Skip to content

release: ship GuardScan 1.1.0 through the zero-touch release train - #32

Draft
ntanwir10 wants to merge 30 commits into
mainfrom
release/1.1.0
Draft

release: ship GuardScan 1.1.0 through the zero-touch release train#32
ntanwir10 wants to merge 30 commits into
mainfrom
release/1.1.0

Conversation

@ntanwir10

@ntanwir10 ntanwir10 commented Jul 26, 2026

Copy link
Copy Markdown
Owner

What changed

  • hardens offline scanning, privacy-sensitive state, provider execution, and deterministic npm packaging
  • adds the zero-touch RC-to-stable release train with append-only ledger events, reconciliation, rollback evidence, signed native-artifact contracts, npm/PyPI publication, and moderated-channel tracking
  • binds every train to the exact release PR head, base, and tree and records canonical provider publication evidence
  • adds fail-closed first-stable withdrawal when no ledger-backed known-good release exists, including exact catalog removal, stale publication-PR closure, retry proofs, and explicit provider-actions-pending state
  • adds one shared ntanwir10/homebrew-tap catalog for both Homebrew and Scoop, generated from an immutable GuardScan release manifest and kept in sync through pull requests plus scheduled reconciliation
  • keeps Homebrew Core outside the selected 1.1.0 train while the first-party tap remains authoritative
  • documents one-time provider onboarding, the empty-ledger migration boundary, and public install contracts

Why

The previous release scaffold could not prove native artifacts, cross-channel identity, promotion timing, moderated-provider state, or safe recovery. This release makes GuardScan the single release authority and treats every downstream package definition as a reproducible projection of the same immutable manifest.

Validation at 773a824

  • npm test -- --runInBand --silent — 73 suites, 846 tests
  • npm run test:release — 8 suites, 102 tests
  • npm run typecheck
  • npm run lint:ratchet
  • npm audit --audit-level=high — 0 vulnerabilities
  • npm run test:package
  • local npm, Yarn Classic, and package-manager artifact smoke tests
  • CI pins and exercises pnpm, Yarn Modern, and Bun
  • npm pack --dry-run — 529 files, 732.5 kB packed, 3.9 MB unpacked
  • release workflow YAML, embedded Node heredocs, and JSON schema parsing
  • git diff --check
  • independent release-provider, bootstrap-closure, and rollback-design audits

Hosted checks for the current head are intentionally required before this draft becomes mergeable.

Known unrelated external check

Workers Builds: guardscan-backend is a stale Cloudflare Git integration. It still targets this repository with root directory backend, but that directory was intentionally moved to the private ntanwir10/GuardScan-Monitoring repository in commit cfdc95a. Disconnecting or rewiring that external integration remains separate from this release-train PR.

External onboarding still required

Publication remains fail-closed with RELEASE_AUTOMATION_ENABLED=false until the inert default-branch bootstrap, GitHub App permissions, OIDC trusted publishers, signing identities, moderated-registry credentials, and rehearsals in docs/RELEASE_ONBOARDING.md are complete. No package publication is authorized by merging this draft alone.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Jul 26, 2026

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
❌ Deployment failed
View logs
guardscan-backend c787d6e Jul 26 2026, 04:47 AM

@coderabbitai

coderabbitai Bot commented Jul 26, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Draft detected.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 08835726-d488-4e85-bb7f-601f7ad69a71

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant