chore(release): promote Registry Stack v0.12.0 beta-14#422
Conversation
Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2068d650e8
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2068d650e8
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2068d650e8
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
💡 Codex ReviewWhen this lands on registry-stack/.github/workflows/ci.yml Line 209 in 641a5bf In the new platform jobs this quoted package spec is passed to Cargo literally whenever a platform path changes. I checked Cargo package selection locally ( When ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
2 similar comments
💡 Codex ReviewWhen this lands on registry-stack/.github/workflows/ci.yml Line 209 in 641a5bf In the new platform jobs this quoted package spec is passed to Cargo literally whenever a platform path changes. I checked Cargo package selection locally ( When ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
💡 Codex ReviewWhen this lands on registry-stack/.github/workflows/ci.yml Line 209 in 641a5bf In the new platform jobs this quoted package spec is passed to Cargo literally whenever a platform path changes. I checked Cargo package selection locally ( When ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 641a5bfa8e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 641a5bfa8e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 641a5bfa8e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
💡 Codex ReviewWhen this lands on registry-stack/.github/workflows/ci.yml Line 209 in 641a5bf In the new platform jobs this quoted package spec is passed to Cargo literally whenever a platform path changes. I checked Cargo package selection locally ( When ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
1 similar comment
💡 Codex ReviewWhen this lands on registry-stack/.github/workflows/ci.yml Line 209 in 641a5bf In the new platform jobs this quoted package spec is passed to Cargo literally whenever a platform path changes. I checked Cargo package selection locally ( When ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
Summary
Promote the complete frozen
release/1.0beta-14 integration tree to protectedmainas one signed-off commit, plus confirmed release-gate fixes. Commit2068d650is byte-for-byte identical torelease/1.0at817ddec63d759653d88f2d934b55943f6a62c7b1.This replaces #420 because the direct branch comparison exposed an older already-integrated unsigned squash commit to the DCO range check. No history was rewritten and no integrated product scope was dropped.
Confirmed promotion blockers
The exact
maincomparison correctly reports the intentional pre-1.0 removal ofGET /oid4vci/credential-offer,POST /oid4vci/nonce, and three corresponding optional response fields. Commita60c6745restores the already-reviewed one-time exception with an exact five-change set;641a5bfaaligns its literal quoting with the workflow-pinnedoasdiff1.23.0 output. It passes only against the pre-promotion baseline and fails once the baseline contains the new contract, so the finalization PR must delete it before tagging. No wildcard or general compatibility suppression is introduced.Review of the fully green promotion head then found a real PostgreSQL OID4VCI boundary mismatch: the application generates canonical
sha256:<64 lowercase hex>issuance commitments, while the encrypted state AAD and database schema accepted only bare 64-hex values. Commit2dfc1cd3makes the state-plane validation, SQL constraints, semantic schema identity, per-major catalog fingerprints, and fixtures agree on the canonical application format. It does not weaken commitment validation. Three duplicate Cargo wildcard comments are false positives because Cargo package specs support this glob and the exact all-features build, clippy, test, and coverage jobs passed.Release
v0.12.0registry-stack-beta-14release-candidateuntil post-publication evidence supports closeoutVerification
oasdiff1.23.0 checksum verified; exact pre-promotion Notary OpenAPI contract check passes with the five-change exception817ddec6, proving the exception self-expires after promotioncargo fmt --all -- --checkgit diff --checkSigned-off-by: Jeremi Joslin jeremi@joslin.fr
Final review also found two release-boundary blockers. Commit
d99368b9binds the temporary OpenAPI exception to the exact pre-promotion contract blob so it cannot affect later baselines, and reserves the new issuance transaction claims against configured subject-claim overwrite. The focused token collision test, future-baseline OpenAPI path, shell syntax, formatting, and diff checks pass locally; the full protected suite is rerunning on the exact head.