Skip to content

chore: sync published workspace versions - #433

Merged
ty-everett merged 1 commit into
mainfrom
automation/sync-published-versions
Aug 6, 2026
Merged

chore: sync published workspace versions#433
ty-everett merged 1 commit into
mainfrom
automation/sync-published-versions

Conversation

@github-actions

@github-actions github-actions Bot commented Aug 6, 2026

Copy link
Copy Markdown
Contributor

Program and scope

  • Tracker or issue: protected release run 31078651461
  • Program gate(s) advanced: published-version reconciliation and reproducible OCI release inputs
  • Why this change is needed: synchronize first-party package floors and standalone infrastructure locks after protected npm publication.
  • Explicitly out of scope: product behavior beyond consuming the already-reviewed package artifacts.
  • Exact head SHA reviewed: e8b2c25.

Impact

  • No public package source or manifest changed
  • Infrastructure source, dependency, image, or deployment configuration changed
  • Security-sensitive boundary changed

Affected services and intended patch versions are the changed infra package manifests in this PR.

Verification

  • Local commands and results: generated by protected release run 31078651461 after successful npm publication.
  • Hosted CI runs: CI 31079755975; container runtime contracts 31079755902; CodeQL 31079756110.
  • Conformance evidence: Not selected because no conformance input changed.
  • Coverage delta: No product source changed.
  • Lint/typecheck delta: Passed hosted affected-graph validation.
  • Browser/mobile/packed-consumer evidence: The protected release passed package, clean-consumer, browser, and mobile verification before publication.
  • Performance or bundle-size delta: No product source or bundle composition changed.
  • I self-reviewed the complete diff for correctness, security, compatibility, public API, artifacts, dependencies, docs, and operations
  • All applicable checks are terminal and successful on the exact head; any scope-based skip is expected and validated by the merge gate

Security and dependencies

  • Changelog, runtime relevance, peer compatibility, transitive graph, and audit results were reviewed by the protected release
  • No new override, advisory dismissal, quality suppression, or skipped test
  • Workflow permissions and lifecycle-script behavior remain least privilege

Dependency evidence

  • Release notes and necessity: The protected release already validated the coordinated package release notes and migration guidance.
  • Runtime, build, and peer compatibility: The release verified the governed Node, browser, mobile, runtime, and peer-dependency contracts.
  • Deduplicated lockfile: Workspace and standalone npm locks were regenerated once from the published first-party versions without lifecycle scripts.
  • Audit and CodeQL: The release rejected high and critical package findings; exact-head CodeQL runs on this PR.
  • Package and consumer tests: The release passed full builds, typecheck, package artifacts, clean consumers, browser, mobile, registry signatures, provenance, and reconciliation.
  • Bundle and performance impact: No bundle composition changed; affected releases retain their documented compatibility contracts.
  • Affected public package versions: Derived from the published workspace manifests synchronized by this exact commit.

Release and operations

  • No npm publication was performed from a workstation or from this PR
  • Required npm patch bumps are included or intentionally deferred by the controlling program
  • Image/SBOM/provenance/deployment/rollback impact is documented by the protected infrastructure release
  • Documentation, changelog, migration, and operational guidance are current

The protected infrastructure release builds Linux/amd64 images, rejects high and critical findings, publishes immutable GHCR tags, and attaches SBOM, provenance, and signature evidence after merge. Existing immutable tags remain the rollback path.

Completion evidence

  • Documentation, changelog, migration notes, release notes, and operator guidance are current or concretely not applicable
  • One qualified maintainer approval is sufficient; no last-pusher restriction is assumed

@github-actions
github-actions Bot requested a review from sirdeggen as a code owner August 6, 2026 06:03
@socket-security

socket-security Bot commented Aug 6, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​@​bsv/​wallet-toolbox@​2.5.0 ⏵ 2.6.166100100 +199 +180
Updatednpm/​@​bsv/​overlay-express@​2.4.9 ⏵ 2.5.075100100 +199 +180
Updatednpm/​@​bsv/​auth-express-middleware@​2.1.5 ⏵ 2.2.078 +1100100 +197 +280
Updatednpm/​@​bsv/​overlay@​2.2.7 ⏵ 2.3.079 +1100100 +198 +180
Updatednpm/​@​bsv/​wallet-toolbox-client@​2.5.0 ⏵ 2.6.183100100 +199 +180

View full report

@github-actions
github-actions Bot force-pushed the automation/sync-published-versions branch from b23b959 to e8b2c25 Compare August 6, 2026 07:04
@ty-everett ty-everett closed this Aug 6, 2026
@ty-everett ty-everett reopened this Aug 6, 2026
@sonarqubecloud

sonarqubecloud Bot commented Aug 6, 2026

Copy link
Copy Markdown

@ty-everett
ty-everett merged commit c583c6c into main Aug 6, 2026
46 checks passed
@ty-everett
ty-everett deleted the automation/sync-published-versions branch August 6, 2026 07:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant