6.5.1 candidate boundary while preserving v6.5.0 publication', () => { + it('enforces v6.5.1 publication while preserving candidate and prior evidence', () => { const status = read('STATUS.md'); const candidate = read(v651CandidatePath); const releaseNotes = read('docs/releases/v6.5.1.md'); - const publication = readOptional(v651PublicationPath); + const publication = read(v651PublicationPath); const v650Publication = read(v650PublicationPath); const v640Publication = read(v640PublicationPath); - expectV651CandidateState(status, candidate, publication); + expectV651CandidateEvidence(candidate); + expectV651PublishedEvidence(status, publication); expect(releaseNotes).toContain( 'passed all 14 release-verifier steps with 6,676 observed' );