Skip to content

Fix registry artifact dependency verification - #211

Merged
xeonvs merged 1 commit into
mainfrom
fix/registry-runtime-dependencies
Sep 19, 2026
Merged

xeonvs merged 1 commit into
mainfrom
fix/registry-runtime-dependencies

Conversation

@xeonvs

@xeonvs xeonvs commented Sep 19, 2026

Copy link
Copy Markdown
Owner

Problem

The v0.11.0 feature merge published TestPyPI development artifacts successfully, but post-publication verification installed the immutable wheel and sdist with --no-deps into empty virtual environments. The first runtime import therefore failed on mcp_types, even though the build-stage artifact smoke had already passed with the hash-locked runtime closure.

Fix

  • export one hash-locked runtime requirements artifact in development and stable builds;
  • transfer it with the reviewed distributions;
  • require the registry verifier to install that exact closure before installing immutable wheel/sdist bytes without dependency resolution;
  • cover the workflow/verifier contract with focused tests.

This changes publication verification only. Runtime federation, DLP, receipts, dependencies, and release authorization semantics are unchanged.

Validation

  • scripts/quality.sh check: passed
  • focused release/TestPyPI tests: 40 passed
  • git diff --check: passed
  • hosted exact-head checks are required before protected merge

Local Gitleaks was not rerun because the repository requires 8.30.1 while the local binary is 8.24.3; the exact-head hosted secrets gate remains authoritative.

Release lifecycle

This corrective PR is required before the separate Release v0.11.0 authorization PR. It intentionally uses no issue-closing keywords; stable workflow receipt reconciliation owns milestone closure.

@xeonvs
xeonvs merged commit 3f40294 into main Sep 19, 2026
13 checks passed
@xeonvs
xeonvs deleted the fix/registry-runtime-dependencies branch September 19, 2026 13:05
@xeonvs xeonvs mentioned this pull request Sep 19, 2026
xeonvs added a commit that referenced this pull request Sep 19, 2026
## Scope

Prepare and authorize stable toolkit **v0.11.0** for the governed MCP
federation, stage-aware DLP and OCR 1.12.0–1.12.7 qualification work
tracked by:

- #188–#193
- #201–#207
- #209
- #210

This release PR contains repository-side preparation only. Stable
publication and external reconciliation remain pending until this exact
PR is merged and the protected Release workflow completes.

## Reviewed implementation

- Feature PR: #208
- Reviewed feature head: `1e3b7d668874b2e86b2700284675d997a1654c0b`
- Protected feature squash merge:
`cc784c157d1b9efb3e45158e0c1a75fbb4801bd5`
- Corrective PR: #211
- Reviewed corrective head: `b41011b0d1744a5481eafe0d0eab4bf280a240c7`
- Protected corrective squash merge and release base:
`3f402948ce4606b935587af63920c467af43fa3b`
- Release head: `9fdabc74e5dc26566105a086d924e609bbe426cb`

## Development publication

- Workflow:
https://github.com/xeonvs/open-code-review-toolkit/actions/runs/35444762966
- Version: `0.11.0.dev98`
- Wheel SHA-256:
`379684bce1983cb4058e1916bb4ae75c61d00cb8d7b0ccf45240b36b57122952`
- Sdist SHA-256:
`36236b7246c722f8df35495775ce6b80c38b8c76fe40e4e7aca22a68fee11d34`
- Workflow verification passed provenance, exact TestPyPI bytes,
hash-locked runtime dependency installation, and clean wheel/sdist CLI
smokes.

## Release preparation

- Stable marker: `0.11.0`
- Next development marker: `0.12.0`
- Deterministic source epoch: `1789823158`
- Authorized issue set: `[188, 189, 190, 191, 192, 193, 201, 202, 203,
204, 205, 206, 207, 209, 210]`
- Towncrier fragments are rendered into `CHANGELOG.md`.
- Public GitLab example pins toolkit `0.11.0` with OCR `1.12.7`.
- Both feature and corrective plans are archived at
`docs/engineering/execution_history/releases.md#plan-toolkit-0-11-0`
with stable external delivery pending.
- `.release-reconciled-version` intentionally remains `0.10.1` until
independent external readback.

## Release validation

- `scripts/quality.sh check`: passed.
- Focused release/documentation suite: **109 passed**.
- Release-note extraction, marker contract and `git diff --check`:
passed.
- Local source-epoch-controlled builds are byte-identical and pass Twine
plus clean wheel/sdist CLI smokes with the hash-locked runtime closure.
Wheel SHA-256:
`fa64701e627e1045cb9b597f79c05f834265f160f127564dcec9702375e2f072`;
sdist SHA-256:
`7a03f4bd1ff657f333111ef9155380fadcbd83f4beac0dce1f44d6818e0d103e`.
- Feature qualification already completed local OCR v1.12.7
(`openai/gpt-5.6-terra`, 61/61 reviews, 22 evidence MCP calls, four
findings fixed) and Codex Security scan
`cc04b394-e16f-48b4-92ac-71cb2a27c963` with no reportable findings. No
material security/runtime delta was introduced by this release-only
commit.
- Local Gitleaks did not run because the repository requires 8.30.1
while the local binary is 8.24.3; the exact-head hosted `secrets` gate
is required before merge.

## Post-merge gates

The protected Release workflow must independently prove stable
TestPyPI/PyPI bytes, PEP 740 provenance, GitHub attestations,
supported-Python installs, annotated tag target, immutable GitHub
Release and exact five assets, the release receipt, and workflow-owned
issue receipts. A later protected documentation-only reconciliation PR
will record those facts, close the milestone from live state, and
advance `.release-reconciled-version` without changing the published
release.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant