Skip to content

chore(release): bump version to v1.29.1 - #910

Merged
qnbs merged 8 commits into
mainfrom
chore/release-v1.29.1
Sep 29, 2026
Merged

qnbs merged 8 commits into
mainfrom
chore/release-v1.29.1

Conversation

@qnbs

@qnbs qnbs commented Sep 29, 2026 •

Copy link
Copy Markdown
Owner

User description

Part of #872.

Why

The signed v1.29.0 tag (e0739537 → cf72dc6d) passed full pre-tag qualification, but its tag-triggered CI/CD failed the enforced OSV scan on the development-only joi 18.2.5 (GHSA-6h2x-m376-mqjq, fixed by #909).

  • The desktop release run was cancelled before its GitHub Release job, so no GitHub Release or desktop assets exist for v1.29.0.
  • GHCR 1.29.0, 1.29 and latest were published. That image contains only the static web build and no joi.

Under the immutable-tag policy (the v1.28.5 → v1.28.6 precedent), the release continues as v1.29.1. The v1.29.0 tag is kept and never moved.

Changes

  • Version 1.29.1 in all five sync authorities: package.json, then sync-tauri-version (Cargo.toml, tauri.conf.json, Cargo.lock) and sync-sw-version (public/sw.js).
  • CHANGELOG:
  • README: Release Candidate badge and marker moved to v1.29.1.
  • AUDIT.md:
  • TODO: current sprint rewritten for v1.29.1; the v1.29.0 block is kept collapsed, with truthful final statuses.
  • Evidence:
    • docs/RELEASE-V1.29.0-EVIDENCE.md records the real outcome: ladder up to TAGGED, gate evidence, the tag-time table (CI/CD failed, Tauri cancelled, Docker published) and the remediation;
    • new docs/RELEASE-V1.29.1-EVIDENCE.md has a ladder, all gates PENDING, and one new gate: Security Audit freshness right before the tag, confirmed at tag time before the desktop release job publishes.

Local checks

  • docs:check passes.
  • Release-notes awk dry run for 1.29.1 gives 901 chars and no guarded phrases.

Summary by Sourcery

Prepare v1.29.1 as the successor release candidate for the tagged but unpublished v1.29.0, including the security remediation and corrected release records.

Bug Fixes:

  • Update the development dependency security posture by upgrading joi and documenting remediation for the advisory that blocked the v1.29.0 tag release.
  • Extend packaged-release qualification to cover upgrades and fresh-install persistence scenarios.

Enhancements:

  • Promote v1.29.1 as the release candidate while preserving the immutable v1.29.0 tag and accurately recording its tag-time outcome.
  • Synchronize the application, desktop packages, service worker, and release-tracking metadata to version 1.29.1.
  • Add v1.29.1 release evidence and update the v1.29.0 evidence to distinguish tagged, container-published, and unpublished desktop-release states.

CI:

  • Add a fresh Security Audit gate immediately before tagging and document procedural protection against publishing when tag-time security checks fail.

Deployment:

  • Document the existing v1.29.0 container publication and plan GHCR 1.29/latest promotion for v1.29.1.

Documentation:

  • Update the changelog, README release-candidate marker, audit, sprint tracking, and release evidence to reflect v1.29.1 and the unpublished desktop v1.29.0 outcome.

Tests:

  • Expand packaged-release qualification with v1.28.8 upgrade and fresh-install save/relaunch checks.

Summary by CodeRabbit

  • Release
    • v1.29.1 succeeds the unpublished v1.29.0 desktop release and includes its changes along with a security fix.
    • v1.29.0 installers and updater assets were not published. Its Docker image remains available.
  • Updates
    • The app version is now v1.29.1. The version change also updates the names used for cached app content.

CodeAnt-AI Description

Prepare v1.29.1 as the successor to the unpublished v1.29.0 release

What Changed

  • Updates the application and desktop package version to 1.29.1, including service-worker cache versioning so previous cached assets are invalidated
  • Adds a v1.29.1 release record and documents the qualification, tagging, publication, and verification gates
  • Records that v1.29.0 was tagged but never published as a desktop release, while its container image remains available
  • Extends the packaged-release checks to cover upgrades from v1.28.8 and fresh-install project saves and reopening
  • Updates the changelog, README, audit, and sprint tracking to identify v1.29.1 as the current release candidate and retain the v1.29.0 outcome

Impact

✅ Correct v1.29.1 version identity across app, desktop, and cached assets
✅ Fewer stale service-worker assets after upgrade
✅ Clearer release status and upgrade guidance

💡 Usage Guide

Checking Your Pull Request

Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.

Talking to CodeAnt AI

Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:

@codeant-ai ask: Your question here

This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.

Example

@codeant-ai ask: Can you suggest a safer alternative to storing this secret?

Preserve Org Learnings with CodeAnt

You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:

@codeant-ai: Your feedback here

This helps CodeAnt AI learn and adapt to your team's coding style and standards.

Example

@codeant-ai: Do not flag unused imports.

Retrigger review

Ask CodeAnt AI to review the PR again, by typing:

@codeant-ai: review

Check Your Repository Health

To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.

v1.29.1 succeeds the signed v1.29.0 tag, whose tag-triggered CI/CD failed the enforced OSV scan on the development-only joi 18.2.5 (fixed by #909); its desktop release was cancelled before publication and the tag stays immutable. Version 1.29.1 in all five sync authorities; CHANGELOG 1.29.1 section with a candidate marker and a never-published note on 1.29.0; README/AUDIT/TODO truth; v1.29.0 outcome recorded and docs/RELEASE-V1.29.1-EVIDENCE.md added.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @qnbs, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 16 hours and 28 minutes by commenting @sourcery-ai review. Upgrade to get a review now.

@codeant-ai

codeant-ai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

🤖 CodeAnt AI — Review Status

Status Commit Started (UTC) Finished (UTC)
✅ Incremental review completed 612e659 Sep 29, 2026 · 23:13 23:13
✅ Reviewed your PR 94a39ea Sep 29, 2026 · 22:54 22:56
✅ Reviewed your PR 2bb1de1 Sep 29, 2026 · 22:30 22:32
✅ Reviewed your PR a68ae13 Sep 29, 2026 · 22:06 22:06
✅ Incremental review completed a68ae13 Sep 29, 2026 · 22:04 22:04

@vercel

vercel Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
worldscript-studio Ready Ready Preview Sep 29, 2026 11:14pm UTC

@codeant-ai

codeant-ai Bot commented Sep 29, 2026

Copy link
Copy Markdown

Thanks for using CodeAnt! 🎉

We're free for open-source projects. if you're enjoying it, help us grow by sharing.

Share on X ·
Reddit ·
LinkedIn

@sourcery-ai

sourcery-ai Bot commented Sep 29, 2026

Copy link
Copy Markdown

Reviewer's Guide

This release-preparation PR promotes v1.29.1 as the immutable successor to the tagged but desktop-unpublished v1.29.0, synchronizes the version across all runtime and desktop authorities, applies the joi security remediation context, and updates changelog, project-status, audit, and release-evidence documentation to distinguish completed v1.29.0 outcomes from pending v1.29.1 qualification and publication gates.

Flow diagram for the v1.29.1 release progression

flowchart LR
    V1290[v1.29.0 tagged] --> OSV[Tag-time OSV scan fails on joi 18.2.5]
    OSV --> Cancel[Desktop release cancelled]
    OSV --> Docker[GHCR 1.29.0 image published]
    Cancel --> Keep[Immutable v1.29.0 tag retained]
    Keep --> V1291[v1.29.1 release candidate]
    V1291 --> Gates[Exact-SHA qualification and fresh Security Audit]
    Gates --> Tag[Signed v1.29.1 tag]
    Tag --> Publish[Desktop release and GHCR tag promotion]
Loading

File-Level Changes

Change Details Files
Bumped the release version consistently across the application, desktop metadata, lockfile, and service-worker cache authorities.
  • Updated package, Cargo, Tauri configuration, Cargo lockfile, and service-worker versions to 1.29.1.
  • Preserved synchronized versioning through the existing release scripts.
package.json
src-tauri/Cargo.toml
src-tauri/tauri.conf.json
src-tauri/Cargo.lock
public/sw.js
Reworked release-facing documentation to accurately represent v1.29.1 as the desktop successor to the tagged but unpublished v1.29.0.
  • Added the v1.29.1 release-candidate changelog section and moved the joi remediation entry into it.
  • Documented v1.29.0 as immutable, tagged, and never published as a desktop release, while retaining its Docker image history.
  • Moved the README release-candidate marker and badge to v1.29.1.
  • Updated the current sprint and preserved the v1.29.0 work record in a collapsed section.
  • Updated AUDIT.md with the v1.29.1 candidate state and a pointer from the historical joi note to current overrides.
CHANGELOG.md
README.md
TODO.md
AUDIT.md
Converted the v1.29.0 evidence record from a pre-release plan into an outcome record and established a pending evidence plan for v1.29.1.
  • Recorded v1.29.0's completed pre-tag gates, signed tag, failed tag-time OSV scan, cancelled desktop publication, and successful Docker publication.
  • Added the v1.29.1 state ladder and exact-SHA pre-tag gates, including a fresh Security Audit check before tagging and before desktop publication.
  • Documented pending post-tag checks for release assets, updater metadata, signatures, and GHCR tag movement.
docs/RELEASE-V1.29.0-EVIDENCE.md
docs/RELEASE-V1.29.1-EVIDENCE.md

Possibly linked issues


Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@codeant-ai codeant-ai Bot added the size:L This PR changes 100-499 lines, ignoring generated files label Sep 29, 2026
@codeant-ai

codeant-ai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

🏁 CodeAnt Quality Gate Results

Commit: 612e6592
Scan Time: 2026-09-29 23:40:50 UTC

✅ Overall Status: PASSED

Quality Gate Details

Quality Gate Status Details
Secrets ✅ PASSED 0 secrets found
Duplicate Code ✅ PASSED 0.0% duplicated
SAST ✅ PASSED No security issues
Bugs ✅ PASSED Rating S: No bugs
IAC ✅ PASSED Rating S: No issues

View Full Results

codescene-access[bot]

This comment was marked as outdated.

@github-actions

github-actions Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

[check-pr-size] PR size is over the target tier (normal profile): 12 files, 274 meaningful lines, 8 commits — limit ≤8 files / ≤400 lines / ≤6 commits. Consider splitting into smaller, independently reviewable PRs.

@codeant-ai

codeant-ai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

CodeAnt Nitpicks

No threshold-suppressed suggestions found in the latest review.

@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

Next included review available in 16 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available. Your 91 included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml

Review profile: CHILL

Plan: Essentials

Run ID: 948a0cb2-2fa9-468b-9b31-78072eca599b

📥 Commits

Reviewing files that changed from the base of the PR and between 2bb1de1 and 612e659.

📒 Files selected for processing (3)
  • TODO.md
  • docs/RELEASE-V1.29.0-PACKAGED-QUALIFICATION.md
  • docs/RELEASE-V1.29.1-EVIDENCE.md
📝 Walkthrough

Walkthrough

The PR records the failed v1.29.0 desktop release and the published Docker image. It documents v1.29.1 release gates and updates release notes, candidate references, and application version identifiers.

Changes

Release candidate

Layer / File(s) Summary
Record v1.29.0 release outcome
AUDIT.md, CHANGELOG.md, TODO.md, docs/RELEASE-V1.29.0-EVIDENCE.md
The records state that the tag-triggered OSV scan failed on development-only joi 18.2.5, desktop publication was cancelled, and the Docker image was published. They record the completed pre-tag checks and the v1.29.0 tag outcome.
Define v1.29.1 candidate gates
TODO.md, docs/RELEASE-V1.29.0-PACKAGED-QUALIFICATION.md, docs/RELEASE-V1.29.1-EVIDENCE.md
The candidate records list release states, exact-candidate qualification gates, packaged upgrade and fresh-install checks, post-tag evidence, and carried-forward limitations.
Update v1.29.1 release identifiers
CHANGELOG.md, README.md, package.json, public/sw.js, src-tauri/Cargo.toml, src-tauri/tauri.conf.json
The release notes and candidate badge identify v1.29.1. Package and application versions change to v1.29.1, which also changes the service worker cache-name version.

Priority: ➖ Normal

Merge Risk: 🔵 Low · up to 2bb1d

The reused qualification protocol leaves two possible destinations for v1.29.1 results, which could split the release evidence. Clarify that the older destination applies only to the original v1.29.0 run.


Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f62d6eb4d4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/RELEASE-V1.29.1-EVIDENCE.md Outdated
Comment thread CHANGELOG.md Outdated
Comment thread CHANGELOG.md Outdated
@codecov

codecov Bot commented Sep 29, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ All tests successful. No failed tests found.

📢 Thoughts on this report? Let us know!

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1


ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml

Review profile: CHILL

Plan: Essentials

Run ID: a0ad5273-1256-4271-92a8-1d603af58384

📥 Commits

Reviewing files that changed from the base of the PR and between 71f4a4a and 625357d.

⛔ Files ignored due to path filters (1)
  • src-tauri/Cargo.lock is excluded by !**/*.lock
📒 Files selected for processing (10)
  • AUDIT.md
  • CHANGELOG.md
  • README.md
  • TODO.md
  • docs/RELEASE-V1.29.0-EVIDENCE.md
  • docs/RELEASE-V1.29.1-EVIDENCE.md
  • package.json
  • public/sw.js
  • src-tauri/Cargo.toml
  • src-tauri/tauri.conf.json

Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

Comment thread docs/RELEASE-V1.29.1-EVIDENCE.md Outdated
…the v1.29.1 note tense-neutral (PR #910)

The release job still needs only bundle, and docker.yml publishes independently, so the tag-time Security Audit confirmation is a watched, procedural fail-closed step, not a pipeline guarantee; mechanical enforcement is tracked in #911. The 1.29.1 lead bullet no longer calls itself published before the tag exists.
codescene-access[bot]

This comment was marked as outdated.

@qnbs

qnbs commented Sep 29, 2026

Copy link
Copy Markdown
Owner Author

CodeAnt nitpicks on f62d6eb4:

  1. Published claim in a candidate section: valid, fixed in 9d35d10b with tense-neutral wording.
  2. PR #TBD: fixed in 625357d0; the line reads PR #910.

Codex P1 and CodeRabbit Major (tag-time audit guard): the record is corrected to describe a procedural guard, and mechanical enforcement is tracked in #911. All 4 threads are replied to and resolved.

@qnbs

qnbs commented Sep 29, 2026

Copy link
Copy Markdown
Owner Author

@CodeAnt-AI review

Comment thread docs/RELEASE-V1.29.1-EVIDENCE.md Outdated
Comment thread docs/RELEASE-V1.29.1-EVIDENCE.md
….1 record (PR #910)

The protocol named only the v1.29.0 candidate and evidence record; it now states that it applies unchanged to the exact v1.29.1 candidate, with results recorded in docs/RELEASE-V1.29.1-EVIDENCE.md.
@qnbs

qnbs commented Sep 29, 2026

Copy link
Copy Markdown
Owner Author

@CodeAnt-AI review

codescene-access[bot]

This comment was marked as outdated.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: fbf3be60cd

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread CHANGELOG.md Outdated
Comment thread docs/RELEASE-V1.29.0-EVIDENCE.md
Comment thread docs/RELEASE-V1.29.1-EVIDENCE.md Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a68ae13b5b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/RELEASE-V1.29.0-PACKAGED-QUALIFICATION.md
Comment thread docs/RELEASE-V1.29.1-EVIDENCE.md Outdated
… a reopen check to protocol E (PR #910)

The release workflow publishes only the 1.29.1 section, so it now lists the main changes since v1.28.8 next to the link to the full 1.29.0 section. Protocol E gains a quit-and-relaunch step on the fresh project, and the v1.29.1 limitations heading no longer says 'shipped' before the release exists.
@qnbs

qnbs commented Sep 29, 2026

Copy link
Copy Markdown
Owner Author

CodeAnt nitpick on a68ae13b (race: cancellation is manual and both workflows run independently of the audit): this is correct and already recorded. The v1.29.1 evidence record states the guard as procedural, and mechanical enforcement for the Tauri release job and the Docker push is tracked in #911. All review threads in this wave are replied to and resolved (2bb1de18).

@qnbs

qnbs commented Sep 29, 2026

Copy link
Copy Markdown
Owner Author

@CodeAnt-AI review

codescene-access[bot]

This comment was marked as outdated.

Comment thread docs/RELEASE-V1.29.1-EVIDENCE.md

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 2bb1de1809

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/RELEASE-V1.29.0-PACKAGED-QUALIFICATION.md

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1


ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml

Review profile: CHILL

Plan: Essentials

Run ID: 5ff7c955-cd9c-4e45-b843-411c98de8ca4

📥 Commits

Reviewing files that changed from the base of the PR and between 625357d and 2bb1de1.

📒 Files selected for processing (4)
  • CHANGELOG.md
  • docs/RELEASE-V1.29.0-EVIDENCE.md
  • docs/RELEASE-V1.29.0-PACKAGED-QUALIFICATION.md
  • docs/RELEASE-V1.29.1-EVIDENCE.md
🚧 Files skipped from review as they are similar to previous changes (2)
  • CHANGELOG.md
  • docs/RELEASE-V1.29.0-EVIDENCE.md

Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

Comment thread docs/RELEASE-V1.29.0-PACKAGED-QUALIFICATION.md
…ject in protocol E (PR #910)

Step 1 now edits, saves, quits and relaunches the upgraded project, so a regression on existing carriers cannot pass behind an opening-only check; the protocol's original results line is scoped to the v1.29.0 run.
@qnbs

qnbs commented Sep 29, 2026

Copy link
Copy Markdown
Owner Author

@CodeAnt-AI review

codescene-access[bot]

This comment was marked as outdated.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 94a39ea5f6

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/RELEASE-V1.29.1-EVIDENCE.md Outdated
…29.1 tag (PR #910)

Re-reading an earlier green scan does not query the current OSV database, which is the v1.29.0 failure mode. The freshness gate now requires a new execution of the Security Audit on the exact frozen candidate right before the tag, with its run identity recorded and a green result required for RELEASE_READY; the TODO no longer implies that the tag-time audit is mechanically enforced (#911).
@qnbs

qnbs commented Sep 29, 2026

Copy link
Copy Markdown
Owner Author

Review convergence ledger (final correction wave 612e6592)

The whole thread set (17 threads, all resolved) and all review comments were re-read against the current head. From here on, #910 is in convergence mode: only release-blocking findings change source.

# Finding Reviewer Sev. Classification Action / evidence Owner Status
1 Fresh OSV execution before tag ("re-check" allowed a stale result) Codex P2 MUST_FIX_NOW_RELEASE_BLOCKER Newly executed Security Audit on the frozen candidate, run identity recorded, green required #910 / #872 FIXED 612e6592
2 Tag-time audit not a publish dependency (Tauri release, Docker push) Codex P1, CodeRabbit Major, CodeAnt ×3 P1 VALID_DEFERRED_WITH_OWNER Record states the guard as procedural; changing the release pipeline is out of scope for the cut. V1_29_1_BLOCKER=NO (watched, cancel if red) #911 / QNB-162 DEFERRED, resume after v1.29.1 VERIFIED
3 TODO implied a mechanical tag-time guarantee self (§10 re-read) – MUST_FIX_NOW_BOUNDED Reworded to procedural + #911 #910 FIXED 612e6592
4 Release notes = only the 1.29.1 section CodeAnt Major MUST_FIX_NOW_BOUNDED Highlights since v1.28.8 + absolute link; awk dry run 1,514 chars, guards clean #910 FIXED 2bb1de18
5 Protocol E: fresh install without reopen; upgrade profile without write/reopen Codex ×2 P2 MUST_FIX_NOW_RELEASE_BLOCKER (#907 class) E1: open, edit, save, quit, reopen on v1.28.8; E2/E3: create, save, quit, reopen, same identity #910 FIXED 2bb1de18, 94a39ea5
6 Protocol results routed to the wrong record CodeAnt, CodeRabbit Major/Minor MUST_FIX_NOW_BOUNDED Reuse note plus scoped v1.29.0 line #910 FIXED fbf3be60, 94a39ea5
7 Candidate tense ("published", "shipped") Codex ×3, CodeAnt P2 MUST_FIX_NOW_BOUNDED Prospective wording in CHANGELOG and evidence #910 FIXED 9d35d10b, a68ae13b, 2bb1de18
8 v1.29.0 TAG_ONLY_PENDING inconsistent with the outcome Codex P2 MUST_FIX_NOW_BOUNDED Per-item outcome recorded #910 FIXED a68ae13b
9 PR #TBD in release notes Codex, CodeAnt P2 ALREADY_FIXED Was PR #910 since 625357d0 – FIXED
10 Docker does not push :latest on tags CodeAnt Major INVALID_FALSE_POSITIVE Run 36618279810 logged a :latest manifest; metadata-action flavor latest=auto for semver – CLOSED with evidence
11 AUDIT.md version line not covered by docs:check CodeAnt Major → minor VALID_MINOR_DEFERRED Real future-staleness risk; governed checker, not release truth #877 (context recorded) DEFERRED, not a blocker
12 #909 carry-over: v1.24.0 joi note vs current range CodeAnt nit MUST_FIX_NOW_BOUNDED Neutral forward pointer #910 FIXED f62d6eb4

Invariants re-checked on 612e6592:

  • v1.29.1 prospective tense;
  • v1.29.0 terminal outcome, with GHCR partially published and no "nothing published" claim;
  • results routed to the right records;
  • protocol E upgrade and fresh-install write/reopen;
  • A/B refused-byte preservation and C migration + reopen unchanged;
  • procedural-only tag-time wording;
  • five version authorities = 1.29.1;
  • docs:check ✅.

No manual review re-triggers from here on.

@codescene-access codescene-access Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gates Passed
3 Quality Gates Passed

See analysis details in CodeScene

Quality Gate Profile: The Bare Minimum
Install CodeScene MCP: safeguard and uplift AI-generated code. Catch issues early with our IDE extension and CLI tool.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 612e6592ef

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/RELEASE-V1.29.1-EVIDENCE.md
@qnbs

qnbs commented Sep 29, 2026

Copy link
Copy Markdown
Owner Author

Ledger addendum (passive Codex review of 612e6592):

# Finding Reviewer Sev. Classification Action Owner Status
13 Freshness rerun: record the run ID + attempt + job databaseId, not a "new run ID" Codex P2 VALID_MINOR_DEFERRED Executed with those identifiers; the row wording is fixed in the truth sync v1.29.1 truth-sync PR / #872 DEFERRED, not a blocker

Exact head 612e6592 state: all 32 checks pass, CI/CD ✅, CodeQL ✅, rollup SUCCESS, all 18 threads resolved. The merge criteria are met.

@qnbs
qnbs merged commit 99a664c into main Sep 29, 2026
43 checks passed
@qnbs
qnbs deleted the chore/release-v1.29.1 branch September 29, 2026 23:41
qnbs added a commit that referenced this pull request Oct 10, 2026
…the v1.29.1 note tense-neutral (PR #910)

The release job still needs only bundle, and docker.yml publishes independently, so the tag-time Security Audit confirmation is a watched, procedural fail-closed step, not a pipeline guarantee; mechanical enforcement is tracked in #911. The 1.29.1 lead bullet no longer calls itself published before the tag exists.
qnbs added a commit that referenced this pull request Oct 10, 2026
….1 record (PR #910)

The protocol named only the v1.29.0 candidate and evidence record; it now states that it applies unchanged to the exact v1.29.1 candidate, with results recorded in docs/RELEASE-V1.29.1-EVIDENCE.md.
qnbs added a commit that referenced this pull request Oct 10, 2026
…eep v1.29.1 prospective (PR #910)

The packaged protocol gains step E (unmodified v1.28.8 upgrade and fresh-install save, the checks that caught P0 #907), which the v1.29.1 gate row now names; the v1.29.0 TAG_ONLY_PENDING list records each item's real outcome at the tag; the 1.29.0 CHANGELOG note says the changes are to be released as v1.29.1.
qnbs added a commit that referenced this pull request Oct 10, 2026
… a reopen check to protocol E (PR #910)

The release workflow publishes only the 1.29.1 section, so it now lists the main changes since v1.28.8 next to the link to the full 1.29.0 section. Protocol E gains a quit-and-relaunch step on the fresh project, and the v1.29.1 limitations heading no longer says 'shipped' before the release exists.
qnbs added a commit that referenced this pull request Oct 10, 2026
…ject in protocol E (PR #910)

Step 1 now edits, saves, quits and relaunches the upgraded project, so a regression on existing carriers cannot pass behind an opening-only check; the protocol's original results line is scoped to the v1.29.0 run.
qnbs added a commit that referenced this pull request Oct 10, 2026
…29.1 tag (PR #910)

Re-reading an earlier green scan does not query the current OSV database, which is the v1.29.0 failure mode. The freshness gate now requires a new execution of the Security Audit on the exact frozen candidate right before the tag, with its run identity recorded and a green result required for RELEASE_READY; the TODO no longer implies that the tag-time audit is mechanically enforced (#911).
qnbs added a commit that referenced this pull request Oct 10, 2026
chore(release): bump version to v1.29.1
qnbs added a commit that referenced this pull request Oct 10, 2026
v1.29.1 is published from f255d76: README badge and CHANGELOG lose the candidate marker (and the #912 pointer bullet), AUDIT and TODO state the released truth, and the v1.29.1 evidence record carries the real ladder, gate results, the freshness executions (including the one that stopped 99a664c) and the rerun-attempt wording deferred from #910.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L This PR changes 100-499 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant