Skip to content

release: 0.1.0-alpha.2 - #45

Merged
imran-siddique merged 1 commit into
mainfrom
release/v0.1.0-alpha.2
Sep 2, 2026
Merged

release: 0.1.0-alpha.2#45
imran-siddique merged 1 commit into
mainfrom
release/v0.1.0-alpha.2

Conversation

@imran-siddique

Copy link
Copy Markdown
Member

Release preparation for 0.1.0-alpha.2, following step 1 and 2 of RELEASING.md.

What is in this release

All three already merged to main:

PR
#41 wire spec_version now matches spec/VERSION
#42 schema $id moved off agentrust.io, a domain we do not own
#43 npm dist-tag derived from spec/VERSION

Why a new version instead of releasing v0.1.0-alpha.1

npm already holds 0.1.0-alpha.1 from the bootstrap publish that RELEASING.md explicitly sanctions:

If npm does not expose publisher settings until the first version exists, bootstrap only that first package ownership using npm's interactive 2FA flow

release.yml publishes both registries from one release event, and release-assets has needs: [publish-pypi, publish-npm]. Cutting v0.1.0-alpha.1 would publish PyPI, fail publish-npm on the duplicate version, and skip attestation entirely. A fresh version lets one build feed both registries with provenance intact, which is what the pipeline exists to do.

PyPI has never been published, so 0.1.0-alpha.2 will be its first version.

On the moved digests

spec/VERSION is the contract version and the source both package versions derive from, so bumping it changes the wire spec_version, which sits inside the RFC 8785 bytes that get hashed. Both goldens were regenerated from the code rather than hand-edited, and Python and TypeScript independently agree on the new tool-transcript hash.

A dead test case, found while bumping

tests/test_repository_gates.py had "0.1.0-alpha.1" as a dict key twice:

"0.1.0-alpha.1": ("0.1.0.dev0", "0.1.0-alpha.1.0"),
"0.1.0-alpha.1": ("0.1.0a1", "0.1.0-alpha.1"),

Python keeps the last, so the first entry was silently discarded and the dev phase has never been tested. Its npm spelling was wrong as well: 0.1.0-alpha.1.0 is not something ecosystem_versions can produce for any input. Restored as a real 0.1.0-dev case, with both alpha spellings now asserted.

Verification

Gate Result
check_versions contract=0.1.0-alpha.2 python=0.1.0a2 npm=0.1.0-alpha.2
check_release_tag v0.1.0-alpha.2 pass
npm_dist_tag alpha
check_schemas / check_typescript_schemas / check_otel_compatibility pass
Conformance fixtures 13/13
Python tests 111 pass
TypeScript tests 41 pass

After this merges

  1. Configure the npm trusted publisher for @agentrust-io/telemetry, now possible because the package exists.
  2. Create the GitHub release tagged v0.1.0-alpha.2 targeting main.
  3. Approve the pypi and npm deployment jobs.

🤖 Generated with Claude Code

https://claude.ai/code/session_01Xyu1wLe68MPCKaqUXeEpXn

Bumps spec/VERSION, which is the single source both package versions derive
from, so the wire spec_version and the golden digests move with it. The two
goldens were regenerated from the code, not hand-edited.

Contents of this release, all already merged to main:

- #41 the wire spec_version now matches spec/VERSION
- #42 the schema $id moved off agentrust.io, a domain we do not own
- #43 the npm dist-tag is derived from spec/VERSION

Why a new version rather than releasing v0.1.0-alpha.1: npm already holds
0.1.0-alpha.1 from the bootstrap publish RELEASING.md sanctions, and the release
workflow publishes both registries from one event with release-assets gated on
both. Cutting the existing version would fail publish-npm on the duplicate and
skip attestation entirely. A fresh version lets one build feed both registries
with provenance intact, which is what the pipeline is for.

Fixes a dead test case found while bumping. tests/test_repository_gates.py had
"0.1.0-alpha.1" as a dict key twice, so Python discarded the first entry and the
dev phase was never exercised. That entry's npm spelling was also wrong,
"0.1.0-alpha.1.0", which ecosystem_versions never produces. Restored as a real
0.1.0-dev case and both alpha spellings are now asserted.

Gates: all four checks, release-tag gate against v0.1.0-alpha.2, dist-tag
resolves to alpha, 13/13 conformance fixtures, 111 Python tests, 41 TypeScript
tests.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Xyu1wLe68MPCKaqUXeEpXn
@imran-siddique
imran-siddique merged commit 29c13cf into main Sep 2, 2026
8 checks passed
@imran-siddique
imran-siddique deleted the release/v0.1.0-alpha.2 branch September 2, 2026 23:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant