Skip to content

release: publish verified Wrangle 1.0.1 through CI - #57

Merged
mikkokotila merged 4 commits into
masterfrom
codex/release-1-0-1
Oct 3, 2026
Merged

mikkokotila merged 4 commits into
masterfrom
codex/release-1-0-1

Conversation

@mikkokotila

@mikkokotila mikkokotila commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Installing Wrangle from PyPI currently delivers the historical 0.7.6 interface.

The project owner explicitly designates bit-mis as the sole reviewer and code owner. Its automated approval satisfies the project review requirement; no separate human approval is required. The unrequested human-reviewer team and required-team rule have been deleted. Governance, contribution guidance and the shipped manual now match this decision without claiming independent human review. Required CI checks, stale-review dismissal, approval after the last push and no administrator bypass remain in place.

GitHub reads CODEOWNERS from the base branch. The old-owner gate is disabled for this transition so it does not require the previous human owners to approve this PR. Once the reviewed CODEOWNERS change reaches master, code-owner enforcement can require bit-mis alone.

Release 1.0.1 makes the native Polars engine, YAML protocols, CLI and agent manual available under the existing wrangle package name.

The release workflow retains separate build and provenance-signing jobs, then downloads and verifies the signed wheel/source archive before uploading those exact distributions to PyPI. Only the upload job receives the existing organization PYPI_API_TOKEN; it has read-only GitHub access and does not check out or execute Wrangle source. Token-based publication retains GitHub/Sigstore provenance and does not claim PyPI index attestations.

The README now gives direct PyPI installation and warns existing 0.x users to follow the migration guide. Release notes are dated for 1.0.1; generated manuals match the source. The measured Scorecard snapshot is updated to 8.7 on commit 9571e6d.

Validation of the release implementation (before the later ownership/governance documentation changes):

  • 1,005 tests passed with warnings as errors; coverage 89.61%.
  • Two builds produced byte-identical wheel and source archives; strict Twine, exact version/checksum checks and all eight installed-package workflows passed.
  • The publication verification step accepted the authentic v1.0.0 signed assets, including repository/workflow/commit/tag/issuer/runner checks; the local checksum command used its documented macOS equivalent.
  • Dependency audit found no known vulnerabilities; Ruff, Bandit, actionlint, lock/catalog freshness and whitespace checks passed.

Review-policy correction validation: verified the human team is deleted, required-team reviewers are empty and the old-owner gate is disabled; before/after comparison confirms CI checks, last-push approval, stale-review dismissal and no bypass remain unchanged. CODEOWNERS names only bit-mis; generated documentation and whitespace checks pass. CI reruns on 9186b7f.

Publication remains pending: merge this PR after bit-mis approval and required checks, then publish tag v1.0.1 from the reviewed master commit. Verify the resulting PyPI 1.0.1 file hashes and fresh CLI preparation against the signed release assets.

@bit-mis bit-mis left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed: no blocking findings.

@bit-mis bit-mis left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed: no blocking findings.

@bit-mis bit-mis left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed: no blocking findings.

bit-mis
bit-mis previously approved these changes Oct 3, 2026

@bit-mis bit-mis left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Change requested in inline comments.

Comment thread .github/CODEOWNERS Outdated
@mikkokotila
mikkokotila requested a review from a team October 3, 2026 12:27
bit-mis
bit-mis previously approved these changes Oct 3, 2026
@mikkokotila
mikkokotila merged commit fc93517 into master Oct 3, 2026
11 checks passed
@mikkokotila
mikkokotila deleted the codex/release-1-0-1 branch October 3, 2026 12:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants