Certify pm CLI 2026.9.21, move merge drivers onto the canonical pm-ops launcher, and fix release visibility - #113
Conversation
…cal pm-ops launcher - Pins @unbrained/pm-cli 2026.9.21, pm-ops 2026.9.18 and pm-changelog 2026.9.18 exactly (package.json and package-lock.json). - scripts/prepare-merge-driver.ts is now a thin launcher over pm-ops/merge-driver, replacing the untyped prepare-merge-driver.mjs; one canonical, tested installer instead of a private copy per repository. - CI installs the drivers before `pm health --strict-exit --require-merge-drivers`, so a clone without them fails the gate instead of hard-conflicting tracker files on the next merge. - Release workflow: 10-minute npm visibility window, GitHub Release decoupled from bun mirror lag with a visible gate step, and a best-effort backfill of missing Releases (companion pm-cli-website-3y5d). pm items: pm-starter-8vta, pm-starter-4tq9. Companion epic pm-cli-website-5s6z. release:check exits 0.
Reviewer's GuideThis PR upgrades and certifies the pm toolchain, makes merge-driver installation canonical and mandatory in CI, and restructures release automation to recover missing GitHub Releases while separating npm publication, Bun mirror verification, and release visibility. Sequence diagram for release publication and visibility gatessequenceDiagram
participant Workflow as Release workflow
participant NPM as npm registry
participant Git as Git tags
participant Bun as Bun mirror
participant GitHub as GitHub Releases
Workflow->>NPM: Publish npm package
loop Up to 20 reads over 10 minutes
Workflow->>NPM: npm view version and dist.attestations --prefer-online
end
Workflow->>Git: Push release tag
Workflow->>Bun: bun add published version
alt Publish and tag succeeded
Workflow->>GitHub: gh release create --verify-tag
end
alt Bun verification fails
Workflow->>Workflow: Fail job visibly
end
Flow diagram for backfilling missing GitHub Releasesflowchart TD
A[Fetch release tags] --> B{GitHub Release exists?}
B -->|Yes| A
B -->|No| C[Convert tag to npm version]
C --> D[npm view version attestations --prefer-online]
D --> E{Published and attested?}
E -->|No| F[Warn and skip tag]
E -->|Yes| G[Generate tag-scoped release notes]
G --> H{Notes generated?}
H -->|No| I[Warn and continue]
H -->|Yes| J[Create GitHub Release]
F --> A
I --> A
J --> A
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Hey - I've found 1 issue
Prompt for AI Agents
Please address the comments from this code review:
## Individual Comments
### Comment 1
<location path="package.json" line_range="38" />
<code_context>
"prepublishOnly": "npm run release:check",
"release:notes": "pm-changelog --pm-root .agents/pm --stdout --since-previous-tag --until-release-tag --release-version-from-package --date-from-version --item-url-base https://github.com/unbraind/pm-starter/blob/main/.agents/pm --respect-item-release --pm-bin ./node_modules/.bin/pm --pm-arg=--output-budget --pm-arg=unbounded --pm-arg=--output-limit --pm-arg=unbounded --github-step-summary",
- "prepare": "node scripts/prepare-merge-driver.mjs",
+ "prepare": "node scripts/prepare-merge-driver.ts",
"merge:install": "pm merge install",
"coverage": "npm run build && npm run build:test && node scripts/coverage-gate.ts",
</code_context>
<issue_to_address>
**issue (bug_risk):** The `prepare` hook unconditionally imports the devDependency `pm-ops`, so an install using `--omit=dev` fails with `ERR_MODULE_NOT_FOUND` before the hook can no-op. This breaks the README's documented production/`--omit=dev` installation path.
**Triggers:** When consumers install the package with development dependencies omitted.
**Suggested fix:** Keep the launcher dependency-free by dynamically importing `pm-ops` only when its CLI is available, or move the required implementation to a runtime dependency while preserving the no-op behavior for production installs.
</issue_to_address>Sourcery assessment
Needs a human reviewer. 1 finding to address first, and the release workflow can create externally visible GitHub Releases and backfill historical tags based on npm visibility and attestations, while also changing the publish and verification gates. Reverting the change would not undo a mistakenly created release or the visibility and downstream effects it already caused.
Blocking findings: package.json:38
|
The prepare launcher statically imports pm-ops, a devDependency, so the README's promise that production / --omit=dev installs cannot break was only true for registry installs (npm never runs prepare for a registry tarball). A production install of a clone omits pm-ops as well and must pass --ignore-scripts, which is what this fleet's own Dockerfiles do. Raised by Greptile and Sourcery on pm-starter#113. The canonical guarded launcher is tracked as companion item pm-cli-website-xy19.
CI ran an explicit pm merge install right before pm health --require-merge-drivers, so the gate only verified the step before it and would have passed with a broken prepare hook. Without that step, the health gate asserts what a fresh clone actually relies on: npm ci runs the prepare launcher, which installs the drivers through pm-ops/merge-driver. Verified on a fresh git clone: no merge.pm* keys before npm ci, all of them after, and pm health --strict-exit --require-merge-drivers exits 1 once they are removed. Raised by Greptile on pm-github#93.
The backfill created a GitHub Release for any fleet-shaped tag whose npm version carried some attestation, without proving the tag's commit produced that artifact, so a stale, moved or hand-made tag could get a misleading Release. Comparing the attested commit with the tag commit is not the fix either: this fleet's provenance names the workflow trigger commit, measured as the tag's direct parent on three real releases. The correct check (same repository and workflow, attested commit an ancestor of the tag) belongs in the canonical pm-ops release verifier. The 10-minute npm visibility window and the Release decoupled from bun mirror lag remain; they fix the root causes. Raised by Greptile on pm-brief#124 and pm-linear#121.
- release.yml: max_attempts is declared before refuse_unattested_or_fail, which expands it, so its visibility no longer depends on call-time reasoning (the fleet's bindings-before-use rule; Greptile on pm-todos#99). Behaviour is unchanged. - pm records: the release Issue no longer claims the backfill that review removed, and the certify Task describes CI as it now is (health gate right after npm ci, no separate install step). The final release.yml is byte-identical to a fresh run of the anchored applier on origin/main (identical).
The resolution, expected result and close reason still described the backfill step that review removed, and the close reason cited the earlier 7-scenario harness run. All three now state the two changes that ship, the 5 applicable harness scenarios, and that the backfill moved to companion item pm-cli-website-mxrp. Raised by Greptile on pm-slack#115.
Summary
Fleet wave of 2026-09-22 (companion epic
pm-cli-website-5s6z), applied by the fleet's deterministic wave script and verified by this repository's own gates.scripts/prepare-merge-driver.tsis a thin launcher overpm-ops/merge-driver(removed: scripts/prepare-merge-driver.mjs). CI runspm health --strict-exit --require-merge-driversright afternpm ci, with no separate install step, so the gate proves that the prepare hook installed the drivers. A broken launcher fails CI instead of silently leaving clones that hard-conflict.toon/history files on the next multi-agent merge.pm items
Review follow-ups
Findings tracked centrally rather than fixed per repository (one pm-ops release moves the whole fleet):
pm-cli-website-xy19: a guarded launcher so thatnpm ci --omit=devin a clone no-ops instead of failingpm-cli-website-mxrp: the release-workflow recovery harness as a checked-in pm-ops verifier run by everyrelease:check, plus the backfill with provenance-ancestry verification (the attested commit must be an ancestor of the tag; this fleet's provenance names the trigger commit,pm-cli-website-nodo)Verification
git config --get-regexp '^merge\.pm'afternpm cipm health --strict-exit --require-merge-driversnpm run release:checkverify-release-publish-attestation: every publish invocation is attested.)changelog:fullthenchangelog:checkDependabot PRs are not absorbed here and will rebase onto this change.
Summary by Sourcery
Certify the updated pm toolchain, enforce canonical merge-driver setup, and make releases resilient to npm and Bun propagation delays.
Bug Fixes:
Enhancements:
CI:
Deployment:
Documentation:
Chores:
Summary by cubic
Certifies pm CLI 2026.9.21, moves merge-driver setup onto the canonical
pm-opslauncher, and makes GitHub Release creation resilient to npm/Bun propagation delays so a late-visible publish no longer skips the Release.Merge drivers
@unbrained/pm-cli2026.9.21,pm-changelog2026.9.18, andpm-ops2026.9.18 inpackage.jsonandpackage-lock.json.scripts/prepare-merge-driver.mjswith a thin launcher overpm-ops/merge-driver.pm health --strict-exit --require-merge-driverswith no explicitpm merge install, so a brokennpm ciprepare hook fails CI instead of masking itself.pm-opsdevDependency, so a production install of a clone must pass--ignore-scripts.Release workflow
--prefer-onlinereads, and declaresmax_attemptsbefore use, so a publish the registry accepts late is treated as success rather than failure.Written for commit cc17fce. Summary will update on new commits.