Skip to content

fix: enforce GDAM publication contract for v0.0.3 - #15

Merged
nicodes merged 1 commit into
mainfrom
fix/165-publish-contract
Sep 16, 2026
Merged

nicodes merged 1 commit into
mainfrom
fix/165-publish-contract

Conversation

@nicodes

@nicodes nicodes commented Sep 16, 2026 •

Copy link
Copy Markdown
Member

Tracks aviorstudio/fieldsofrevik#165 (do not close until production verification).

Remove undeclared publish.version, retain and pin valid install.version, select exact tested ZIP among multiple release assets, and verify the installed GDAM executable SHA-256. Add immutable upstream metadata/script fixtures and a structural workflow gate with negative/restored controls plus credential-free exact-tag/legacy/unknown CLI stub tests. Canonical CI/release gates run this before existing package/native/Web tests. Prepare approved patch v0.0.3; no Supabase API/session changes.

Local verification: npm ci; npm run test:publish (4 passing); npm audit (zero); external unsupported-version mutation fails and restored workflow passes; Python package build/verify; node --check; bash -n; git diff --check. Existing full package/native/Web suite remains required in exact-head CI. Release and fresh registry verification follow merge; v0.0.2 will not be overwritten.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@nicodes
nicodes merged commit d7909de into main Sep 16, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant