feat(release): committed toolchain manifest — npm ci replaces ad-hoc installs #135

Merged
ryangr0 merged 1 commit from ryangr0/release-toolchain-manifest into main 2026-08-28 19:49:53 +00:00 AGit
Owner

Root package.json + package-lock.json pin the entire release toolchain
(semantic-release 25.0.9, @webgrip/semantic-release-config 1.2.3,
semantic-release-monorepo 8.0.2, preset 10.4.0) with the overrides block
mirroring the config's own verbatim — the npm-sanctioned mechanism for
forcing the PR #10 notes pair (generator 15.0.0-beta.2 / analyzer
14.0.0-beta.3) that no install argument can express: both betas sit outside
semantic-release's ^14/^13 ranges, so any manifest-less install nests stable
copies under semantic-release, whose plugin loader (own dir before cwd)
loads them — measured across runs 426-435.

The composite's install step becomes npm ci at the repo root
(semantic-release-monorepo's documented root-install mode for monorepos),
plus a loud post-install assertion (no nested generator, pair >=15/>=10)
because this failure mode renders EMPTY notes silently. npx replaced with
the explicit bin path so a missing install can never fall back to a
registry fetch. config-version input is now vestigial; the npm cache keys
on the lockfile hash.

Verified locally against the real tree: overrides applied (single copies,
betas resolved), and ops/docker/agent-runner/.releaserc.cjs loads from its
own directory through the root tree with the config's load-time pairing
guard passing.

Supersedes PR #133 (the scratch-prefix bridge) per Ryan's direct call:
same intent — honour PR #10's design — expressed as committed state
instead of install-time reconstruction.

Co-Authored-By: Claude Fable 5 noreply@anthropic.com

Root package.json + package-lock.json pin the entire release toolchain (semantic-release 25.0.9, @webgrip/semantic-release-config 1.2.3, semantic-release-monorepo 8.0.2, preset 10.4.0) with the overrides block mirroring the config's own verbatim — the npm-sanctioned mechanism for forcing the PR #10 notes pair (generator 15.0.0-beta.2 / analyzer 14.0.0-beta.3) that no install argument can express: both betas sit outside semantic-release's ^14/^13 ranges, so any manifest-less install nests stable copies under semantic-release, whose plugin loader (own dir before cwd) loads them — measured across runs 426-435. The composite's install step becomes `npm ci` at the repo root (semantic-release-monorepo's documented root-install mode for monorepos), plus a loud post-install assertion (no nested generator, pair >=15/>=10) because this failure mode renders EMPTY notes silently. npx replaced with the explicit bin path so a missing install can never fall back to a registry fetch. config-version input is now vestigial; the npm cache keys on the lockfile hash. Verified locally against the real tree: overrides applied (single copies, betas resolved), and ops/docker/agent-runner/.releaserc.cjs loads from its own directory through the root tree with the config's load-time pairing guard passing. Supersedes PR #133 (the scratch-prefix bridge) per Ryan's direct call: same intent — honour PR #10's design — expressed as committed state instead of install-time reconstruction. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Root package.json + package-lock.json pin the entire release toolchain
(semantic-release 25.0.9, @webgrip/semantic-release-config 1.2.3,
semantic-release-monorepo 8.0.2, preset 10.4.0) with the overrides block
mirroring the config's own verbatim — the npm-sanctioned mechanism for
forcing the PR #10 notes pair (generator 15.0.0-beta.2 / analyzer
14.0.0-beta.3) that no install argument can express: both betas sit outside
semantic-release's ^14/^13 ranges, so any manifest-less install nests stable
copies under semantic-release, whose plugin loader (own dir before cwd)
loads them — measured across runs 426-435.

The composite's install step becomes `npm ci` at the repo root
(semantic-release-monorepo's documented root-install mode for monorepos),
plus a loud post-install assertion (no nested generator, pair >=15/>=10)
because this failure mode renders EMPTY notes silently. npx replaced with
the explicit bin path so a missing install can never fall back to a
registry fetch. config-version input is now vestigial; the npm cache keys
on the lockfile hash.

Verified locally against the real tree: overrides applied (single copies,
betas resolved), and ops/docker/agent-runner/.releaserc.cjs loads from its
own directory through the root tree with the config's load-time pairing
guard passing.

Supersedes PR #133 (the scratch-prefix bridge) per Ryan's direct call:
same intent — honour PR #10's design — expressed as committed state
instead of install-time reconstruction.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
webgrip/infrastructure!135
No description provided.