Skip to content

release: Cockroach Browser 0.5.0-rc.1 - #57

Merged
AjnasNB merged 20 commits into
mainfrom
release/cockroach-browser-0.5.0-rc.1-20260903
Sep 3, 2026
Merged

AjnasNB merged 20 commits into
mainfrom
release/cockroach-browser-0.5.0-rc.1-20260903

Conversation

@AjnasNB

@AjnasNB AjnasNB commented Sep 2, 2026

Copy link
Copy Markdown
Owner

Release candidate

Prepares Cockroach Browser 0.5.0-rc.1 as a proof-led prerelease for AI-operated browser automation.

What ships

  • 130 declared capabilities: 119 available now and 11 adapter-backed, with zero entries labelled planned
  • two execution lanes: a constrained non-visual Obscura/CDP lane and full Chromium, Firefox, and WebKit lanes
  • fail-closed capability preflight, continuous resource governance, structured extraction, network boundaries, session/team controls, webhooks, SDK parity, MCP, Qarinah provenance, and auditable action history
  • refreshed documentation, market positioning, production site, JSON schemas, and the 25-page Technical White Paper v1.2
  • guarded release workflow using annotated tags reachable from protected main, npm OIDC publication, immutable GitHub assets, and prerelease-aware dist-tags

Frozen lightweight proof

Pinned engine: Obscura 0.2.1, binary SHA-256 5b609fb46bc00da79e450fb0fbd34bd442e565b1394f4af95433e0b341078221.

  • 30 MiB target: PASS, maximum browser-tree RSS 29,622,272 bytes, exactly 28.25 MiB
  • 25 MiB target: FAIL, maximum browser-tree RSS 29,679,616 bytes, approximately 28.30 MiB
  • 20 fresh launches per target; 958 retained observations total
  • every launch passed connect, JavaScript, DOM, form, screenshot-preflight, and teardown checks
  • proof verifier passed against the frozen artifacts, runtime build, source tree, and harness hashes

This does not claim that every site or full rendering engine stays below 30 MiB. The measured claim applies only to the pinned constrained non-visual workload and records the failed 25 MiB boundary alongside the pass.

Verification

  • npm run check: 184 tests, 164 passed, 20 explicit integration-gated skips, 0 failed; build, types, API, proof, package, site, audit, and pack checks passed
  • consolidated Linux/WSL engine suite: 45 passed, 0 failed, 0 skipped across headed/headless Chromium, Firefox, WebKit, raw Puppeteer, CDP, BiDi, network boundaries, and resource E2E
  • Windows lightweight/resource suite: 25 passed, 0 failed, 0 skipped
  • packed-consumer test passed against all 130 capabilities
  • daemon authentication and loopback binding smoke passed
  • Cloudflare Worker dry-run passed with 96 assets; site smoke passed 20 desktop/mobile viewports without overflow or console errors
  • Python, Java, and Go SDK checks passed; Ruby, Maven, and .NET remain covered by CI because those local SDKs were unavailable
  • production dependency audit: 0 known vulnerabilities across 130 dependencies

The host's installed full Chrome/Firefox binaries have a Windows SideBySide manifest failure before automation begins. The equivalent full-engine matrix passed under Linux/WSL, and Windows Playwright Chromium-shell plus Obscura/resource lanes passed. Docker Compose validates, but a local image build was unavailable because Docker Desktop was stopped.

Release boundary

Merge through protected main, create annotated tag v0.5.0-rc.1 on the merged commit, let the release workflow publish npm/GitHub assets, then deploy the exact static site snapshot to Cloudflare. The site is intentionally not deployed before npm publication so its quickstart cannot point at a nonexistent version.

@AjnasNB
AjnasNB enabled auto-merge (squash) September 2, 2026 21:13
@AjnasNB

AjnasNB commented Sep 2, 2026

Copy link
Copy Markdown
Owner Author

@cognifyrdotco The protected matrix is fully green, including the corrected hardened-container build and smoke test. Please review this RC when available; auto-merge is enabled and will preserve the required independent-approval gate.

@AjnasNB
AjnasNB merged commit dd9a7cc into main Sep 3, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants