Skip to content

Certify pm CLI 2026.9.21, move merge drivers onto the canonical pm-ops launcher, and fix release visibility - #117

Merged
unbraind merged 6 commits into
mainfrom
pm-cli-2026-9-21-canonical-merge-driver-release-window
Sep 22, 2026
Merged

unbraind merged 6 commits into
mainfrom
pm-cli-2026-9-21-canonical-merge-driver-release-window

Conversation

@unbraind

@unbraind unbraind commented Sep 22, 2026 •

Copy link
Copy Markdown
Owner

Summary

Fleet wave of 2026-09-22 (companion epic pm-cli-website-5s6z), applied by the fleet's deterministic wave script and verified by this repository's own gates.

  • Certify pm CLI 2026.9.21, with exact pins in package.json and package-lock.json: @unbrained/pm-cli 2026.9.17 -> 2026.9.21, pm-changelog 2026.9.16 -> 2026.9.18, pm-ops 2026.9.13 -> 2026.9.18.
  • Canonical merge driver: scripts/prepare-merge-driver.ts is a thin launcher over pm-ops/merge-driver (removed: scripts/prepare-merge-driver.mjs). CI runs pm health --strict-exit --require-merge-drivers right after npm ci, with no separate install step, so the gate proves that the prepare hook installed the drivers. A broken launcher fails CI instead of silently leaving clones that hard-conflict .toon/history files on the next multi-agent merge.
  • Release workflow: 10-minute npm visibility window and a GitHub Release decoupled from bun mirror lag, with a visible gate step for bun failures (companion pm-cli-website-3y5d). The backfill step first proposed here was removed after review; see Review follow-ups.

pm items

Review follow-ups

  • 56109e3: State the real install contract of the canonical merge-driver launcher
  • 306902a: Let CI prove that npm ci's prepare hook installs the merge drivers
  • 3bf2372: Drop the release backfill step until it can verify provenance ancestry
  • 0746875: Declare max_attempts before use and correct the wave's pm records
  • c585c42: Make every closure field of the release Issue match the final scope

Findings tracked centrally rather than fixed per repository (one pm-ops release moves the whole fleet):

  • companion pm-cli-website-xy19: a guarded launcher so that npm ci --omit=dev in a clone no-ops instead of failing
  • companion pm-cli-website-mxrp: the release-workflow recovery harness as a checked-in pm-ops verifier run by every release:check, plus the backfill with provenance-ancestry verification (the attested commit must be an ancestor of the tag; this fleet's provenance names the trigger commit, pm-cli-website-nodo)

Verification

Check Result
git config --get-regexp '^merge\.pm' after npm ci drivers registered
pm health --strict-exit --require-merge-drivers exit 0
npm run release:check exit 0 (ok - the flag changes the heading: '## 2026.1.2-2 - 2026-01-02' with it, '## 202)
changelog:full then changelog:check regenerated after the pm writes, consistent

Dependabot PRs are not absorbed here and will rebase onto this change.

Summary by Sourcery

Certify the updated pm toolchain, centralize merge-driver setup, and make release status accurately reflect npm, bun, and GitHub visibility outcomes.

Bug Fixes:

  • Make release publication resilient to delayed npm visibility and ensure GitHub Releases are created after successful publishing and tagging even when bun mirror verification fails.
  • Surface bun mirror verification failures explicitly instead of masking them or silently skipping the GitHub Release.

Enhancements:

  • Route merge-driver setup through the canonical pm-ops launcher and use CI health checks to verify that npm ci provisions the required drivers.
  • Certify the pm CLI toolchain with updated pinned versions and document the merge-driver installation contract.

CI:

  • Update CI to rely on the npm prepare hook and strict pm health validation rather than a separate merge-driver installation step.

Documentation:

  • Document production-install behavior and the canonical merge-driver launcher.

Chores:

  • Record the associated pm task and issue with their histories and update the unreleased changelog.

Summary by cubic

Certifies the pm CLI toolchain at 2026.9.21, replaces the vendored merge-driver install with a thin launcher over pm-ops/merge-driver, and makes release creation resilient to npm propagation and bun mirror lag.

Bug Fixes

  • Widened the npm visibility window to 10 minutes (with --prefer-online reads and an end-of-window re-check) so a late-visible publish is treated as success instead of a false failure.
  • GitHub Releases are now created whenever publish and tag push succeed, independent of bun verification, and bun failures fail the job visibly through a gate step.
  • A planned backfill of missing Releases was dropped because it couldn't prove a tag's commit produced the artifact; that check moves to the canonical pm-ops release verifier.

Refactors

  • scripts/prepare-merge-driver.ts now delegates to the canonical pm-ops/merge-driver launcher, replacing the vendored scripts/prepare-merge-driver.mjs.
  • CI no longer runs an explicit pm merge install; the pm health --strict-exit --require-merge-drivers gate now proves that npm ci's prepare hook installed the drivers, so a broken prepare hook or missing drivers fail the gate instead of silently hard-conflicting tracker files on the next merge.
  • Pinned @unbrained/pm-cli 2026.9.17 → 2026.9.21, pm-changelog 2026.9.16 → 2026.9.18, and pm-ops 2026.9.13 → 2026.9.18 in package.json and package-lock.json.
  • Documented in the README that the launcher statically imports the devDependency pm-ops, so a production install of a clone must pass --ignore-scripts; registry installs never run prepare.

Written for commit c585c42. Summary will update on new commits.

Review in cubic

…cal pm-ops launcher

- Pins @unbrained/pm-cli 2026.9.21, pm-ops 2026.9.18 and pm-changelog 2026.9.18 exactly
  (package.json and package-lock.json).
- scripts/prepare-merge-driver.ts is now a thin launcher over pm-ops/merge-driver, replacing
  the untyped prepare-merge-driver.mjs; one
  canonical, tested installer instead of a private copy per repository.
- CI installs the drivers before `pm health --strict-exit --require-merge-drivers`, so a clone
  without them fails the gate instead of hard-conflicting tracker files on the next merge.
- Release workflow: 10-minute npm visibility window, GitHub Release decoupled from bun mirror lag with a visible gate step, and a best-effort backfill of missing Releases (companion pm-cli-website-3y5d).

pm items: pm-context-2axh, pm-context-ims7.
Companion epic pm-cli-website-5s6z. release:check exits 0.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @unbraind, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 4 hours and 51 minutes by commenting @sourcery-ai review. Upgrade to get a review now.

@coderabbitai

coderabbitai Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 986758c0-c2d6-46f2-bf94-7deafb1d0892


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sourcery-ai

sourcery-ai Bot commented Sep 22, 2026

Copy link
Copy Markdown

Reviewer's Guide

The PR certifies the 2026.9.21 pm toolchain, centralizes merge-driver installation in pm-ops with stricter CI enforcement, and restructures release automation to tolerate npm/bun propagation differences while backfilling missing GitHub Releases and keeping failures visible.

Sequence diagram for release publication and visibility handling

sequenceDiagram
    participant Workflow
    participant NPM
    participant Git
    participant Bun
    participant GitHub

    Workflow->>NPM: Publish package with provenance
    loop 10-minute visibility window
        Workflow->>NPM: Check version and dist.attestations with --prefer-online
    end
    NPM-->>Workflow: Attested version visible
    Workflow->>Git: Push release tag
    Workflow->>Bun: Verify bun add
    Workflow->>GitHub: Create GitHub Release
    alt Bun verification fails
        Bun-->>Workflow: Install failure
        Workflow->>Workflow: Fail job visibly
    else Bun verification succeeds
        Bun-->>Workflow: Install success
    end
Loading

Flow diagram for backfilling missing GitHub Releases

flowchart TD
    Tags[Fetch release tags] --> Existing{GitHub Release exists?}
    Existing -->|Yes| Next[Continue to next tag]
    Existing -->|No| Version[Convert tag to npm version]
    Version --> Attested{npm version visible with attestations?}
    Attested -->|No| Skip[Skip and warn]
    Attested -->|Yes| Notes[Generate tag-scoped release notes]
    Notes --> Create[Create GitHub Release]
    Create --> Next
    Notes -->|Failure| Warn[Warn and continue]
    Create -->|Failure| Warn
Loading

File-Level Changes

Change Details Files
Certify the updated pm toolchain and route merge-driver setup through pm-ops.
  • Pin pm CLI, changelog, and operations packages to the certified versions.
  • Replace the standalone merge-driver implementation with a thin TypeScript launcher over pm-ops.
  • Update the prepare hook and documentation, and require merge-driver installation/health checks in CI.
  • Record the associated task and issue artifacts and changelog entries.
package.json
package-lock.json
scripts/prepare-merge-driver.ts
scripts/prepare-merge-driver.mjs
README.md
CHANGELOG.md
.agents/pm/tasks/pm-context-2axh.toon
.agents/pm/issues/pm-context-ims7.toon
.agents/pm/history/pm-context-2axh.jsonl
.agents/pm/history/pm-context-ims7.jsonl
Make release publication resilient to npm visibility delays and recover missing GitHub Releases.
  • Backfill missing Releases by scanning valid release tags, checking online npm visibility and attestations, generating tag-scoped notes, and continuing best-effort on errors.
  • Extend post-publish npm reconciliation to a 10-minute online visibility window with a final read.
  • Separate bun mirror verification from Release creation: create the Release after successful publish/tagging, then fail visibly if bun verification fails.
  • Add step IDs and outcome-based workflow conditions so bun failures cannot silently suppress Releases.
.github/workflows/release.yml

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@greptile-apps

greptile-apps Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

The PR appears safe to merge; no new actionable defects remain in the changes since the previous review.

Summary

This PR certifies the updated pm toolchain, delegates merge-driver preparation to the canonical pm-ops launcher, and makes release visibility resilient to npm propagation and Bun mirror lag.

  • Pins @unbrained/pm-cli, pm-changelog, and pm-ops to the certified fleet versions.
  • Makes CI verify that the prepare lifecycle provisioned clone-local merge drivers.
  • Extends attested npm publication reconciliation to a ten-minute visibility window.
  • Creates the GitHub Release after successful publication and tagging even if Bun verification fails, while preserving a visible job failure for that Bun failure.
  • Removes the unsafe proposed historical-release backfill and aligns the pm records with the final implementation.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart TD
    A[npm ci] --> B[prepare hook]
    B --> C[pm-ops merge-driver launcher]
    C --> D[Clone-local merge drivers]
    D --> E[Strict CI health gate]

    F[Publish with provenance] --> G{Attested version visible?}
    G -- Delayed --> H[Poll npm for up to 10 minutes]
    H --> G
    G -- Yes --> I[Push verified tag]
    I --> J[Bun install verification]
    I --> K[Create GitHub Release]
    J -- Success --> L[Release job succeeds]
    J -- Failure --> M[Visible Bun failure gate]
    K --> L
    K --> M
Loading

Reviews (6) · Last reviewed commit: "Make every closure field of the release ..."

Comment thread .github/workflows/release.yml Outdated
The prepare launcher statically imports pm-ops, a devDependency, so the
README's promise that production / --omit=dev installs cannot break was
only true for registry installs (npm never runs prepare for a registry
tarball). A production install of a clone omits pm-ops as well and must
pass --ignore-scripts, which is what this fleet's own Dockerfiles do.

Raised by Greptile and Sourcery on pm-starter#113. The canonical guarded
launcher is tracked as companion item pm-cli-website-xy19.
CI ran an explicit pm merge install right before pm health
--require-merge-drivers, so the gate only verified the step before it and
would have passed with a broken prepare hook. Without that step, the
health gate asserts what a fresh clone actually relies on: npm ci runs the
prepare launcher, which installs the drivers through pm-ops/merge-driver.

Verified on a fresh git clone: no merge.pm* keys before npm ci, all of
them after, and pm health --strict-exit --require-merge-drivers exits 1
once they are removed. Raised by Greptile on pm-github#93.
The backfill created a GitHub Release for any fleet-shaped tag whose npm
version carried some attestation, without proving the tag's commit
produced that artifact, so a stale, moved or hand-made tag could get a
misleading Release. Comparing the attested commit with the tag commit is
not the fix either: this fleet's provenance names the workflow trigger
commit, measured as the tag's direct parent on three real releases. The
correct check (same repository and workflow, attested commit an ancestor
of the tag) belongs in the canonical pm-ops release verifier.

The 10-minute npm visibility window and the Release decoupled from bun
mirror lag remain; they fix the root causes. Raised by Greptile on
pm-brief#124 and pm-linear#121.
@greptile-apps

This comment has been minimized.

- release.yml: max_attempts is declared before refuse_unattested_or_fail,
  which expands it, so its visibility no longer depends on call-time
  reasoning (the fleet's bindings-before-use rule; Greptile on
  pm-todos#99). Behaviour is unchanged.
- pm records: the release Issue no longer claims the backfill that review
  removed, and the certify Task describes CI as it now is (health gate
  right after npm ci, no separate install step).

The final release.yml is byte-identical to a fresh run of the anchored
applier on origin/main (identical).
The resolution, expected result and close reason still described the
backfill step that review removed, and the close reason cited the
earlier 7-scenario harness run. All three now state the two changes that
ship, the 5 applicable harness scenarios, and that the backfill moved to
companion item pm-cli-website-mxrp. Raised by Greptile on pm-slack#115.
@unbraind
unbraind merged commit 8c0a70d into main Sep 22, 2026
11 checks passed
@unbraind
unbraind deleted the pm-cli-2026-9-21-canonical-merge-driver-release-window branch September 22, 2026 06:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant