Skip to content

chore(release): prepare v0.16.0 - #255

Merged
mbeacom merged 3 commits into
mainfrom
chore/release-v0.16.0
Oct 1, 2026
Merged

mbeacom merged 3 commits into
mainfrom
chore/release-v0.16.0

Conversation

@mbeacom

@mbeacom mbeacom commented Oct 1, 2026

Copy link
Copy Markdown
Owner

What and why

Prepares v0.16.0. The main reason to release now is security: published @v0 Action consumers still run the v0.15.0 bundle with undici 6.27.0 (GHSA-rfgv-xxqx-mfg5, high), fixed on main in #251. It also ships adr accept and the queue's terminal view (#250). adrkit.dev has documented both since that merged, so anyone on @adrkit/cli@0.15.0 following the site today gets "unknown command".

Version moves, following #244: the four public packages, CLI_VERSION, SERVER_INFO/server.json, bun.lock's workspace entries, and every documented pin (README, ci.mdx, badges.mdx, quickstart, the site hero, RELEASING.md, the bug-report template).

CHANGELOG, with what Unreleased was missing:

  • Security: undici 6.29.0 in both Action bundles.
  • Added: adr accept, the queue terminal view, and acceptAdrSource (a new @adrkit/core runtime export, called out per the release policy).
  • Changed: adr queue --format defaults to auto. Only a terminal sees a difference; pipes, CI, the managed-issue Action, and agents still get Markdown byte for byte. Also the Bun 1.4.2 move, which makes the Action bundles about 25% smaller by dropping unused zod locales and helpers.

Docs catching up with accept:

  • the AGENTS.md status line and the CLI README command list name it;
  • the CLI README (the npm page) and the root README gain a short queue-and-accept section showing the terminal view;
  • the container section lists accept among the commands that write.

Checklist

  • Commits are DCO signed off.
  • No recorded decision changes.
  • Schema: unchanged.
  • packages/ci/dist rebuilt under linux/amd64 bun 1.4.2 from a clean install: byte-identical, nothing to commit.
  • Tests: version bumps and docs only. The full suite passes (3,201), as do typecheck, lint, check:doc-pins, check:stale-refs, check:site-grammar, check:deps, check:freeze-hashes, check:clause8, check:no-spike-heuristics, and adr lint (44 records).
  • bun run build and release:pack pass, preparing 5 packages for v0.16.0.

Notes for reviewers

  • After merge, the release is the usual path in docs/RELEASING.md: tag v0.16.0 (annotated, on main), let Release publish to npm, then publish the draft with the Marketplace selection, which moves v0 and publishes the container.
  • The agent plugin, the Spec Kit extension, and the MCP server's behavior are unchanged; none needs its own release.

Moves the lockstep surface to 0.16.0: the four public packages,
CLI_VERSION, SERVER_INFO and server.json, bun.lock's workspace entries,
and every documented pin (README, ci.mdx, badges.mdx, quickstart, the
site hero, RELEASING.md, the bug-report template).

The CHANGELOG's Unreleased section becomes 0.16.0, with what it was
missing:
- Security: the Action bundles' undici 6.29.0 (GHSA-rfgv-xxqx-mfg5,
  #251). It is the main reason to release now, since published v0
  consumers still run 6.27.0.
- Added: acceptAdrSource, a new @adrkit/core runtime export, which the
  release policy requires calling out.
- Changed: adr queue --format defaults to auto (only a terminal sees a
  difference), and the Bun 1.4.2 toolchain move, which shrinks the
  Action bundles by dropping unused zod locales and helpers.

The docs also catch up with adr accept, which adrkit.dev has described
since #250 merged but npm doesn't ship yet: the AGENTS.md status line
and the CLI README command lists name it, the CLI README and root README
gain a short queue-and-accept section with the terminal view, and the
container section lists accept among the commands that write.

The Action bundles rebuild byte-identical under linux/amd64 Bun 1.4.2,
and release:pack prepares all five packages for v0.16.0.

Signed-off-by: Mark Beacom <m@beacom.dev>
Copilot AI balanced review requested due to automatic review settings October 1, 2026 02:53
The queue row now says the shipped workflow includes ratifying from
the queue, not only reporting it.

Signed-off-by: Mark Beacom <m@beacom.dev>
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

Decisions governing this change

  • 0003 — Ship as a Spec Kit extension plus a standalone CLI, not a competing harness
    • via path: packages/cli/**
  • 0007 — Isolate integrations as optional adapters and build only against public surfaces
    • via path: packages/*/package.json
  • 0010 — Use Bun as the package manager and test runner while publishing Node-targeted artifacts
    • via path: package.json
  • 0011 — Host the canonical JSON Schema at its $id on adrkit.dev
    • via path: site/**
  • 0016 — Require every check to be observed failing before it counts as coverage
    • via path: packages/*/test/**
  • 0017 — Keep dependency audit scope explicit and release-scoped
    • via path: packages/*/package.json
  • 0018 — Adopt MCP SDK v2 and serve protocol revision 2026-07-28 dual-era
    • via path: packages/mcp/**
  • 0022 — Scan inbound markers in check and CI without giving them exit-code authority
    • via path: packages/cli/src/index.ts
  • 0024 — Report the measured scan extent, not the window constant
    • via path: packages/cli/src/index.ts
  • 0025 — Ship badges as recipes over existing output, not a new CLI surface
    • via path: package.json
    • via path: site/src/content/docs/badges.mdx
  • 0026 — Identify the CI comment by the strongest author evidence the token allows
    • via path: site/src/content/docs/ci.mdx
  • 0027 — Ratify the deterministic evaluator and bind calibration reporting to the first probabilistic pass
    • via path: packages/evaluator/**
  • 0029 — Scope Backstage publication as a downstream consumer, tiered on the entity-ownership mapping
    • via path: packages/cli/src/index.ts
  • 0030 — Keep extension surfaces that carry a dependency tree outside this repository
    • via path: package.json
  • 0031 — Publish a narrow consumer SDK as the contract, and document the CLI JSON as its sibling
    • via path: docs/RELEASING.md
    • via path: packages/cli/src/index.ts
  • 0032 — Publish one lockstep OCI image after the coordinated release succeeds
    • via path: README.md
    • via path: docs/RELEASING.md
  • 0033 — Select interactive graph presentation at the CLI boundary while preserving piped DOT
    • via path: packages/cli/src/index.ts
    • via path: site/src/content/docs/**
  • 0036 — Expose the governing-decisions Action through one root Marketplace entry point
    • via path: docs/RELEASING.md
  • 0037 — Treat generated knowledge systems as downstream read models, not decision authorities
    • via path: README.md
    • via path: site/src/content/docs/**
  • 0038 — Offer the bootstrap decision record as an offer rather than a backfill candidate
    • via path: site/src/content/docs/quickstart.mdx
  • 0039 — Derive a valid-time window from date and supersession, and resolve a git ref at the CLI boundary
    • via path: packages/cli/src/index.ts
  • 0040 — Keep derived surfaces in lockstep with three mechanisms matched to three classes of drift
    • via path: AGENTS.md

Historical records that once covered this change

These no longer bind this change, and are listed for context only:

  • 0005 — Gate proposals with a deterministic-first evaluator and declarative escalation (superseded) — superseded by 0027
    • via path: packages/evaluator/**
  • 0021 — Resolve inbound source annotations without changing the schema (superseded) — superseded by 0022
    • via path: packages/cli/src/index.ts

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The changelog incorrectly claims all other bundled dependencies are unchanged despite the documented undici upgrade.

Review effort: Balanced
Findings: 1 Low severity

Open (1)
What changed in this PR

Prepares the lockstep v0.16.0 release, documenting the security update and newly shipped queue/accept functionality.

Changes:

  • Aligns package, lockfile, CLI, and MCP versions.
  • Updates release notes, documentation, examples, and current-version references.
  • Documents adr accept and terminal queue output.

Decision-context MCP was unavailable, so marker-only governance was not independently verified.

File Description
.github/​ISSUE_TEMPLATE/​bug_report.yml Updates version placeholder.
AGENTS.md Updates release status and command inventory.
CHANGELOG.md Adds v0.16.0 release notes.
README.md Documents accept, terminal queues, and release pins.
bun.lock Aligns workspace versions.
docs/​RELEASING.md Updates current release references.
package.json Bumps root version.
packages/​cli/​README.md Documents queue and acceptance workflows.
packages/​cli/​package.json Bumps CLI version.
packages/​cli/​src/​index.ts Updates CLI_VERSION.
packages/​cli/​test/​color.test.ts Updates expected version output.
packages/​core/​package.json Bumps core version.
packages/​evaluator/​package.json Bumps evaluator version.
packages/​mcp/​package.json Bumps MCP package version.
packages/​mcp/​server.json Aligns MCP registry versions.
packages/​mcp/​src/​server.ts Updates SERVER_INFO.
site/​src/​components/​Hero.astro Updates hero release version.
site/​src/​content/​docs/​badges.mdx Updates pinned CLI recipes.
site/​src/​content/​docs/​ci.mdx Updates immutable Action pins.
site/​src/​content/​docs/​index.mdx Updates published-version status.
site/​src/​content/​docs/​quickstart.mdx Updates npm release notice.

Comment thread CHANGELOG.md Outdated
…anged

The 0.16.0 Changed entry said every other bundled dependency was
unchanged, which contradicts the undici update under Security in the
same release. It now says that, apart from zod's dropped locales and
helpers and that undici update, the bundles contain the same modules as
0.15.0. I checked that against both bundles at v0.15.0 and on main.

Signed-off-by: Mark Beacom <m@beacom.dev>
@mbeacom
mbeacom merged commit 14596e9 into main Oct 1, 2026
17 checks passed
@mbeacom
mbeacom deleted the chore/release-v0.16.0 branch October 1, 2026 03:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants