Skip to content

Certify pm CLI 2026.9.21, move merge drivers onto the canonical pm-ops launcher, and fix release visibility - #115

Merged
unbraind merged 6 commits into
mainfrom
pm-cli-2026-9-21-canonical-merge-driver-release-window
Sep 22, 2026
Merged

unbraind merged 6 commits into
mainfrom
pm-cli-2026-9-21-canonical-merge-driver-release-window

Conversation

@unbraind

@unbraind unbraind commented Sep 22, 2026 •

Copy link
Copy Markdown
Owner

Summary

Fleet wave of 2026-09-22 (companion epic pm-cli-website-5s6z), applied by the fleet's deterministic wave script and verified by this repository's own gates.

  • Certify pm CLI 2026.9.21, with exact pins in package.json and package-lock.json: @unbrained/pm-cli 2026.9.17 -> 2026.9.21, pm-changelog 2026.9.16 -> 2026.9.18, pm-ops 2026.9.13 -> 2026.9.18.
  • Canonical merge driver: scripts/prepare-merge-driver.ts is a thin launcher over pm-ops/merge-driver (removed: scripts/prepare-merge-driver.mjs). CI runs pm health --strict-exit --require-merge-drivers right after npm ci, with no separate install step, so the gate proves that the prepare hook installed the drivers. A broken launcher fails CI instead of silently leaving clones that hard-conflict .toon/history files on the next multi-agent merge.
  • Release workflow: 10-minute npm visibility window and a GitHub Release decoupled from bun mirror lag, with a visible gate step for bun failures (companion pm-cli-website-3y5d). The backfill step first proposed here was removed after review; see Review follow-ups.

pm items

Review follow-ups

  • edd6024: State the real install contract of the canonical merge-driver launcher
  • 9df292d: Let CI prove that npm ci's prepare hook installs the merge drivers
  • 13adbd4: Drop the release backfill step until it can verify provenance ancestry
  • 620b60c: Declare max_attempts before use and correct the wave's pm records
  • bf45345: Make every closure field of the release Issue match the final scope

Findings tracked centrally rather than fixed per repository (one pm-ops release moves the whole fleet):

  • companion pm-cli-website-xy19: a guarded launcher so that npm ci --omit=dev in a clone no-ops instead of failing
  • companion pm-cli-website-mxrp: the release-workflow recovery harness as a checked-in pm-ops verifier run by every release:check, plus the backfill with provenance-ancestry verification (the attested commit must be an ancestor of the tag; this fleet's provenance names the trigger commit, pm-cli-website-nodo)

Verification

Check Result
git config --get-regexp '^merge\.pm' after npm ci drivers registered
pm health --strict-exit --require-merge-drivers exit 0
npm run release:check exit 0 (ok - the flag changes the heading: '## 2026.1.2 - 2026-01-02' with it, '## 2026.)
changelog:full then changelog:check regenerated after the pm writes, consistent

Dependabot PRs are not absorbed here and will rebase onto this change.


Summary by cubic

Certifies pm CLI 2026.9.21 (pinned with pm-changelog 2026.9.18 and pm-ops 2026.9.18), moves the merge-driver installer onto the canonical pm-ops launcher with CI enforcement, and fixes release visibility when npm propagates late or bun's mirror lags.

Merge drivers

  • scripts/prepare-merge-driver.ts is now a thin launcher over pm-ops/merge-driver, replacing the vendored prepare-merge-driver.mjs.
  • CI no longer runs an explicit install; the health gate now verifies what a fresh clone actually relies on, so a clone whose npm ci prepare hook doesn't wire the drivers fails instead of silently hard-conflicting tracker files.
  • README states the real install contract: registry installs never run prepare, and a production install of a clone must pass --ignore-scripts.

Release workflow

  • The npm reconcile now waits up to 10 minutes for visibility and reports honestly when a publish isn't confirmed instead of claiming it failed.
  • The GitHub Release is created whenever the publish and tag push succeed, independent of bun verification; bun failures now fail the job through a visible gate step.

Written for commit bf45345. Summary will update on new commits.

Review in cubic

Summary by Sourcery

Certify the updated pm toolchain, enforce canonical merge-driver setup, and make release publication resilient to registry propagation and Bun mirror delays.

Bug Fixes:

  • Improve release handling so npm propagation delays and Bun mirror lag no longer suppress creation of an otherwise valid GitHub Release.
  • Report Bun installation verification failures explicitly while preserving the release record when npm publishing and tagging succeed.

Enhancements:

  • Certify the project against pm CLI 2026.9.21, pm-changelog 2026.9.18, and pm-ops 2026.9.18.
  • Use the canonical pm-ops merge-driver launcher and require CI to verify merge drivers are installed after dependency installation.
  • Clarify the merge-driver installation contract for development and production installs.

CI:

  • Strengthen CI validation by requiring registered merge drivers in the health check.

Deployment:

  • Extend npm and Bun visibility checks to ten minutes and decouple GitHub Release creation from Bun mirror verification while retaining a visible failure gate.

Documentation:

  • Document the canonical merge-driver launcher and installation behavior.

Chores:

  • Add project-management records and generated history for the release and merge-driver work.

…cal pm-ops launcher

- Pins @unbrained/pm-cli 2026.9.21, pm-ops 2026.9.18 and pm-changelog 2026.9.18 exactly
  (package.json and package-lock.json).
- scripts/prepare-merge-driver.ts is now a thin launcher over pm-ops/merge-driver, replacing
  the untyped prepare-merge-driver.mjs; one
  canonical, tested installer instead of a private copy per repository.
- CI installs the drivers before `pm health --strict-exit --require-merge-drivers`, so a clone
  without them fails the gate instead of hard-conflicting tracker files on the next merge.
- Release workflow: 10-minute npm visibility window, GitHub Release decoupled from bun mirror lag with a visible gate step, and a best-effort backfill of missing Releases (companion pm-cli-website-3y5d).

pm items: pm-slack-h3ba, pm-slack-x0wg.
Companion epic pm-cli-website-5s6z. release:check exits 0.
@coderabbitai

coderabbitai Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 61a091aa-071d-4b45-81ff-90819f99de09


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @unbraind, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 4 hours and 45 minutes by commenting @sourcery-ai review. Upgrade to get a review now.

@sourcery-ai

sourcery-ai Bot commented Sep 22, 2026

Copy link
Copy Markdown

Reviewer's Guide

This PR certifies the 2026.9.21 pm toolchain, centralizes merge-driver setup in pm-ops with CI enforcement, and hardens release automation against npm propagation and Bun mirror lag by adding attested release backfill, decoupled GitHub Release creation, and explicit Bun failure reporting.

Sequence diagram for release publication and visibility handling

sequenceDiagram
    participant Workflow
    participant NPM
    participant Git
    participant Bun
    participant GitHub

    Workflow->>NPM: Publish package with provenance
    NPM-->>Workflow: Publish result
    alt Version not immediately visible
        loop Up to 10-minute visibility window
            Workflow->>NPM: npm view --prefer-online
            NPM-->>Workflow: Version and attestations
        end
    end
    Workflow->>Git: Push release tag
    Workflow->>Bun: bun add published version
    Bun-->>Workflow: Verification result
    Workflow->>GitHub: Create Release after publish and tag push
    alt Bun verification failed
        Workflow->>Workflow: Fail job visibly
    end
Loading

Flow diagram for backfilling missing GitHub Releases

flowchart TD
    TAGS["Fetch fleet-shaped release tags"] --> EXISTS{"GitHub Release exists?"}
    EXISTS -->|Yes| NEXT["Continue to next tag"]
    EXISTS -->|No| VERSION["Convert tag to npm version"]
    VERSION --> ATTESTED{"npm version visible with attestations?"}
    ATTESTED -->|No| SKIP["Warn and skip backfill"]
    ATTESTED -->|Yes| NOTES["Generate tag-scoped release notes"]
    NOTES --> CREATE["gh release create --verify-tag"]
    CREATE --> NEXT
Loading

File-Level Changes

Change Details Files
Certify updated pm tooling and route merge-driver installation through the canonical pm-ops implementation.
  • Pin pm CLI, changelog, and operations packages to the certified versions.
  • Replace the vendored merge-driver script with a thin TypeScript launcher.
  • Install merge drivers in CI and require them during strict pm health checks.
  • Update package metadata and documentation for the new launcher.
package.json
package-lock.json
scripts/prepare-merge-driver.ts
scripts/prepare-merge-driver.mjs
.github/workflows/ci.yml
README.md
Make release publication resilient to npm propagation delays while preserving attestation requirements.
  • Use online npm reads and extend the post-publish visibility reconciliation to a 10-minute window.
  • Improve failure reporting when npm visibility cannot be confirmed, without downgrading provenance checks.
  • Keep exact-version attestation checks for release decisions and backfill eligibility.
.github/workflows/release.yml
Decouple GitHub Release creation from Bun mirror verification and recover previously missing releases.
  • Create the GitHub Release after successful publish and tag push even if Bun verification fails.
  • Run Bun installation verification for up to 10 minutes and fail through an explicit visible gate.
  • Backfill missing releases only for attested fleet-shaped tags, generating tag-scoped notes best-effort.
.github/workflows/release.yml
Record the fleet work items and regenerate project changelog entries for the release-process and tooling changes.
  • Add the completed task and issue tracker records with their history.
  • Document release visibility fixes and pm tooling certification in the Unreleased changelog.
.agents/pm/tasks/pm-slack-h3ba.toon
.agents/pm/issues/pm-slack-x0wg.toon
.agents/pm/history/pm-slack-h3ba.jsonl
.agents/pm/history/pm-slack-x0wg.jsonl
CHANGELOG.md

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@greptile-apps

greptile-apps Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

The PR appears safe to merge; no outstanding previous findings or actionable new defects remain.

Summary

Certifies the updated pm toolchain, delegates merge-driver preparation to the canonical pm-ops launcher, strengthens CI verification, and makes release completion independent of delayed Bun visibility while keeping Bun failures visible.

  • Pins @unbrained/pm-cli, pm-changelog, and pm-ops to the certified fleet versions.
  • Requires CI to verify that npm ci installed the configured merge drivers.
  • Extends npm and Bun visibility windows and creates the GitHub Release after successful publication and tagging even if Bun verification fails.
  • Corrects the project-management closure record so it no longer claims the removed backfill feature was delivered.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart LR
  A[Verified protected main commit] --> B[Publish package with provenance]
  B --> C[Confirm attested npm visibility]
  C --> D[Push matching release tag]
  D --> E[Verify installation through Bun]
  D --> F[Create GitHub Release]
  E -->|Success| G[Release job succeeds]
  E -->|Failure after retry window| H[Visible failure gate]
  F --> H
Loading

Reviews (5) · Last reviewed commit: "Make every closure field of the release ..."

Comment thread scripts/prepare-merge-driver.ts
Comment thread .github/workflows/release.yml Outdated
The prepare launcher statically imports pm-ops, a devDependency, so the
README's promise that production / --omit=dev installs cannot break was
only true for registry installs (npm never runs prepare for a registry
tarball). A production install of a clone omits pm-ops as well and must
pass --ignore-scripts, which is what this fleet's own Dockerfiles do.

Raised by Greptile and Sourcery on pm-starter#113. The canonical guarded
launcher is tracked as companion item pm-cli-website-xy19.
CI ran an explicit pm merge install right before pm health
--require-merge-drivers, so the gate only verified the step before it and
would have passed with a broken prepare hook. Without that step, the
health gate asserts what a fresh clone actually relies on: npm ci runs the
prepare launcher, which installs the drivers through pm-ops/merge-driver.

Verified on a fresh git clone: no merge.pm* keys before npm ci, all of
them after, and pm health --strict-exit --require-merge-drivers exits 1
once they are removed. Raised by Greptile on pm-github#93.
The backfill created a GitHub Release for any fleet-shaped tag whose npm
version carried some attestation, without proving the tag's commit
produced that artifact, so a stale, moved or hand-made tag could get a
misleading Release. Comparing the attested commit with the tag commit is
not the fix either: this fleet's provenance names the workflow trigger
commit, measured as the tag's direct parent on three real releases. The
correct check (same repository and workflow, attested commit an ancestor
of the tag) belongs in the canonical pm-ops release verifier.

The 10-minute npm visibility window and the Release decoupled from bun
mirror lag remain; they fix the root causes. Raised by Greptile on
pm-brief#124 and pm-linear#121.
@greptile-apps

This comment has been minimized.

- release.yml: max_attempts is declared before refuse_unattested_or_fail,
  which expands it, so its visibility no longer depends on call-time
  reasoning (the fleet's bindings-before-use rule; Greptile on
  pm-todos#99). Behaviour is unchanged.
- pm records: the release Issue no longer claims the backfill that review
  removed, and the certify Task describes CI as it now is (health gate
  right after npm ci, no separate install step).

The final release.yml is byte-identical to a fresh run of the anchored
applier on origin/main (identical).
Comment thread .agents/pm/issues/pm-slack-x0wg.toon Outdated
The resolution, expected result and close reason still described the
backfill step that review removed, and the close reason cited the
earlier 7-scenario harness run. All three now state the two changes that
ship, the 5 applicable harness scenarios, and that the backfill moved to
companion item pm-cli-website-mxrp. Raised by Greptile on pm-slack#115.
@unbraind
unbraind merged commit 296704a into main Sep 22, 2026
9 checks passed
@unbraind
unbraind deleted the pm-cli-2026-9-21-canonical-merge-driver-release-window branch September 22, 2026 06:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant