Repository navigation
release: prepare 0.5.0 candidate and migration guidance #423
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
codeforester
merged 116 commits into
main
from
enhancement/307-20261003-v1-0-publish-the-post-0-4-3-fixes-under-a-new-package-versio
Oct 5, 2026
Merged
Changes from all commits
Commits
Show all changes
116 commits
Select commit
Hold shift + click to select a range
30e9e71
ci: cover all consumer fixtures in style and strict typing gates
codeforester 710208b
ci: keep Markdown examples under the documentation gate
codeforester 8bb0562
fix: preserve consumer logging ownership and routing
codeforester 6556889
perf: reuse logging locks and cache source paths
codeforester c87eeda
fix: enforce native Windows bundle retention safely
codeforester f0f9ece
ci: satisfy Windows retention style and typing checks
codeforester 9679928
perf: skip contended retention housekeeping
codeforester 6280ebb
security: bound and validate discovered project configuration
codeforester 7db92d8
test: exercise recursion failures at bounded YAML composition
codeforester 5e84077
fix: capture child and descriptor stdout in JSON envelopes
codeforester dd21781
ci: reconcile Project Intake through REST with scheduled recovery
codeforester a166e45
perf: cache second-precision human log timestamps
codeforester ee489ee
fix: preserve Python newline bytes in descriptor capture
codeforester baf0ff3
Merge branch 'enhancement/381-20261003-perf-lifecycle-logging-costs-1…
codeforester c7c21ae
Merge branch 'bug/378-20261003-bug-run-bundle-retention-is-inoperativ…
codeforester 40b1401
Merge branch 'enhancement/386-20261003-perf-retention-serializes-conc…
codeforester 74d2f5c
Merge branch 'security/385-20261003-security-validate-trust-of-ancest…
codeforester a83fa1f
Merge branch 'bug/379-20261003-bug-json-single-envelope-stdout-contra…
codeforester d352e43
Merge remote-tracking branch 'origin/main' into ci/393-20261003-ci-ru…
codeforester 6ee5cc9
Merge branch 'ci/393-20261003-ci-ruff-check-and-mypy-do-not-cover-the…
codeforester f9787b1
Merge branch 'bug/387-20261003-bug-configure-logger-closes-consumer-o…
codeforester 3780821
Merge branch 'enhancement/381-20261003-perf-lifecycle-logging-costs-1…
codeforester 333ac40
Merge branch 'bug/378-20261003-bug-run-bundle-retention-is-inoperativ…
codeforester 4f08c7d
Merge branch 'enhancement/386-20261003-perf-retention-serializes-conc…
codeforester 369f986
Merge branch 'security/385-20261003-security-validate-trust-of-ancest…
codeforester 514949a
Merge branch 'bug/379-20261003-bug-json-single-envelope-stdout-contra…
codeforester 08017ed
ci: gate concurrent retention and logging throughput
codeforester fbe36d6
release: prepare 0.5.0 candidate and migration guidance
codeforester 6e4394f
fix: avoid racing Windows lock-sidecar initialization
codeforester bd210cd
Merge branch 'enhancement/381-20261003-perf-lifecycle-logging-costs-1…
codeforester f1bda9a
Merge branch 'bug/378-20261003-bug-run-bundle-retention-is-inoperativ…
codeforester a1683c4
Merge branch 'enhancement/386-20261003-perf-retention-serializes-conc…
codeforester 5f39a1f
Merge branch 'security/385-20261003-security-validate-trust-of-ancest…
codeforester 7c65de4
Merge branch 'bug/379-20261003-bug-json-single-envelope-stdout-contra…
codeforester 727d575
Merge branch 'ci/311-20261003-v1-0-make-project-intake-resilient-to-g…
codeforester da28ad5
Merge branch 'ci/391-20261003-ci-add-concurrency-and-log-throughput-s…
codeforester 73770a5
ci: separate sustained persistence cost from hosted filesystem tails
codeforester bdf26d9
Merge branch 'ci/393-20261003-ci-ruff-check-and-mypy-do-not-cover-the…
codeforester c3eb5dc
Merge branch 'bug/387-20261003-bug-configure-logger-closes-consumer-o…
codeforester 0597aaa
Merge branch 'enhancement/381-20261003-perf-lifecycle-logging-costs-1…
codeforester b24372d
Merge branch 'bug/378-20261003-bug-run-bundle-retention-is-inoperativ…
codeforester d1fd067
Merge branch 'enhancement/386-20261003-perf-retention-serializes-conc…
codeforester 5ba2267
Merge branch 'security/385-20261003-security-validate-trust-of-ancest…
codeforester 77618cb
Merge branch 'bug/379-20261003-bug-json-single-envelope-stdout-contra…
codeforester 268bb7d
Merge branch 'ci/311-20261003-v1-0-make-project-intake-resilient-to-g…
codeforester 8ca0027
docs: regenerate public API signatures for configuration trust options
codeforester 9191a7e
Merge branch 'bug/387-20261003-bug-configure-logger-closes-consumer-o…
codeforester b7fd5df
Merge branch 'enhancement/381-20261003-perf-lifecycle-logging-costs-1…
codeforester 331e583
Merge branch 'enhancement/386-20261003-perf-retention-serializes-conc…
codeforester 6ba56eb
Merge branch 'security/385-20261003-security-validate-trust-of-ancest…
codeforester 5d8860e
docs: regenerate public API signatures for configuration trust options
codeforester 6e9d231
Merge branch 'bug/378-20261003-bug-run-bundle-retention-is-inoperativ…
codeforester e10d684
Merge branch 'ci/391-20261003-ci-add-concurrency-and-log-throughput-s…
codeforester dcb4dff
Merge branch 'ci/311-20261003-v1-0-make-project-intake-resilient-to-g…
codeforester 682811f
Merge branch 'bug/379-20261003-bug-json-single-envelope-stdout-contra…
codeforester 039564e
docs: use a published changelog URL in migration guidance
codeforester 07d5301
ci: calibrate logging budget from hosted macOS measurements
codeforester f78c756
Merge branch 'ci/391-20261003-ci-add-concurrency-and-log-throughput-s…
codeforester 857e52e
Merge main for branch maintenance (#426)
codeforester b48e444
Merge updated PR #414 for branch maintenance (#426)
codeforester 0441cec
Merge updated PR #419 for branch maintenance (#426)
codeforester 9012457
Merge updated PR #418 for branch maintenance (#426)
codeforester 96fba37
Merge updated PR #422 for branch maintenance (#426)
codeforester f5330b2
Merge updated PR #420 for branch maintenance (#426)
codeforester 65a3689
Merge updated PR #421 for branch maintenance (#426)
codeforester c4af745
Merge updated PR #417 for branch maintenance (#426)
codeforester 66ce268
Merge updated PR #415 for branch maintenance (#426)
codeforester e82ce1f
Merge updated PR #416 for branch maintenance (#426)
codeforester 2a0a9bb
fix: preserve incomplete JSON stdout captures
codeforester 3d397ae
security: clarify discovered config verification
codeforester 82f5df1
release: address changelog and migration review
codeforester b7f54fe
ci: isolate scheduled Project reconciliation failures
codeforester 8826871
ci: control hosted contention benchmark batches
codeforester b00c288
fix: defer contended retention index refresh
codeforester 9db3464
fix: preserve logger routing and levels
codeforester fbcc75c
fix: harden logging caches and sidecar locks
codeforester 841d1e6
fix: handle Windows retention reparse leaves
codeforester 72336ec
ci: expose consumer typing source coverage
codeforester 3b4fc3f
docs: document process-wide JSON capture
codeforester 311c280
test: verify retention converges after contention
codeforester ae935d1
fix: serialize logger reconfiguration
codeforester ff3f148
security: make trust errors actionable
codeforester 97135b0
fix: type incomplete capture failures explicitly
codeforester f15f2c2
style: clean retention convergence test
codeforester 990cb66
style: format typing gate test
codeforester 59c7249
fix: validate README against latest published release
codeforester 9ba2a3a
fix: preserve incomplete JSON stdout captures
codeforester eb3ae08
docs: document process-wide JSON capture
codeforester 73b7eb7
fix: type incomplete capture failures explicitly
codeforester 50b0695
style: format sidecar lock condition
codeforester c8e829d
Merge remote-tracking branch 'origin/enhancement/381-20261003-perf-li…
codeforester 496decf
style: format retention lock logging
codeforester 0f35aae
Merge remote-tracking branch 'origin/main' into ci/393-20261003-ci-ru…
codeforester 6efcb60
test: cover debug logging with consumer handlers
codeforester 436807b
test: cover concurrent and inherited logging state
codeforester 2a916ea
test: verify Windows retention pinning and reparse cleanup
codeforester 3f58457
Merge remote-tracking branch 'origin/ci/393-20261003-ci-ruff-check-an…
codeforester 92cad10
Merge remote-tracking branch 'origin/bug/387-20261003-bug-configure-l…
codeforester e15763e
Merge remote-tracking branch 'origin/enhancement/381-20261003-perf-li…
codeforester 2f96072
Merge remote-tracking branch 'origin/bug/378-20261003-bug-run-bundle-…
codeforester 5e8e01f
Merge remote-tracking branch 'origin/enhancement/386-20261003-perf-re…
codeforester 40d9e2a
Merge remote-tracking branch 'origin/security/385-20261003-security-v…
codeforester 52f2e4e
Merge remote-tracking branch 'origin/bug/379-20261003-bug-json-single…
codeforester 54be619
Merge remote-tracking branch 'origin/ci/311-20261003-v1-0-make-projec…
codeforester e059756
Merge remote-tracking branch 'origin/ci/391-20261003-ci-add-concurren…
codeforester 89b3404
style: format changelog validation diagnostic
codeforester 9c9b56f
docs: clarify host logging level behavior
codeforester 7001a5d
fix: calibrate macOS logging benchmark budget
codeforester c1ff77a
Merge remote-tracking branch 'origin/ci/391-20261003-ci-add-concurren…
codeforester 51b411d
fix: allow hosted macOS logging tails
codeforester 8eb6d0c
Merge remote-tracking branch 'origin/ci/391-20261003-ci-add-concurren…
codeforester 1cddd44
fix: calibrate Unix logging benchmark budget
codeforester 7a620df
Merge remote-tracking branch 'origin/ci/391-20261003-ci-add-concurren…
codeforester df6ee90
fix: relax Unix logging benchmark edge
codeforester 845e505
Merge remote-tracking branch 'origin/ci/391-20261003-ci-add-concurren…
codeforester 4cd6b8d
Merge main into 0.5.0 release candidate
codeforester File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1 +1 @@ | ||
| 0.4.3 | ||
| 0.5.0 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,33 @@ | ||
| # Migrating from 0.4.x to 0.5.0 | ||
|
|
||
| 0.5.0 is a pre-1.0 minor release. It retains the Click/Typer lifecycle APIs while | ||
| strengthening configuration, output, logging, retention, and release contracts. | ||
| The published 0.4.3 tag and distributions remain immutable. | ||
|
|
||
| - Convenience-profile project configuration now verifies POSIX ownership and | ||
| permissions, refuses symlink/reparse paths, and stops discovery at `.git`, a | ||
| filesystem boundary, or the configured ancestor limit. Repair permissions or | ||
| set `verify_discovered_config=False` explicitly for a knowingly shared | ||
| workspace; see [local configuration](local-config.md). | ||
| - YAML inputs are bounded before alias construction. Split unusually large | ||
| configuration files and remove recursive or excessive alias graphs. | ||
| - JSON mode captures descriptor and inherited child stdout. Wait for children | ||
| and flush native stdio before returning. Output over 8 MiB produces an error; | ||
| a detached child produces `capture_incomplete` with the partial captured | ||
| output; use NDJSON for larger streams. See [JSON contracts](json-contracts.md). | ||
| - Consumer logging handlers and configured levels survive CLI cleanup. Foreign | ||
| handlers and parent routing are preserved while `--debug` and `--quiet` still | ||
| control the Base-owned stream. An explicitly configured host logger level may | ||
| filter persistent DEBUG messages; a foreign handler without a level does not. | ||
| Configure the host logger at DEBUG when those records are required. See | ||
| [integrations](integrations.md). | ||
| - Native Windows enforces bundle retention through pinned directory handles; | ||
| contended maintenance passes skip without blocking command execution. | ||
| - Repeated source paths and human log timestamps are cached; log-sidecar I/O | ||
| errors use logging's error path without aborting commands. | ||
| - Click 8.5 is supported within the declared Click window. Typer consumers must | ||
| use the documented compatible Click/Typer pairs. | ||
|
|
||
| Review the dated [changelog](https://github.com/basefoundry/base-cli/blob/main/CHANGELOG.md) and the [platform boundary](platform-support.md) | ||
| when upgrading. Test the installed wheel in a clean environment, including your | ||
| JSON consumers, config permissions, and host logging integration. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,26 @@ | ||
| # 0.5.0 release candidate checklist | ||
|
|
||
| This is release preparation. A dated changelog section does not mean the version | ||
| has been tagged or published. The proposed date must be refreshed if publication | ||
| happens on another day. Issue #307 remains open until publication evidence exists. | ||
|
|
||
| 1. Merge the reviewed 0.5.0 issue train and all remaining 0.5.0 PRs. Refresh the | ||
| release PR against their final integrated commit and include their changelog | ||
| entries in 0.5.0 before approval. | ||
| 2. Obtain independent approval and passing required checks on the exact release | ||
| head. Keep the repository and environment approval rules in place. | ||
| 3. Validate the 0.4.x migration boundary in [migration guidance](migration-0.5.md), | ||
| then run the full local gate and hosted platform, dependency, consumer, | ||
| benchmark, package, and provenance checks. | ||
| 4. Rehearse the reviewed artifact through the protected TestPyPI environment. | ||
| Install exactly `base-cli==0.5.0` from a new environment and run lifecycle/JSON | ||
| smoke checks; retain the artifact digest and workflow URL. | ||
| 5. After the release PR is merged, create annotated `v0.5.0` on the independently | ||
| approved protected-main commit. Never alter `v0.4.3` or its distributions. | ||
| 6. Approve the protected production environment. Publish the exact reviewed | ||
| wheel/sdist, then verify matching SHA256SUMS, SPDX SBOM, provenance and SBOM | ||
| attestations, RELEASE-BOM-ROW, tag target, and GitHub release assets. | ||
| 7. Verify a clean installation of exactly `base-cli==0.5.0` from PyPI. Record the | ||
| immutable release URL and evidence on #307, then close it. | ||
|
|
||
| The operational commands and recovery rules remain in [Releasing](releasing.md). |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.