Skip to content

docs: the documents describe the 0.1.0 release; main moves to 0.1.1.dev0 - #98

Merged
krzysztof-smartdataengines merged 2 commits into
mainfrom
docs/after-0.1.0
Sep 27, 2026
Merged

krzysztof-smartdataengines merged 2 commits into
mainfrom
docs/after-0.1.0

Conversation

@krzysztof-smartdataengines

Copy link
Copy Markdown
Contributor

Summary

0.1.0 is on both registries, and the documents still spoke of candidates. They now say what
happened on 27 September. main also moves to a development version, 0.1.1.dev0 and
0.1.1-dev.0, so a build of a later commit cannot carry the released number.

Why the version moves

If main stayed at 0.1.0, every later commit would build an artefact named like the release, and
pip treats a local install of one as the release. Measured: I built a wheel of f4d57c4 with one
extra comment and installed it. Then pip install smart-data-engine-sdk==0.1.0 answered
"Requirement already satisfied", and the comment stayed installed.

tools/release_tag.py still accepts the manifest's version on this tree, so the test that ties the
tag to sde.__version__ holds. Nothing is tagged here.

What changed

  • Install commands in docs/weather-starter.md pin 0.1.0, and the artifact names are the
    ones a later commit builds. README.md and examples/weather/README.md name the release.
  • docs/implementations.md: pip install and npm install install 0.1.0.
  • CHANGELOG.md: the publication date. Each tag published on its first run, with attestations
    and provenance, and on npm 0.1.0 is latest.
  • docs/publishing.md:
    • The state table no longer says the npm package is unpublished.
    • §1 lists three npm versions. Its paragraph about an unpublished package is now past tense, and
      step 4 no longer says the first publish should come from CI.
    • "Why this is worth doing before the first release" no longer says the name resolves to nothing.
    • §5.1 says main moves to a development version after a release, and why.
    • §5.3's three owner steps are marked done, and §5.4 says what the provenance gap turned out to be.
    • §5.5 step 7 records the final release and what to expect next time.
  • docs/github-security.md:
    • Provenance is in the past tense.
    • The checklist marks the release workflow and the registry accounts' 2FA as done, and names the
      tag patterns and the released versions.
    • The CI line no longer counts Pythons and Nodes. It refers to docs/platforms.md, which a test
      holds.
    • "Eleven required status checks" becomes fourteen.

A test that could not see a count

test_the_security_document_counts_the_required_checks_the_ruleset_requires matched only
"N required checks". So "Eleven required status checks" in the threat model stayed wrong from twelve
checks to fourteen. The pattern now matches every order the document uses.

Mutations on docs/github-security.md, each restored from a copy kept beside it:

Mutation Result
M1 "Fourteen required status checks" → Eleven (the old pattern's blind spot) red
M2 "all fourteen status checks required" → thirteen (also unseen before) red
M3 "fourteen required checks" → twelve (the old pattern's case) red
C1 control: "private vulnerability reporting" → "reports" green

Before the text was fixed, the broadened test failed with
the ruleset requires 14 checks (fourteen) and the document says 'eleven'.

Tests

  • make check with both live engines on 704b521:
    • ruff and mypy are clean;
    • Python: 2101 passed and 10 skipped (the orderbook slice);
    • TypeScript: 999 of 999.
  • On 2e15e52, which only replaces one sentence in docs/publishing.md with measured times, the
    release, packaging, platforms, README-claims and implementer-document tests passed: 94 of 94.
  • 0.1.0 itself, from PyPI, into a clean CPython 3.14.7, ran the suite of f4d57c4 with both
    engines: 2096 passed, 10 skipped, and 5 failed. The five are the candidate's five: each computes
    a repository path from sde.__file__, which for an installed package points into
    site-packages.

🤖 Generated with Claude Code

0.1.0 is on both registries. The install commands pin it, and the pages that
still spoke of candidates, of an unpublished npm package or of a publish
workflow yet to be written now say what happened on 27 September.

main moves to 0.1.1.dev0 and 0.1.1-dev.0. Otherwise every later commit builds
an artefact carrying the released number, and pip treats a local install of one
as the release: measured with a wheel of f4d57c4 plus one comment,
`pip install smart-data-engine-sdk==0.1.0` answered "Requirement already
satisfied" and the comment stayed installed.

The test that holds the security document's count of required checks matched
only "N required checks", so "Eleven required status checks" stayed wrong from
twelve checks to fourteen. It now matches every order the document uses, and
went red on the stale sentence before the sentence was fixed.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The first version of this sentence said "straight after the upload" and
"about a minute later". The measured times: the wheel was uploaded at
20:49:10Z and the JSON API listed it at 20:51:58Z, while an unpinned
`pip install --no-cache-dir` started at 20:52:49Z still resolved 0.1.0rc1.
The simple index listed 0.1.0 at 20:53:29Z. pip's cache was excluded, so the
lag was the index's.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@krzysztof-smartdataengines
krzysztof-smartdataengines merged commit 45c274d into main Sep 27, 2026
14 checks passed
@krzysztof-smartdataengines
krzysztof-smartdataengines deleted the docs/after-0.1.0 branch September 27, 2026 21:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant