Skip to content

feat(release): validate complete partitioned candidates - #300

Merged
DecisionNerd merged 3 commits into
mainfrom
feature/293-release-candidate-manifest
Aug 1, 2026
Merged

DecisionNerd merged 3 commits into
mainfrom
feature/293-release-candidate-manifest

Conversation

@DecisionNerd

@DecisionNerd DecisionNerd commented Aug 1, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • replace checksum-only candidate records with graphforge-release-candidate-v2, one root version, 24 public nodes, exact dependency edges, and four retained artifact groups
  • reopen exact Python, npm, and crate archives to verify runtime entrypoints, native modules, metadata, legal files, inventories, byte lengths, checksums, and SRI
  • make Binding RC derive the aligned version, pack workspace dependencies exactly, add legal inventory to native npm packages, and validate the complete offline candidate before any write
  • retain historical v1 clean-environment compatibility and document the v2 contract

Validation

  • make pre-push-fast
  • python3 scripts/ci/test-release-candidate.py
  • python3 scripts/ci/test-binding-release-candidate.py
  • python3 scripts/ci/test-m1-release-certification.py
  • python3 scripts/ci/test-ci-storage-policy.py
  • python3 scripts/ci/test-release-publish-preflight.py
  • python3 scripts/ci/test-clean-env-verify.py
  • python3 scripts/ci/test-prepare-napi-packages.py
  • python3 scripts/ci/test-publish-npm-artifacts.py
  • python3 scripts/ci/test-publish-crates.py
  • uv run pytest tests/unit/test_record_release_artifacts.py -q
  • real archive inspection: packed CLI + agent skills, existing maturin sdist, and cargo package -p graphforge-core --no-verify

No registry writes, tags, releases, or release-certification workflow dispatches were performed.

Closes #293


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Note

Replace checksum-only release records with a partitioned v2 candidate manifest enforcing the full 24-node public package set

  • Introduces release_candidate_manifest.py, a new module implementing the graphforge-release-candidate-v2 schema with artifact grouping (python/npm/crates/evidence), dual-algorithm integrity (sha256+sha512), dependency graph validation, and retention window checks.
  • Rewrites record_release_artifacts.py to delegate manifest construction to build_manifest, deriving recorded_at and commit_sha from git and emitting deterministically sorted JSON.
  • Updates binding-release-candidate.yml to derive a single non-dev root version, run prepare-napi-packages.py to inject legal files into N-API packages, and parameterize all artifact names and manifest commands by that version.
  • Extends clean-env-verify.py and publish_crates.py to accept both v1 release records and v2 candidate manifests.
  • The CI test in test-release-candidate.py validates 24 nodes, 8 npm paths, explicit publication states, retention expiry, and rejects ~15 mutation scenarios including missing entrypoints, version divergence, dependency cycles, and unsafe paths.
  • Behavioral Change: artifact discovery now expects partitioned subdirectories (python/, npm/, crates/) rather than a flat dist directory.

Macroscope summarized 8a09aa2.

@coderabbitai

coderabbitai Bot commented Aug 1, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

You’ve reached a temporary PR review limit under our Fair Usage Limits Policy.

Your recent review volume is higher than typical usage, so adaptive limits are currently applied.

Next review available in: 37 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: c3921d6a-92af-4ad6-946b-0d90952587e7

📥 Commits

Reviewing files that changed from the base of the PR and between dd67a97 and 8a09aa2.

⛔ Files ignored due to path filters (6)
  • .github/workflows/README.md is excluded by !**/*.md, !**/.github/**
  • .github/workflows/binding-release-candidate.yml is excluded by !**/.github/**
  • .github/workflows/test.yml is excluded by !**/.github/**
  • CHANGELOG.md is excluded by !**/*.md
  • docs/development/release-artifact-record.md is excluded by !**/*.md, !**/docs/**
  • docs/reference/changelog.md is excluded by !**/*.md, !**/docs/**
📒 Files selected for processing (11)
  • scripts/ci/clean-env-verify.py
  • scripts/ci/prepare-napi-packages.py
  • scripts/ci/release-candidate.py
  • scripts/ci/release_candidate_manifest.py
  • scripts/ci/test-binding-release-candidate.py
  • scripts/ci/test-clean-env-verify.py
  • scripts/ci/test-prepare-napi-packages.py
  • scripts/ci/test-release-candidate.py
  • scripts/publish_crates.py
  • scripts/record_release_artifacts.py
  • tests/unit/test_record_release_artifacts.py

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added testing Test coverage and testing infrastructure documentation Improvements or additions to documentation ci-cd CI/CD configuration changes tooling Developer tooling and automation labels Aug 1, 2026
@DecisionNerd
DecisionNerd merged commit 5121fb3 into main Aug 1, 2026
20 checks passed
@DecisionNerd
DecisionNerd deleted the feature/293-release-candidate-manifest branch August 1, 2026 13:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci-cd CI/CD configuration changes documentation Improvements or additions to documentation testing Test coverage and testing infrastructure tooling Developer tooling and automation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

release: define candidate manifest, state model, and package completeness

1 participant