From 2bf643bfe7c4de1d181de6aae1d74cdbc1d91109 Mon Sep 17 00:00:00 2001 From: Ramesh Padmanabhaiah <22363102+codeforester@users.noreply.github.com> Date: Thu, 8 Oct 2026 10:58:14 +0530 Subject: [PATCH 1/2] docs: add demo validation to the 0.5 release checklist --- docs/release-0.5.0-checklist.md | 15 ++++++++++++++- 1 file changed, 14 insertions(+), 1 deletion(-) diff --git a/docs/release-0.5.0-checklist.md b/docs/release-0.5.0-checklist.md index 6499c10..f48d99c 100644 --- a/docs/release-0.5.0-checklist.md +++ b/docs/release-0.5.0-checklist.md @@ -16,7 +16,12 @@ historical issue number. benchmark, package, and provenance checks. 4. Rehearse the reviewed artifact through the protected TestPyPI environment. Install exactly `base-cli==0.5.0` from a new environment and run lifecycle/JSON - smoke checks; retain the artifact digest and workflow URL. + smoke checks; retain the artifact digest and workflow URL. Using that exact + candidate wheel, check out the pinned `base-cli-demo` revision and run its + documented validation suite, including optional integration scenarios when + their declared extras are installed. Record the demo commit, candidate + digest, and result on the active release-tracking issue. A demo failure must + block completion or be explicitly deferred there. 5. After the release PR is merged, create annotated `v0.5.0` on the independently approved protected-main commit. Never alter `v0.4.3` or its distributions. 6. Approve the protected production environment. Publish the exact reviewed @@ -28,6 +33,14 @@ historical issue number. on the active release-tracking issue. Close that issue only after every required artifact and compatibility result has been independently verified. +8. Complete the post-publication consumer step tracked by + [`base-cli-demo#47`](https://github.com/basefoundry/base-cli-demo/issues/47): + update the demo dependency window, lockfile, compatibility/release + workflows, README, and docs for `base-cli>=0.5.0,<0.6`, then run the demo + suite against the published PyPI package. Do not call the 0.5.0 release + train complete until that consumer validation is green or the active + release-tracking issue records an explicit deferral and owner. + Merged release preparation is not publication completion: the release is not complete while the tag, GitHub release, PyPI package, or required evidence is missing, even when the preparation pull request and local gates are green. From 46c321ddd1a3b9699b2752ea38c2d97fd2b408d0 Mon Sep 17 00:00:00 2001 From: Ramesh Padmanabhaiah <22363102+codeforester@users.noreply.github.com> Date: Thu, 8 Oct 2026 22:32:29 +0530 Subject: [PATCH 2/2] docs: make demo release validation authoritative --- docs/release-0.5.0-checklist.md | 21 ++++++++++++++------- 1 file changed, 14 insertions(+), 7 deletions(-) diff --git a/docs/release-0.5.0-checklist.md b/docs/release-0.5.0-checklist.md index f48d99c..8e78e61 100644 --- a/docs/release-0.5.0-checklist.md +++ b/docs/release-0.5.0-checklist.md @@ -17,11 +17,17 @@ historical issue number. 4. Rehearse the reviewed artifact through the protected TestPyPI environment. Install exactly `base-cli==0.5.0` from a new environment and run lifecycle/JSON smoke checks; retain the artifact digest and workflow URL. Using that exact - candidate wheel, check out the pinned `base-cli-demo` revision and run its - documented validation suite, including optional integration scenarios when - their declared extras are installed. Record the demo commit, candidate - digest, and result on the active release-tracking issue. A demo failure must - block completion or be explicitly deferred there. + candidate wheel, check out the pinned `base-cli-demo` revision and install + it with `python -m pip install --no-deps .` so dependency resolution cannot + replace the candidate with an older published framework. Verify that + `importlib.metadata.version("base-cli")` is exactly `0.5.0`, run + `python -m pip check`, and then run the demo's documented validation suite, + including optional integration scenarios when their declared extras are + installed. If the pinned demo still declares a pre-0.5 dependency window, + record that compatibility mismatch and the required #47 update as an + explicit deferral; do not accept a run against 0.4.x. Record the demo + commit, candidate digest, and result on the active release-tracking issue. + A demo failure must block completion or be explicitly deferred there. 5. After the release PR is merged, create annotated `v0.5.0` on the independently approved protected-main commit. Never alter `v0.4.3` or its distributions. 6. Approve the protected production environment. Publish the exact reviewed @@ -30,8 +36,9 @@ historical issue number. 7. Verify a clean installation of exactly `base-cli==0.5.0` from PyPI. Record the immutable tag and GitHub release URLs, PyPI result, checksums, SPDX SBOM, provenance and SBOM attestations, RELEASE-BOM-ROW, and downstream evidence - on the active release-tracking issue. Close that issue only after every - required artifact and compatibility result has been independently verified. + on the active release-tracking issue. Keep that issue open until the + post-publication consumer step below and every required artifact and + compatibility result have been independently verified. 8. Complete the post-publication consumer step tracked by [`base-cli-demo#47`](https://github.com/basefoundry/base-cli-demo/issues/47):