From 7247dfaf8e79accf539bb38ced4fca6116db7ef2 Mon Sep 17 00:00:00 2001 From: Shaan Satsangi Date: Thu, 1 Oct 2026 05:49:37 +0530 Subject: [PATCH] docs: close out v1.0.13 (tagged + released) Ticks the remaining v1.0.13 exit criteria with the evidence behind each: production smoke, Dependabot and Sentry housekeeping, and the tag and GitHub Release. Records the release in the progress log. --- PLAN.md | 8 ++++---- docs/PROGRESS_LOG.md | 29 +++++++++++++++++++++++++++++ 2 files changed, 33 insertions(+), 4 deletions(-) diff --git a/PLAN.md b/PLAN.md index 3a4d87c..7cfaa75 100644 --- a/PLAN.md +++ b/PLAN.md @@ -60,7 +60,7 @@ | **v1.0.10** | Dependency-manifest drift guard — CI fails if `pyproject.toml` / `uv.lock` / `requirements.txt` disagree | ✅ shipped | | **v1.0.11** | Cache Components navigation-state sweep — roast duplication, `/me` staleness, analytics double-count, badge a11y, session snapshot; + fixture time-bomb and backend version-drift guards | ✅ shipped | | **v1.0.12** | Narrative output sweep — truncated/empty/markdown narratives, alertable fallback signal; + alembic logging bug, 72 DB tests enabled in CI (12 repaired), Next 16.3.2 | ✅ shipped | -| **v1.0.13** | Audit remediation + dependency refresh — two critical Next.js advisories, commit-before-response, singleflight coalescing, fresh force refresh, cron classification, honest share/delete UI, structured logs; `requirements.txt` generated in CI | 🚧 PR open, tag pending | +| **v1.0.13** | Audit remediation + dependency refresh — two critical Next.js advisories, commit-before-response, singleflight coalescing, fresh force refresh, cron classification, honest share/delete UI, structured logs; `requirements.txt` generated in CI | ✅ shipped | | **v1.0.14** | Toolchain majors — TypeScript 6, Vitest 5, jest-dom 7, Sentry SDK 11, framer-motion 13, openai 3, SQLAlchemy 2.1, each proven alone | 📋 proposed | --- @@ -1050,9 +1050,9 @@ The narrative-mode CHECK constraint was a third drift in the same family — the - [x] Backend: ruff clean; full suite green with a database attached. - [x] Frontend: lint, tsc, vitest and a production build pass; `npm audit` reports 0. - [x] All four version constants at `1.0.13`. -- [ ] PR checks green and merged; prod smoke passed. -- [ ] Housekeeping: blocked Dependabot PRs closed; Sentry noise archived. -- [ ] `CHANGELOG.md` `[1.0.13]`; tag `v1.0.13` (operator checkpoint). +- [x] PR **#111** checks green and merged; prod smoke passed: `/health` reports 1.0.13 on GET and HEAD, the narrator streams, and log lines arrive in Vercel as JSON carrying a `request_id` that matches the response's `X-Request-Id`. +- [x] Housekeeping: Dependabot PRs 12 → 1 (blocked majors and superseded updates closed with notes; #75 kept for v1.0.14); Sentry FRONTEND-3/4/5 archived until escalating; 0 open Dependabot alerts (21 marked fixed). +- [x] `CHANGELOG.md` `[1.0.13]`; tag `v1.0.13` on `d1b1e58`; GitHub Release published. --- diff --git a/docs/PROGRESS_LOG.md b/docs/PROGRESS_LOG.md index b426a98..bc7c07f 100644 --- a/docs/PROGRESS_LOG.md +++ b/docs/PROGRESS_LOG.md @@ -19,6 +19,35 @@ Format: --- +## 2026-10-01 — Claude (Opus 5.5) with Shaan — v1.0.13 released + +**Slice:** v1.0.13 closeout. + +**Done:** +- **Merged and deployed.** PR #111 merged as `d1b1e58`, with all five checks green on the PR and on `main`. +- **Production verified:** + - `/health` returns `{"status":"ok","version":"1.0.13","db":"up","cache":"up"}`, and `HEAD /health` returns 200 (it was 405). + - Security headers are unchanged. + - A live mentor narrative streamed (292 chunks in 4.3s, ended by the done sentinel, not truncated). + - A cache-hit request's log line reached Vercel as JSON (`event`, `level`, `logger`, `timestamp`) with a `request_id` matching the response's `X-Request-Id`. + - The new deployment logged zero `HTTP Request:` lines, even with a live Groq call. +- **Dependabot alerts: 17 open → 0**; GitHub marked 21 as fixed. +- **Dependabot PRs: 12 → 1.** + - Dependabot closed #20, #73 and #74 itself once the ignore rules landed, with a generic "no longer updated" note, so each now also has a comment naming the real blocker. + - It also closed the superseded group PRs #107–#110. + - #71, #77, #78 and #80 were closed by hand as superseded. + - #75 (jest-dom 7) stays open for v1.0.14. +- **Sentry:** FRONTEND-3/4/5 archived "until escalating" through a headless Sentry MCP session, so they return on their own if they recur. +- **Released:** tagged `v1.0.13` on `d1b1e58`, and `release.yml` published the GitHub Release from `CHANGELOG [1.0.13]`. + +**Blocked / open:** +- The deferred minors in the 2026-09-30 entry. +- Operator items: the Sentry alert rule and source-map upload; browser-only checks of sign-in and share revoke on production. + +**Next:** v1.0.14, toolchain majors. + +--- + ## 2026-09-30 — Claude (Opus 5.5) with Shaan — v1.0.13: full audit, remediation and dependency refresh **Slice:** v1.0.13 (spec `docs/superpowers/specs/2026-09-30-v1.0.13-audit-remediation-design.md`, plan `docs/superpowers/plans/2026-09-30-v1.0.13-audit-remediation.md`).