Skip to content

release: v0.9.2 — pinned Beeper, gated :next channel, stronger release gates - #29

Merged
hamr0 merged 7 commits into
masterfrom
chore/fix-ledger
Sep 30, 2026
Merged

hamr0 merged 7 commits into
masterfrom
chore/fix-ledger

Conversation

@hamr0

@hamr0 hamr0 commented Sep 30, 2026

Copy link
Copy Markdown
Owner

Summary

  • Beeper pin: beeper-version.txt (read via scripts/pinned-beeper-version.sh) is the Beeper version for releases, :edge and the PR gate — passed as BEEPER_VERSION so the GHA cache can't reuse a stale download (the reason :latest shipped 4.3.123 unexpectedly).
  • :next channel: beeper-next.yml (weekly + manual) builds master with the newest stable Beeper when it differs from the pin, gates it, publishes :next / :next-beeper-<ver>, and opens a beeper-update issue.
  • Stronger gates: first-paint gate also checks the API through the forwarder and the HEALTHCHECK; rfb.py full-length handshake reads; least-privilege tokens on gate jobs; notify-failure opens a release-gate-failed issue.
  • Docs: PRD version history to 0.9.1, :next in README.
  • PATCH: release/packaging tooling only — the running container is unchanged.

Review

/branch-review medium at 63aca16: ready, no blockers (4 non-blocking items to the fix ledger). Unit tests 48/48; first-paint gate passed locally. mcp-guard-check and vnc-auth-check first run here in CI.

🤖 Generated with Claude Code

hamr0 and others added 7 commits September 30, 2026 18:39
The table stopped at 0.8.0; add 0.8.1, 0.9.0 and 0.9.1 from the CHANGELOG.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01U1PKBQDukuTNc4Eak9icLz
…he gate jobs

- scripts/rfb.py: read the version string, count byte and refusal reason until
  the full length arrives or the peer closes, so a read split across TCP
  segments is no longer misjudged as "not an RFB server". Error messages are
  unchanged.
- release.yml: verify and verify-arm64 only build locally and never push, so
  they get `contents: read` instead of inheriting `packages: write`.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01U1PKBQDukuTNc4Eak9icLz
… an issue on failure

- scripts/resolve-beeper-version.sh resolves Beeper stable once per run; prepare
  exposes it and verify, verify-arm64, publish and :edge build with
  BEEPER_VERSION. The fixed "latest stable" download step was served from the
  GHA build cache, so v0.9.1 shipped Beeper 4.3.123 while stable was newer and
  verify and publish could build different Beepers.
- first-paint-check.sh now also requires Beeper's API to answer from the host
  through the socat forwarder and the container healthcheck to report healthy,
  in the same fresh-profile boot.
- notify-failure opens a release-gate-failed issue assigned to the owner, or
  comments on the open one; the summary step takes its values through env and
  says when the publish itself failed.
- docs: CHANGELOG [Unreleased], CLAUDE.md, PRD, Dockerfile comment.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…channel

- beeper-version.txt (4.3.123) is the single Beeper version for releases,
  :latest, :edge and PR builds. prepare reads it from the release ref, so each
  tag keeps its Beeper on weekly rebuilds; a ref without the file fails closed
  (release-gate-failed issue) instead of falling back to latest stable.
- beeper-next.yml (weekly + dispatch): if the newest stable differs from the pin,
  gate it on amd64 + arm64 and publish :next / :next-beeper-X.Y.Z, then open or
  comment a beeper-update issue (passed/failed, how to promote). A failed
  version check also opens an issue.
- self-review fixes: a failed or empty version resolve now fails the step; the
  PR gate builds the pinned Beeper; dead sed removed from notify-failure.
- scripts: pinned-beeper-version.sh + shared beeper-artifacts-lib.sh.
- docs: CHANGELOG, CLAUDE.md, PRD, context, Dockerfile comment.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…er-update lines

- beeper-next.yml: check resolves the master commit once (sha output); both
  gates and publish-next check out that exact commit, so a merge mid-run can't
  push untested code to :next. The beeper-update issue names the commit.
- PRD: three lines still said Beeper auto-updates by default; releases, :edge
  and PR builds use beeper-version.txt, only manual builds roll.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Nq41md4rvS7JVETodUvToU
Mention the :next channel in the README install section.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…e gates

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@hamr0
hamr0 merged commit e2728db into master Sep 30, 2026
3 checks passed
@hamr0
hamr0 deleted the chore/fix-ledger branch September 30, 2026 20:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant