diff --git a/.changeset/20594-observability-provenance-anchors.md b/.changeset/20594-observability-provenance-anchors.md new file mode 100644 index 00000000000..b5683c22602 --- /dev/null +++ b/.changeset/20594-observability-provenance-anchors.md @@ -0,0 +1,11 @@ +--- +'@objectstack/observability': patch +--- + +A provenance comment in `@objectstack/observability` was re-anchored + +The `SEMCONV` comment beside the retired `http_request_errors_total` entry +cited a tracker number that no longer resolves on GitHub. It now cites the +commit in this repository's history that moved `http_request_duration_ms` to +the transport seam. Comment only: no metric name, label, export, type or +runtime behaviour changes. diff --git a/packages/observability/src/semconv.ts b/packages/observability/src/semconv.ts index 6d11794d409..8b025b7a190 100644 --- a/packages/observability/src/semconv.ts +++ b/packages/observability/src/semconv.ts @@ -46,7 +46,7 @@ export const SEMCONV = { // status, elapsedMs}` and no throw signal at all. // ⇒ Read the 5xx rate from `http_requests_total{status=~"5.."}` instead. // The transport emits that family through the seam, so it covers every - // inbound surface (#9650 / #9835 / #10004) and carries the status label + // inbound surface (#9650 / #9835 / commit 1e050a5b1) and carries the status label // this counter only stood in for. Maintainer ruling 2026-08-20. // ── Storage — emitted by `@objectstack/service-storage` adapters ── diff --git a/packages/verify/src/erasure-transaction-authorization.test.ts b/packages/verify/src/erasure-transaction-authorization.test.ts index f44740ce0fe..bbd5c98db70 100644 --- a/packages/verify/src/erasure-transaction-authorization.test.ts +++ b/packages/verify/src/erasure-transaction-authorization.test.ts @@ -160,11 +160,11 @@ describe('#10792 — the erasure route answers authorization on a pool max=1 dia it('a signed-in plain member gets the AUTHORIZATION refusal, not 401', async () => { const answer = await fire('POST', '/auth/admin/remove-user', { userId: targets[2] }, memberToken); expect(answer.status, `member remove-user: ${answer.status} ${answer.body}`).toBe(403); - // #11477 (maintainer-ruled option A): the route is now shaded by an + // Commit 6dd3e6968 (maintainer-ruled option A): the route is now shaded by an // ObjectStack raw mount whose gateAdmin runs BEFORE the break-glass guard, // so the refusal a plain member hears is the gate's target-independent // PERMISSION_DENIED — no longer the vendor's - // YOU_ARE_NOT_ALLOWED_TO_DELETE_USERS, which the pre-#11477 route only + // YOU_ARE_NOT_ALLOWED_TO_DELETE_USERS, which the route before that commit only // reached after the guard had already answered. This pin's intent is // unchanged: the member hears an AUTHORIZATION verdict, and asserting the // code (not just the status) keeps a 403 from some unrelated layer from diff --git a/packages/verify/src/harness.ts b/packages/verify/src/harness.ts index 7610839f97f..47a921ad0bc 100644 --- a/packages/verify/src/harness.ts +++ b/packages/verify/src/harness.ts @@ -577,7 +577,7 @@ export async function bootStack( // booted multi-tenant off a hoisted copy — and the RLS posture a fixture // then asserted against depended on the launcher. // - // #10943: the undeclared FALLBACK is this package's own resolution only if + // Commit 46d34ab7c: the undeclared FALLBACK is this package's own resolution only if // this package supplies it. A bare `import()` written inside // `@objectstack/types` resolves against THAT package — which declares // `@objectstack/spec` and nothing else — so the helper's documented