Repository navigation
docs(releases): the curated 17.7.0 release page and upgrade checklist - #21994
Merged
objectstack-fleet[bot] merged 4 commits intoOct 6, 2026
Merged
Conversation
…cklist Adds content/docs/releases/v17/17-7.mdx, compiled from the 323 changesets the version commit 4e4e881 consumed, the ADR-0087 registry entries added since 17.6.0 and the five objectui pin moves; wires it into the v17 meta.json, index.mdx and the docs-audit list; and appends one dated correction to 17-6.mdx for the anonymous-endpoint known issue. Claude-Session: https://claude.ai/code/session_016tKoy8NJa35Yih1FdzrVmn Co-authored-by: Claude <noreply@anthropic.com>
A second pass over every cited sha, PR number, key name and behavioural claim on the 17.7.0 page, against each changeset. Among the corrections: element:text variant is an advisory component-props finding, not a parse refusal; the missing-table exit 1 of the one-shot previews was superseded in the same release by empty work and exit 0; the cloud AI runtime never read agent.lifecycle; #21464 has nine stages, not eleven; and a job body's write of the stored-metadata tables is not covered by #21563. Claude-Session: https://claude.ai/code/session_016tKoy8NJa35Yih1FdzrVmn Co-authored-by: Claude <noreply@anthropic.com>
…stored row under a code-defined datasource name The read half of #21922 landed on main after the 17.7.0 publish (1abfc58, #21985; not an ancestor of the version commit 4e4e881). Claude-Session: https://claude.ai/code/session_016tKoy8NJa35Yih1FdzrVmn Co-authored-by: Claude <noreply@anthropic.com>
Contributor
📓 Docs Drift CheckNothing in this diff resolved to a documentable surface (no symbol, route or SDK anchor derived from 0 changed package(s)), so this run has no opinion about the docs. What this run could not see
Coarse fallback — 0 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): |
This was referenced Oct 6, 2026
Each finding re-verified against its cited commit, changeset or code at the version commit before it was applied. The stored-metadata summary no longer calls the metadata protocol the only reader for app-authored work (a flow's get_record node reads the projected, keyed form); the data-door filter refusal names its class, not the shapes that evaded 17.6.0's refusal, and two Security lines are reduced to their class the same way; 0fc8087 joins the smaller breaking changes; the datasource default refusal, the public-form withdrawal, the field-level read list, the account-linking opt-out and the approval-node registration claim are narrowed to what their changesets say; 49524f6 joins the Security list; the console CHANGELOG cap is stated; the os secret rewrap step is marked optional with its rollback cost; and the 17-6 correction's link label names where it lands. Claude-Session: https://claude.ai/code/session_016tKoy8NJa35Yih1FdzrVmn Co-authored-by: Claude <noreply@anthropic.com>
objectstack-fleet
Bot
deleted the
claude/issue-21989-release-notes-17-7
branch
October 6, 2026 15:42
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #21989
Clause-②: no
What this is
This PR adds the curated release page for 17.7.0,
content/docs/releases/v17/17-7.mdx(1,402 lines). It was written after the publish: npmlatestmoved on 2026-10-06, and@objectstack/spec@17.7.0went out at 12:22:14Z. It also wires the page in:content/docs/releases/v17/meta.json:17-7comes ahead of17-6.content/docs/releases/v17/index.mdx: the status blockquote, the minors warning, the per-release list and the checklist links now name 17.7.0 as current. This is the same shape docs(releases): finalize the 17.6.0 notes after publish #21362 used for 17.6.0.scripts/docs-audit/handwritten-docs.json: the page joins the docs-accuracy audit scope.content/docs/releases/v17/17-6.mdx: one dated correction (2026-10-06) on the anonymous-endpoints known issue. security(core, plugin-security): an unauthenticated principal never resolves the permission sets bound to theguestanchor; ADR-0090 D9 is declared and seeded but not enforced #21158 was closed as not planned on 2026-10-04.The page follows the 17.6 page's structure:
Sources and counts
The version commit
4e4e881427(chore: version packages #21352) consumed 323 changesets. 322 are new. One,748b240(feat(types,automation): a host's per-kernel scheduled-work OFF reports its own reason #21270), shipped in 17.6.0 and is listed again; the page explains this in its own section.69 CHANGELOGs carry a 17.7.0 section, and 48 of them have entries. Their 444 entries (194 minor, 250 patch) de-duplicate to the 323 changesets.
Two commits landed on
mainafter the Version Packages PR's last refresh and before it merged:8a399b2b15(fix(service-datasource): the admin door reads a datasource's origin from provenance, and a metadata-door write reaches it in the same boot #21977, for finding(service-datasource): a datasource created through the metadata door is missing from the admin door until restart, then reads as code-defined because the admin read defaults a missing origin to code #21923)04e776b39a(docs(spec, docs): App.defaultAgent and actions-as-tools name the agent route as the one chat door #21976, for docs(spec, docs): App.defaultAgent's docblock and actions-as-tools.mdx name POST /api/v1/ai/assistant/chat, a route cloud retired (cloud#2621) #21968)Both are ancestors of the version commit (exit 0 for each), so the 17.7.0 packages carry their code. But the version commit did not consume their changesets, so no 17.7.0 CHANGELOG line names them. The release-integrity audit named both in a warning.
objectui: the pin moved five times and ends at
0abd4f9f8769:89cad75d5570(chore(objectui): bump the console pin to 89cad75d5570 (carries objectui 0858267e, 8001068b, 3ae91930 and d0fba91aa) #21380)ab1879721595(chore(objectui): bump the console pin to ab1879721595 (carries objectui f624f278, b0bf413c and ab187972) #21625)2e818d0b51ec(chore(objectui): bump the console pin to 2e818d0b51ec (carries objectui#11466, #11574, #11578, #11581 and #11583) #21710)9dfaca654311(chore(objectui): bump the console pin to 9dfaca654311 (carries objectui#11611, #11614 and #11619) #21800)0abd4f9f8769(chore(objectui): bump the console pin to 0abd4f9f8769 (carries objectui#11636, #11637, #11635, #11624 and #11640) #21827)Across 173 commits, 254 changesets were added and 229 of them release something. 65 are declared breaking, plus one commit marked
!. The Console table answers each.PROTOCOL_VERSIONis still 17.0.0.Premise corrections
9dfaca654311. The tree has five, ending at0abd4f9f8769(8832655, chore(objectui): bump the console pin to 0abd4f9f8769 (carries objectui#11636, #11637, #11635, #11624 and #11640) #21827). The page covers all five.check:role-wordrefuses on docs pages, and release pages are not in its baseline. The coverage table therefore names that entry by its subject and points atos migrate meta --from 17.Fact-check
A second pass checked every cited SHA, PR number, key name and behavioural claim against the commits, changesets and registry entries. It corrected 31 claims (commit
e4a6280b46).Two more corrections came earlier, while drafting:
ui-object-*members, not eighteen.Mechanical checks on the final page:
After the fact-check,
maingained1abfc58(#21985), which lands the read half of #21922. It is not an ancestor of the version commit: the test returned exit 1, and the control commit753e7a1returned exit 0. So in 17.7.0, the metadata door's reads still serve a stored row under a code-defined datasource name. Commit8347e0d172says so in the datasource migration bullet.Independent fact-check and fix round
An independent, read-only fact-check of head
8347e0d172returned FAIL with 13 findings (record: #21989 comment 6018402030): 2 wrong facts (a flow'sget_recordnode still reads the stored-metadata tables, in projected form), 1 security line that named the filter shapes and depth threshold evading 17.6.0's refusal, 1 breaking change missing from the Breaking section (0fc8087, #21626), 1 link whose label did not match its target, 4 overstatements, 1 missing security fix (49524f6, #21420), 1 missing rollback caveat onos secret rewrap --apply, and 2 minor wording issues.All 13 were re-verified against their sources and applied in
a53c972fa7; none was refuted. A scan for any other line naming a bypass shape of a fixed issue reduced two more lines to their class (0728cbf,fb69825).Measured on
a53c972fa7node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commandsderives 57 commands; all 57 exited 0 (--ran: "57 run, 0 NOT-MEASURED (a DERIVED zero)"). The verdicts include:check:role-word,check:release-notesandcheck:release-page-status: OK.--strict(10 minors).check:nul-bytes: OK.TURBO_FORCE=true pnpm turbo run build --filter=@objectstack/docs, run under the verify lock, reportsTasks: 2 successful, 2 totalandCached: 0 cached. The builtreleases/v17/17-7.htmlcarries the corrected text and none of the removed text.Not in this PR
skip-changeset).Generated by Claude Code