Skip to content

release: ship GuardScan 1.1.0 through the zero-touch release train#32

Draft
ntanwir10 wants to merge 22 commits into
mainfrom
release/1.1.0
Draft

release: ship GuardScan 1.1.0 through the zero-touch release train#32
ntanwir10 wants to merge 22 commits into
mainfrom
release/1.1.0

Conversation

@ntanwir10

@ntanwir10 ntanwir10 commented Jul 26, 2026

Copy link
Copy Markdown
Owner

What changed

  • hardens offline scanning, privacy-sensitive state, provider execution, and deterministic npm packaging
  • adds the zero-touch RC-to-stable release train with append-only ledger events, reconciliation, rollback evidence, signed native-artifact contracts, npm/PyPI publication, and moderated-channel tracking
  • adds one shared ntanwir10/homebrew-tap catalog for both Homebrew and Scoop, generated from an immutable GuardScan release manifest and kept in sync through pull requests plus scheduled reconciliation
  • keeps a future Homebrew Core submission as an optional non-blocking discoverability path while the first-party tap remains authoritative
  • documents one-time provider onboarding and the public install contracts

Why

The previous release scaffold only published npm directly and could not prove native artifacts, cross-channel identity, promotion timing, or rollback state. This release makes GuardScan the single release authority and treats every downstream package definition as a reproducible projection of the same immutable manifest.

Validation

  • npm run typecheck
  • npm run build
  • npm test -- --runInBand — 69 suites, 797 tests
  • npm test -- --coverage --runInBand — 69 suites, 797 tests
  • npm run lint:ratchet
  • npm 10.9.8 and npm 11 clean-install lockfile validation
  • npm audit --omit=dev --audit-level=high — 0 vulnerabilities
  • npm run test:release — 8 suites, 63 tests
  • npm run test:package
  • npm and Yarn Classic package-manager smoke tests
  • release schema/config validation
  • workflow YAML, embedded Bash/Python/Node syntax validation
  • git diff --check
  • two independent final release package builds produced the same SHA-256: 16812f6bc503e1d554bd4bf6bb30c71ea82032ba571900280affebd27a37d12f

External onboarding still required

Publication is fail-closed with RELEASE_AUTOMATION_ENABLED=false until the GitHub App, OIDC trusted publishers, signing identities, and moderated-registry credentials described in docs/RELEASE_ONBOARDING.md are configured. The eight protected zero-reviewer environments, shared catalog repository, release ledger branch, and branch protections are already bootstrapped.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Jul 26, 2026

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
❌ Deployment failed
View logs
guardscan-backend c787d6e Jul 26 2026, 04:47 AM

@coderabbitai

coderabbitai Bot commented Jul 26, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Draft detected.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 97f9330d-caca-4a1d-aee0-fcb8d6e76bf6

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant