Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/workflows/tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -52,11 +52,11 @@ jobs:
run: |
output="$RUNNER_TEMP/spdx-validation-artifact"
scripts/release-artifact build \
--version 2.2.1 \
--version 2.2.2 \
--commit "$(git rev-parse --verify 'HEAD^{commit}')" \
--output "$output"
"$RUNNER_TEMP/spdx-tools/bin/python" tests/validate-spdx.py \
"$output/base-bash-libs-v2.2.1.spdx.json"
"$output/base-bash-libs-v2.2.2.spdx.json"
"$RUNNER_TEMP/spdx-tools/bin/python" tests/validate-spdx.py \
--expect-missing-sha1 tests/fixtures/spdx/missing-sha1.spdx.json

Expand Down
4 changes: 4 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,10 @@ and versions are tracked in the repo-root `VERSION` file.

## [Unreleased]

No unreleased changes yet.

## [2.2.2] - 2026-10-08

### Documentation

- Repositioned the README around the v2 application framework, added a
Expand Down
12 changes: 6 additions & 6 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,9 +6,9 @@

| Version | License | Install | Release notes |
| --- | --- | --- | --- |
| `2.2.1` | [Apache-2.0](LICENSE) | `brew install basefoundry/base/base-bash-libs` | [v2.2.1](https://github.com/basefoundry/base-bash-libs/releases/tag/v2.2.1) |
| `2.2.2` | [Apache-2.0](LICENSE) | `brew install basefoundry/base/base-bash-libs` | [v2.2.2](https://github.com/basefoundry/base-bash-libs/releases/tag/v2.2.2) |

The v2.2.1 release is published with a deterministic [bundle archive](https://github.com/basefoundry/base-bash-libs/releases/download/v2.2.1/base-bash-libs-v2.2.1.tar.gz), [checksum manifest](https://github.com/basefoundry/base-bash-libs/releases/download/v2.2.1/base-bash-libs-v2.2.1.SHA256SUMS), [SPDX SBOM](https://github.com/basefoundry/base-bash-libs/releases/download/v2.2.1/base-bash-libs-v2.2.1.spdx.json), and [provenance statement](https://github.com/basefoundry/base-bash-libs/releases/download/v2.2.1/base-bash-libs-v2.2.1.provenance.json). First-party consumers and Homebrew can promote to its exact immutable commit through the coordinated release handoff; the original v2.0.0 cutover is recorded in completed issue #240.
The v2.2.2 release is published with a deterministic [bundle archive](https://github.com/basefoundry/base-bash-libs/releases/download/v2.2.2/base-bash-libs-v2.2.2.tar.gz), [checksum manifest](https://github.com/basefoundry/base-bash-libs/releases/download/v2.2.2/base-bash-libs-v2.2.2.SHA256SUMS), [SPDX SBOM](https://github.com/basefoundry/base-bash-libs/releases/download/v2.2.2/base-bash-libs-v2.2.2.spdx.json), and [provenance statement](https://github.com/basefoundry/base-bash-libs/releases/download/v2.2.2/base-bash-libs-v2.2.2.provenance.json). First-party consumers and Homebrew can promote to its exact immutable commit through the coordinated release handoff; the original v2.0.0 cutover is recorded in completed issue #240.

Base Bash is a Bash 4.2.53+ application framework and standard library for
declarative CLIs, typed configuration, lifecycle-safe cleanup, and reliable
Expand Down Expand Up @@ -70,7 +70,7 @@ for portable primitives, add the building blocks your script needs, and use
- **Building blocks:** [`lib/bash/process/lib_process.sh`](lib/bash/process/README.md)
Preview-only process-supervision primitives for owner-guardian liveness and
asynchronous cleanup, layered on the stdlib. This post-GA module first
shipped in `v2.1.0` and is included in the current immutable `v2.2.1`
shipped in `v2.1.0` and is included in the current immutable `v2.2.2`
release, but is not part of the stable API.
- [`lib/bash/file/lib_file.sh`](lib/bash/file/README.md)
File editing helpers built on the stdlib, including idempotent
Expand Down Expand Up @@ -201,7 +201,7 @@ Pin the checkout to the full current release commit instead of consuming the
moving default branch:

```bash
base_bash_libs_ref='v2.2.1'
base_bash_libs_ref='v2.2.2'
mkdir -p vendor
git clone https://github.com/basefoundry/base-bash-libs.git vendor/base-bash-libs
git -C vendor/base-bash-libs fetch --tags origin "$base_bash_libs_ref"
Expand Down Expand Up @@ -282,13 +282,13 @@ The repo-root `VERSION` file is the source of truth for the package version.
The top strip in this README and the runtime `BASE_BASH_LIBS_VERSION` constant
are validated against that file.

`v2.2.1` is the current stable release. It is a post-GA release on the v2 line;
`v2.2.2` is the current stable release. It is a post-GA release on the v2 line;
SemVer compatibility guarantees began at v2.0.0. See the [versioning and
release-line policy](docs/versioning-policy.md) for immutable consumption and
the post-GA support contract.

The `process` module remains preview-only. It first shipped in `v2.1.0` and is
included in `v2.2.1`, but is not part of the stable API; consumers pinned to
included in `v2.2.2`, but is not part of the stable API; consumers pinned to
`v2.0.0` do not have it.

Pinned checkout, archive, Homebrew, vendored, and standalone consumption is
Expand Down
2 changes: 1 addition & 1 deletion VERSION
Original file line number Diff line number Diff line change
@@ -1 +1 @@
2.2.1
2.2.2
4 changes: 2 additions & 2 deletions docs/consumer-validation-status.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ verified. The canonical archive SHA256 is

## Current release line and latest validation

The current release line is `base-bash-libs` v2.2.1, a documentation and
The current release line is `base-bash-libs` v2.2.2, a documentation and
release-contract patch with no intended public API or runtime behavior changes.
The latest completed full runtime validation is the [v2.2.0 release validation
run](https://github.com/basefoundry/base-bash-libs/actions/runs/37647096223), which
Expand All @@ -42,7 +42,7 @@ results count as independent adoption evidence.
| --- | --- | --- | --- | --- | --- |
| Base | First-party direct consumer | published [v1.8.0](https://github.com/basefoundry/base/releases/tag/v1.8.0), commit `26b9af5` | CI and source-checkout workflows pin GA commit `b424376` (v2.0.0) | PR [#1936](https://github.com/basefoundry/base/pull/1936) passed Python/pylint, integration, security, BATS, Ubuntu source-checkout, macOS smoke, and branch policy; v1.8.0 release preflight and publication passed | GA pin and release pass |
| Base Demo | First-party representative consumer | merged [#217](https://github.com/basefoundry/base-demo/pull/217) at `fb7a2b6` | CI and source-checkout workflows pin GA commit `b424376` (v2.0.0) | Local full validation and hosted validate, Ubuntu, and source-checkout checks passed | GA pin and validation pass |
| Base Bash Demo | First-party isolated reference consumer | released [v0.1.2](https://github.com/basefoundry/base-bash-libs-demo/releases/tag/v0.1.2) at `ab4da09`; docs and vendor target the verified v2.2.0 bundle while v2.2.1 is the current upstream release | Commits the verified canonical v2.2.0 bundle, lock, checksum manifest, provenance, and SPDX SBOM; candidate checks use an explicit release tag or full commit without changing the default pin | Ubuntu, exact Bash 4.2.53, macOS Homebrew Bash, and standalone artifact jobs passed for the v0.1.2 release preparation | v2.2.0 first-party release validation pass; excluded from independent count |
| Base Bash Demo | First-party isolated reference consumer | released [v0.1.2](https://github.com/basefoundry/base-bash-libs-demo/releases/tag/v0.1.2) at `ab4da09`; docs and vendor target the verified v2.2.0 bundle while v2.2.2 is the current upstream release | Commits the verified canonical v2.2.0 bundle, lock, checksum manifest, provenance, and SPDX SBOM; candidate checks use an explicit release tag or full commit without changing the default pin | Ubuntu, exact Bash 4.2.53, macOS Homebrew Bash, and standalone artifact jobs passed for the v0.1.2 release preparation | v2.2.0 first-party release validation pass; excluded from independent count |
| BankBuddy | Adjacent repository; no direct `base-bash-libs` reference | `e32561c` | None | Repository validation: **312 passed** | Excluded from the consumer count |
| BanyanLabs | Adjacent repository; no direct `base-bash-libs` reference | `15ef6cd` | None | Repository baseline present | Excluded from the consumer count |
| Homebrew | First-party package-manager consumer | merged [#85](https://github.com/basefoundry/homebrew-base/pull/85), bottle release `base-v1.8.0` | `base-bash-libs` v2.0.0 bundle and Base v1.8.0 archive are hash-pinned; both macOS bottles published | Both bottle builds and v2 API smoke tests passed; installed GA upgrade, formula tests, and rollback to Base 1.7.0/base-bash-libs 1.4.0 passed | GA formula, bottles, upgrade, and rollback pass |
Expand Down
4 changes: 2 additions & 2 deletions docs/pinned-consumption.md
Original file line number Diff line number Diff line change
Expand Up @@ -27,8 +27,8 @@ Verify the release asset checksum before unpacking it. Keep the complete
release commit (when published), and artifact provenance. Then source the
stdlib and use only package-relative imports:

The v2.2.1 release's canonical files are the archive,
`base-bash-libs-v2.2.1.SHA256SUMS`, SPDX SBOM, and provenance statement. Do not
The v2.2.2 release's canonical files are the archive,
`base-bash-libs-v2.2.2.SHA256SUMS`, SPDX SBOM, and provenance statement. Do not
substitute GitHub's automatic tag archive or a moving branch. Maintainers can
re-run the repository-owned `scripts/release-artifact verify-remote` check to
confirm that all four files still bind to the annotated tag commit.
Expand Down
6 changes: 3 additions & 3 deletions docs/v2/quickstart.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,11 +6,11 @@ checks, tests, and a deterministic bundle.

## 1. Select a verified release

Use the published `v2.2.1` tag and its verified commit. The reference is
Use the published `v2.2.2` tag and its verified commit. The reference is
intentionally required rather than defaulting to a moving branch:

```bash
export BASE_BASH_LIBS_REF='v2.2.1'
export BASE_BASH_LIBS_REF='v2.2.2'
mkdir -p vendor
git clone https://github.com/basefoundry/base-bash-libs.git vendor/base-bash-libs
git -C vendor/base-bash-libs fetch --tags origin "$BASE_BASH_LIBS_REF"
Expand All @@ -23,7 +23,7 @@ Do not replace the ref with `main`, a short SHA, or an automatically generated
archive URL. Verify the published checksum asset before distributing a
consumer application.

The preview `process` module is present in this v2.2.1 checkout. It first
The preview `process` module is present in this v2.2.2 checkout. It first
shipped in v2.1.0, remains outside the stable API, and should be used only
when a consumer explicitly opts into the preview contract; the stable `gh` API
may use it privately.
Expand Down
20 changes: 10 additions & 10 deletions docs/versioning-policy.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

## Current Release Line

`v2.2.1` is the current stable Base Bash release, backed by its verified
`v2.2.2` is the current stable Base Bash release, backed by its verified
canonical release asset. `v1.4.0` and earlier releases are historical references;
the 5/5 initiative has one stable target and will not create a stable `v1.5.0`
or reset the version to 0.x.
Expand All @@ -11,7 +11,7 @@ Those choices would either hide breaking changes inside the current 1.x
compatibility range or move version precedence backward.

Post-GA releases use one repository-owned v2 SemVer policy. Compatibility
guarantees began at `v2.0.0`; `v2.2.1` is the current release on that line:
guarantees began at `v2.0.0`; `v2.2.2` is the current release on that line:

```text
2.MINOR.PATCH
Expand Down Expand Up @@ -60,9 +60,9 @@ sentinel-file override. Maintainers can inspect any candidate without changing
GitHub state:

```bash
scripts/release check --version 2.2.1 --manifest base_manifest.yaml
scripts/release plan --version 2.2.1 --manifest base_manifest.yaml
scripts/release publish --version 2.2.1 --manifest base_manifest.yaml --dry-run
scripts/release check --version 2.2.2 --manifest base_manifest.yaml
scripts/release plan --version 2.2.2 --manifest base_manifest.yaml
scripts/release publish --version 2.2.2 --manifest base_manifest.yaml --dry-run
```

The generic `basectl release` command is not a substitute for this guard. Its
Expand All @@ -72,7 +72,7 @@ artifact, provenance, or GA gates.
Before any real publication attempt, run the repository-owned tag preflight:

```bash
scripts/release refs --version 2.2.1
scripts/release refs --version 2.2.2
```

The preflight checks both the exact candidate tag in the local checkout and the
Expand Down Expand Up @@ -126,13 +126,13 @@ The complete checkout, archive, Homebrew, vendored, and standalone verification
procedure is maintained in [`pinned-consumption.md`](pinned-consumption.md).

Do not install from an unpinned default-branch checkout. Use the canonical
`v2.2.1` release asset and verify its checksum, or pin the stable source to the
full commit resolved from the annotated `v2.2.1` tag:
`v2.2.2` release asset and verify its checksum, or pin the stable source to the
full commit resolved from the annotated `v2.2.2` tag:

```bash
git clone https://github.com/basefoundry/base-bash-libs.git vendor/base-bash-libs
git -C vendor/base-bash-libs fetch --tags origin v2.2.1
git -C vendor/base-bash-libs checkout --detach v2.2.1
git -C vendor/base-bash-libs fetch --tags origin v2.2.2
git -C vendor/base-bash-libs checkout --detach v2.2.2
base_bash_libs_commit="$(git -C vendor/base-bash-libs rev-parse HEAD)"
test "$(git -C vendor/base-bash-libs rev-parse HEAD)" = "$base_bash_libs_commit"
```
Expand Down
2 changes: 1 addition & 1 deletion lib/bash/base-bash-libs.release
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
schema_version=1
version=2.2.1
version=2.2.2
commit=unknown
dirty_state=unknown
provenance=release-artifact
Loading