From ab954d7db464bc6e49cced00061d2a16932f8932 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Sat, 3 Oct 2026 19:14:18 +0000 Subject: [PATCH] Release Platform packages --- .changeset/billing-bin-shim.md | 5 --- .changeset/calm-tools-name.md | 5 --- .changeset/clear-mcp-challenges.md | 5 --- .changeset/generic-mcp-conformance.md | 5 --- .changeset/kernel-malformed-authorization.md | 10 ------ .changeset/oauth-kit-baseurl-type.md | 5 --- .changeset/platform-cli.md | 30 ----------------- packages/billing/CHANGELOG.md | 6 ++++ packages/billing/package.json | 2 +- packages/design-system/CHANGELOG.md | 4 +++ packages/design-system/package.json | 2 +- packages/mcp-server-kit/CHANGELOG.md | 12 +++++++ packages/mcp-server-kit/package.json | 4 +-- packages/oauth-server-kit/CHANGELOG.md | 6 ++++ packages/oauth-server-kit/package.json | 2 +- packages/observability/CHANGELOG.md | 4 +++ packages/observability/package.json | 2 +- packages/platform-cli/CHANGELOG.md | 35 ++++++++++++++++++++ packages/platform-cli/package.json | 2 +- packages/platform-cli/src/preset.json | 16 ++++----- packages/platform-conformance/CHANGELOG.md | 9 +++++ packages/platform-conformance/package.json | 4 +-- packages/platform/CHANGELOG.md | 10 ++++++ packages/platform/package.json | 2 +- 24 files changed, 104 insertions(+), 83 deletions(-) delete mode 100644 .changeset/billing-bin-shim.md delete mode 100644 .changeset/calm-tools-name.md delete mode 100644 .changeset/clear-mcp-challenges.md delete mode 100644 .changeset/generic-mcp-conformance.md delete mode 100644 .changeset/kernel-malformed-authorization.md delete mode 100644 .changeset/oauth-kit-baseurl-type.md delete mode 100644 .changeset/platform-cli.md diff --git a/.changeset/billing-bin-shim.md b/.changeset/billing-bin-shim.md deleted file mode 100644 index d9f9d93..0000000 --- a/.changeset/billing-bin-shim.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@codelitdev/billing": patch ---- - -Ship the `codelit-billing` CLI through a committed `bin/codelit-billing.js` shim so workspace installs link the command before `dist/` is built. diff --git a/.changeset/calm-tools-name.md b/.changeset/calm-tools-name.md deleted file mode 100644 index bd62b57..0000000 --- a/.changeset/calm-tools-name.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@codelitdev/platform-cli": patch ---- - -Derive generated product names from the destination directory basename so absolute and nested paths produce valid workspace scopes, and keep generated Next.js configuration stable after its first production build. diff --git a/.changeset/clear-mcp-challenges.md b/.changeset/clear-mcp-challenges.md deleted file mode 100644 index 876f4b7..0000000 --- a/.changeset/clear-mcp-challenges.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@codelitdev/platform-conformance": patch ---- - -Require MCP conformance adapters to expose the unauthenticated HTTP response headers and fail when the 401 response lacks a canonical protected-resource bearer challenge. diff --git a/.changeset/generic-mcp-conformance.md b/.changeset/generic-mcp-conformance.md deleted file mode 100644 index 297f7f6..0000000 --- a/.changeset/generic-mcp-conformance.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@codelitdev/platform-conformance": patch ---- - -Document product adoption and add a standalone HTTP MCP OAuth discovery suite that does not require reference-product routes or fixtures. diff --git a/.changeset/kernel-malformed-authorization.md b/.changeset/kernel-malformed-authorization.md deleted file mode 100644 index aa57ead..0000000 --- a/.changeset/kernel-malformed-authorization.md +++ /dev/null @@ -1,10 +0,0 @@ ---- -"@codelitdev/platform": minor -"@codelitdev/mcp-server-kit": patch ---- - -`selectHttpCredential` and `selectMcpCredential` now reject an `Authorization` header that is present but is not `Bearer ` with a new `{ kind: "malformed" }` selection (error code `unauthenticated`). Previously such a header was ignored, so a request could fall back to a session cookie or API key, contrary to ADR 0001. `Bearer ` is also malformed now. `mcp-server-kit` rejects malformed headers before calling `authenticate`. - -**Product changes** - -- Code that branches on the selection result must handle `"malformed"` like `"ambiguous"` (return a rejected result with `selected.error`). TypeScript reports the unhandled case where the code reads `selected.credential`. diff --git a/.changeset/oauth-kit-baseurl-type.md b/.changeset/oauth-kit-baseurl-type.md deleted file mode 100644 index bbabea7..0000000 --- a/.changeset/oauth-kit-baseurl-type.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@codelitdev/oauth-server-kit": patch ---- - -Accept Better Auth 1.7 instances in `createMcpOAuthDiscoveryRoutes` without a cast: `auth.options.baseURL` is typed as `unknown` and rejected at runtime unless it is a static URL string. diff --git a/.changeset/platform-cli.md b/.changeset/platform-cli.md deleted file mode 100644 index 454b8a3..0000000 --- a/.changeset/platform-cli.md +++ /dev/null @@ -1,30 +0,0 @@ ---- -"@codelitdev/platform-cli": minor ---- - -Replace versioned `upgrade` with `sync`, bundle the compatibility preset, and update the template. - -**CLI** - -- `sync` replaces `upgrade`. It re-renders the CLI-managed files from this release's template and refuses to overwrite a file whose hash no longer matches the manifest. Writes need a clean Git worktree; `--dry-run` works in a dirty one. -- The manifest is `schemaVersion: 2`: it records the product name and slug and the CLI version that last synced, and drops `templateVersion`, `appliedUpgrades`, and `presetVersion`. v1 manifests are migrated on the next `sync`. -- The compatibility preset ships inside the CLI (`dist/preset.json`). `@codelitdev/platform-preset` is no longer published. -- External pins now come from the template's exact versions: better-auth 1.7.7, @electric-sql/pglite 0.5.8, drizzle-kit 0.31.10, Next.js 16.3.6, and React 19.2.8. -- The only managed file is `.github/workflows/platform-conformance.yml`. `tooling/platform/config.ts` and the API README title codemod are removed. -- The package includes its README. - -**Template** - -- `platform-conformance.yml` (managed) runs `doctor` with the pinned CLI version, `check:drift`, and the API package's `test:conformance` script. Lint, typecheck, test, and build move to a product-owned `code-quality.yml`. -- `create` writes a product-owned `.github/dependabot.yml` that groups `@codelitdev/*` updates into one pull request per release. -- The Better Auth schema is regenerated for 1.7.7, which drops `account.issuer`. -- `.env.example` points at the Postgres service in `docker-compose.yml`. -- Removed leftover reference-product branding, the unused `logger.ts`, and the duplicate root `generate:check` script. - -**Product changes for this release** - -- Add a `test:conformance` script to the API package that runs the product's `@codelitdev/platform-conformance` suites. The conformance workflow fails without it. -- `sync` removes test, typecheck, and build from the managed workflow. If no other workflow runs them, copy `templates/saas-product/.github/workflows/code-quality.yml`. -- Upgrade to the new external pins, including Next.js 16, or `doctor` fails. -- Add a migration that drops or relaxes `account.issuer` before running Better Auth 1.7.7. -- Handle the new `"malformed"` credential selection from `@codelitdev/platform` (see its release notes). diff --git a/packages/billing/CHANGELOG.md b/packages/billing/CHANGELOG.md index 8df1133..7f2c995 100644 --- a/packages/billing/CHANGELOG.md +++ b/packages/billing/CHANGELOG.md @@ -1,5 +1,11 @@ # @codelitdev/billing +## 0.2.0 + +### Patch Changes + +- 9bef99a: Ship the `codelit-billing` CLI through a committed `bin/codelit-billing.js` shim so workspace installs link the command before `dist/` is built. + ## 0.1.0 ### Patch Changes diff --git a/packages/billing/package.json b/packages/billing/package.json index c633b4e..86cfa1c 100644 --- a/packages/billing/package.json +++ b/packages/billing/package.json @@ -1,6 +1,6 @@ { "name": "@codelitdev/billing", - "version": "0.1.0", + "version": "0.2.0", "description": "Provider-neutral billing engine for CodeLit products", "author": "CodeLit", "type": "module", diff --git a/packages/design-system/CHANGELOG.md b/packages/design-system/CHANGELOG.md index 95940b0..b2c0a4c 100644 --- a/packages/design-system/CHANGELOG.md +++ b/packages/design-system/CHANGELOG.md @@ -1,5 +1,9 @@ # @codelitdev/design-system +## 0.2.0 + +No changes in this release. + ## 0.1.0 ### Patch Changes diff --git a/packages/design-system/package.json b/packages/design-system/package.json index f67c307..0cdb1b0 100644 --- a/packages/design-system/package.json +++ b/packages/design-system/package.json @@ -1,6 +1,6 @@ { "name": "@codelitdev/design-system", - "version": "0.1.0", + "version": "0.2.0", "description": "Shared CodeLit design tokens, Tailwind preset, and React primitives for CourseLit, MediaLit, SendLit, and FrontLit.", "license": "Apache-2.0", "author": "CodeLit", diff --git a/packages/mcp-server-kit/CHANGELOG.md b/packages/mcp-server-kit/CHANGELOG.md index 43463b2..3c7f484 100644 --- a/packages/mcp-server-kit/CHANGELOG.md +++ b/packages/mcp-server-kit/CHANGELOG.md @@ -1,5 +1,17 @@ # @codelitdev/mcp-server-kit +## 0.2.0 + +### Patch Changes + +- 047058c: `selectHttpCredential` and `selectMcpCredential` now reject an `Authorization` header that is present but is not `Bearer ` with a new `{ kind: "malformed" }` selection (error code `unauthenticated`). Previously such a header was ignored, so a request could fall back to a session cookie or API key, contrary to ADR 0001. `Bearer ` is also malformed now. `mcp-server-kit` rejects malformed headers before calling `authenticate`. + + **Product changes** + + - Code that branches on the selection result must handle `"malformed"` like `"ambiguous"` (return a rejected result with `selected.error`). TypeScript reports the unhandled case where the code reads `selected.credential`. +- Updated dependencies [047058c] + - @codelitdev/platform@0.2.0 + ## 0.1.0 ### Patch Changes diff --git a/packages/mcp-server-kit/package.json b/packages/mcp-server-kit/package.json index f01271a..e9ee63e 100644 --- a/packages/mcp-server-kit/package.json +++ b/packages/mcp-server-kit/package.json @@ -1,6 +1,6 @@ { "name": "@codelitdev/mcp-server-kit", - "version": "0.1.0", + "version": "0.2.0", "description": "MCP transport, session, auth hooks, and error mapping for CodeLit products", "author": "CodeLit", "type": "module", @@ -37,7 +37,7 @@ "zod": "^3.25.76" }, "peerDependencies": { - "@codelitdev/platform": ">=0.1.0-alpha.0" + "@codelitdev/platform": ">=0.2.0" }, "devDependencies": { "@codelitdev/platform": "workspace:*", diff --git a/packages/oauth-server-kit/CHANGELOG.md b/packages/oauth-server-kit/CHANGELOG.md index 75ceb4f..bff07e7 100644 --- a/packages/oauth-server-kit/CHANGELOG.md +++ b/packages/oauth-server-kit/CHANGELOG.md @@ -1,5 +1,11 @@ # @codelitdev/oauth-server-kit +## 0.2.0 + +### Patch Changes + +- 047058c: Accept Better Auth 1.7 instances in `createMcpOAuthDiscoveryRoutes` without a cast: `auth.options.baseURL` is typed as `unknown` and rejected at runtime unless it is a static URL string. + ## 0.1.1 ### Patch Changes diff --git a/packages/oauth-server-kit/package.json b/packages/oauth-server-kit/package.json index 00bb77c..30c8fdf 100644 --- a/packages/oauth-server-kit/package.json +++ b/packages/oauth-server-kit/package.json @@ -1,6 +1,6 @@ { "name": "@codelitdev/oauth-server-kit", - "version": "0.1.0", + "version": "0.2.0", "description": "Lean Better Auth OAuth authentication framework for web, mobile, REST, and MCP surfaces.", "author": "CodeLit", "license": "MIT", diff --git a/packages/observability/CHANGELOG.md b/packages/observability/CHANGELOG.md index 08ad1fe..11465e4 100644 --- a/packages/observability/CHANGELOG.md +++ b/packages/observability/CHANGELOG.md @@ -1,5 +1,9 @@ # @codelitdev/observability +## 0.2.0 + +No changes in this release. + ## 0.1.0 ### Patch Changes diff --git a/packages/observability/package.json b/packages/observability/package.json index 5488b62..cac7904 100644 --- a/packages/observability/package.json +++ b/packages/observability/package.json @@ -1,6 +1,6 @@ { "name": "@codelitdev/observability", - "version": "0.1.0", + "version": "0.2.0", "description": "Provider-neutral logging and optional telemetry for CodeLit products", "author": "CodeLit", "type": "module", diff --git a/packages/platform-cli/CHANGELOG.md b/packages/platform-cli/CHANGELOG.md index 46d7b95..1372066 100644 --- a/packages/platform-cli/CHANGELOG.md +++ b/packages/platform-cli/CHANGELOG.md @@ -1,5 +1,40 @@ # @codelitdev/platform-cli +## 0.2.0 + +### Minor Changes + +- 047058c: Replace versioned `upgrade` with `sync`, bundle the compatibility preset, and update the template. + + **CLI** + + - `sync` replaces `upgrade`. It re-renders the CLI-managed files from this release's template and refuses to overwrite a file whose hash no longer matches the manifest. Writes need a clean Git worktree; `--dry-run` works in a dirty one. + - The manifest is `schemaVersion: 2`: it records the product name and slug and the CLI version that last synced, and drops `templateVersion`, `appliedUpgrades`, and `presetVersion`. v1 manifests are migrated on the next `sync`. + - The compatibility preset ships inside the CLI (`dist/preset.json`). `@codelitdev/platform-preset` is no longer published. + - External pins now come from the template's exact versions: better-auth 1.7.7, @electric-sql/pglite 0.5.8, drizzle-kit 0.31.10, Next.js 16.3.6, and React 19.2.8. + - The only managed file is `.github/workflows/platform-conformance.yml`. `tooling/platform/config.ts` and the API README title codemod are removed. + - The package includes its README. + + **Template** + + - `platform-conformance.yml` (managed) runs `doctor` with the pinned CLI version, `check:drift`, and the API package's `test:conformance` script. Lint, typecheck, test, and build move to a product-owned `code-quality.yml`. + - `create` writes a product-owned `.github/dependabot.yml` that groups `@codelitdev/*` updates into one pull request per release. + - The Better Auth schema is regenerated for 1.7.7, which drops `account.issuer`. + - `.env.example` points at the Postgres service in `docker-compose.yml`. + - Removed leftover reference-product branding, the unused `logger.ts`, and the duplicate root `generate:check` script. + + **Product changes for this release** + + - Add a `test:conformance` script to the API package that runs the product's `@codelitdev/platform-conformance` suites. The conformance workflow fails without it. + - `sync` removes test, typecheck, and build from the managed workflow. If no other workflow runs them, copy `templates/saas-product/.github/workflows/code-quality.yml`. + - Upgrade to the new external pins, including Next.js 16, or `doctor` fails. + - Add a migration that drops or relaxes `account.issuer` before running Better Auth 1.7.7. + - Handle the new `"malformed"` credential selection from `@codelitdev/platform` (see its release notes). + +### Patch Changes + +- 93b95f7: Derive generated product names from the destination directory basename so absolute and nested paths produce valid workspace scopes, and keep generated Next.js configuration stable after its first production build. + ## 0.1.0 ### Patch Changes diff --git a/packages/platform-cli/package.json b/packages/platform-cli/package.json index ef86334..76db58a 100644 --- a/packages/platform-cli/package.json +++ b/packages/platform-cli/package.json @@ -1,6 +1,6 @@ { "name": "@codelitdev/platform-cli", - "version": "0.1.0", + "version": "0.2.0", "description": "Create, check, and sync CodeLit Platform products", "author": "CodeLit", "type": "module", diff --git a/packages/platform-cli/src/preset.json b/packages/platform-cli/src/preset.json index 6112b5b..4c56720 100644 --- a/packages/platform-cli/src/preset.json +++ b/packages/platform-cli/src/preset.json @@ -5,42 +5,42 @@ }, "packages": { "@codelitdev/platform": { - "recommended": "0.1.0", + "recommended": "0.2.0", "supported": ">=0.1.0-alpha.0 <2", "minimumSecure": "0.1.0-alpha.0" }, "@codelitdev/observability": { - "recommended": "0.1.0", + "recommended": "0.2.0", "supported": ">=0.1.0-alpha.0 <2", "minimumSecure": "0.1.0-alpha.0" }, "@codelitdev/mcp-server-kit": { - "recommended": "0.1.0", + "recommended": "0.2.0", "supported": ">=0.1.0-alpha.0 <2", "minimumSecure": "0.1.0-alpha.0" }, "@codelitdev/platform-conformance": { - "recommended": "0.1.0", + "recommended": "0.2.0", "supported": ">=0.1.0-alpha.0 <2", "minimumSecure": "0.1.0-alpha.0" }, "@codelitdev/platform-cli": { - "recommended": "0.1.0", + "recommended": "0.2.0", "supported": ">=0.1.0-alpha.0 <2", "minimumSecure": "0.1.0-alpha.0" }, "@codelitdev/billing": { - "recommended": "0.1.0", + "recommended": "0.2.0", "supported": ">=0.1.0-alpha.4 <1", "minimumSecure": "0.1.0-alpha.4" }, "@codelitdev/oauth-server-kit": { - "recommended": "0.1.0", + "recommended": "0.2.0", "supported": ">=0.1.0-alpha.2 <1", "minimumSecure": "0.1.0-alpha.2" }, "@codelitdev/design-system": { - "recommended": "0.1.0", + "recommended": "0.2.0", "supported": ">=0.1.0-alpha.7 <1", "minimumSecure": "0.1.0-alpha.7" } diff --git a/packages/platform-conformance/CHANGELOG.md b/packages/platform-conformance/CHANGELOG.md index 4b41f3c..f8c767e 100644 --- a/packages/platform-conformance/CHANGELOG.md +++ b/packages/platform-conformance/CHANGELOG.md @@ -1,5 +1,14 @@ # @codelitdev/platform-conformance +## 0.2.0 + +### Patch Changes + +- 047058c: Require MCP conformance adapters to expose the unauthenticated HTTP response headers and fail when the 401 response lacks a canonical protected-resource bearer challenge. +- 047058c: Document product adoption and add a standalone HTTP MCP OAuth discovery suite that does not require reference-product routes or fixtures. +- Updated dependencies [047058c] + - @codelitdev/platform@0.2.0 + ## 0.1.0 ### Patch Changes diff --git a/packages/platform-conformance/package.json b/packages/platform-conformance/package.json index 5d9e4de..f866103 100644 --- a/packages/platform-conformance/package.json +++ b/packages/platform-conformance/package.json @@ -1,6 +1,6 @@ { "name": "@codelitdev/platform-conformance", - "version": "0.1.0", + "version": "0.2.0", "description": "Shared HTTP conformance suites for CodeLit Platform products", "author": "CodeLit", "type": "module", @@ -37,7 +37,7 @@ "tag": "latest" }, "peerDependencies": { - "@codelitdev/platform": ">=0.1.0-alpha.0" + "@codelitdev/platform": ">=0.2.0" }, "devDependencies": { "@codelitdev/platform": "workspace:*", diff --git a/packages/platform/CHANGELOG.md b/packages/platform/CHANGELOG.md index f2036e6..d8a2fd2 100644 --- a/packages/platform/CHANGELOG.md +++ b/packages/platform/CHANGELOG.md @@ -1,5 +1,15 @@ # @codelitdev/platform +## 0.2.0 + +### Minor Changes + +- 047058c: `selectHttpCredential` and `selectMcpCredential` now reject an `Authorization` header that is present but is not `Bearer ` with a new `{ kind: "malformed" }` selection (error code `unauthenticated`). Previously such a header was ignored, so a request could fall back to a session cookie or API key, contrary to ADR 0001. `Bearer ` is also malformed now. `mcp-server-kit` rejects malformed headers before calling `authenticate`. + + **Product changes** + + - Code that branches on the selection result must handle `"malformed"` like `"ambiguous"` (return a rejected result with `selected.error`). TypeScript reports the unhandled case where the code reads `selected.credential`. + ## 0.1.0 ### Patch Changes diff --git a/packages/platform/package.json b/packages/platform/package.json index 27263fb..0a0f1be 100644 --- a/packages/platform/package.json +++ b/packages/platform/package.json @@ -1,6 +1,6 @@ { "name": "@codelitdev/platform", - "version": "0.1.0", + "version": "0.2.0", "description": "Composition kernel for CodeLit Platform products", "author": "CodeLit", "type": "module",