Repository navigation
chore(release): bump version to v1.29.1 - #910
Conversation
v1.29.1 succeeds the signed v1.29.0 tag, whose tag-triggered CI/CD failed the enforced OSV scan on the development-only joi 18.2.5 (fixed by #909); its desktop release was cancelled before publication and the tag stays immutable. Version 1.29.1 in all five sync authorities; CHANGELOG 1.29.1 section with a candidate marker and a never-published note on 1.29.0; README/AUDIT/TODO truth; v1.29.0 outcome recorded and docs/RELEASE-V1.29.1-EVIDENCE.md added.
🤖 CodeAnt AI — Review Status
|
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Thanks for using CodeAnt! 🎉We're free for open-source projects. if you're enjoying it, help us grow by sharing. Share on X · |
Reviewer's GuideThis release-preparation PR promotes v1.29.1 as the immutable successor to the tagged but desktop-unpublished v1.29.0, synchronizes the version across all runtime and desktop authorities, applies the joi security remediation context, and updates changelog, project-status, audit, and release-evidence documentation to distinguish completed v1.29.0 outcomes from pending v1.29.1 qualification and publication gates. Flow diagram for the v1.29.1 release progressionflowchart LR
V1290[v1.29.0 tagged] --> OSV[Tag-time OSV scan fails on joi 18.2.5]
OSV --> Cancel[Desktop release cancelled]
OSV --> Docker[GHCR 1.29.0 image published]
Cancel --> Keep[Immutable v1.29.0 tag retained]
Keep --> V1291[v1.29.1 release candidate]
V1291 --> Gates[Exact-SHA qualification and fresh Security Audit]
Gates --> Tag[Signed v1.29.1 tag]
Tag --> Publish[Desktop release and GHCR tag promotion]
File-Level Changes
Possibly linked issues
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
🏁 CodeAnt Quality Gate ResultsCommit: ✅ Overall Status: PASSEDQuality Gate Details
|
|
[check-pr-size] PR size is over the target tier (normal profile): 12 files, 274 meaningful lines, 8 commits — limit ≤8 files / ≤400 lines / ≤6 commits. Consider splitting into smaller, independently reviewable PRs. |
CodeAnt NitpicksNo threshold-suppressed suggestions found in the latest review. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Warning Review limit reachedNext included review available in 16 minutes. View limit detailsLimit details: You’ve used the included review currently available. Your 91 included PR review attempts over the past 7 days set your current allowance at 1 review per hour. Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. Review configuration: ⚙️ Run configurationConfiguration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml Review profile: CHILL Plan: Essentials Run ID: 📒 Files selected for processing (3)
📝 WalkthroughWalkthroughThe PR records the failed v1.29.0 desktop release and the published Docker image. It documents v1.29.1 release gates and updates release notes, candidate references, and application version identifiers. ChangesRelease candidate
Priority: ➖ Normal Merge Risk: 🔵 Low · up to The reused qualification protocol leaves two possible destinations for v1.29.1 results, which could split the release evidence. Clarify that the older destination applies only to the original v1.29.0 run. Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f62d6eb4d4
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
There was a problem hiding this comment.
Actionable comments posted: 1
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml
Review profile: CHILL
Plan: Essentials
Run ID: a0ad5273-1256-4271-92a8-1d603af58384
⛔ Files ignored due to path filters (1)
src-tauri/Cargo.lockis excluded by!**/*.lock
📒 Files selected for processing (10)
AUDIT.mdCHANGELOG.mdREADME.mdTODO.mddocs/RELEASE-V1.29.0-EVIDENCE.mddocs/RELEASE-V1.29.1-EVIDENCE.mdpackage.jsonpublic/sw.jssrc-tauri/Cargo.tomlsrc-tauri/tauri.conf.json
Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour.
…the v1.29.1 note tense-neutral (PR #910) The release job still needs only bundle, and docker.yml publishes independently, so the tag-time Security Audit confirmation is a watched, procedural fail-closed step, not a pipeline guarantee; mechanical enforcement is tracked in #911. The 1.29.1 lead bullet no longer calls itself published before the tag exists.
|
CodeAnt nitpicks on
Codex P1 and CodeRabbit Major (tag-time audit guard): the record is corrected to describe a procedural guard, and mechanical enforcement is tracked in #911. All 4 threads are replied to and resolved. |
|
@CodeAnt-AI review |
….1 record (PR #910) The protocol named only the v1.29.0 candidate and evidence record; it now states that it applies unchanged to the exact v1.29.1 candidate, with results recorded in docs/RELEASE-V1.29.1-EVIDENCE.md.
|
@CodeAnt-AI review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: fbf3be60cd
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a68ae13b5b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
… a reopen check to protocol E (PR #910) The release workflow publishes only the 1.29.1 section, so it now lists the main changes since v1.28.8 next to the link to the full 1.29.0 section. Protocol E gains a quit-and-relaunch step on the fresh project, and the v1.29.1 limitations heading no longer says 'shipped' before the release exists.
|
CodeAnt nitpick on |
|
@CodeAnt-AI review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2bb1de1809
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
Actionable comments posted: 1
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml
Review profile: CHILL
Plan: Essentials
Run ID: 5ff7c955-cd9c-4e45-b843-411c98de8ca4
📒 Files selected for processing (4)
CHANGELOG.mddocs/RELEASE-V1.29.0-EVIDENCE.mddocs/RELEASE-V1.29.0-PACKAGED-QUALIFICATION.mddocs/RELEASE-V1.29.1-EVIDENCE.md
🚧 Files skipped from review as they are similar to previous changes (2)
- CHANGELOG.md
- docs/RELEASE-V1.29.0-EVIDENCE.md
Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour.
…ject in protocol E (PR #910) Step 1 now edits, saves, quits and relaunches the upgraded project, so a regression on existing carriers cannot pass behind an opening-only check; the protocol's original results line is scoped to the v1.29.0 run.
|
@CodeAnt-AI review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 94a39ea5f6
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…29.1 tag (PR #910) Re-reading an earlier green scan does not query the current OSV database, which is the v1.29.0 failure mode. The freshness gate now requires a new execution of the Security Audit on the exact frozen candidate right before the tag, with its run identity recorded and a green result required for RELEASE_READY; the TODO no longer implies that the tag-time audit is mechanically enforced (#911).
Review convergence ledger (final correction wave
|
| # | Finding | Reviewer | Sev. | Classification | Action / evidence | Owner | Status |
|---|---|---|---|---|---|---|---|
| 1 | Fresh OSV execution before tag ("re-check" allowed a stale result) | Codex | P2 | MUST_FIX_NOW_RELEASE_BLOCKER | Newly executed Security Audit on the frozen candidate, run identity recorded, green required | #910 / #872 | FIXED 612e6592 |
| 2 | Tag-time audit not a publish dependency (Tauri release, Docker push) |
Codex P1, CodeRabbit Major, CodeAnt ×3 | P1 | VALID_DEFERRED_WITH_OWNER | Record states the guard as procedural; changing the release pipeline is out of scope for the cut. V1_29_1_BLOCKER=NO (watched, cancel if red) | #911 / QNB-162 | DEFERRED, resume after v1.29.1 VERIFIED |
| 3 | TODO implied a mechanical tag-time guarantee | self (§10 re-read) | – | MUST_FIX_NOW_BOUNDED | Reworded to procedural + #911 | #910 | FIXED 612e6592 |
| 4 | Release notes = only the 1.29.1 section | CodeAnt | Major | MUST_FIX_NOW_BOUNDED | Highlights since v1.28.8 + absolute link; awk dry run 1,514 chars, guards clean |
#910 | FIXED 2bb1de18 |
| 5 | Protocol E: fresh install without reopen; upgrade profile without write/reopen | Codex ×2 | P2 | MUST_FIX_NOW_RELEASE_BLOCKER (#907 class) | E1: open, edit, save, quit, reopen on v1.28.8; E2/E3: create, save, quit, reopen, same identity | #910 | FIXED 2bb1de18, 94a39ea5 |
| 6 | Protocol results routed to the wrong record | CodeAnt, CodeRabbit | Major/Minor | MUST_FIX_NOW_BOUNDED | Reuse note plus scoped v1.29.0 line | #910 | FIXED fbf3be60, 94a39ea5 |
| 7 | Candidate tense ("published", "shipped") | Codex ×3, CodeAnt | P2 | MUST_FIX_NOW_BOUNDED | Prospective wording in CHANGELOG and evidence | #910 | FIXED 9d35d10b, a68ae13b, 2bb1de18 |
| 8 | v1.29.0 TAG_ONLY_PENDING inconsistent with the outcome |
Codex | P2 | MUST_FIX_NOW_BOUNDED | Per-item outcome recorded | #910 | FIXED a68ae13b |
| 9 | PR #TBD in release notes |
Codex, CodeAnt | P2 | ALREADY_FIXED | Was PR #910 since 625357d0 |
– | FIXED |
| 10 | Docker does not push :latest on tags |
CodeAnt | Major | INVALID_FALSE_POSITIVE | Run 36618279810 logged a :latest manifest; metadata-action flavor latest=auto for semver |
– | CLOSED with evidence |
| 11 | AUDIT.md version line not covered by docs:check |
CodeAnt | Major → minor | VALID_MINOR_DEFERRED | Real future-staleness risk; governed checker, not release truth | #877 (context recorded) | DEFERRED, not a blocker |
| 12 | #909 carry-over: v1.24.0 joi note vs current range |
CodeAnt | nit | MUST_FIX_NOW_BOUNDED | Neutral forward pointer | #910 | FIXED f62d6eb4 |
Invariants re-checked on 612e6592:
- v1.29.1 prospective tense;
- v1.29.0 terminal outcome, with GHCR partially published and no "nothing published" claim;
- results routed to the right records;
- protocol E upgrade and fresh-install write/reopen;
- A/B refused-byte preservation and C migration + reopen unchanged;
- procedural-only tag-time wording;
- five version authorities = 1.29.1;
docs:check✅.
No manual review re-triggers from here on.
There was a problem hiding this comment.
Gates Passed
3 Quality Gates Passed
See analysis details in CodeScene
Quality Gate Profile: The Bare Minimum
Install CodeScene MCP: safeguard and uplift AI-generated code. Catch issues early with our IDE extension and CLI tool.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 612e6592ef
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Ledger addendum (passive Codex review of
Exact head |
…the v1.29.1 note tense-neutral (PR #910) The release job still needs only bundle, and docker.yml publishes independently, so the tag-time Security Audit confirmation is a watched, procedural fail-closed step, not a pipeline guarantee; mechanical enforcement is tracked in #911. The 1.29.1 lead bullet no longer calls itself published before the tag exists.
….1 record (PR #910) The protocol named only the v1.29.0 candidate and evidence record; it now states that it applies unchanged to the exact v1.29.1 candidate, with results recorded in docs/RELEASE-V1.29.1-EVIDENCE.md.
…eep v1.29.1 prospective (PR #910) The packaged protocol gains step E (unmodified v1.28.8 upgrade and fresh-install save, the checks that caught P0 #907), which the v1.29.1 gate row now names; the v1.29.0 TAG_ONLY_PENDING list records each item's real outcome at the tag; the 1.29.0 CHANGELOG note says the changes are to be released as v1.29.1.
… a reopen check to protocol E (PR #910) The release workflow publishes only the 1.29.1 section, so it now lists the main changes since v1.28.8 next to the link to the full 1.29.0 section. Protocol E gains a quit-and-relaunch step on the fresh project, and the v1.29.1 limitations heading no longer says 'shipped' before the release exists.
…ject in protocol E (PR #910) Step 1 now edits, saves, quits and relaunches the upgraded project, so a regression on existing carriers cannot pass behind an opening-only check; the protocol's original results line is scoped to the v1.29.0 run.
…29.1 tag (PR #910) Re-reading an earlier green scan does not query the current OSV database, which is the v1.29.0 failure mode. The freshness gate now requires a new execution of the Security Audit on the exact frozen candidate right before the tag, with its run identity recorded and a green result required for RELEASE_READY; the TODO no longer implies that the tag-time audit is mechanically enforced (#911).
chore(release): bump version to v1.29.1
v1.29.1 is published from f255d76: README badge and CHANGELOG lose the candidate marker (and the #912 pointer bullet), AUDIT and TODO state the released truth, and the v1.29.1 evidence record carries the real ladder, gate results, the freshness executions (including the one that stopped 99a664c) and the rerun-attempt wording deferred from #910.
User description
Part of #872.
Why
The signed
v1.29.0tag (e0739537→cf72dc6d) passed full pre-tag qualification, but its tag-triggered CI/CD failed the enforced OSV scan on the development-onlyjoi18.2.5 (GHSA-6h2x-m376-mqjq, fixed by #909).GitHub Releasejob, so no GitHub Release or desktop assets exist for v1.29.0.1.29.0,1.29andlatestwere published. That image contains only the static web build and nojoi.Under the immutable-tag policy (the v1.28.5 → v1.28.6 precedent), the release continues as v1.29.1. The
v1.29.0tag is kept and never moved.Changes
package.json, thensync-tauri-version(Cargo.toml, tauri.conf.json, Cargo.lock) andsync-sw-version(public/sw.js).[1.29.1]section with<!-- release-candidate: v1.29.1 -->;[1.29.0]section, with an absolute tag link;[Unreleased];[1.29.0]: the candidate marker is removed (the tag now exists), and a "never published as a desktop release" note is added, modeled on[1.28.5];[Unreleased].joinote keeps its wording and gains a neutral forward pointer to the Known Overrides table.docs/RELEASE-V1.29.0-EVIDENCE.mdrecords the real outcome: ladder up toTAGGED, gate evidence, the tag-time table (CI/CD failed, Tauri cancelled, Docker published) and the remediation;docs/RELEASE-V1.29.1-EVIDENCE.mdhas a ladder, all gatesPENDING, and one new gate: Security Audit freshness right before the tag, confirmed at tag time before the desktop release job publishes.Local checks
docs:checkpasses.awkdry run for1.29.1gives 901 chars and no guarded phrases.Summary by Sourcery
Prepare v1.29.1 as the successor release candidate for the tagged but unpublished v1.29.0, including the security remediation and corrected release records.
Bug Fixes:
Enhancements:
CI:
Deployment:
Documentation:
Tests:
Summary by CodeRabbit
CodeAnt-AI Description
Prepare v1.29.1 as the successor to the unpublished v1.29.0 release
What Changed
Impact
✅ Correct v1.29.1 version identity across app, desktop, and cached assets✅ Fewer stale service-worker assets after upgrade✅ Clearer release status and upgrade guidance💡 Usage Guide
Checking Your Pull Request
Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.
Talking to CodeAnt AI
Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:
This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.
Example
Preserve Org Learnings with CodeAnt
You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:
This helps CodeAnt AI learn and adapt to your team's coding style and standards.
Example
Retrigger review
Ask CodeAnt AI to review the PR again, by typing:
Check Your Repository Health
To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.