Skip to content

chore(release): cut 0.4.10 - #55

Merged
steipete merged 1 commit into
mainfrom
release/0.4.10
Sep 14, 2026
Merged

steipete merged 1 commit into
mainfrom
release/0.4.10

Conversation

@steipete

Copy link
Copy Markdown
Collaborator

Prepare goplaces 0.4.10 with the finalized release notes, led by redirect/API-key security fixes and corrected routing across the international date line.

Refresh the reviewed shared signing-helper library pin and its contract assertion. The helper changes sanitize credential-provider diagnostics, quote direct secret handoffs safely, start credential runners reliably, and drain signing-canary output before checking its status. Prefer the installed Homebrew Go 1.26 toolchain while retaining exact version and canonical-path checks, allowing release production alongside a newer default Go installation.

Validation: Go 1.26.8 build, unit and race tests, vet, lint, coverage, documentation metadata, release contract suites, security scans, credential-free snapshots and reproducibility checks, plus independent P0–P2 review. The signed tag and publication follow only after CI and the protected-main release preflight pass.

Homebrew remains held by the existing documented Formula/Cask handoff blocker.

@steipete
steipete requested a review from a team as a code owner September 14, 2026 01:49
@clawsweeper

clawsweeper Bot commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@clawsweeper clawsweeper Bot added P2 Normal priority bug or improvement with limited blast radius. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. labels Sep 14, 2026
@clawsweeper

clawsweeper Bot commented Sep 14, 2026

Copy link
Copy Markdown
Contributor

Codex review: needs maintainer review before merge. Reviewed September 13, 2026, 9:52 PM ET / September 14, 2026, 01:52 UTC.

ClawSweeper review

What this changes

Prepares the 0.4.10 release notes, updates the shared signing-helper library pin, and prefers Homebrew’s Go 1.26 installation while retaining exact toolchain checks.

Merge readiness

✅ Ready for maintainer review

This release preparation remains distinct from current main and the published v0.4.9 release. No blocking defect was found; collaborator-authored work also remains outside automatic cleanup.

Priority: P2
Reviewed head: 8a44443b2b2b00dd34737249a4804f4cb6723f86

Review scores

Measure Result What it means
Overall readiness 🐚 platinum hermit (4/6) A focused release patch with verified dependency provenance and no concrete blocking finding.
Proof confidence 🌊 off-meta tidepool Not applicable: The ordinary contributor-proof gate is exempt for this collaborator-authored PR; the inspected changes establish no unresolved material authority expansion requiring exceptional final-effect proof.
Patch quality 🐚 platinum hermit (4/6) No actionable review findings were identified.

Verification

Check Result Evidence
Real behavior Not applicable Not applicable: The ordinary contributor-proof gate is exempt for this collaborator-authored PR; the inspected changes establish no unresolved material authority expansion requiring exceptional final-effect proof.
Evidence reviewed 8 items Verified introduced scope: The local comparison matches the supplied introduction evidence: four files, eight added lines and seven removed lines, limited to release notes, release documentation, two script constants, and the matching pin assertion.
Toolchain and signing boundaries retained: Tool resolution still requires the canonical Homebrew Go 1.26.8 executable and validates its actual version. The helper is hashed, copied privately, and rechecked before execution; signing uses the frozen producer path and a restricted manifest. These execution sites establish the affirmative dependency on the external signing helper.
New dependency pin verified: GitHub repository metadata verified ownership as steipete/agent-scripts. The library at this revision hashes to 170b05a794e5ade32a603a01c7942f8170d44ccc13b678c5285076510a008baf, exactly matching the proposed pin. The previous pinned revision was independently checked against its previous digest.
Findings None None.
Security None None.

How this fits together

The local release pipeline turns protected-main source into signed, notarized binaries and verified GitHub release assets. It validates toolchains and signing helpers before entering the credential-bearing build process.

flowchart LR
  A[Protected main source] --> C[Release preflight]
  B[Pinned tools and signing helper] --> C
  C --> D[Signed and notarized builds]
  D --> E[Draft release assets]
  E --> F[Independent asset verification]
  F --> G[Gated publication]
Loading

Before merge

None.

Agent review details

Security

None.

Review metrics

None.

Technical review

Best possible solution:

Land the focused release preparation while preserving the documented protected-main, signing, verification, and publication gates and the separate Homebrew hold.

Do we have a high-confidence way to reproduce the issue?

Not applicable: this is release preparation, and no introduced failure was established through source review; runtime tests were not executed.

Is this the best way to solve the issue?

Yes: the patch uses the existing release pipeline, updates its exact helper pin, and fixes tool discovery without relaxing the accepted Go version or signing checks.

AGENTS.md: not found in the target repository.

Codex review notes: model internal, reasoning medium; reviewed against eb85c7372af0.

Labels

Label changes:

  • add P2: This is bounded release preparation with a verified signing-helper update and no demonstrated urgent regression introduced by the patch.
  • add rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🌊 off-meta tidepool and patch quality is 🐚 platinum hermit.
  • add status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Not applicable: The ordinary contributor-proof gate is exempt for this collaborator-authored PR; the inspected changes establish no unresolved material authority expansion requiring exceptional final-effect proof.

Label justifications:

  • P2: This is bounded release preparation with a verified signing-helper update and no demonstrated urgent regression introduced by the patch.
  • rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🌊 off-meta tidepool and patch quality is 🐚 platinum hermit.
  • status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Not applicable: The ordinary contributor-proof gate is exempt for this collaborator-authored PR; the inspected changes establish no unresolved material authority expansion requiring exceptional final-effect proof.

Evidence

What I checked:

  • Verified introduced scope: The local comparison matches the supplied introduction evidence: four files, eight added lines and seven removed lines, limited to release notes, release documentation, two script constants, and the matching pin assertion. (scripts/release-local:25, 8a44443b2b2b)
  • Toolchain and signing boundaries retained: Tool resolution still requires the canonical Homebrew Go 1.26.8 executable and validates its actual version. The helper is hashed, copied privately, and rechecked before execution; signing uses the frozen producer path and a restricted manifest. These execution sites establish the affirmative dependency on the external signing helper. (scripts/release-local:237, 8a44443b2b2b)
  • New dependency pin verified: GitHub repository metadata verified ownership as steipete/agent-scripts. The library at this revision hashes to 170b05a794e5ade32a603a01c7942f8170d44ccc13b678c5285076510a008baf, exactly matching the proposed pin. The previous pinned revision was independently checked against its previous digest. (skills/release-mac-app/scripts/lib/mac_release.sh, 7eb5b58b2276)
  • Dependency changes inspected: The complete library patch between the verified old and new pins matches the PR description: sanitized credential-provider diagnostics, shell-safe secret quoting, direct credential-runner startup with system Bash, and draining signing-canary output. The canary retains Apple trust verification and the same Developer ID authority predicate. The target rejects the optional package-secret configuration paths. (skills/release-mac-app/scripts/lib/mac_release.sh:1586, 7eb5b58b2276)
  • Still necessary on the reviewed main: The pinned main changelog retains an Unreleased section. GitHub reports v0.4.9 as the latest published release, published on 2026-08-24; the open-pull listing returned only this PR. No merged replacement was established. (CHANGELOG.md:3, eb85c7372af0)
  • Published release check: The latest release endpoint identifies v0.4.9 at target commit 424df65. (424df65ba142)

Likely related people:

  • unknown: The claimed source-line change could not be verified from bounded local history. (role: source history unknown; confidence: low)

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

@steipete
steipete merged commit ce57ab1 into main Sep 14, 2026
11 checks passed
@steipete
steipete deleted the release/0.4.10 branch September 14, 2026 02:10
@clawsweeper clawsweeper Bot mentioned this pull request Sep 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

P2 Normal priority bug or improvement with limited blast radius. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant