chore(release): 0.61.0 - #349
Merged
Merged
Conversation
tangletools
approved these changes
Oct 4, 2026
tangletools
left a comment
Collaborator
There was a problem hiding this comment.
✅ Auto-approved PR — c679943b
Blanket team auto-approval is intentional. This is not a code review.
No automated review runs on this PR. This approval rests on the rule above alone.
tangletools · auto-approval · reason: blanket_auto_approve · 2026-10-04T02:19:49Z
drewstone
reviewed
Oct 4, 2026
drewstone
left a comment
Contributor
There was a problem hiding this comment.
Summary
- This PR contains a minimal release commit: CHANGELOG.md additions for 0.61.0 and a package.json version bump from 0.60.1 → 0.61.0.
- No code or dependency changes were introduced in this diff.
- I resolved the merge base successfully and reviewed the diff 78d3f7f... → HEAD.
Files changed
- CHANGELOG.md
- Lines added: 3–12 (new 0.61.0 section and bullets)
- package.json
- Line changed: 3 (version field)
Detailed findings (file:line)
CHANGELOG.md
- Lines 3–12:
3: "## 0.61.0"
5: "- feat(ads): publish paid advertising catalog contracts"
6: "- fix: validate native paid advertising mutation receipts"
7: "- feat(hub): register paid ads through shared credential and catalog paths"
8: "- fix(ads): require LinkedIn beneficiary and native mutation receipts"
9: "- feat(ads): add Meta TikTok and Snapchat campaign execution"
10: "- feat: add Microsoft Pinterest and Amazon paid ads adapters"
11: "- fix(x-ads): require native promoted post identity and media keys"
12: "- feat(ads): add X LinkedIn and Reddit paid campaign adapters"
Comments:
- Correctness: The new release notes are formatted consistently with the rest of the changelog. The section header and bullet list are syntactically normal Markdown and align with existing style.
- Completeness: The entries are short and descriptive; if consumers expect links to PRs/issue numbers or authors for auditability, consider expanding entries to include PR references (e.g., "(#349)"), or linking to the merged commits, but that is a repository policy decision rather than a correctness issue.
- Risk/sensitivity: The changelog references new paid-advertising adapters and adapter/platform integrations (LinkedIn, TikTok, Snapchat, Microsoft/Pinterest/Amazon, X, LinkedIn, Reddit). These represent security- and privacy-sensitive functionality in general. Although no code changes are present in this PR, ensure that:
- The underlying code and adapters were reviewed and tested in their feature PRs prior to being released.
- Any required documentation, privacy disclosures, or required credentials/permissions are in place for these adapters.
- If any of the listed items introduce new network scopes, secret handling, or billing flows, those should be validated as part of the release pipeline (this is an operational note — nothing in this diff changes behavior).
- Formatting: No Markdown syntax errors observed. Spacing and header level fit existing file structure.
package.json
- Line 3:
3: "version": "0.61.0",
Comments:
- Correctness: The version bump accurately corresponds to the new changelog entry (0.61.0). This is the standard single-field change for a release commit.
- Security: No dependency changes were introduced in this commit (dependencies/devDependencies remain unchanged). There is no new package metadata that would alter publish behavior (publishConfig remains "access": "public"). No suspicious fields were added.
- Efficiency / Build: package.json scripts and configuration remain unchanged. The repository requires Node >=20.19.0 (line 173) and uses tsdown/build scripts (lines 148–161). The release script is present ("release": "node scripts/release.mjs") and prepack/prepublishOnly hooks run check:bundled-manifest-freshness. No changes to these flows in this PR; ensure CI runs the build/test/typecheck steps as expected.
- Consistency: Ensure that any other files expected to be updated during a release (for example, package-lock/pnpm-lock or other manifest files, or bundled manifests generated by scripts) are either intentionally not changed here or modified in the release pipeline. I note pnpm-lock.yaml is present in the repo root but was not updated by this PR — if your release flow updates the lockfile, confirm that it is intentionally omitted or will be updated in a separate step.
Other notes and recommendations
- Release process hygiene:
- If your release process requires updating lockfiles (pnpm-lock.yaml) or generated files (dist, built manifests), ensure they are handled consistently. This PR only touches package.json and CHANGELOG.md; that is fine for a metadata-only release commit if your CI/build pipeline generates build artifacts upon publish.
- The package.json contains "prepack" and "prepublishOnly" that will run build and manifest checks. Ensure CI for release runs those in a clean environment; since the version changed, downstream published tarballs should include matching built artifacts.
- Attribution / auditability:
- Consider including PR/commit references in the changelog entries for traceability (e.g., link to feature PRs that added the adapters). This aids future audits when sensitive integrations are involved.
- Security reminder:
- Given changelog mentions many new adapter integrations and paid-ad features, confirm that secrets and credential handling code were previously reviewed and that no secret values have been inadvertently committed elsewhere. This particular PR does not add secrets.
Summary (most important findings)
- This PR is a minimal release update: CHANGELOG.md entries for 0.61.0 (lines 3–12) and a version bump in package.json (line 3). No code, dependency, or build-script changes are included.
- No direct security regressions are visible in this diff. However, the changelog indicates newly released paid-ad and third-party adapter work; verify those feature changes were reviewed and tested in their original PRs and that any operational/credentials/privacy requirements are satisfied before publishing.
- Consider adding PR/commit references in the changelog entries for better traceability and auditability.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Release-time preparation from merged main. Feature PRs do not carry version or changelog edits.