fix(release): record release floors and refuse versions at or below them #197

Merged
ryangr0 merged 4 commits from ryangr0/release-floors-and-identity into development 2026-10-03 15:13:56 +00:00 AGit
Owner

Refs VIK-1794 (handoff OPS-04, milestone M4 release stream).

What

A read-only audit of every Ploeg and Vloer release destination after the 2026-10-03 history rewrite and the move to webgrip/unfold, plus the repository changes it calls for. The record is docs/research/2026-10-03-release-floors-and-identity.md with the full inventory in the .json next to it.

Findings

  • Every Ploeg and Vloer version up to 0.4.0-rc.34 is taken somewhere. Ploeg's withdrawn 1.0.0-rc.1 is still published (Go proxy, GHCR ploegd and charts/ploeg, Forgejo ploegd). ADR-0018's proposed 0.5.0-rc.1 for both trains is above every floor.
  • Public Go history for github.com/webgrip/ploeg: 66 proxy versions. 35 match the checksum database from the origin. 14 stop: v0.3.0-rc.5 and every v0.4.0-rc.* export now serve different bytes from GitHub (a direct download fails with SECURITY ERROR; the changes are .mailmap, test files, OpenSpec docs and one research note, no non-test Go source). 17 exist only in the proxy. @latest is v0.2.0.
  • Identity: Forgejo and GitHub webgrip/unfold are canonical, tags and branches are identical, and the rc.34 signing job's OIDC claim was repository: webgrip/unfold. The release preflight would have stopped at the deleted webgrip/ploeg / webgrip/de-vloer, and the published extension still links to the deleted webgrip/de-vloer.

Changes

  1. docs(release): the audit record, a dated note on ADR-0018 (highest Go version is v0.4.0-rc.32, not rc.34), and the cutover playbook's dead GitHub link and signing row.
  2. fix(release): scripts/release-floors.json records the floors (Ploeg and Vloer 0.4.0-rc.34, Ploeg 1.0.0-rc.1 never reusable). The release policy refuses a computed version at or below a floor or any existing tag, including orphaned ones, before semantic-release prepares or tags. publish_release.py and publish_chart.py refuse at-or-below-floor versions before any registry or forge call. Python and JS implementations share one case table.
  3. fix(release): the preflight requires Forgejo and GitHub to answer as webgrip/unfold itself (no rename redirect). It accepts a retired name that is gone or redirects, and refuses one recreated with Actions enabled. Logic moved into main() so it is testable.
  4. fix(vloer): the extension's homepage, repository, bugs and Q&A links name webgrip/unfold. Package, extension, image, chart and module identities are unchanged.

Nothing here creates, moves or deletes a tag, release or package, and nothing publishes. webgrip/homelab-cluster is not touched.

Overlap with other branches

  • fix/release-publisher-unfold-identity and docs/adr-ploeg-independent-releases have no commits beyond development. Their work is merged (#164/#165 renamed the scripts, #183 is ADR-0018).
  • ryangr0/release-publish-unfold-repo (915a354c) is an earlier copy of what merged as #165. This PR does not repeat that rename. It adds the floors, the redirect-proof identity checks, the retired-name handling and the extension metadata.
  • Open #192 also edits docs/operations/ci.md, scripts/verify.mjs and apps/site/package.json. I left the site's stale repository URL alone to avoid a conflict. Any conflict in ci.md or verify.mjs is a one-line merge.
  • VIK-1827 (Ploeg missing from GHCR for rc.33/34) is consistent with the inventory. This PR does not repair those partial releases.

Checks

  • Regression first: the new publisher tests fail against development's publish_release.py/publish_chart.py (3 failures, 4 errors: they reach the registry/env for occupied versions). The old preflight cannot even be imported without credentials.
  • mise run setup: passed.
  • mise exec -- node --test scripts/release-floors.test.cjs: 6/6 passed.
  • mise exec -- uv run --frozen python -m unittest discover -s scripts -p 'test_release*.py': 40 tests OK.
  • mise run release-check (pinned semantic-release-monorepo:0.3.4, network none): 42 tests, 41 passed, 1 skipped (opt-in UNFOLD_RELEASE_HISTORY).
  • mise run verify: all gates passed (vloer 7, demo-replay 1, vloer-extension 4, ploeg 7, brand 1, site 5, site-demo 1, helm 15, release 3, integration 1, docs 1). The warnings scan shows only a local VIRTUAL_ENV notice from the shell.
  • mise run docs-check: passed.

Not run: UNFOLD_RELEASE_HISTORY=true against the real tags. The worktree's Git directory is outside the container mount, so it needs a full clone, and CI can run it. Harbor contents need credentials and were not read.

Owner decisions

  1. The 14 Go versions whose origin bytes changed: leave the GitHub tags and document them, or delete those tags so direct downloads fail as "unknown revision". Re-exporting or re-tagging is never allowed.
  2. The withdrawn 1.0.0-rc.1: keep it in GHCR/Forgejo (tools rank it above every 0.x), or delete those registry versions. Go cannot drop it.
  3. @latest stays v0.2.0 until a stable Ploeg release, which needs a change to ADR-0028.
  4. Remove webgrip/glide, webgrip/ploeg and webgrip/de-vloer from the OpenBao cosign-signer binding in homelab-cluster (separate change).

Next (OPS-05/06)

OPS-05 needs channel state for the ploeg-v/vloer-v trains that starts above 0.4.0-rc.34 without aliasing an old version, because semantic-release would otherwise propose 0.3.0-rc.8. Its trains must call refuseOccupied for their own component. OPS-06 can take the floors and candidate identities from the record.

🤖 Generated with Claude Code

Refs VIK-1794 (handoff OPS-04, milestone M4 release stream). ## What A read-only audit of every Ploeg and Vloer release destination after the 2026-10-03 history rewrite and the move to `webgrip/unfold`, plus the repository changes it calls for. The record is `docs/research/2026-10-03-release-floors-and-identity.md` with the full inventory in the `.json` next to it. **Findings** - Every Ploeg and Vloer version up to `0.4.0-rc.34` is taken somewhere. Ploeg's withdrawn `1.0.0-rc.1` is still published (Go proxy, GHCR `ploegd` and `charts/ploeg`, Forgejo `ploegd`). ADR-0018's proposed `0.5.0-rc.1` for both trains is above every floor. - Public Go history for `github.com/webgrip/ploeg`: 66 proxy versions. 35 match the checksum database from the origin. **14 stop**: `v0.3.0-rc.5` and every `v0.4.0-rc.*` export now serve different bytes from GitHub (a direct download fails with SECURITY ERROR; the changes are `.mailmap`, test files, OpenSpec docs and one research note, no non-test Go source). 17 exist only in the proxy. `@latest` is `v0.2.0`. - Identity: Forgejo and GitHub `webgrip/unfold` are canonical, tags and branches are identical, and the rc.34 signing job's OIDC claim was `repository: webgrip/unfold`. The release preflight would have stopped at the deleted `webgrip/ploeg` / `webgrip/de-vloer`, and the published extension still links to the deleted `webgrip/de-vloer`. **Changes** 1. `docs(release)`: the audit record, a dated note on ADR-0018 (highest Go version is `v0.4.0-rc.32`, not rc.34), and the cutover playbook's dead GitHub link and signing row. 2. `fix(release)`: `scripts/release-floors.json` records the floors (Ploeg and Vloer `0.4.0-rc.34`, Ploeg `1.0.0-rc.1` never reusable). The release policy refuses a computed version at or below a floor or any existing tag, including orphaned ones, before semantic-release prepares or tags. `publish_release.py` and `publish_chart.py` refuse at-or-below-floor versions before any registry or forge call. Python and JS implementations share one case table. 3. `fix(release)`: the preflight requires Forgejo and GitHub to answer as `webgrip/unfold` itself (no rename redirect). It accepts a retired name that is gone or redirects, and refuses one recreated with Actions enabled. Logic moved into `main()` so it is testable. 4. `fix(vloer)`: the extension's homepage, repository, bugs and Q&A links name `webgrip/unfold`. Package, extension, image, chart and module identities are unchanged. Nothing here creates, moves or deletes a tag, release or package, and nothing publishes. `webgrip/homelab-cluster` is not touched. ## Overlap with other branches - `fix/release-publisher-unfold-identity` and `docs/adr-ploeg-independent-releases` have no commits beyond `development`. Their work is merged (#164/#165 renamed the scripts, #183 is ADR-0018). - `ryangr0/release-publish-unfold-repo` (915a354c) is an earlier copy of what merged as #165. This PR does not repeat that rename. It adds the floors, the redirect-proof identity checks, the retired-name handling and the extension metadata. - Open #192 also edits `docs/operations/ci.md`, `scripts/verify.mjs` and `apps/site/package.json`. I left the site's stale repository URL alone to avoid a conflict. Any conflict in ci.md or verify.mjs is a one-line merge. - VIK-1827 (Ploeg missing from GHCR for rc.33/34) is consistent with the inventory. This PR does not repair those partial releases. ## Checks - Regression first: the new publisher tests fail against `development`'s `publish_release.py`/`publish_chart.py` (3 failures, 4 errors: they reach the registry/env for occupied versions). The old preflight cannot even be imported without credentials. - `mise run setup`: passed. - `mise exec -- node --test scripts/release-floors.test.cjs`: 6/6 passed. - `mise exec -- uv run --frozen python -m unittest discover -s scripts -p 'test_release*.py'`: 40 tests OK. - `mise run release-check` (pinned `semantic-release-monorepo:0.3.4`, network none): 42 tests, 41 passed, 1 skipped (opt-in `UNFOLD_RELEASE_HISTORY`). - `mise run verify`: all gates passed (vloer 7, demo-replay 1, vloer-extension 4, ploeg 7, brand 1, site 5, site-demo 1, helm 15, release 3, integration 1, docs 1). The warnings scan shows only a local `VIRTUAL_ENV` notice from the shell. - `mise run docs-check`: passed. **Not run:** `UNFOLD_RELEASE_HISTORY=true` against the real tags. The worktree's Git directory is outside the container mount, so it needs a full clone, and CI can run it. Harbor contents need credentials and were not read. ## Owner decisions 1. The 14 Go versions whose origin bytes changed: leave the GitHub tags and document them, or delete those tags so direct downloads fail as "unknown revision". Re-exporting or re-tagging is never allowed. 2. The withdrawn `1.0.0-rc.1`: keep it in GHCR/Forgejo (tools rank it above every 0.x), or delete those registry versions. Go cannot drop it. 3. `@latest` stays `v0.2.0` until a stable Ploeg release, which needs a change to ADR-0028. 4. Remove `webgrip/glide`, `webgrip/ploeg` and `webgrip/de-vloer` from the OpenBao `cosign-signer` binding in homelab-cluster (separate change). ## Next (OPS-05/06) OPS-05 needs channel state for the `ploeg-v`/`vloer-v` trains that starts above `0.4.0-rc.34` without aliasing an old version, because semantic-release would otherwise propose `0.3.0-rc.8`. Its trains must call `refuseOccupied` for their own component. OPS-06 can take the floors and candidate identities from the record. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
A read-only audit of every Ploeg and Vloer destination after the history
rewrite and the move to webgrip/unfold. Every version up to 0.4.0-rc.34
is taken somewhere, and Ploeg's withdrawn 1.0.0-rc.1 is still published
in the Go module proxy, GHCR and Forgejo.

Of 66 public Go module versions, 35 still download from the origin with
the recorded bytes, 14 now differ from the checksum database (a direct
download fails with SECURITY ERROR) and 17 exist only in the proxy.
@latest resolves to v0.2.0. The record keeps the pre-rewrite to current
source and export mapping, the joint train's completion state and the
canonical identities, including the OIDC claim of the rc.34 signing job.

ADR-0018 gets a dated note: the highest Go version is v0.4.0-rc.32, not
rc.34, and 0.5.0-rc.1 clears every floor. The cutover playbook's dead
GitHub link and signing row now name webgrip/unfold.

VIK-1794
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
New component trains would restart from ploeg-v0.3.0-rc.7 and
vloer-v0.3.0-rc.16 and compute versions the joint train already
published. An orphaned release tag also let semantic-release recompute
an existing version and push a duplicate release commit before the tag
step failed.

scripts/release-floors.json records each application's floor
(0.4.0-rc.34 for both), the withdrawn versions above it and the tag
prefixes that carried it. The release policy now refuses a computed
version at or below either floor or any existing tag, including tags no
longer reachable from development. Both publishers refuse a version at
or below their floor before reading a registry or the forge. Python and
JavaScript share one table of cases.

VIK-1794
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The preflight read the deleted Forgejo repositories webgrip/ploeg and
webgrip/de-vloer and raised on their 404, so the next release preview
would have stopped there. A rename redirect also passed as the
canonical repository, because the API read followed it.

The preflight now requires the Forgejo and GitHub APIs to answer as
webgrip/unfold itself. A retired name the signing role still binds
(webgrip/glide, webgrip/ploeg, webgrip/de-vloer) passes when it is gone
or redirects, and stops the preflight when it exists again with Actions
enabled. The checks run in main(), so the script is testable.

VIK-1794
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
fix(vloer): point the extension's repository links at webgrip/unfold
Some checks failed
[Workflow] On Pull Request / checks (pull_request) Has been cancelled
[Workflow] On Pull Request / warnings (pull_request) Has been cancelled
[Workflow] On Pull Request / release-policy (pull_request) Has been cancelled
43e07e927f
Every published VSIX names the deleted webgrip/de-vloer as its homepage,
repository, issue tracker and Q&A page, so those links on Open VSX are
dead. They now name webgrip/unfold and the extension's directory. The
extension's identity (webgrip.de-vloer) is unchanged.

VIK-1794
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
ryangr0 merged commit 188f3aab0d into development 2026-10-03 15:13:56 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
webgrip/unfold!197
No description provided.