Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
21 changes: 12 additions & 9 deletions STATUS.md
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
# STATUS

**Last tagged release:** `v6.5.0` (`2026-07-18`)
**Current release state:** `v6.5.1` release candidate; tag, npm publication, and GitHub Release remain pending the reviewed tag workflow.
**Latest verification:** the versioned `v6.5.1` candidate passed 14/14 release-verifier steps with 6,676 observed tests across Node, Bun, Deno, and all three real-Git integration suites; tag and publication verification remain pending.
**Last tagged release:** `v6.5.1` (`2026-07-18`)
**Current release state:** `v6.5.1` is published to npm with provenance and to GitHub Releases.
**Latest verification:** the reviewed release tree passed 14/14 release-verifier steps with 6,676 observed tests; release workflow `29666480492` then passed validation, tests, trusted npm publication, and final GitHub Release creation from merge `49b7d5cb`.
**Playback truth:** `main`
**Runtimes:** Node.js 22.x, Bun, Deno
**Current planning method:** [WORKFLOW.md](./WORKFLOW.md)
Expand All @@ -18,10 +18,11 @@
- The machine-facing `git cas agent` surface exists and now supports
OS-keychain passphrase sources for vault-derived key flows, but parity and
portability are still partial.
- **v6.5.1 candidate posture** — bounded immutable page payload reuse is merged
through reviewed commit `ad5b91b2`; npm, JSR, and runtime version metadata
identify `6.5.1`, while the tag and registry artifacts remain deliberately
absent until release-candidate review completes.
- **v6.5.1 artifact posture** — signed tag `v6.5.1` resolves to reviewed merge
`49b7d5cb`; npm reports `@git-stunts/git-cas@6.5.1` as `latest` with SLSA
provenance, and the final GitHub Release is published. Bounded immutable page
payload reuse is shipped. JSR dry-run validation is healthy, but JSR
publication is not part of the release workflow.
- **v6.5.0 artifact posture** — signed tag `v6.5.0` resolves to reviewed merge
`f464b929`; npm reports `@git-stunts/git-cas@6.5.0` as `latest` with SLSA
provenance, and the final GitHub Release is published. Bounded direct bundle
Expand Down Expand Up @@ -115,9 +116,11 @@
- GitHub Issues are canonical. If this section and GitHub disagree, GitHub
wins and this section should be corrected.
- Current release goalpost:
[#85 Bounded immutable page payload reuse](https://github.com/git-stunts/git-cas/issues/85)
[#39 v6.6.0: Operator TUI](https://github.com/git-stunts/git-cas/issues/39)
and
[#40 v6.6.0: Agent automation follow-through](https://github.com/git-stunts/git-cas/issues/40)
under the
[`v6.5.1` milestone](https://github.com/git-stunts/git-cas/milestone/11).
[`v6.6.0` milestone](https://github.com/git-stunts/git-cas/milestone/9).
- The latest landed design record is
[0051-bounded-page-payload-reuse](./docs/design/0051-bounded-page-payload-reuse/bounded-page-payload-reuse.md).

Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,80 @@
# PERF-0051 v6.5.1 Publication Witness

Date: 2026-07-18

Issue: #85

## Immutable Release Identity

- Feature PR: [#87](https://github.com/git-stunts/git-cas/pull/87)
- Release PR: [#88](https://github.com/git-stunts/git-cas/pull/88)
- Reviewed merge commit: `49b7d5cb9d589d73fa17d393e48d40bd6f139e57`
- Signed annotated tag: `v6.5.1`
- Tag object: `ed905f8f8cde55ffae08f607dc02f545f9e0565b`
- Peeled tag target: `49b7d5cb9d589d73fa17d393e48d40bd6f139e57`
- Signing key: `01A63D8E9DBEEDE32918AF9C39560E0406CA9135`
- GitHub Release:
[v6.5.1](https://github.com/git-stunts/git-cas/releases/tag/v6.5.1)
(final, not a draft or prerelease; published `2026-07-19T00:14:32Z`)

Local `git tag -v v6.5.1` reported a good signature. The remote tag object and
peeled target match the local tag and reviewed merge commit exactly.

## Release Workflow

[Release run 29666480492](https://github.com/git-stunts/git-cas/actions/runs/29666480492)
completed successfully against `v6.5.1`:

| Job | Result | Evidence |
| -------------- | ------ | ---------------------------------------------- |
| Validate | pass | Tag version matched `package.json` |
| Test | pass | Lint, unit, Node/Bun/Deno real-Git integration |
| Publish npm | pass | OIDC trusted publication completed |
| GitHub Release | pass | Final release created after npm publication |

Before tagging, `pnpm run release:verify` passed all 14 steps against PR head
`b73ee15a610dbb4a19b265d884c4a232ffdb5808`, observing 6,676 tests and
completing public type compatibility, npm package inspection, and the JSR
publication dry-run. That head and reviewed merge `49b7d5cb` share exact tree
`afe3b71ac88c1bed3220e578956a271a8d848dc2`. The tag push also passed the
local pre-push lint and 2,036-test Node unit gate.

## npm Registry Evidence

Independent registry queries after the workflow completed reported:

| Field | Value |
| ------------- | ------------------------------------------------------------------------------------------------- |
| Package | `@git-stunts/git-cas@6.5.1` |
| Published | `2026-07-19T00:14:20.719Z` |
| Dist-tag | `latest` -> `6.5.1` |
| Integrity | `sha512-rRPDuuMUsy1KpysIDlQ0oclUxnECAN+b7TNGOBZdE+c7inqaj3Mv4dHuZ2Bb4I/jKwQ+e13wSSG+IaWfkrmOXw==` |
| Shasum | `3811131c703a0ccea5f4fdbb906778a6bdd06eb0` |
| File count | `250` |
| Unpacked size | `2,158,035` bytes |
| Tarball | `https://registry.npmjs.org/@git-stunts/git-cas/-/git-cas-6.5.1.tgz` |

The registry exposes the package-version
[attestation endpoint](https://registry.npmjs.org/-/npm/v1/attestations/@git-stunts%2fgit-cas@6.5.1)
with npm publish and `https://slsa.dev/provenance/v1` predicates. The SLSA
statement resolves the build to Git commit
`49b7d5cb9d589d73fa17d393e48d40bd6f139e57` from tag `v6.5.1` and release
workflow run `29666480492`.

## Downstream Gate

The registry artifact now satisfies the dependency gate for git-warp. The
git-cas v6.5.1 goalpost can close on this publication evidence, while
[git-stunts/git-warp#738](https://github.com/git-stunts/git-warp/issues/738)
and
[git-stunts/git-warp#758](https://github.com/git-stunts/git-warp/issues/758)
remain open until git-warp consumes published version `6.5.1` and records
executable compatibility, CPU, wall-clock, Git-command, and bounded-memory
evidence. A local path override is not acceptable proof of the released
contract.

Publication does not prove path-local retained-page derivation or eliminate
git-warp's remaining structural root-rebuild cost. That follow-up remains
[git-cas#86](https://github.com/git-stunts/git-cas/issues/86). JSR publication
was not claimed or attempted; its dry-run is healthy, but npm and GitHub
Releases are the v6.5.1 publication surfaces.
51 changes: 32 additions & 19 deletions test/unit/docs/release-state.test.js
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
import { describe, expect, it } from 'vitest';
import { existsSync, readFileSync } from 'node:fs';
import { readFileSync } from 'node:fs';
import path from 'node:path';

const repoRoot = process.cwd();
const v651CandidateMarker = '**Current release state:** `v6.5.1` release candidate';
const v651PublishedMarker = '**Current release state:** `v6.5.1` is published';
const v651CandidatePath =
'docs/design/0051-bounded-page-payload-reuse/witness/release-candidate.md';
const v651PublicationPath =
Expand All @@ -17,10 +17,6 @@ function read(relPath) {
return readFileSync(path.join(repoRoot, relPath), 'utf8');
}

function readOptional(relPath) {
return existsSync(path.join(repoRoot, relPath)) ? read(relPath) : null;
}

function v6Heading(changelog) {
return changelog.match(/^## \[6\.0\.0\] — (.+)$/m)?.[1];
}
Expand Down Expand Up @@ -48,23 +44,39 @@ function expectNoV651PublicationEvidence(...documents) {
}
}

function expectV651CandidateState(status, candidate, publication) {
expect(status).toContain('**Last tagged release:** `v6.5.0` (`2026-07-18`)');
expect(status).toContain(v651CandidateMarker);
expect(status).toContain('remain pending the reviewed tag workflow');
expect(status).toContain(
'passed 14/14 release-verifier steps with 6,676 observed tests'
);
expect(status).toContain('#85 Bounded immutable page payload reuse');
function expectV651CandidateEvidence(candidate) {
expect(candidate).toContain('# PERF-0051 v6.5.1 Release Candidate Witness');
expect(candidate).toContain('Implementation review: #87');
expect(candidate).toContain('Release review: #88');
expect(candidate).toContain('ad5b91b2ff7c156526961a8d0575be1a250d92c6');
expect(candidate).toContain('**PASS (14/14)**');
expect(candidate).toContain('**6,676**');
expect(candidate).toMatch(/explicitly\s+unpublished candidate/);
expect(publication).toBeNull();
expectNoV651PublicationEvidence(status, candidate);
expectNoV651PublicationEvidence(candidate);
}

function expectV651PublishedEvidence(status, publication) {
expect(status).toContain('**Last tagged release:** `v6.5.1` (`2026-07-18`)');
expect(status).toContain(v651PublishedMarker);
expect(status).toContain('49b7d5cb');
expect(status).toContain('29666480492');
expect(status).toContain('#39 v6.6.0: Operator TUI');
expect(status).toContain('#40 v6.6.0: Agent automation follow-through');
expect(publication).toContain('# PERF-0051 v6.5.1 Publication Witness');
expect(publication).toContain('49b7d5cb9d589d73fa17d393e48d40bd6f139e57');
expect(publication).toContain('ed905f8f8cde55ffae08f607dc02f545f9e0565b');
expect(publication).toContain('01A63D8E9DBEEDE32918AF9C39560E0406CA9135');
expect(publication).toContain('- Signed annotated tag: `v6.5.1`');
expect(publication).toContain('https://github.com/git-stunts/git-cas/releases/tag/v6.5.1');
expect(publication).toContain('actions/runs/29666480492');
expect(publication).toMatch(/\| Package\s+\| `@git-stunts\/git-cas@6\.5\.1`\s+\|/);
expect(publication).toMatch(/\| Dist-tag\s+\| `latest` -> `6\.5\.1`\s+\|/);
expect(publication).toContain(
'sha512-rRPDuuMUsy1KpysIDlQ0oclUxnECAN+b7TNGOBZdE+c7inqaj3Mv4dHuZ2Bb4I/jKwQ+e13wSSG+IaWfkrmOXw=='
);
expect(publication).toContain('3811131c703a0ccea5f4fdbb906778a6bdd06eb0');
expect(publication).toContain('2,158,035');
expect(publication).toContain('attestations/@git-stunts%2fgit-cas@6.5.1');
}

function expectV650PublishedEvidence(status, publication) {
Expand Down Expand Up @@ -100,15 +112,16 @@ function expectCurrentV640PublicationEvidence(publication) {
}

describe('release state docs', () => {
it('enforces the v6.5.1 candidate boundary while preserving v6.5.0 publication', () => {
it('enforces v6.5.1 publication while preserving candidate and prior evidence', () => {
const status = read('STATUS.md');
const candidate = read(v651CandidatePath);
const releaseNotes = read('docs/releases/v6.5.1.md');
const publication = readOptional(v651PublicationPath);
const publication = read(v651PublicationPath);
const v650Publication = read(v650PublicationPath);
const v640Publication = read(v640PublicationPath);

expectV651CandidateState(status, candidate, publication);
expectV651CandidateEvidence(candidate);
expectV651PublishedEvidence(status, publication);
expect(releaseNotes).toContain(
'passed all 14 release-verifier steps with 6,676 observed'
);
Expand Down
Loading