Skip to content

chore: version packages - #20639

Merged
os-zhuang merged 1 commit into
mainfrom
changeset-release/main
Oct 2, 2026
Merged

os-zhuang merged 1 commit into
mainfrom
changeset-release/main

Conversation

@github-actions

@github-actions github-actions Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and publish to npm yourself or setup this action to publish automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

The changelog information of each package has been omitted from this message, as the content exceeds the size limit.

@objectstack/cli@17.6.0

@objectstack/client@17.6.0

@objectstack/console@17.6.0

@objectstack/core@17.6.0

@objectstack/driver-memory@17.6.0

@objectstack/driver-mongodb@17.6.0

@objectstack/driver-sql@17.6.0

@objectstack/driver-turso@17.6.0

@objectstack/lint@17.6.0

@objectstack/mcp@17.6.0

@objectstack/metadata-protocol@17.6.0

@objectstack/objectql@17.6.0

@objectstack/platform-objects@17.6.0

@objectstack/plugin-approvals@17.6.0

@objectstack/plugin-audit@17.6.0

@objectstack/plugin-auth@17.6.0

@objectstack/plugin-security@17.6.0

@objectstack/rest@17.6.0

@objectstack/runtime@17.6.0

@objectstack/sdui-parser@17.6.0

@objectstack/service-analytics@17.6.0

@objectstack/service-automation@17.6.0

@objectstack/spec@17.6.0

@objectstack/types@17.6.0

@objectstack/hono@17.6.0

@objectstack/account@17.6.0

@objectstack/setup@17.6.0

@objectstack/studio@17.6.0

@objectstack/client-react@17.6.0

@objectstack/cloud-connection@17.6.0

@objectstack/connector-mcp@17.6.0

@objectstack/connector-openapi@17.6.0

@objectstack/connector-rest@17.6.0

@objectstack/connector-slack@17.6.0

create-objectstack@17.6.0

@objectstack/driver-sqlite-wasm@17.6.0

@objectstack/formula@17.6.0

@objectstack/metadata@17.6.0

@objectstack/metadata-core@17.6.0

@objectstack/metadata-fs@17.6.0

@objectstack/observability@17.6.0

@objectstack/embedder-openai@17.6.0

@objectstack/knowledge-memory@17.6.0

@objectstack/knowledge-ragflow@17.6.0

@objectstack/organizations@17.6.0

@objectstack/plugin-dev@17.6.0

@objectstack/plugin-email@17.6.0

@objectstack/plugin-hono-server@17.6.0

@objectstack/plugin-pinyin-search@17.6.0

@objectstack/plugin-sharing@17.6.0

@objectstack/plugin-webhooks@17.6.0

@objectstack/service-cache@17.6.0

@objectstack/service-cluster@17.6.0

@objectstack/service-cluster-redis@17.6.0

@objectstack/service-datasource@17.6.0

@objectstack/service-i18n@17.6.0

@objectstack/service-job@17.6.0

@objectstack/service-knowledge@17.6.0

@objectstack/service-messaging@17.6.0

@objectstack/service-package@17.6.0

@objectstack/service-queue@17.6.0

@objectstack/service-realtime@17.6.0

@objectstack/service-settings@17.6.0

@objectstack/service-sms@17.6.0

@objectstack/service-storage@17.6.0

@objectstack/trigger-api@17.6.0

@objectstack/trigger-record-change@17.6.0

@objectstack/trigger-schedule@17.6.0

@objectstack/verify@17.6.0

@objectstack/example-crm@4.0.98

@objectstack/example-multi-package@0.0.5

@objectstack/example-showcase@0.3.20

@objectstack/example-todo@4.0.98

@objectstack/example-embed-objectql@0.0.38

@objectstack/dogfood@0.0.46

@objectstack/downstream-contract@0.0.44

@objectstack/http-conformance@0.1.6

This was referenced Sep 29, 2026
veigajoao pushed a commit to veigajoao/objectstack that referenced this pull request Sep 29, 2026
…ough @objectstack/console/package.json, so a project without its own manifest gets full component checking (objectstack-ai#20589)

Fixes objectstack-ai#19922
Clause-②: no

## What this changes

`resolveSduiManifest()` (`packages/cli/src/utils/sdui-manifest.ts`) is
the one resolver `os validate`, `os compile` / `os build` and `os lint`
use to arm the JSX page gate. `os dev` and `os start` run `compile`
before they boot when `dist/objectstack.json` is missing or `--compile`
is passed, and `dev`'s default watch mode reruns it when a watched file
changes. The resolver's second place to look, the copy
`@objectstack/console` ships as `dist/sdui.manifest.json`, asked Node
for that file by its own subpath. The console's `exports` map publishes
`./package.json` alone, so the resolve threw
`ERR_PACKAGE_PATH_NOT_EXPORTED`, a `catch` swallowed it, and every
project with no `sdui.manifest.json` of its own had its `kind: 'html'`
pages checked at parse level only.

The fallback now resolves `@objectstack/console/package.json` from the
CLI's own location (`import.meta.url`, the CLI's declared dependency in
the same fixed release group) and joins `dist/sdui.manifest.json` to its
directory, through a new `consoleSduiManifestPath(origin)`. The
console's `exports` stays closed. `resolveSduiManifest(cwd,
consoleOrigin)` gains an optional origin, used only by the pins.

The old module header handed one decision to whoever made this leg
reachable: what a broken shipped copy should do. It now gets the project
leg's rule. A shipped copy that is present but cannot be read or parsed
is `unusable` (new `source: 'console'`), and the command is refused with
exit 1, naming the file, with the remedy "reinstall
@objectstack/console". It is never read as "not found". With no page to
check it is read by nothing and not refused, the same as the project
leg.

## This round (the seat's unlock record `5890591366` on objectstack-ai#19922)

The ledger entry `ui-html-page-div-refused` landed on `main` (objectstack-ai#20592, PR
objectstack-ai#20610), and Version Packages objectstack-ai#17076 consumed
`.changeset/sdui-manifest-one-producer.md`. This round:

1. **Merged `origin/main` at `f1e921ab8e`** (a merge, not a rebase;
merge commit `f9cb969f44`). One conflict:
`.changeset/sdui-manifest-one-producer.md`, modify/delete, resolved in
favour of `main`'s deletion.
`build-json-failure-conversions.e2e.test.ts` and
`validate-json-failure-conversions.e2e.test.ts` auto-merged: `main`
changed other regions of both, and the `box` fixture line and its
docblock sentence survived. The branch's delta against `main` is exactly
the 7 intended files. `main` has since gained one commit (`cd901d7a5f`),
which touches none of them.
2. **The correction moved into this PR's changeset.** The released note
is `@objectstack/console` 17.5.0, patch entry `28ce612`. A new paragraph
goes through its closing paragraph one sentence at a time:
- two sentences stop being true with this release: the file is no longer
"only present in the tarball", and the CLI fallback no longer "keeps
parse-level validation";
   - two still hold: `exports` is unchanged.

No `CHANGELOG.md`, no `content/docs/releases/` and nothing under
`packages/spec/` is edited.
3. **The ADR-0087 marker** now reads `not-required (already-registered
ui-html-page-div-refused)` with its reason. The gate's verdict:
"check-adr-0087-registration: 1 declared-breaking changeset(s), each
carrying an ADR-0087 disposition … not-required (already-registered)",
exit 0.
4. **Two sentences re-measured and corrected:**
- **"the html-tier renderer still renders `div`" was false.** At the
pinned objectui `dd3f7e1be3`, read with `git show` from the sibling
checkout (nothing checked out, nothing edited):
- `packages/components/src/renderers/layout/page.tsx:487-488` builds the
html compile's whitelist from `getKnownTypes()` minus `deprecationFor(t,
'html')`;
- `packages/components/src/renderers/basic/div.tsx` registers `div` with
`deprecated.surfaces: ['json', 'html']`;
- `nameHtmlTierReplacement` turns the resulting `forbidden-tag` into a
refusal naming the replacement.

That pin shipped in `@objectstack/console` 17.5.0: its CHANGELOG entry
`3cf6449` says a `kind:'html'` page that authors a `div` "is refused at
compile time, and the error names `box`". The changeset now says the
console has refused `div` since 17.5.0, and that what is new is every
other tag the manifest does not declare. The console's html compile
accepts every non-deprecated registered component, while the manifest
declares the public contract plus the html intrinsics. Measured below
with `avatar`.
- **"`objectstack compile` (which `dev` and `start` run first)" was
inexact.** It now says exactly when they run it: `dev.ts:319` compiles
on `flags.compile` or a missing artifact, and `dev.ts:383` re-runs it in
watch mode; `start.ts:228-232` has the same condition.

## Premise and hypotheses, measured

Round-1 readings (on `f11b5f20a2`) are kept where they still hold.
Round-2 readings are on `77338a7186`: Node v26.7.0, macOS.

- **H0 (premise holds).** On unmodified `f11b5f20a2`, a real `os init`
project with a `kind: 'html'` page rooted in `div` passes `os validate`,
`os compile` and `os lint` at exit 0. Each prints only the parse-level
notice, and it does so even with a `cmp`-identical copy of the tracked
manifest at `packages/console/dist/sdui.manifest.json`. From
`packages/cli/dist`, the old subpath throws
`ERR_PACKAGE_PATH_NOT_EXPORTED`.
- **H1 (the route finds the file in both layouts).**
- Workspace: `consoleSduiManifestPath()` answers
`packages/console/dist/sdui.manifest.json`.
- Installed package: `npm pack` of `packages/console` with a stand-in
dist lists `dist/sdui.manifest.json`. Extracted under a scratch
`node_modules`, the old subpath throws `ERR_PACKAGE_PATH_NOT_EXPORTED`
from a sibling CLI origin, while `resolveSduiManifest` answers
`resolved`.
- **H2 (Clause-② arm: narrowing).** Round 2, merged tree, with the
console copy present (`cmp`-identical stand-in):
- a `div` page gives exit 1 (`jsx-forbidden-tag`,
`jsx-unknown-component`);
  - a `box` page gives exit 0, with no findings;
- an `avatar` page gives exit 1 (`jsx-forbidden-tag`,
`jsx-unknown-component`).

With no copy, all three exit 0 with the notice only. `avatar` is
registered at the pin (`renderers/data-display/avatar.tsx:17`) and not
deprecated, so the console's html compile renders it and nothing refused
it before this change. That is the narrowing the `(narrowing)` arm and
BREAKING rest on.
- ⚠️ **Round 1 misread this half.** It took "the renderer still renders
`div`" from ruling A's reading, which predates objectui#10757, instead
of reading the pin. The pin had landed on `main` (objectstack-ai#20436) before round 1
ran. For `div`, this change moves a refusal the 17.5.0 console already
gives at render time to author time. The arm still holds because of the
undeclared tags.
- **CLI fixtures the live fallback newly refuses** (round 1, with the
console copy present): 23 tests went red across
`build-json-failure-conversions.e2e` (5),
`validate-json-failure-conversions.e2e` (4) and
`jsx-gate-manifest-notice.e2e` (14). `lint-conversion-notices.e2e`
stayed green, but its page is refused too. The three conversion fixtures
moved from `div` to `box`. The notice file's 14 manifest-less cases are
skipped by name where the CLI's own console copy exists. They run in the
CI job, which builds no console, and their rules are pinned hermetically
in `src/utils/sdui-manifest.test.ts`.
- **Examples:** only `examples/app-showcase` carries html pages (three).
- **H3 (shipped pages stay clean)**, round 2, merged tree. `main`
brought a regenerated `sdui.manifest.json` carrying `tier: 'html'` marks
(objectstack-ai#20582).
  - `validate-jsx-pages.production-witness.test.ts`: 5/5 pass.
- `examples/app-showcase` with the console copy present: exit 0 on `os
validate` / `os compile` / `os lint`, with zero `jsx-*` / `sdui/*`
findings.
- **H4 (ablation, round 1)**, through `node
scripts/ablation-replace.mjs` in WRAP mode:
- the anchor `resolve(CONSOLE_PACKAGE_JSON)` went 1 → 0, and
`resolve(CONSOLE_SDUI_MANIFEST)` (the old subpath) 0 → 1;
  - 4 console-leg pins went red ("expected undefined to be defined");
- restore: the blob is back at the HEAD blob `be1f8d4ad33e`, and `git
diff HEAD` is empty.

The pins import the subject from `src/`, so no `dist/` sits on that
path. This round changed no source or test file.

## Tests, at `77338a7186`

- The whole CLI `unit` project (`--project unit --maxWorkers=2`) with a
real-path `TMPDIR`: 234/234 files, 3347/3347 tests. With the default
macOS `TMPDIR`: 232/234. The 2 files are `published-subpath-console.pin`
and `published-subpath-hook-body.pin`, 5 cases comparing `/var` against
`/private/var`. They are host-only and untouched here.
- `pnpm --filter @objectstack/cli typecheck` (`tsc --noEmit` plus
`check:test-typecheck`): exit 0.
- The four touched nightly `*.e2e` files (`OS_TEST_TIERS=nightly
--project integration`):
  - with the console copy present: 53 passed, 14 skipped;
  - without it (the CI state): 67/67 passed.

  The rest of the integration layer is declared to CI.

## Gates, at `77338a7186`

- `node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack
--commands`: 63 derived, the same 63 as round 1. All 63 exit 0, and
`--ran` reconciled "63 run, 0 NOT-MEASURED (a DERIVED zero — all 63
recorded an exit code and none of them is 3)".
`check:dual-build-cjs-loads` first answered PREREQUISITE NOT MET, then
exit 0 after building its eight missing packages.
- `check-adr-0087-registration --base origin/main`,
`check-empty-changeset --base origin/main` (it now reads "No changeset
from the merge base modified or deleted by this diff") and
`check-changeset-no-major --base origin/main`: all exit 0.
- Roster rows that could apply, all exit 0: `check-changeset-fixed`,
`check-sdui-manifest` (plus `--self-test`), `check:authz-resolver`,
`check:error-code-casing`, `check:filter-alias-parity`,
`check:cli-examples-parity`, `check:published-readme-exports`,
`check:scaffold-emission-policy`, `check:console-injection`.
- `pnpm lint` (full repo, not narrowed): exit 0, no output.
- `node scripts/check-issue-citations.mjs --base origin/main`: exit 0.
- `check:nul-bytes`: exit 0, plus a control-byte scan of the 7 changed
files: 0.

**Declared narrowing — verification ran UNLOCKED.**
`scripts/pm/os-verify-lock.sh`
could not take the shared verify lock on this host: no usable `flock`.
The shared
verify lock is declared Linux-only (`flock` is util-linux, and a stock
macOS does
not ship it), so the command below was run directly, without the lock —
a declared narrowing, not a silent one. No serialization guarantee held
for this
run, nor for any sibling agent in this container while it ran.

every build, test, typecheck, ablation and `pnpm lint` command named
above

## Acceptance notes

- **Where the `div` → `box` prescription reaches an upgrader.** The
CLI's refusal text does not carry it: the gate answers "is not an
allowed component" / "is not a known component", from
`@objectstack/sdui-parser` (`parse.ts`). The upgrade guide does not
carry it either: `packages/spec/scripts/build-upgrade-guide.ts:78` loops
majors up to `PROTOCOL_MAJOR`, `PROTOCOL_VERSION` is `17.0.0`, and
`docs/protocol-upgrade-guide.md` does not name
`ui-html-page-div-refused`. What does carry it:
  - this changeset's FROM → TO table;
  - the console's own render-time refusal, which names `box`;
- `objectstack migrate meta --from 17`. Measured on a stack with a `div`
page, it lists the entry as one of 242 "manual change(s) require your
judgment", headed "⚠ [protocol 18] kind:'html' page source …", with
`box` as the replacement, and exits 0.
- The ledger entry's own `why` text
(`packages/spec/src/migrations/entries/semantic/18.ui-html-page-div-refused.ts`,
the spec seat's file) still says "`objectstack compile` (which `dev` and
`start` run first)", the phrasing corrected here. Noted, not edited.
- Release order, flagged by the seat in `5890591366`: Version Packages
PR objectstack-ai#20639 carries the ledger entry's changeset. If it merges before this
PR, the ledger row ships one release ahead of the CLI refusal it
describes.
- `packages/cli/src/utils/scaffold-validate.ts` (the note at :128-:133)
was re-read. It is true now, so it is not edited. A pre-existing
imprecision stays as it was: `os init` reads the invoker's directory,
which may carry its own `sdui.manifest.json` (this repository's root
does).
- Comment drift outside this claim, noted only:
- `.github/workflows/lint.yml` (:899) and
`scripts/check-sdui-manifest.mjs` (:28-30, :240) still say
`resolveSduiManifest()` degrades to parse-only silently;
- the header of `packages/lint/src/validate-jsx-pages.ts` still calls
manifest validation "not wired";
- `docs/qa/platform-checklist/areas/studio-authoring.json` describes the
showcase tree as flex/div/a.
- The five macOS-only `published-subpath-*` failures come from a
`tmpdir()` path compared with the real path that module resolution
returns. They are host-specific.
- Measurement scaffolding was all in scratch, or in this worktree's
gitignored `packages/console/dist/`, with each stand-in trap-removed.
`git status --porcelain` printed 0 lines after every run.

---
_Generated by [Claude
Code](https://claude.ai/code/session_local_1d2a197c-c20e-4e90-9be8-413d4d432289)_

---------

Co-authored-by: Jack Zhuang <50353452+hotlong@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>
veigajoao pushed a commit to veigajoao/objectstack that referenced this pull request Sep 29, 2026
… notes (objectstack-ai#20667)

Fixes objectstack-ai#20622

Clause-②: no

One new `patch` changeset (`@objectstack/cli`, in the fixed release
group) and nothing else. No code, no docs pages, no edit to any existing
changeset.

## What it carries

1. An upgrade line: the raised dependency floors cover what objectstack
loads; a lockfile-preserving upgrade can keep an older `hono` under
`@modelcontextprotocol/sdk` (via `@objectstack/cli` to
`@objectstack/mcp`), which objectstack never loads. `pnpm update hono`
clears a scanner. It states no version number.
2. A section naming, by PR number and title only, the 16 changesets (15
PRs) that shipped inside 17.5.0 without being consumed. Breaking entries
first: objectstack-ai#20458, objectstack-ai#20504, objectstack-ai#20567 (two changesets).

## Measurement

The brief's range command (`git log --diff-filter=A --name-only
8c87d26..0f6dcac -- .changeset/`) yields only 8 files. The other 8
were added BEFORE the version commit and were already left unconsumed by
it (the tree at `8c87d26a5d` still holds them). The set that shipped in
17.5.0 and is still pending is the changeset directory at `0f6dcac5e9`
intersected with `origin/main`: 16 files, all still pending, matching
the triage's 16 and its breaking set (3 PRs, 4 files). Breaking was
decided by each file's text (`BREAKING` banner / narrowing arm).

Code anchors for the upgrade line: `packages/mcp/package.json` depends
on `@modelcontextprotocol/sdk ^1.30.0`; `packages/cli/package.json`
depends on `@objectstack/mcp`;
`packages/plugins/plugin-hono-server/package.json` carries `hono
^4.13.5`; `packages/mcp/src` imports only `server/mcp`, `server/stdio`,
`server/webStandardStreamableHttp` and `types` from the SDK (no
`server/streamableHttp`).

## Gates

19 derived by `dispatch-gates.mjs --commands`, all 19 run and exit 0
(adr-0087-registration, changeset-no-major, closing-keyword-parity,
comment-mask-corpus, empty-changeset, gate self-tests, nul-bytes,
published-files and the rest); `--ran` reconciliation: 19 derived, 19
run, 0 NOT-MEASURED, 0 UNRUN. `check-changeset-fixed` green. Ordering:
must land before objectstack-ai#20639 (Version Packages, open at the time of writing).

---

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01VDtqoecgES7ScQYGbFVDRv

---------

Co-authored-by: Claude <noreply@anthropic.com>
@github-actions
github-actions Bot force-pushed the changeset-release/main branch from 5ce847c to 14f155a Compare September 29, 2026 18:14
@github-actions
github-actions Bot force-pushed the changeset-release/main branch from 14f155a to c477a7d Compare September 30, 2026 00:29
@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor Author

📓 Docs Drift Check

⚠️ 144 changed file(s) yielded no anchor (packages/adapters/hono/CHANGELOG.md, packages/adapters/hono/package.json, packages/apps/account/CHANGELOG.md, …), so the pages documenting them are NOT COVERED by this run — this is not a clean bill of health for those files. Nothing else in this diff resolved to a documentable surface (no symbol, route or SDK anchor derived from 72 changed package(s)).

What this run could not see
  • 144 changed file(s) yielded no anchor (packages/adapters/hono/CHANGELOG.md, packages/adapters/hono/package.json, packages/apps/account/CHANGELOG.md, …) — pages documenting those are invisible to this run
  • a page that states a rule by its inputs shares no identifier with the emitter that implements the rule, so an emitter-only diff cannot list it — not on this run and not on any run. Measured on fix(driver-sql): emit varchar(maxLength) for a text field a declared index keys on #11430: content/docs/protocol/objectql/types.mdx documents the text-family column mapping by the ObjectQL type names it maps FROM (text / textarea / html) while the diff changed createColumn; it went unlisted, and it was the page that diff falsified, in four places. No shared token exists to detect this on, so a rule your change carries has to be re-read by hand in the pages that restate it.
  • a key NAME is not a key, so the hand re-read the line above prescribes can land on the wrong schema. The same spelling is authorable on one governed type and a [REMOVED] tombstone on another for each of active, aria, joins, objects, template, tools and version (censused on [finding] tools is a key on BOTH AgentSchema (tombstoned, dead) and SkillSchema (live, cloud-attested), so a name-based search attributes skill examples to the agent key — it produced a false stop-the-line alarm on PR #19059 #19093 over the liveness ledger's governed types, top-level keys); nothing in a search result distinguishes the two, so a grep hit on a LIVE example reads as evidence about the DEAD key. Measured on fix(spec): the agent.tools liveness row says dead — it claimed live on a key the schema tombstoned #19059: content/docs/ai/agents.mdx was reported as contradicting the agent.tools tombstone over its tools: example at :161, which is inside the defineSkill({ block opened at :155 — the page was already correct. Settle ownership by PARSING the value against both schemas, never by the name: that literal PASSES SkillSchema, and as an AgentSchema it FAILS at tools with the tombstone prescription. ⛔ These names are not the whole class — a key retired through a .strict() guidance map leaves no tombstone in the walked shape and none of them here (tool.category, live as AIToolDefinition.category).

Coarse fallback — 166 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): node scripts/docs-audit/affected-docs.mjs --json c7396f1a99bf3ec6358186796a9a880a762a2efd → packageMentionDocs.

@github-actions
github-actions Bot force-pushed the changeset-release/main branch from 8bf27b1 to aa96b96 Compare October 1, 2026 18:17
@github-actions
github-actions Bot force-pushed the changeset-release/main branch from aa96b96 to f671889 Compare October 1, 2026 23:52
@os-zhuang
os-zhuang enabled auto-merge October 1, 2026 23:53
@os-zhuang
os-zhuang added this pull request to the merge queue Oct 2, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 2, 2026
@github-actions
github-actions Bot force-pushed the changeset-release/main branch from f671889 to 43369f6 Compare October 2, 2026 01:23
@os-zhuang
os-zhuang enabled auto-merge October 2, 2026 01:24
@os-zhuang
os-zhuang added this pull request to the merge queue Oct 2, 2026
Merged via the queue into main with commit 617f25f Oct 2, 2026
40 checks passed
@os-zhuang
os-zhuang deleted the changeset-release/main branch October 2, 2026 02:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file documentation Improvements or additions to documentation size/xl tooling

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant