Skip to content

release: ship GuardScan 1.1.0 through the zero-touch release train - #32

Draft
ntanwir10 wants to merge 25 commits into
mainfrom
release/1.1.0
Draft

release: ship GuardScan 1.1.0 through the zero-touch release train#32
ntanwir10 wants to merge 25 commits into
mainfrom
release/1.1.0

Conversation

@ntanwir10

@ntanwir10 ntanwir10 commented Jul 26, 2026

Copy link
Copy Markdown
Owner

What changed

  • hardens offline scanning, privacy-sensitive state, provider execution, and deterministic npm packaging
  • adds the zero-touch RC-to-stable release train with append-only ledger events, reconciliation, rollback evidence, signed native-artifact contracts, npm/PyPI publication, and moderated-channel tracking
  • adds one shared ntanwir10/homebrew-tap catalog for both Homebrew and Scoop, generated from an immutable GuardScan release manifest and kept in sync through pull requests plus scheduled reconciliation
  • keeps a future Homebrew Core submission as an optional non-blocking discoverability path while the first-party tap remains authoritative
  • documents one-time provider onboarding and the public install contracts

Why

The previous release scaffold only published npm directly and could not prove native artifacts, cross-channel identity, promotion timing, or rollback state. This release makes GuardScan the single release authority and treats every downstream package definition as a reproducible projection of the same immutable manifest.

Validation

  • final hosted release gate: https://github.com/ntanwir10/GuardScan/actions/runs/30188343801
  • all 27 GuardScan jobs passed at exact PR head c787d6e468f82f7c2ee04b866bac8c7f817efe31
  • npm run typecheck
  • npm run build
  • npm test -- --runInBand — 69 suites, 806 tests
  • npm test -- --coverage --runInBand — 69 suites, 806 tests
  • npm run lint:ratchet
  • npm 10.9.8 and npm 11 clean-install lockfile validation
  • npm audit --omit=dev --audit-level=high — 0 vulnerabilities
  • npm run test:release — 8 suites, 72 tests
  • npm run test:package
  • npm, pnpm, Yarn Classic, Yarn Modern, and Bun package-manager smoke tests
  • all five required standalone SEA target contracts
  • release schema/config validation
  • workflow YAML and embedded Bash/Python/Node syntax validation
  • git diff --check
  • two independent final release package builds produced the same SHA-256: 589a6ef315df8c77b4f5c27f6269f8d60d974d3913ef16e7f4020eaa6b33a420
  • shared Homebrew/Scoop catalog bootstrap merged through ci: bootstrap shared GuardScan channel catalog homebrew-tap#1 with its post-merge verification green

Known unrelated external check

Workers Builds: guardscan-backend is a stale Cloudflare Git integration. It still targets this repository with root directory backend, but that directory was intentionally moved to the private ntanwir10/GuardScan-Monitoring repository in commit cfdc95a. The Cloudflare build fails before installation with root directory not found; the existing production Worker and api.guardscancli.com/health remain healthy. Disconnecting or rewiring that external integration is intentionally separate from this release-train PR.

External onboarding still required

Publication is fail-closed with RELEASE_AUTOMATION_ENABLED=false until the GitHub App, OIDC trusted publishers, signing identities, and moderated-registry credentials described in docs/RELEASE_ONBOARDING.md are configured. The eight protected zero-reviewer environments, shared catalog repository, release ledger branch, immutable GitHub releases, and branch protections are already bootstrapped.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Jul 26, 2026

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
❌ Deployment failed
View logs
guardscan-backend c787d6e Jul 26 2026, 04:47 AM

@coderabbitai

coderabbitai Bot commented Jul 26, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Draft detected.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: deba5092-345f-4488-8dbf-e67fcd2b1dde

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant