Skip to content

fix(release): add approved beta workflow and update dependencies - #2

Merged
omermorad merged 1 commit into
nextfrom
fix/beta-release-safeguards
Oct 8, 2026
Merged

omermorad merged 1 commit into
nextfrom
fix/beta-release-safeguards

Conversation

@omermorad

Copy link
Copy Markdown
Contributor

Scope

  • Add only the missing release-action.yml, using native GitHub Actions steps. No package-release capability is added to the Action.
  • Require manual dispatch from next, existing release environment approval, an exact reviewed commit, and an immutable beta version tag.
  • Verify the committed bundle and published Contractual beta dependencies before creating a GitHub prerelease. Major-alias updates default to off and require separate explicit approval.
  • Update vulnerable dependency resolutions and Vitest, satisfy its Vite peer dependency, and rebuild the committed bundle.
  • Preserve Action source, inputs/outputs, existing CI, the Node 22/24/26 matrix, and the existing changesets patch. No new scripts or test files.

Validation

  • Workflow linting and git diff --check pass.
  • Existing typecheck, all 22 tests, and build pass; the committed bundle is reproducible.

Remaining blockers and release order

This is a draft, not approval to release. pnpm audit --audit-level low still reports braces: GHSA-vfj7-8cjw-p6xm, with no patched version listed. No audit exclusions were added, and the release audit gate remains enabled.

The Action still uses published @contractual/cli and @contractual/governance 0.1.0-dev.7. Contractual must first receive separate approval for a beta publication; a follow-up PR can then upgrade these dependencies and rebuild the Action. The new workflow deliberately rejects the current dev dependency versions.

No workflows have been dispatched, and no tags, packages, releases, or major aliases have been published or moved. Existing history and version tags are unchanged. Omer must explicitly approve future tagging/publishing and any major-alias update.

@omermorad
omermorad marked this pull request as ready for review October 8, 2026 10:09
@omermorad
omermorad merged commit 4085fe5 into next Oct 8, 2026
6 checks passed
@omermorad
omermorad deleted the fix/beta-release-safeguards branch October 8, 2026 10:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant