Skip to content

build: enforce pinned Cloud tools and transitive dependency locks - #6

Merged
deku2026 merged 2 commits into
mainfrom
codex/wp02-00-toolchain-locks
Sep 21, 2026
Merged

deku2026 merged 2 commits into
mainfrom
codex/wp02-00-toolchain-locks

Conversation

@deku2026

Copy link
Copy Markdown
Contributor

Cloud now selects a reviewed Java patch in CI, checks the executing Node/npm versions against the committed pins, and enables central transitive NuGet pinning. Resolved package versions and application behavior remain unchanged. A new immutable release profile and superseding records bind the changed build configuration while preserving previous legal admissions.

Validation: isolated npm and .NET locked restores plus offline repeats; wrong-version and stale-lock rejection; full npm check (67 tests), Release managed build and 5 tests, formatting and Kotlin consumer build. The actual final Linux AOT image was built locally through existing WSL Docker, inspected, exercised by real .NET/TS/Kotlin protocol consumers and restart tests; the candidate Worker bundle and legal contents also passed. The complete hosted Worker/runtime and exact Java selection gates must pass before merge.

@deku2026
deku2026 merged commit 4f53ed6 into main Sep 21, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant