Prepare workspace release with licensed auth and router notices - #60
Merged
Merged
Conversation
added 6 commits
September 15, 2026 08:35
first-assist
marked this pull request as ready for review
September 15, 2026 01:15
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Prepare the next immutable workspace release with MIT-licensed agql-auth v0.19.1 and a router archive that carries its third-party notice/source evidence. The verified auth tag resolves to 96bafbf21adbc7ad963729e1e981feaba5debe90.
Seven dependencies have license declarations but no recovered standalone notice file. Their source archives and explicit dispositions are retained for the designated owner review; the notice configuration does not grant distribution approval. The quick-xml/rsa advisory findings retain ADR-0008's existing execution restrictions.
Validation
All 66 local release commands pass, including every provider, test-owned SQLite/PostgreSQL/MSSQL lanes, Clippy, Rustdoc, SemVer and dependency trees. Release lanes use stable Rust 1.98.1; router MSRV/SemVer lanes use Rust 1.90.0. The subsequent packaging-only commit preserves that entire Rust package and Cargo.lock tree.
Thirteen notice-packaging regressions, six manifest tests, documentation, inventory, release state, package policy, actionlint and the clean tag-tree manifest preview pass. A local optimized router build passes its CLI contract; an archive check verifies the binary and every packaged notice/source hash. The local candidate requires at most GLIBC_2.38 symbol versions. Hosted CI and Managed SMB pass on final commit be29f48.
Existing versions were already advanced for this release. Immutable tags for unchanged storage, backup and protocol packages retain their original source trees. Before publication, configure the protected release environment and immutable releases, and retain the designated router distribution approval reference.