Skip to content

chore: sync published workspace versions - #529

Merged
ty-everett merged 1 commit into
mainfrom
automation/sync-published-versions
Sep 10, 2026
Merged

ty-everett merged 1 commit into
mainfrom
automation/sync-published-versions

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Program and scope

  • Tracker or issue: protected release run 34536408129
  • Program gate(s) advanced: published-version reconciliation and reproducible OCI release inputs
  • Why this change is needed: synchronize first-party package floors and standalone infrastructure locks after protected npm publication.
  • Explicitly out of scope: product behavior beyond consuming the already-reviewed package artifacts.
  • Exact head SHA reviewed: generated sync commit; hosted checks bind validation to the PR head.

Impact

  • No public package source or manifest changed
  • Infrastructure source, dependency, image, or deployment configuration changed
  • Security-sensitive boundary changed

Affected services and intended patch versions are the changed infra package manifests in this PR.

Verification

  • Local commands and results: generated by protected release run 34536408129 after successful npm publication.
  • Hosted CI run: pending for this exact head.
  • Conformance evidence: Not selected because no conformance input changed.
  • Coverage delta: No product source changed.
  • Lint/typecheck delta: Pending hosted affected-graph validation.
  • Browser/mobile/packed-consumer evidence: The protected release passed package, clean-consumer, browser, and mobile verification before publication.
  • Performance or bundle-size delta: No product source or bundle composition changed.
  • I self-reviewed the complete diff for correctness, security, compatibility, public API, artifacts, dependencies, docs, and operations
  • All applicable checks are terminal and successful on the exact head; any scope-based skip is expected and validated by the merge gate

Security and dependencies

  • Changelog, runtime relevance, peer compatibility, transitive graph, and audit results were reviewed by the protected release
  • No new override, advisory dismissal, quality suppression, or skipped test
  • Workflow permissions and lifecycle-script behavior remain least privilege

Dependency evidence

  • Release notes and necessity: The protected release already validated the coordinated package release notes and migration guidance.
  • Runtime, build, and peer compatibility: The release verified the governed Node, browser, mobile, runtime, and peer-dependency contracts.
  • Deduplicated lockfile: Workspace and standalone npm locks were regenerated once from the published first-party versions without lifecycle scripts.
  • Audit and CodeQL: The release rejected high and critical package findings; exact-head CodeQL runs on this PR.
  • Package and consumer tests: The release passed full builds, typecheck, package artifacts, clean consumers, browser, mobile, registry signatures, provenance, and reconciliation.
  • Bundle and performance impact: No bundle composition changed; affected releases retain their documented compatibility contracts.
  • Affected public package versions: Derived from the published workspace manifests synchronized by this exact commit.

Release and operations

  • No npm publication was performed from a workstation or from this PR
  • Required npm patch bumps are included or intentionally deferred by the controlling program
  • Image/SBOM/provenance/deployment/rollback impact is documented by the protected infrastructure release
  • Documentation, changelog, migration, and operational guidance are current

The protected infrastructure release builds Linux/amd64 images, rejects high and critical findings, publishes immutable GHCR tags, and attaches SBOM, provenance, and signature evidence after merge. Existing immutable tags remain the rollback path.

Completion evidence

  • Documentation, changelog, migration notes, release notes, and operator guidance are current or concretely not applicable
  • One qualified maintainer approval is sufficient; no last-pusher restriction is assumed

@github-actions
github-actions Bot requested a review from sirdeggen as a code owner September 10, 2026 22:35

@ty-everett ty-everett left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved as the generated dependency and image-version synchronization for the verified PR #486 npm release.

@sonarqubecloud

Copy link
Copy Markdown

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​@​bsv/​wallet-toolbox@​2.12.0 ⏵ 2.13.074 +110010099 +180
Addednpm/​@​bsv/​sdk@​2.6.0741001009980
Addednpm/​@​bsv/​wallet-toolbox-client@​2.13.0831001009980

View full report

@ty-everett
ty-everett merged commit 6e53b21 into main Sep 10, 2026
47 checks passed
@ty-everett
ty-everett deleted the automation/sync-published-versions branch September 10, 2026 22:41
Quaakee added a commit to Quaakee/ts-stack that referenced this pull request Sep 15, 2026
Quaakee added a commit to Quaakee/ts-stack that referenced this pull request Sep 19, 2026
Quaakee added a commit to Quaakee/ts-stack that referenced this pull request Sep 25, 2026
… fork main (bsv-blockchain#59) [skip ci]

Merge base 0b01acd. Upstream's auth rework (134e4ec session-identity
binding, 813d8b9 auth policy, e5c5334 BRC-104 empty-body preimage,
cc1256c discovery deadlines, e095155 empty AES-GCM payloads) and the
wallet-toolbox correctness fixes (476b135/eacfe4b63, c52049f) are taken
intact; the fork's bsv-blockchain#529 zero-field initial-response certificate proofs and
bsv-blockchain#520 exact signed-failed-action resume are re-applied on top. Versions follow
upstream (@bsv/sdk 2.8.2, @bsv/wallet-toolbox 2.14.0).

Conflicted files:

- packages/sdk/src/auth/Peer.ts: upstream's file is the base. bsv-blockchain#529's session
  snapshot is upstream's own PeerSession.certificatePolicy (same contract:
  locally retained, never on the wire) and bsv-blockchain#529's "Wrong peer" check is
  upstream's initialResponse identity check. Re-applied on top: the policy the
  session store actually retained is captured in authenticateInitialResponse
  before upstream's `certificatePolicy ??=` refill and is the only zero-field
  authority (validateCertificates(..., allowZeroFields = retained != null));
  the standalone certificateResponse path passes allowZeroFields=false. No
  upstream check is weakened, reordered or bypassed.
- packages/sdk/src/auth/types.ts: upstream's certificatePolicy and
  pendingCertificateRequests fields; the fork's requestedCertificates field is
  dropped as redundant and its zero-field contract folded into the
  certificatePolicy doc comment.
- packages/sdk/src/auth/utils/validateCertificates.ts (auto-merged, reviewed):
  upstream's bounded snapshots, 100-certificate cap and non-empty disclosed
  field assertion, with bsv-blockchain#529's allowZeroFields early return before
  decryptFields for an exact fields=[] request with an empty/nullish keyring.
- packages/sdk/package.json: upstream 2.8.2.
- packages/sdk/CHANGELOG.md, packages/sdk/README.md: upstream entries kept;
  the fork's zero-field notes re-worded for the 2.8.2 base and
  certificatePolicy.
- packages/wallet/wallet-toolbox/src/storage/methods/attemptToPostReqsToNetwork.ts:
  upstream's typed imports and input-spend-evidence double-spend
  classification plus the fork's exact-resume lock/post/updateExactResume
  path; the only textual conflict was updateExactResume's placement.
- packages/wallet/wallet-toolbox/src/storage/methods/processAction.ts:
  upstream's argument normalization, complete-set gating and delayed-share
  error status plus the fork's resumeFailedSendWith call and exact-resume
  scheduling; the now-unused transactionIds local is dropped.
- packages/wallet/wallet-toolbox/README.md: both sections kept.
- governance/package-release-notes.json: upstream's 2.8.2 sdk and 2.14.0
  toolbox records with the fork's bsv-blockchain#529/bsv-blockchain#520 sentences appended.
- docs/packages/sdk/bsv-sdk.md: manifest version 2.8.2, upstream prose plus
  the fork's zero-field paragraph.
- docs/reference/package-api-migrations.md, docs/reference/stack-facts.md:
  regenerated with scripts/package-documentation.mjs and
  scripts/generate-stack-facts.mjs.
- governance/repository-health/baselines.json: upstream's
  publicPackageVersions (every manifest version is upstream's);
  scripts/repository-health.mjs reports 0 findings.

Test adaptations: Peer.zeroFields.test.ts follows upstream's store contract
(claimMessageNonce/claimInitialRequestNonce, certificatePolicy, upstream error
texts, responder-side authentication before a standalone response);
Peer.certificatePolicy.test.ts expects validateCertificates' explicit
allowZeroFields=false on the standalone path. The bsv-blockchain#520 fixtures
(test/atlas/exact-resume.cjs, real-wpm.cjs) pass chain 'mock' to StorageKnex,
Monitor and Wallet, matching MockServices as upstream's own tests do, because
upstream's Monitor now requires monitor, services and ChainTracks to agree.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant