Skip to content

chore(release): 0.203.1 - #907

Merged
drewstone merged 1 commit into
mainfrom
release/v0.203.1
Oct 1, 2026
Merged

drewstone merged 1 commit into
mainfrom
release/v0.203.1

Conversation

@github-actions

@github-actions github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Release-time preparation from merged main. Feature PRs do not carry version or changelog edits. A maintainer must approve the bot-created Actions workflow run before its checks can run.

@tangletools tangletools left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved PR — b404b49a

Blanket team auto-approval is intentional. The merge gates are CI and codex-p1.
No automated review runs on this PR. This approval rests on the rule above alone.

tangletools · auto-approval · reason: blanket_auto_approve · 2026-10-01T16:52:51Z

@drewstone

Copy link
Copy Markdown
Contributor

Independent review at b404b49 confirms generated release metadata only.
The four existing JavaScript/Python version fields change from0.203.0 to0.203.1.
The changelog references already merged changes.
No source, dependency, workflow or package gate changes.
The actual45-response usage proof remains in merged906.
Fetched main and checked clean merge-tree and whitespace.
The bot-created CI run requires separate GitHub approval; that is not a source defect.
Merging the exact release head under the user's standing delivery authorization.
Public artifact, provenance and consumer qualification remain owned by the current publisher lane.

@drewstone
drewstone merged commit 25c1488 into main Oct 1, 2026
2 checks passed
@drewstone

Copy link
Copy Markdown
Contributor

Public patch delivery is complete for 0.203.1.

  • Immutable tag v0.203.1 pins merged source 25c148892b7e47b1e3605e142752170819ac4a5b, containing fix(usage): preserve reported Router cache components #906.
  • Maintained publisher 36895706803 completed verification, npm and PyPI publication.
  • Actual served npm archive: 4,664,431 bytes; SHA256 184d51d2fd1a20d0be84e377d65b37a89c69452c46520443dbd7bc85967cf508. Publisher SHA1, registry integrity, native signature audit and exact source/tag/workflow/run provenance match.
  • All 554 installed regular-file bytes match the archive. Archive and installed modes are retained separately; native installation added group write.
  • The actual installed public reader replays all 45 original HTTP bodies from 16 retained source files: 23 explicit-zero and 11 positive cache-write components now survive; all 161 existing components remain unchanged.
  • Public Python wheel and sdist pass PyPA cryptographic attestation verification. Certificates bind the same source and tag. All 16 packaged Python sources match Git; a fresh installed Client imports at 0.203.1.

Receipts are retained under /mnt/traces/eval-release-02031-20261001: public-package-verification.json, public-usage-replay.json, public-python-package-verification.json, original publication logs, public distributions, signatures and attestations.

No source, dependency or gate changes were made in this release lane. No new tests or local suites ran. Existing publisher gates ran unchanged. Zero model calls. This qualifies package delivery and usage-reader behavior; it does not establish complete physical-call accounting, billing, deployment or research outcomes.

Measurement corrections remain explicit: an initial equality assertion ignored native install permission behavior, and a Python import instrument assumed a nonexistent AsyncClient export. The actual published Client source was then used.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants