fix(release): record release floors and refuse versions at or below them #197
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "ryangr0/release-floors-and-identity"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Refs VIK-1794 (handoff OPS-04, milestone M4 release stream).
What
A read-only audit of every Ploeg and Vloer release destination after the 2026-10-03 history rewrite and the move to
webgrip/unfold, plus the repository changes it calls for. The record isdocs/research/2026-10-03-release-floors-and-identity.mdwith the full inventory in the.jsonnext to it.Findings
0.4.0-rc.34is taken somewhere. Ploeg's withdrawn1.0.0-rc.1is still published (Go proxy, GHCRploegdandcharts/ploeg, Forgejoploegd). ADR-0018's proposed0.5.0-rc.1for both trains is above every floor.github.com/webgrip/ploeg: 66 proxy versions. 35 match the checksum database from the origin. 14 stop:v0.3.0-rc.5and everyv0.4.0-rc.*export now serve different bytes from GitHub (a direct download fails with SECURITY ERROR; the changes are.mailmap, test files, OpenSpec docs and one research note, no non-test Go source). 17 exist only in the proxy.@latestisv0.2.0.webgrip/unfoldare canonical, tags and branches are identical, and the rc.34 signing job's OIDC claim wasrepository: webgrip/unfold. The release preflight would have stopped at the deletedwebgrip/ploeg/webgrip/de-vloer, and the published extension still links to the deletedwebgrip/de-vloer.Changes
docs(release): the audit record, a dated note on ADR-0018 (highest Go version isv0.4.0-rc.32, not rc.34), and the cutover playbook's dead GitHub link and signing row.fix(release):scripts/release-floors.jsonrecords the floors (Ploeg and Vloer0.4.0-rc.34, Ploeg1.0.0-rc.1never reusable). The release policy refuses a computed version at or below a floor or any existing tag, including orphaned ones, before semantic-release prepares or tags.publish_release.pyandpublish_chart.pyrefuse at-or-below-floor versions before any registry or forge call. Python and JS implementations share one case table.fix(release): the preflight requires Forgejo and GitHub to answer aswebgrip/unfolditself (no rename redirect). It accepts a retired name that is gone or redirects, and refuses one recreated with Actions enabled. Logic moved intomain()so it is testable.fix(vloer): the extension's homepage, repository, bugs and Q&A links namewebgrip/unfold. Package, extension, image, chart and module identities are unchanged.Nothing here creates, moves or deletes a tag, release or package, and nothing publishes.
webgrip/homelab-clusteris not touched.Overlap with other branches
fix/release-publisher-unfold-identityanddocs/adr-ploeg-independent-releaseshave no commits beyonddevelopment. Their work is merged (#164/#165 renamed the scripts, #183 is ADR-0018).ryangr0/release-publish-unfold-repo(915a354c) is an earlier copy of what merged as #165. This PR does not repeat that rename. It adds the floors, the redirect-proof identity checks, the retired-name handling and the extension metadata.docs/operations/ci.md,scripts/verify.mjsandapps/site/package.json. I left the site's stale repository URL alone to avoid a conflict. Any conflict in ci.md or verify.mjs is a one-line merge.Checks
development'spublish_release.py/publish_chart.py(3 failures, 4 errors: they reach the registry/env for occupied versions). The old preflight cannot even be imported without credentials.mise run setup: passed.mise exec -- node --test scripts/release-floors.test.cjs: 6/6 passed.mise exec -- uv run --frozen python -m unittest discover -s scripts -p 'test_release*.py': 40 tests OK.mise run release-check(pinnedsemantic-release-monorepo:0.3.4, network none): 42 tests, 41 passed, 1 skipped (opt-inUNFOLD_RELEASE_HISTORY).mise run verify: all gates passed (vloer 7, demo-replay 1, vloer-extension 4, ploeg 7, brand 1, site 5, site-demo 1, helm 15, release 3, integration 1, docs 1). The warnings scan shows only a localVIRTUAL_ENVnotice from the shell.mise run docs-check: passed.Not run:
UNFOLD_RELEASE_HISTORY=trueagainst the real tags. The worktree's Git directory is outside the container mount, so it needs a full clone, and CI can run it. Harbor contents need credentials and were not read.Owner decisions
1.0.0-rc.1: keep it in GHCR/Forgejo (tools rank it above every 0.x), or delete those registry versions. Go cannot drop it.@lateststaysv0.2.0until a stable Ploeg release, which needs a change to ADR-0028.webgrip/glide,webgrip/ploegandwebgrip/de-vloerfrom the OpenBaocosign-signerbinding in homelab-cluster (separate change).Next (OPS-05/06)
OPS-05 needs channel state for the
ploeg-v/vloer-vtrains that starts above0.4.0-rc.34without aliasing an old version, because semantic-release would otherwise propose0.3.0-rc.8. Its trains must callrefuseOccupiedfor their own component. OPS-06 can take the floors and candidate identities from the record.🤖 Generated with Claude Code