Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion BEARING.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ timeline

## Current State

`v6.5.10` shipped on `2026-08-24`.
`v6.5.11` shipped on `2026-10-02`. Published Plumbing 3.3.2 now classifies closed mktree transport input for the existing bounded immutable-object retry; producer errors and mutable-ref semantics are unchanged.
Application asset, bundle, page, cache,
expiry, witness, and repository-diagnostics APIs sit above mutable root sets
and the low-level CAS pipeline. Direct bundle-reference reads and bounded
Expand Down
4 changes: 2 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -53,9 +53,9 @@ Unlike traditional LFS which moves files to external servers, `git-cas` treats t
Existing v5 users should read [UPGRADING.md](./UPGRADING.md) and run
`npm run upgrade` in dry-run mode before restoring old encrypted vault entries.
For the release overview, see the
[v6.5.10 Release Notes](./docs/releases/v6.5.10.md).
[v6.5.11 Release Notes](./docs/releases/v6.5.11.md).

The v6.5.11 candidate adopts published Plumbing 3.3.2 for bounded recovery from closed mktree transports after external Git GC. It preserves producer error identity and existing object formats; see [v6.5.11 Release Notes](./docs/releases/v6.5.11.md). Registry publication is pending release verification and merge.
Published v6.5.11 adopts published Plumbing 3.3.2 for bounded recovery from closed mktree transports after external Git GC. It preserves producer error identity and existing object formats; see [v6.5.11 Release Notes](./docs/releases/v6.5.11.md). Publication and independent registry-consumer evidence are recorded in the [release record](https://github.com/git-stunts/git-cas/pull/132).

### 1. CLI Usage

Expand Down
9 changes: 5 additions & 4 deletions STATUS.md
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
# STATUS

**Last tagged release:** `v6.5.10` (`2026-08-24`)
**Current release state:** `v6.5.10` is published to npm and GitHub Releases.
**Latest verification:** reviewed release merge `4316f4ec` passed 14/14 release-verifier stages with 7,192 observed tests; signed tag `v6.5.10` peels to that merge, and release workflow `32782415971` published the matching npm artifact plus final GitHub Release.
**Last tagged release:** `v6.5.11` (`2026-10-02`)
**Current release state:** `v6.5.11` is published to npm and GitHub Releases.
**Latest verification:** reviewed merge `1bcd6311` passed 14/14 release gates with 7,224 observations across runtimes. Signed tag `v6.5.11`, npm gitHead and release workflow `37008258240` agree; a fresh registry consumer passed six recovery checks, store/restore and CLI verification.
**Playback truth:** `main`
**Runtimes:** Node.js 22.x, Bun, Deno
**Current planning method:** [WORKFLOW.md](./WORKFLOW.md)
Expand All @@ -18,11 +18,12 @@
- The machine-facing `git cas agent` surface exists and now supports
OS-keychain passphrase sources for vault-derived key flows, but parity and
portability are still partial.
- **v6.5.11 artifact posture** — published Plumbing 3.3.2 supplies bounded mktree transport recovery through the existing CAS retry. [Publication evidence](docs/design/0062-mktree-transport-recovery/witness/release-publication.md) pins the merged source, tag, registry integrity and Docker consumer proof. No stored format, handle, mutable-ref retry or application migration changes. Git-warp attachment adoption remains separate.
- **v6.5.10 artifact posture** — implementation PR
[#128](https://github.com/git-stunts/git-cas/pull/128) and release PR
[#129](https://github.com/git-stunts/git-cas/pull/129) merged normally.
Signed tag `v6.5.10` resolves to reviewed release merge `4316f4ec`; npm
reports `@git-stunts/git-cas@6.5.10` as `latest` with publish and SLSA
retains `@git-stunts/git-cas@6.5.10` with publish and SLSA
provenance, and release workflow `32782415971` published the final GitHub
Release. The additive contract admits bounded asset waves into the compound
scope and can retain exact selected terminal roots without changing stored
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -136,7 +136,7 @@ This dependency repair does not restore git-warp Runtime/Lane node/edge attachme

## Retrospective

Record after merge and publication, with PR and release receipts.
See the [post-release retrospective](../../method/retro/0062-mktree-transport-recovery/mktree-transport-recovery.md) and [publication witness](witness/release-publication.md).

## Data / State Model

Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
{
"version": "6.5.11",
"sourceCommit": "1bcd6311e93ca9782e2f4a25af106af0651813fb",
"tag": "v6.5.11",
"tagObject": "a77ebbdff9b5e2bbce73f90e8d51a5d0cd71b98d",
"releaseRun": 37008258240,
"registry": {
"integrity": "sha512-C6coWmKmOeRZ+X5nP5Ek7spwYpA5q6mgif09u9dDO0ISQQ+Hz4KVxAXrOPRRhNJzLEP74Ndbra55fxX5Cms5gw==",
"shasum": "184c18fce40629afd28a897cbf3672cb4cc0d43e",
"tarball": "https://registry.npmjs.org/@git-stunts/git-cas/-/git-cas-6.5.11.tgz",
"attestations": {
"url": "https://registry.npmjs.org/-/npm/v1/attestations/@git-stunts%2fgit-cas@6.5.11",
"provenance": {
"predicateType": "https://slsa.dev/provenance/v1"
}
}
},
"plumbingVersion": "3.3.2",
"releaseVerification": {
"stagesPassed": 14,
"stagesSkipped": 0,
"observedTests": 7224,
"rawLogSha256": "cdefc3ed121de8e861b984c31cf5ee48d73aea05eca0632d1de3972864e71e09"
},
"publicConsumer": {
"recoveryTestsPassed": 6,
"storeRestore": "passed",
"cliVersion": "6.5.11+1bcd631",
"verifiedSignatures": 63,
"verifiedAttestations": 31,
"rawLogSha256": "42d7195c11774f9c2cc0aff0b55d72372383f30a24e98774548acb732c3c81c2"
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
# v6.5.11 publication witness

PR [#132](https://github.com/git-stunts/git-cas/pull/132) merged as `1bcd6311e93ca9782e2f4a25af106af0651813fb`. Signed annotated tag `v6.5.11` has object `a77ebbdff9b5e2bbce73f90e8d51a5d0cd71b98d` and peels to that exact merge; its SSH signature was verified before push. [Release workflow 37008258240](https://github.com/git-stunts/git-cas/actions/runs/37008258240) completed successfully and created the [GitHub release](https://github.com/git-stunts/git-cas/releases/tag/v6.5.11).

## Registry identity

Npm reports `@git-stunts/git-cas@6.5.11` with gitHead `1bcd6311e93ca9782e2f4a25af106af0651813fb` and integrity `sha512-C6coWmKmOeRZ+X5nP5Ek7spwYpA5q6mgif09u9dDO0ISQQ+Hz4KVxAXrOPRRhNJzLEP74Ndbra55fxX5Cms5gw==`. The artifact requires published Plumbing `^3.3.2`. Initial cached metadata returned 404 after publication; fresh registry metadata and a subsequent clean installation established visibility. No tag or version was rewritten.

## Merged-main verification

All 14 canonical release gates passed inside COPY-based Docker, without host repository or Git mounts. Node and Bun each passed 2,204 unit tests with three existing skips; Deno passed 2,195 with twelve existing skips. Each runtime passed 207 integration tests. Three maintained examples, public types, lint, metadata stamping, npm pack and JSR dry-run passed. The 7,224 total counts observations across runtimes, not unique tests. JSR was validated but is not a publication target of this workflow.

## Independent public consumer

A new Docker image installed the exact npm versions of git-cas 6.5.11 and Plumbing 3.3.2, with no checkout dependencies, patches or host mounts. All six deterministic transport-recovery tests passed. The public store/restore example returned matching bytes and passed integrity verification; the installed CLI reported `6.5.11+1bcd631`. Npm verified 63 registry signatures and 31 attestations across this consumer installation, which includes Vitest as test tooling. Those counts are specific to this fixture, not a package dependency-count guarantee.

## Limits and follow-through

Synthetic transport failures establish bounded retries and error identity; they do not prove every concurrent external-GC race. Git-warp [#923](https://github.com/git-stunts/git-warp/issues/923) owns attachment/GC adoption and evidence. This release does not implement git-warp Runtime/Lane attachments or complete its bounded streaming issue. Deno dependency installation reported an ESLint9 deprecation warning; no warning-free validation claim is made.

The [machine-readable receipt](publication.json) records immutable identities and raw-log SHA-256 digests. Historical preparation and candidate receipts retain their original source coordinates.
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
# Retro — 0062 Mktree transport recovery

## Drift check

The fix stayed at the owning dependency boundary: Plumbing classifies transport failures; CAS retains its existing one-retry immutable-object policy. No duplicate runtime patch, mutable-ref retry, stored format change or attachment API claim was introduced.

## Shipped result

PR #132 merged as `1bcd6311e93ca9782e2f4a25af106af0651813fb`. The signed v6.5.11 tag, npm artifact and successful release workflow agree on that commit. Full merged-main verification passed all 14 gates in Docker, followed by an independent public registry consumer. The publication witness records identities and proof limits.

## What the audit caught

The release gate caught the stale CLI version export. A separate self-audit found the legacy host BATS dispatcher and replaced it with direct Docker orchestration. Independent review identified a temporary validation Dockerfile in the JSR dry-run payload; removing that private harness input restored a clean payload. An approved review did not replace further scrutiny.

## Remaining work and debt

Git-warp #923 owns dependency adoption and real attachment/GC acceptance; #818 and #901 own bounded streams and public attachment capability. Synthetic fault recovery is not a claim about every GC interleaving. Deno installation emitted an ESLint9 deprecation warning; all lint and runtime checks still passed. Existing runtime-specific skips remain explicit in the release witness.

## Next release process

Advance the CLI version export alongside metadata, inspect every executable validation entry point, and keep generated validation Dockerfiles outside publishable source. Separate candidate evidence, publication evidence, and downstream capability evidence by immutable source coordinates.
2 changes: 1 addition & 1 deletion docs/releases/v6.5.11.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,4 +12,4 @@ All tests and benchmarks require a physical Docker marker before test modules lo

## Evidence And Delivery

Issue [#131](https://github.com/git-stunts/git-cas/issues/131) and PR [#132](https://github.com/git-stunts/git-cas/pull/132) own delivery. [Preparatory evidence](../design/0062-mktree-transport-recovery/witness/preparation.md) pins candidate behavior separately from registry delivery. The six recovery checks fail in four cases against Plumbing 3.3.0 and pass against published Plumbing 3.3.2. Full release verification, merge, signed tag, npm publication and registry consumer evidence remain required; this candidate document claims no published 6.5.11 artifact.
Issue [#131](https://github.com/git-stunts/git-cas/issues/131) and PR [#132](https://github.com/git-stunts/git-cas/pull/132) own delivery. [Preparatory evidence](https://github.com/git-stunts/git-cas/blob/243592ce1b72865ce4f1fd552f504e9488780246/docs/design/0062-mktree-transport-recovery/witness/preparation.md) pins candidate behavior separately from registry delivery. The six recovery checks fail in four cases against Plumbing 3.3.0 and pass against published Plumbing 3.3.2. The reviewed merge passed all 14 release gates; signed tag, trusted npm/GitHub publication and independent public-consumer verification are recorded in the [publication witness](https://github.com/git-stunts/git-cas/pull/132). JSR dry-run passed; JSR publication is not part of the release workflow.
1 change: 1 addition & 0 deletions test/unit/docs/package-docs.test.js
Original file line number Diff line number Diff line change
Expand Up @@ -106,6 +106,7 @@ function publicPackagedMarkdownFiles(files) {
'docs/releases/v6.5.8.md',
'docs/releases/v6.5.9.md',
'docs/releases/v6.5.10.md',
'docs/releases/v6.5.11.md',
'docs/THREAT_MODEL.md',
'docs/WALKTHROUGH.md',
].filter((file) => files.has(file));
Expand Down
15 changes: 14 additions & 1 deletion test/unit/docs/release-state.test.js
Original file line number Diff line number Diff line change
Expand Up @@ -474,7 +474,6 @@ function expectV6510CandidateEvidence(candidate, releaseNotes) {
}

function expectV6510PublishedEvidence(status, publication) {
expect(status).toContain('**Last tagged release:** `v6.5.10` (`2026-08-24`)');
expect(status).toContain('**v6.5.10 artifact posture**');
expect(status).toContain('4316f4ec');
expect(status).toContain('32782415971');
Expand Down Expand Up @@ -847,3 +846,17 @@ describe('historical v6 release evidence', () => {
expect(releaseCard).not.toContain('Push the final pre-tag `main` commit');
});
});


describe('current publication identity', () => {
it('distinguishes the latest published release from retained historical evidence', () => {
const status = read('STATUS.md');
const receipt = JSON.parse(read('docs/design/0062-mktree-transport-recovery/witness/publication.json'));
expect(status).toContain(`**Last tagged release:** \`${receipt.tag}\``);
expect(receipt.version).toBe(JSON.parse(read('package.json')).version);
expect(receipt.sourceCommit).toBe('1bcd6311e93ca9782e2f4a25af106af0651813fb');
expect(receipt.releaseVerification.stagesPassed).toBe(14);
expect(receipt.publicConsumer.cliVersion).toBe('6.5.11+1bcd631');
expect(status).toContain('**v6.5.10 artifact posture**');
});
});
Loading