chore(release): prepare v0.16.0 - #255
Merged
Merged
Conversation
Moves the lockstep surface to 0.16.0: the four public packages, CLI_VERSION, SERVER_INFO and server.json, bun.lock's workspace entries, and every documented pin (README, ci.mdx, badges.mdx, quickstart, the site hero, RELEASING.md, the bug-report template). The CHANGELOG's Unreleased section becomes 0.16.0, with what it was missing: - Security: the Action bundles' undici 6.29.0 (GHSA-rfgv-xxqx-mfg5, #251). It is the main reason to release now, since published v0 consumers still run 6.27.0. - Added: acceptAdrSource, a new @adrkit/core runtime export, which the release policy requires calling out. - Changed: adr queue --format defaults to auto (only a terminal sees a difference), and the Bun 1.4.2 toolchain move, which shrinks the Action bundles by dropping unused zod locales and helpers. The docs also catch up with adr accept, which adrkit.dev has described since #250 merged but npm doesn't ship yet: the AGENTS.md status line and the CLI README command lists name it, the CLI README and root README gain a short queue-and-accept section with the terminal view, and the container section lists accept among the commands that write. The Action bundles rebuild byte-identical under linux/amd64 Bun 1.4.2, and release:pack prepares all five packages for v0.16.0. Signed-off-by: Mark Beacom <m@beacom.dev>
The queue row now says the shipped workflow includes ratifying from the queue, not only reporting it. Signed-off-by: Mark Beacom <m@beacom.dev>
Decisions governing this change
Historical records that once covered this changeThese no longer bind this change, and are listed for context only:
|
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The changelog incorrectly claims all other bundled dependencies are unchanged despite the documented undici upgrade.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Prepares the lockstep v0.16.0 release, documenting the security update and newly shipped queue/accept functionality.
Changes:
- Aligns package, lockfile, CLI, and MCP versions.
- Updates release notes, documentation, examples, and current-version references.
- Documents
adr acceptand terminal queue output.
Decision-context MCP was unavailable, so marker-only governance was not independently verified.
| File | Description |
|---|---|
.github/ISSUE_TEMPLATE/bug_report.yml |
Updates version placeholder. |
AGENTS.md |
Updates release status and command inventory. |
CHANGELOG.md |
Adds v0.16.0 release notes. |
README.md |
Documents accept, terminal queues, and release pins. |
bun.lock |
Aligns workspace versions. |
docs/RELEASING.md |
Updates current release references. |
package.json |
Bumps root version. |
packages/cli/README.md |
Documents queue and acceptance workflows. |
packages/cli/package.json |
Bumps CLI version. |
packages/cli/src/index.ts |
Updates CLI_VERSION. |
packages/cli/test/color.test.ts |
Updates expected version output. |
packages/core/package.json |
Bumps core version. |
packages/evaluator/package.json |
Bumps evaluator version. |
packages/mcp/package.json |
Bumps MCP package version. |
packages/mcp/server.json |
Aligns MCP registry versions. |
packages/mcp/src/server.ts |
Updates SERVER_INFO. |
site/src/components/Hero.astro |
Updates hero release version. |
site/src/content/docs/badges.mdx |
Updates pinned CLI recipes. |
site/src/content/docs/ci.mdx |
Updates immutable Action pins. |
site/src/content/docs/index.mdx |
Updates published-version status. |
site/src/content/docs/quickstart.mdx |
Updates npm release notice. |
…anged The 0.16.0 Changed entry said every other bundled dependency was unchanged, which contradicts the undici update under Security in the same release. It now says that, apart from zod's dropped locales and helpers and that undici update, the bundles contain the same modules as 0.15.0. I checked that against both bundles at v0.15.0 and on main. Signed-off-by: Mark Beacom <m@beacom.dev>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

What and why
Prepares v0.16.0. The main reason to release now is security: published
@v0Action consumers still run the v0.15.0 bundle withundici6.27.0 (GHSA-rfgv-xxqx-mfg5, high), fixed onmainin #251. It also shipsadr acceptand the queue's terminal view (#250). adrkit.dev has documented both since that merged, so anyone on@adrkit/cli@0.15.0following the site today gets "unknown command".Version moves, following #244: the four public packages,
CLI_VERSION,SERVER_INFO/server.json,bun.lock's workspace entries, and every documented pin (README,ci.mdx,badges.mdx, quickstart, the site hero,RELEASING.md, the bug-report template).CHANGELOG, with what Unreleased was missing:
undici6.29.0 in both Action bundles.adr accept, the queue terminal view, andacceptAdrSource(a new@adrkit/coreruntime export, called out per the release policy).adr queue --formatdefaults toauto. Only a terminal sees a difference; pipes, CI, the managed-issue Action, and agents still get Markdown byte for byte. Also the Bun 1.4.2 move, which makes the Action bundles about 25% smaller by dropping unusedzodlocales and helpers.Docs catching up with
accept:AGENTS.mdstatus line and the CLI README command list name it;acceptamong the commands that write.Checklist
packages/ci/distrebuilt under linux/amd64 bun 1.4.2 from a clean install: byte-identical, nothing to commit.check:doc-pins,check:stale-refs,check:site-grammar,check:deps,check:freeze-hashes,check:clause8,check:no-spike-heuristics, andadr lint(44 records).bun run buildandrelease:packpass, preparing 5 packages for v0.16.0.Notes for reviewers
docs/RELEASING.md: tagv0.16.0(annotated, onmain), letReleasepublish to npm, then publish the draft with the Marketplace selection, which movesv0and publishes the container.