Bump to 0.20.0 - #940
Bump to 0.20.0#940
Conversation
11 version files and 8 lockfiles, written by scripts/bump-version.sh. MIGRATING.md's '# Unreleased' section is promoted to '# v0.20.0'. Thirteen commits since v0.19.0 (2026-09-16), the substantial ones being the #925 chain — #931 finding operations by exclusion so no HTTP verb can drop one in silence, #932 stopping a refusal from destroying generated output, and #938 deriving gen-catalog's emission bound from the shared declaration — plus #926's embedded tool Catalog, #930's Automation split, #924's event-feed body validation at the wrapper's decode, and #937's anyio bump for CVE-2026-63374. Ran the release's own preflight here rather than discovering it at tag time: promote-migrating --check passes, rs-publish-check packages and dry-run-uploads 0.20.0 clean, and all four lockfile freshness assertions hold.
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
Copilot review overview
🟢 Approved
All release declarations and lockfile references consistently target 0.20.0.
Review effort: Balanced
Findings: None
What changed in this PR
Prepares the multi-language SDK for the v0.20.0 release, including generator safeguards, catalog/domain improvements, event-feed validation, and a critical AnyIO security update.
Changes:
- Synchronizes SDK manifests, runtime constants, and lockfiles to 0.20.0.
- Promotes the unreleased migration notes to v0.20.0.
- Makes no behavioral code changes.
[!TIP]
If you aren't ready for review, convert to a draft PR.
Click "Convert to draft" or rungh pr ready --undo.
Click "Ready for review" or rungh pr readyto reengage.
| File | Description |
|---|---|
| typescript/src/client.ts | Updates the TypeScript runtime version. |
| typescript/package.json | Updates the TypeScript package version. |
| typescript/package-lock.json | Synchronizes the TypeScript lockfile version. |
| swift/Sources/Basecamp/BasecampConfig.swift | Updates the Swift SDK version. |
| rust/Cargo.lock | Synchronizes the Rust lockfile version. |
| rust/basecamp-sdk/Cargo.toml | Updates the Rust crate version. |
| ruby/lib/basecamp/version.rb | Updates the Ruby SDK version. |
| ruby/Gemfile.lock | Synchronizes Ruby lockfile metadata. |
| python/uv.lock | Synchronizes the Python lockfile version. |
| python/src/basecamp/_version.py | Updates the Python runtime version. |
| python/pyproject.toml | Updates the Python package version. |
| package.json | Updates the root package version. |
| MIGRATING.md | Promotes migration notes to v0.20.0. |
| kotlin/sdk/src/commonMain/kotlin/com/basecamp/sdk/BasecampConfig.kt | Updates the Kotlin runtime version. |
| kotlin/sdk/build.gradle.kts | Updates the Kotlin package version. |
| go/pkg/basecamp/version.go | Updates the Go SDK version. |
| conformance/runner/typescript/package-lock.json | Synchronizes the TypeScript runner lockfile. |
| conformance/runner/rust/Cargo.lock | Synchronizes the Rust runner lockfile. |
| conformance/runner/ruby/Gemfile.lock | Synchronizes the Ruby runner lockfile. |
| conformance/runner/python/uv.lock | Synchronizes the Python runner lockfile. |
Files not reviewed (2)
- conformance/runner/typescript/package-lock.json: Generated file
- typescript/package-lock.json: Generated file
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
…#941) * Stop the release version constants failing the API compatibility gate Every release bump changes `Version`, and `DefaultUserAgent` is `"basecamp-sdk-go/" + Version + " (api:" + APIVersion + ")"` so it follows. apidiff classifies an exported constant's value change as incompatible, which for these two is true and beside the point — a consumer pinning the literal is asserting "compiled against exactly 0.19.0", and no release can preserve that. Changing is what the constant is for. The reason to fix it is the gate's integrity, not convenience. Cutting v0.20.0 (#940) failed this required check with 12/12 contexts green and both reported lines version constants; the printed remedy is to apply `breaking` and re-run. Every release hits that, so the label becomes a reflex on the one PR where a real break is least likely to be read — the diff is machine-generated and skimmed. The label should mean a real break was looked at and accepted, which it cannot mean while it is also the routine cost of shipping. The two lines are partitioned out of the verdict only. They are still printed, under their own heading, and the full "All API Changes" report is untouched. The exemption is narrow: only `value changed`, only those two symbols. Removing `Version`, changing its type or renaming it still fails, as does any other symbol's value change. grep's exit 1 ("no lines matched") is an ordinary outcome for both partitions and must not abort under `set -e`; 2 or above is a tool failure and must not read as an empty partition, so it aborts loudly — the same distinction run_apidiff already draws. Verified against the real #940 output plus five neighbours: the two version lines alone pass; those lines beside a removed method still fail; `Version` removed, `Version` retyped and another constant's value change each still fail; a clean 0-byte report stays clean. actionlint and zizmor clean. * Exempt the user agent by value, not by name Both reviewers found the same hole, independently: keying the exemption on the symbol name waived every `DefaultUserAgent` value change, not only the one a release bump causes. Rewriting the header to "unexpected-client", or dropping the `(api:...)` component, emits the same generic `value changed` line and would have passed the gate silently. The user-agent line is now exempt only when it is exactly what this bump's `Version` change implies: same `basecamp-sdk-go/` prefix, same API-version component on both sides, version component moving from the old value to the new one. A user-agent change with no `Version` change beside it is never exempt. Naming the format here as well as in client.go is deliberate. If the format changes this stops matching and the gate fails, which is the direction a duplicated fact should fail in. awk rather than grep because the decision is no longer a line-level regex — it reads the `Version` line to decide about the user-agent line — and awk avoids the heredoc indentation trap inside a YAML block scalar. Verified against seven cases including both reviewers' counterexamples: the real v0.20.0 bump passes; user agent to "unexpected-client" with a version bump fails; the API component dropped fails; a user-agent change with no version bump fails; a bump beside a removed method fails; `Version: removed` fails; a clean 0-byte report stays clean. My own verification missed this. I tested the symbol axis and the change-kind axis and never the value axis — the exemption was only ever sound for values derived from the bump, and I never asserted the derivation.
Version bump for v0.20.0. Mechanical —
scripts/bump-version.shwrote 11 version files and synced 8 lockfiles;MIGRATING.md's# Unreleasedsection is promoted to# v0.20.0. No source changes.What ships
Thirteen commits since v0.19.0 (2026-09-16). The substantial ones:
gen-catalog's emission bound derived fromspec/generated-verbs.jsoninstead of a seventh copyanyiopast CVE-2026-63374 (CRITICAL, TLSStream IDNA 2003 host name encoding)Plus #927, #928, #929, #939 and the Rust generator fix.
Preflight
Ran the release target's own verification here rather than discovering a failure at tag time:
promote-migrating.sh --check 0.20.0'# v0.20.0' is the newest section — promotedmake rs-publish-checkbasecamp-sdk v0.20.0cleantypescript/package-lock.jsonruby/Gemfile.lock(PATH + CHECKSUMS)python/uv.lock --checkrust+ conformance runnerCargo.lock--lockedresolvesNo
0.19.0remains in any version file.After this merges
make release VERSION=0.20.0from a cleanmain— it re-verifies every version constant and lockfile, requires a clean tree onmain, then pushesmain, tagsv0.20.0and pushes the tag, which triggers the eight publish workflows. I'll confirm before running that step, since the tag and the eight registry publishes are the irreversible part.Summary by cubic
Mechanical version bump: all SDK version constants and lockfiles are updated from 0.19.0 to 0.20.0, with no logic changes, and the
# Unreleasedsection inMIGRATING.mdis promoted to# v0.20.0(covering thelistLineupMarkersmove from Automation to Lineup). Release preflight checks pass.What ships
gen-catalogderives its emission bound fromspec/generated-verbs.jsonvia the new embedded Tool Catalog.anyiois bumped past CVE-2026-63374.After merging
make release VERSION=0.20.0from a cleanmaintree; it re-verifies every version constant and lockfile, then pushesmain, tagsv0.20.0, and pushes the tag to trigger the eight publish workflows.Written for commit 09b237f. Summary will update on new commits.