From c567d83b173d0bbc2f786cdcd663d8561ea9b561 Mon Sep 17 00:00:00 2001 From: Efe Genc <50203466+Bubblegunn@users.noreply.github.com> Date: Tue, 22 Sep 2026 20:56:35 +0300 Subject: [PATCH] docs: credit #40 on the day it merged MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The integration test for the npm 12 pack shape, and the marker that keeps it from passing while the stub sits unused. Written by @shivam-070208, closing #37. Recorded as a patch rather than a minor: the change is test-only and nothing in the published package moves. I told the contributor 0.6.0 in the review before thinking about what actually ships; the entry corrects that. Sade dil (teknik olmayan biri için): - Ne yapıldı: Bir kontrolün gerçekten çalıştığını kanıtlayan test eklendi ve yazan kişiye aynı gün teşekkür yazıldı. - Ne işe yarar: Yeşil görünen ama aslında hiçbir şey denetlemeyen testler yüzünden hata kaçırmıyoruz. Co-Authored-By: Claude Opus 5 (1M context) --- CHANGELOG.md | 21 +++++++++++++++++++++ 1 file changed, 21 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 22eb5d1..f835c77 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,26 @@ # Changelog +## 0.5.1 (unreleased) + +**The npm 12 fix had no test that could tell whether it was being exercised.** `extractPackedFiles` +was covered four ways, and the line wiring it into `release-gate.mjs` was not: reverting that line to +`packed[0].files` left the whole suite green, because npm 11 returns the array shape and the gate +handles it either way. + +There is now an integration test that puts a fake `npm` on `PATH`, forwards to the real one and +reshapes its output into the npm 12 object, with a `.cmd` beside the shell script for the Windows +runner and an assertion on the arguments the gate passes. The stub writes a marker that both tests +read, so a test cannot pass while the stub sits unused, which is the way this check could have gone +quiet without anyone noticing. + +Written by [@shivam-070208](https://github.com/shivam-070208) +([#40](https://github.com/Bubblegunn/workproof/pull/40), closes +[#37](https://github.com/Bubblegunn/workproof/issues/37)). Measured before merging: with the +injection removed the npm 12 test now fails, where it passed before the marker; reverting the wired +line fails both new tests; and replacing the unrecognised-shape `throw` with an empty list fails +exactly the test written for it. Nothing in the published package changes, which is why this is a +patch entry. + ## 0.5.0 (2026-09-21) **Bot detection was partly guesswork, and the guesswork ran on the expensive side.** Two definitions