Repository navigation
feat(release): validate complete partitioned candidates - #300
Conversation
|
Warning Review limit reachedYou’ve reached a temporary PR review limit under our Fair Usage Limits Policy. Next review available in: 37 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Run ID: ⛔ Files ignored due to path filters (6)
📒 Files selected for processing (11)
Comment |
Summary
graphforge-release-candidate-v2, one root version, 24 public nodes, exact dependency edges, and four retained artifact groupsValidation
make pre-push-fastpython3 scripts/ci/test-release-candidate.pypython3 scripts/ci/test-binding-release-candidate.pypython3 scripts/ci/test-m1-release-certification.pypython3 scripts/ci/test-ci-storage-policy.pypython3 scripts/ci/test-release-publish-preflight.pypython3 scripts/ci/test-clean-env-verify.pypython3 scripts/ci/test-prepare-napi-packages.pypython3 scripts/ci/test-publish-npm-artifacts.pypython3 scripts/ci/test-publish-crates.pyuv run pytest tests/unit/test_record_release_artifacts.py -qcargo package -p graphforge-core --no-verifyNo registry writes, tags, releases, or release-certification workflow dispatches were performed.
Closes #293
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Note
Replace checksum-only release records with a partitioned v2 candidate manifest enforcing the full 24-node public package set
release_candidate_manifest.py, a new module implementing thegraphforge-release-candidate-v2schema with artifact grouping (python/npm/crates/evidence), dual-algorithm integrity (sha256+sha512), dependency graph validation, and retention window checks.record_release_artifacts.pyto delegate manifest construction tobuild_manifest, derivingrecorded_atandcommit_shafrom git and emitting deterministically sorted JSON.binding-release-candidate.ymlto derive a single non-dev root version, runprepare-napi-packages.pyto inject legal files into N-API packages, and parameterize all artifact names and manifest commands by that version.clean-env-verify.pyandpublish_crates.pyto accept both v1 release records and v2 candidate manifests.test-release-candidate.pyvalidates 24 nodes, 8 npm paths, explicit publication states, retention expiry, and rejects ~15 mutation scenarios including missing entrypoints, version divergence, dependency cycles, and unsafe paths.python/,npm/,crates/) rather than a flat dist directory.Macroscope summarized 8a09aa2.