Skip to content

Verify npm releases after registry processing - #11

Merged
cloneismin merged 2 commits into
mainfrom
codex/sdk-publish-propagation-20261002
Oct 2, 2026
Merged

cloneismin merged 2 commits into
mainfrom
codex/sdk-publish-propagation-20261002

Conversation

@cloneismin

@cloneismin cloneismin commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

npm can accept publication while the version is still being processed. Wait up to five minutes for the exact version before validating an anonymous installation. Add a verification-only input so an already submitted immutable version can be checked without republishing it. Verify imports, registry signatures and attestations, and require the downloaded tarball to match the GitHub release byte for byte.

Scope the failed-telemetry browser assertion to the submitted request. A new suggestion can legitimately add another presentation event after sending; the check still requires presentation, acceptance and submission delivery to fail while host submission succeeds exactly once.

Validation: actionlint passed; generated types unchanged; full local SDK checks passed (90 unit, 6 script, 26 source browser, 52 packaged React 18/19 browser tests and consumer builds). The affected React and assistant-ui case passed 10 repeated checks. An independent anonymous installation of public 0.6.4 passed root/server imports and npm signature/attestation verification; its tarball matches v0.6.4 and its generated example builds.

@cloneismin
cloneismin merged commit 3c95c9d into main Oct 2, 2026
3 checks passed
@cloneismin
cloneismin deleted the codex/sdk-publish-propagation-20261002 branch October 2, 2026 06:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant