Skip to content

Release Platform packages - #1

Merged
rajat1saxena merged 1 commit into
mainfrom
changeset-release/main
Oct 3, 2026
Merged

rajat1saxena merged 1 commit into
mainfrom
changeset-release/main

Conversation

@github-actions

@github-actions github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@codelitdev/platform@0.2.0

Minor Changes

  • 047058c: selectHttpCredential and selectMcpCredential now reject an Authorization header that is present but is not Bearer <token> with a new { kind: "malformed" } selection (error code unauthenticated). Previously such a header was ignored, so a request could fall back to a session cookie or API key, contrary to ADR 0001. Bearer <token> <extra> is also malformed now. mcp-server-kit rejects malformed headers before calling authenticate.

    Product changes

    • Code that branches on the selection result must handle "malformed" like "ambiguous" (return a rejected result with selected.error). TypeScript reports the unhandled case where the code reads selected.credential.

@codelitdev/platform-cli@0.2.0

Minor Changes

  • 047058c: Replace versioned upgrade with sync, bundle the compatibility preset, and update the template.

    CLI

    • sync replaces upgrade. It re-renders the CLI-managed files from this release's template and refuses to overwrite a file whose hash no longer matches the manifest. Writes need a clean Git worktree; --dry-run works in a dirty one.
    • The manifest is schemaVersion: 2: it records the product name and slug and the CLI version that last synced, and drops templateVersion, appliedUpgrades, and presetVersion. v1 manifests are migrated on the next sync.
    • The compatibility preset ships inside the CLI (dist/preset.json). @codelitdev/platform-preset is no longer published.
    • External pins now come from the template's exact versions: better-auth 1.7.7, @electric-sql/pglite 0.5.8, drizzle-kit 0.31.10, Next.js 16.3.6, and React 19.2.8.
    • The only managed file is .github/workflows/platform-conformance.yml. tooling/platform/config.ts and the API README title codemod are removed.
    • The package includes its README.

    Template

    • platform-conformance.yml (managed) runs doctor with the pinned CLI version, check:drift, and the API package's test:conformance script. Lint, typecheck, test, and build move to a product-owned code-quality.yml.
    • create writes a product-owned .github/dependabot.yml that groups @codelitdev/* updates into one pull request per release.
    • The Better Auth schema is regenerated for 1.7.7, which drops account.issuer.
    • .env.example points at the Postgres service in docker-compose.yml.
    • Removed leftover reference-product branding, the unused logger.ts, and the duplicate root generate:check script.

    Product changes for this release

    • Add a test:conformance script to the API package that runs the product's @codelitdev/platform-conformance suites. The conformance workflow fails without it.
    • sync removes test, typecheck, and build from the managed workflow. If no other workflow runs them, copy templates/saas-product/.github/workflows/code-quality.yml.
    • Upgrade to the new external pins, including Next.js 16, or doctor fails.
    • Add a migration that drops or relaxes account.issuer before running Better Auth 1.7.7.
    • Handle the new "malformed" credential selection from @codelitdev/platform (see its release notes).

Patch Changes

  • 93b95f7: Derive generated product names from the destination directory basename so absolute and nested paths produce valid workspace scopes, and keep generated Next.js configuration stable after its first production build.

@codelitdev/billing@0.2.0

Patch Changes

  • 9bef99a: Ship the codelit-billing CLI through a committed bin/codelit-billing.js shim so workspace installs link the command before dist/ is built.

@codelitdev/mcp-server-kit@0.2.0

Patch Changes

  • 047058c: selectHttpCredential and selectMcpCredential now reject an Authorization header that is present but is not Bearer <token> with a new { kind: "malformed" } selection (error code unauthenticated). Previously such a header was ignored, so a request could fall back to a session cookie or API key, contrary to ADR 0001. Bearer <token> <extra> is also malformed now. mcp-server-kit rejects malformed headers before calling authenticate.

    Product changes

    • Code that branches on the selection result must handle "malformed" like "ambiguous" (return a rejected result with selected.error). TypeScript reports the unhandled case where the code reads selected.credential.
  • Updated dependencies [047058c]

    • @codelitdev/platform@0.2.0

@codelitdev/oauth-server-kit@0.2.0

Patch Changes

  • 047058c: Accept Better Auth 1.7 instances in createMcpOAuthDiscoveryRoutes without a cast: auth.options.baseURL is typed as unknown and rejected at runtime unless it is a static URL string.

@codelitdev/platform-conformance@0.2.0

Patch Changes

  • 047058c: Require MCP conformance adapters to expose the unauthenticated HTTP response headers and fail when the 401 response lacks a canonical protected-resource bearer challenge.
  • 047058c: Document product adoption and add a standalone HTTP MCP OAuth discovery suite that does not require reference-product routes or fixtures.
  • Updated dependencies [047058c]
    • @codelitdev/platform@0.2.0

@codelitdev/design-system@0.2.0

No changes in this release.

@codelitdev/observability@0.2.0

No changes in this release.

@github-actions
github-actions Bot force-pushed the changeset-release/main branch 4 times, most recently from 6f33337 to c069473 Compare October 3, 2026 19:11
@github-actions
github-actions Bot force-pushed the changeset-release/main branch from c069473 to ab954d7 Compare October 3, 2026 19:14
@rajat1saxena
rajat1saxena self-requested a review October 3, 2026 19:16
@rajat1saxena
rajat1saxena merged commit 981e2e9 into main Oct 3, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant