Skip to content

Bump to 0.20.0 - #940

Merged
jeremy merged 1 commit into
mainfrom
sdk-bump-0.20.0
Sep 20, 2026
Merged

jeremy merged 1 commit into
mainfrom
sdk-bump-0.20.0

Conversation

@jeremy

@jeremy jeremy commented Sep 20, 2026 •

Copy link
Copy Markdown
Member

Version bump for v0.20.0. Mechanical — scripts/bump-version.sh wrote 11 version files and synced 8 lockfiles; MIGRATING.md's # Unreleased section is promoted to # v0.20.0. No source changes.

What ships

Thirteen commits since v0.19.0 (2026-09-16). The substantial ones:

Plus #927, #928, #929, #939 and the Rust generator fix.

Preflight

Ran the release target's own verification here rather than discovering a failure at tag time:

gate result
promote-migrating.sh --check 0.20.0 '# v0.20.0' is the newest section — promoted
make rs-publish-check packages and dry-run-uploads basecamp-sdk v0.20.0 clean
typescript/package-lock.json 0.20.0
ruby/Gemfile.lock (PATH + CHECKSUMS) 0.20.0
python/uv.lock --check fresh
rust + conformance runner Cargo.lock --locked resolves

No 0.19.0 remains in any version file.

After this merges

make release VERSION=0.20.0 from a clean main — it re-verifies every version constant and lockfile, requires a clean tree on main, then pushes main, tags v0.20.0 and pushes the tag, which triggers the eight publish workflows. I'll confirm before running that step, since the tag and the eight registry publishes are the irreversible part.


Summary by cubic

Mechanical version bump: all SDK version constants and lockfiles are updated from 0.19.0 to 0.20.0, with no logic changes, and the # Unreleased section in MIGRATING.md is promoted to # v0.20.0 (covering the listLineupMarkers move from Automation to Lineup). Release preflight checks pass.

What ships

  • Operations are now found by exclusion, so no HTTP verb can drop one in silence.
  • A refusal no longer destroys generated Kotlin or TypeScript output.
  • gen-catalog derives its emission bound from spec/generated-verbs.json via the new embedded Tool Catalog.
  • Event-feed bodies are now validated at the wrapper's decode.
  • The Automation catch-all is now split into six domains.
  • anyio is bumped past CVE-2026-63374.

After merging

  • Run make release VERSION=0.20.0 from a clean main tree; it re-verifies every version constant and lockfile, then pushes main, tags v0.20.0, and pushes the tag to trigger the eight publish workflows.
  • The tag and registry publishes are irreversible, so confirm before running.

Written for commit 09b237f. Summary will update on new commits.

Review in cubic

11 version files and 8 lockfiles, written by scripts/bump-version.sh.
MIGRATING.md's '# Unreleased' section is promoted to '# v0.20.0'.

Thirteen commits since v0.19.0 (2026-09-16), the substantial ones being
the #925 chain — #931 finding operations by exclusion so no HTTP verb can
drop one in silence, #932 stopping a refusal from destroying generated
output, and #938 deriving gen-catalog's emission bound from the shared
declaration — plus #926's embedded tool Catalog, #930's Automation split,
#924's event-feed body validation at the wrapper's decode, and #937's
anyio bump for CVE-2026-63374.

Ran the release's own preflight here rather than discovering it at tag
time: promote-migrating --check passes, rs-publish-check packages and
dry-run-uploads 0.20.0 clean, and all four lockfile freshness assertions
hold.
Copilot AI balanced review requested due to automatic review settings September 20, 2026 07:32
@github-actions github-actions Bot added typescript Pull requests that update TypeScript code ruby Pull requests that update the Ruby SDK go kotlin swift conformance Conformance test suite python Pull requests that update the Python SDK rust Rust SDK labels Sep 20, 2026
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 20, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-20T07:33:59.632572Z 09b237f PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approved

All release declarations and lockfile references consistently target 0.20.0.

Review effort: Balanced
Findings: None

What changed in this PR

Prepares the multi-language SDK for the v0.20.0 release, including generator safeguards, catalog/domain improvements, event-feed validation, and a critical AnyIO security update.

Changes:

  • Synchronizes SDK manifests, runtime constants, and lockfiles to 0.20.0.
  • Promotes the unreleased migration notes to v0.20.0.
  • Makes no behavioral code changes.

[!TIP]
If you aren't ready for review, convert to a draft PR.
Click "Convert to draft" or run gh pr ready --undo.
Click "Ready for review" or run gh pr ready to reengage.

File Description
typescript/​src/​client.ts Updates the TypeScript runtime version.
typescript/​package.json Updates the TypeScript package version.
typescript/​package-lock.json Synchronizes the TypeScript lockfile version.
swift/​Sources/​Basecamp/​BasecampConfig.swift Updates the Swift SDK version.
rust/​Cargo.lock Synchronizes the Rust lockfile version.
rust/​basecamp-sdk/​Cargo.toml Updates the Rust crate version.
ruby/​lib/​basecamp/​version.rb Updates the Ruby SDK version.
ruby/​Gemfile.lock Synchronizes Ruby lockfile metadata.
python/​uv.lock Synchronizes the Python lockfile version.
python/​src/​basecamp/​_version.py Updates the Python runtime version.
python/​pyproject.toml Updates the Python package version.
package.json Updates the root package version.
MIGRATING.md Promotes migration notes to v0.20.0.
kotlin/​sdk/​src/​commonMain/​kotlin/​com/​basecamp/​sdk/​BasecampConfig.kt Updates the Kotlin runtime version.
kotlin/​sdk/​build.gradle.kts Updates the Kotlin package version.
go/​pkg/​basecamp/​version.go Updates the Go SDK version.
conformance/​runner/​typescript/​package-lock.json Synchronizes the TypeScript runner lockfile.
conformance/​runner/​rust/​Cargo.lock Synchronizes the Rust runner lockfile.
conformance/​runner/​ruby/​Gemfile.lock Synchronizes the Ruby runner lockfile.
conformance/​runner/​python/​uv.lock Synchronizes the Python runner lockfile.
Files not reviewed (2)
  • conformance/runner/typescript/package-lock.json: Generated file
  • typescript/package-lock.json: Generated file

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@jeremy jeremy added the breaking Breaking change to public API label Sep 20, 2026
@jeremy
jeremy merged commit a74f558 into main Sep 20, 2026
81 of 82 checks passed
@jeremy
jeremy deleted the sdk-bump-0.20.0 branch September 20, 2026 07:37
jeremy added a commit that referenced this pull request Sep 20, 2026
…#941)

* Stop the release version constants failing the API compatibility gate

Every release bump changes `Version`, and `DefaultUserAgent` is
`"basecamp-sdk-go/" + Version + " (api:" + APIVersion + ")"` so it follows.
apidiff classifies an exported constant's value change as incompatible,
which for these two is true and beside the point — a consumer pinning the
literal is asserting "compiled against exactly 0.19.0", and no release can
preserve that. Changing is what the constant is for.

The reason to fix it is the gate's integrity, not convenience. Cutting
v0.20.0 (#940) failed this required check with 12/12 contexts green and
both reported lines version constants; the printed remedy is to apply
`breaking` and re-run. Every release hits that, so the label becomes a
reflex on the one PR where a real break is least likely to be read — the
diff is machine-generated and skimmed. The label should mean a real break
was looked at and accepted, which it cannot mean while it is also the
routine cost of shipping.

The two lines are partitioned out of the verdict only. They are still
printed, under their own heading, and the full "All API Changes" report is
untouched. The exemption is narrow: only `value changed`, only those two
symbols. Removing `Version`, changing its type or renaming it still fails,
as does any other symbol's value change.

grep's exit 1 ("no lines matched") is an ordinary outcome for both
partitions and must not abort under `set -e`; 2 or above is a tool failure
and must not read as an empty partition, so it aborts loudly — the same
distinction run_apidiff already draws.

Verified against the real #940 output plus five neighbours: the two version
lines alone pass; those lines beside a removed method still fail; `Version`
removed, `Version` retyped and another constant's value change each still
fail; a clean 0-byte report stays clean. actionlint and zizmor clean.

* Exempt the user agent by value, not by name

Both reviewers found the same hole, independently: keying the exemption on
the symbol name waived every `DefaultUserAgent` value change, not only the
one a release bump causes. Rewriting the header to "unexpected-client", or
dropping the `(api:...)` component, emits the same generic `value changed`
line and would have passed the gate silently.

The user-agent line is now exempt only when it is exactly what this bump's
`Version` change implies: same `basecamp-sdk-go/` prefix, same API-version
component on both sides, version component moving from the old value to the
new one. A user-agent change with no `Version` change beside it is never
exempt.

Naming the format here as well as in client.go is deliberate. If the format
changes this stops matching and the gate fails, which is the direction a
duplicated fact should fail in.

awk rather than grep because the decision is no longer a line-level regex —
it reads the `Version` line to decide about the user-agent line — and awk
avoids the heredoc indentation trap inside a YAML block scalar.

Verified against seven cases including both reviewers' counterexamples: the
real v0.20.0 bump passes; user agent to "unexpected-client" with a version
bump fails; the API component dropped fails; a user-agent change with no
version bump fails; a bump beside a removed method fails; `Version: removed`
fails; a clean 0-byte report stays clean.

My own verification missed this. I tested the symbol axis and the
change-kind axis and never the value axis — the exemption was only ever
sound for values derived from the bump, and I never asserted the derivation.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

breaking Breaking change to public API conformance Conformance test suite go kotlin python Pull requests that update the Python SDK ruby Pull requests that update the Ruby SDK rust Rust SDK swift typescript Pull requests that update TypeScript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants