Repository navigation
chore(release): prepare v0.1.5 fix-forward - #6758
Conversation
Move the workspace, desktop and public npm package versions to 0.1.5, with every path-dependency requirement and lockfile record following. Add the 0.1.5 changelog section (Windows digest fix #6717, ODRL prohibition fixes #6734/#6737) and note the v0.1.4 fix-forward in docs/release.md. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0184oZyLYQNVPp7HYBAr6uYz
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0184oZyLYQNVPp7HYBAr6uYz
The chain-root lock is the #6647 pin, so the version bump must not edit it. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0184oZyLYQNVPp7HYBAr6uYz
|
"native credential and circuit composition" fails because this bump moves Generated by Claude Code |
🔎 Codex reviewer —
|
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0184oZyLYQNVPp7HYBAr6uYz
|
"GUI build + clippy (arm64-linux, advisory)" fails at Generated by Claude Code |
🔎 Codex reviewer —
|
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0184oZyLYQNVPp7HYBAr6uYz
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0184oZyLYQNVPp7HYBAr6uYz
🔎 Codex reviewer —
|
|
Handoff for whoever merges this PR. It is Codex-clean at 95d1b8d.
Generated by Claude Code |
…-methods lock Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0184oZyLYQNVPp7HYBAr6uYz
|
On the low finding (CHANGELOG coverage): I'm leaving this PR as is for now. Filling in the full v0.1.4..v0.1.5 behaviour-change list is a separate docs pass. The table in the review is a good checklist for whoever cuts the release, and the version, merge and three new-entry checks all passed. Generated by Claude Code |
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0184oZyLYQNVPp7HYBAr6uYz
🔎 Codex reviewer —
|
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0184oZyLYQNVPp7HYBAr6uYz
🔎 Codex reviewer —
|
The bump moves sparq-canon and sparq-core to 0.1.5 in the native lock. Re-record candidate_lock_sha256 and since_chain_root with verify.py's lock_delta(); no third-party package changes. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0184oZyLYQNVPp7HYBAr6uYz
…eview Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0184oZyLYQNVPp7HYBAr6uYz
🔎 Codex reviewer —
|
Before: the
v0.1.4tag's release run stopped at "collect archive digests" because the Windows rows wrote*<name>digest records. No GitHub Release, npm or PyPI package came out of it. The release runbook (docs/release.md §3b) says a failed tag stays fixed and the release fixes forward.After: merging this PR makes release-plz tag
v0.1.5. That tag carries the Windows digest fix (#6717) and the ODRL prohibition security fixes (#6734, #6737), and runs the normalrelease.yml→ GitHub Release →publish.yml(npm + PyPI) path.How:
@sparq-org/sparq,@sparq-org/solid-server,@sparq-org/eyereasoner-compatand the GUI app. Every path-dependency requirement follows, as do the sparq-* records in all 27 Cargo.lock files and the workspace records inpackage-lock.json. No external dependency changes.[Unreleased]entries become## [0.1.5] - 2026-10-09, plus a Fixed section for ci(release): text-mode sha256 records so Windows archive digests pass the collector #6717 and the ODRL fixes. The ODRL line is neutral; a "See GHSA-…" pointer gets added only if the maintainer publishes an advisory. Compare links are updated.Checks run locally:
cargo metadata --lockedpasses for the root, gui/src-tauri, fuzz, examples and three bench workspaces.check-release-source.py --tag v0.1.5passes, with and without--publish, against a throwaway local tag that was deleted afterwards.test_release_source,test_release_publish_guard,test_release_slsa_l3_provenance,test_publish_strip,test_release_container_multiarch,test_release_gui_staging).release-interval-guard.py --self-testpasses.Not for merge by the session that opened it.
release-interval-guard --dry-runcurrently measures from the v0.1.3 tag and says ALLOW, but the project is waiting for the 24 hours from v0.1.4 anyway.🤖 Generated with Claude Code
https://claude.ai/code/session_0184oZyLYQNVPp7HYBAr6uYz
Generated by Claude Code