Skip to content

release: 1.3.4 — status beta - #264

Merged
dshakes merged 1 commit into
mainfrom
release/1.3.4
Aug 18, 2026
Merged

dshakes merged 1 commit into
mainfrom
release/1.3.4

Conversation

@dshakes

@dshakes dshakes commented Aug 17, 2026

Copy link
Copy Markdown
Owner

Ships the status badge change from #263: pre-alpha → beta.

Why beta, not stable

Every stage command ships, all four registries carry matching 1.3.3 artifacts, and the three-package install is documented and verified end to end from the published wheels.

It is not stable because blocker #2 in docs/95-ga-readiness.md is open: observe has never been pointed at real traffic. That is the least-exercised code with the most sensitive job — NFR-3 lives on that path. Claiming stable over an unexercised redaction guarantee would be the same defect this repo keeps finding: a green label over something that has not happened.

Also in

docs/95-ga-readiness.md had gone stale within a day of being written — it still described blockers 1 and 3 as open after #260 closed both, and still said 1.3.2. A readiness doc that misreports readiness is worse than not having one.

Verification

  • Rust 251 passed · Python 1964 passed / 23 skipped / 20 xfailed · ruff clean
  • release_preflight.py 8/8 ok, consistent at 1.3.4
  • bump.py set all 18 version surfaces

After the tag

Check the registries, not the workflow's conclusion:

curl -s https://pypi.org/pypi/onpar/1.3.4/json | jq -r '.urls[].filename'
npm view onpar-cli version

Expect onpar, onpar-core (3 wheels), onpar-gateway (3 wheels) at 1.3.4.

Ships the status badge change: pre-alpha -> beta.

Beta and not stable, deliberately. Every stage command ships, all four
registries carry matching artifacts, and the three-package install is
documented and verified end to end. What is still open is blocker 2 in
docs/95-ga-readiness.md — observe has never been pointed at real traffic,
which is the invariant with the highest cost of being wrong.

Also corrects 95-ga-readiness.md, which had gone stale within a day of
being written: it described blockers 1 and 3 as open after #260 closed
both.
@dshakes dshakes added the agent:reviewed-clean Reviewer found no Blocking issues this round label Aug 17, 2026
@github-actions github-actions Bot added the domain:infra Touches infra / CI / deploy / migrations label Aug 17, 2026
@github-actions

Copy link
Copy Markdown
Contributor

🔎 Codex cross-audit (agent:audit)

No Blocking findings.

I found no correctness, security, or edge-case regressions in this PR. The diff is a scoped 1.3.3 → 1.3.4 release bump across manifests, lockfile, npm metadata, and install docs.

Checks run:

  • python3 tools/bump.py confirms all managed version surfaces are consistent at 1.3.4.
  • git diff --check origin/main...HEAD passes.

Note: Formula/onpar.rb still points at 1.3.3, but this appears intentional for this stage: the release workflow updates the Homebrew formula after the tag exists, because the tarball checksum is not knowable before publish.

@github-actions

Copy link
Copy Markdown
Contributor

🔷 Gemini cross-audit (agent:audit-gemini)

Unified Diff Audit: Version Bump to 1.3.4

Verdict: PASS (No Blocking Issues)

The unified diff in pr-diff.patch was thoroughly audited against the base codebase. It represents a clean, comprehensive, and correct version bump from 1.3.3 to 1.3.4 across all defined project surfaces.


Key Findings & Verification

  1. Surface Completeness (18/18 Matches)
    Every single one of the 18 version-carrying surfaces registered in tools/bump.py has been updated cleanly. There are no missed occurrences that would cause tests/test_docs_lab.py::test_every_version_surface_agrees_with_the_manifest to fail.

  2. Dependency Pins Alignment

    • Intra-workspace dep pins in onpar-gateway/Cargo.toml and onpar-py/Cargo.toml are correctly bumped to 1.3.4.
    • Cargo workspace manifest and Cargo.lock lockfile packages (onpar-core, onpar-gateway, onpar-py) match at 1.3.4.
    • This ensures Rust builds resolve cleanly without major/minor version boundary mismatch panics.
  3. Install Pins & Documentation Alignment

    • Documentation examples (including README.md, site/index.html, and site/docs/index.html) correctly reference pinned 1.3.4 tags for uvx and npx.
    • Both registries (npm and PyPI) are kept perfectly in sync.
  4. Homebrew Formula Exception
    Formula/onpar.rb is untouched by the bump. This is the correct and expected behavior, as the URL tag and the tarball SHA-256 are populated post-tag by the release workflow itself (.github/workflows/release.yml) and should not be modified locally.


Security and Correctness Assessment

  • Regressions: None. The patch contains only literal changes to the version number strings.
  • Security: No secrets, credentials, or unsafe code pathways are introduced.
  • Compatibility: All components remain aligned, preserving runtime compatibility gates (onpar-py dynamic seam versioning) perfectly.

@dshakes
dshakes merged commit 04d7dd0 into main Aug 18, 2026
22 checks passed
@dshakes
dshakes deleted the release/1.3.4 branch August 18, 2026 00:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

agent:reviewed-clean Reviewer found no Blocking issues this round domain:infra Touches infra / CI / deploy / migrations

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant