Skip to content

Prepare Framework v5: security, correctness and release validation - #243

Merged
andrewzolotukhin merged 5 commits into
developmentfrom
chore/v5-release-readiness
Oct 4, 2026
Merged

andrewzolotukhin merged 5 commits into
developmentfrom
chore/v5-release-readiness

Conversation

@andrewzolotukhin

@andrewzolotukhin andrewzolotukhin commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Prepare the Framework v5 release from the latest development baseline with correctness/security fixes, reproducible release checks, and current consumer documentation. No release, merge or deployment is performed by this PR.

Correctness and security

  • Harden JWT object/claim validation, expiration boundaries, JOSE extensions and algorithm/key-family handling; make cookie parsing prototype-safe and serialization reject attribute injection.
  • Require an explicit verified authorization scope for server idempotency. Separate method/URL scopes, coalesce concurrent retries, bound retained keys/bodies, restore response hooks, and preserve complete streamed responses. Document in-process limitations and 409/503 outcomes.
  • Bound response-cache retention and bypass private/no-store/Set-Cookie responses. Preserve response headers/chunks and directly assigned batch status codes.
  • Share concurrent request-body reads and failures; reject interrupted bodies and use prototype-safe query/header dictionaries.
  • Preserve DI scope/cycle checks through factories; optional resolution no longer swallows registered-service failures.
  • Fix client deduplication body-consumption races, timeout listener cleanup, and the declared-but-unbuilt @cleverbrush/client/idempotency export.
  • Close CLI database pools before schema-drift/production-guard exits. Correct migration --to documentation.
  • Honor telemetry disable flags instead of allowing SDK environment defaults to recreate exporters; adapt updated OpenTelemetry processors.

Release and documentation

  • Require Node 24+ across all 22 published packages; correct npm metadata, package licenses, local workspace build ordering and Docker lockfile installation.
  • Standardize the root and all 22 published-package LICENSE files on BSD-3-Clause, matching manifests and current documentation. Verify source and installed tarball license contents and metadata, with 10 regression tests. Preserve historical release snapshots and third-party notices.
  • Refresh workspace CLI executable links after building (fresh npm installs cannot link a not-yet-built cb-orm). Smoke-test the packed CLI as well as module exports. Give in-process compiler fixture tests explicit CI/coverage time budgets without relaxing assertions.
  • Refresh dependency resolutions and vulnerable minimums. The initial audit reported 71 affected packages (3 critical / 33 high); the current high-severity gate passes, with 5 low/moderate transitive findings described below.
  • Restore discovery of 14 previously excluded server test files (275 tests). Add focused regressions and per-package unit coverage floors. Refresh all published-package badges, clearly labeled unit coverage.
  • Pack and install every library in an isolated consumer; check licenses, exports, declarations, the actual root README example, and browser-safe bundles.
  • Repair API-reference generation with package build configs and include storage packages. Correct obsolete imports, quick-start examples and unresolved JSDoc links. Add security and v4.x-to-v5 migration guidance.
  • Remove the empty feature-candidates placeholder only; retain historical docs, changelogs and migration guides. No temporary audit report is committed.
  • Gate beta/stable publication on reusable CI: mandatory gates, coverage, security audit, packaged-consumer checks, both website builds, API-reference generation, PostgreSQL in two timezones, S3 integration and full demo E2E.
  • Include a changeset for every published package. The release plan resolves the fixed group to 5.0.0; no versioning or publishing command was run.

Some test-only/source formatting changes are required by the refreshed Biome version; they are mechanical and contain no semantic changes.

Verification

  • Clean npm ci
  • npm run lint — zero warnings/errors
  • npm run build — all 24 workspace tasks
  • npm run test — 5,104 tests, 261 files, no type errors
  • Unit coverage and all 22 package floors — approximately 82.2% statements
  • Packed consumer — 22 packages, 52 entry points, BSD-3-Clause license contents and metadata, declarations and browser bundle
  • Both documentation site typechecks and production builds
  • TypeDoc API generation — no errors; remaining warnings are noted below
  • PostgreSQL query integration — 100 tests in UTC and America/Los_Angeles
  • PostgreSQL scheduler integration — 12 tests in both timezones
  • Durable and recurring job demos
  • Isolated Garage S3 integration — 9 tests
  • Dependency high/critical gate and Changesets fixed-group release plan
  • Full Docker demo API/browser/telemetry E2E — 51 tests passed in PR CI (46 API/WebSocket/telemetry, 5 browser)

All four CI jobs passed for commit 8022074c: final validation run. Initial CI failures exposed missing clean-checkout CLI links, compiler fixture timeouts under coverage, and a root-versus-workspace Playwright browser mismatch; all were corrected and the complete workflow rerun successfully.

Remaining findings / review notes

  • npm audit reports 5 affected packages: 3 low, 2 moderate. DOMPurify/Monaco concerns an IN_PLACE plus afterSanitize hook combination; esbuild concerns its Windows development server through tsup; uuid/gaxios concerns older UUID buffer APIs through the demo's Google authentication dependency. These are retained and visible, not suppressed with forced transitive major overrides. The high/critical gate passes, not a claim of zero vulnerabilities.
  • TypeDoc still reports 265 warnings, chiefly internal types referenced by public generic signatures and sibling README links. Generation succeeds and all packages are included. Malformed examples, unsupported tags, obsolete subclassing advice, shadowed example identifiers and unresolved source links have been corrected; no blanket warning suppression is added.
  • Low unit-only coverage for database adapters is not presented as complete behavioral coverage: the dedicated real-PostgreSQL suites run separately and gate publication.
  • Large contract-consumer compiler fixtures remain expensive (roughly 11–15 million type instantiations and 2–3 GB during local checks). The explicit test budgets accommodate instrumentation/runner overhead; this PR does not claim to solve that separate type-performance concern.
  • This is a bounded release audit, not a guarantee that all defects or security risks have been eliminated. Review the breaking security defaults and migration guidance before merging.

Comment thread libs/deep/LICENSE Outdated
Comment on lines +1 to +5
Cleverbrush Framework is dual-licensed under both the "Unlicense" and the
"Zero-Clause BSD" (0BSD) licenses. The intent of this dual-licensing
structure is to make Cleverbrush Framework as consumable as possible in as many
environments / countries / companies as possible without encumbering
users.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All libraries are under the BSD license, fix it everywhere.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed in 8022074.

The root LICENSE contained outdated dual Unlicense/0BSD text, which I had copied into the package LICENSE files despite the manifests and documentation declaring BSD-3-Clause. The root and all 22 published packages now contain the same BSD-3-Clause text, with the existing copyright attribution retained. I also normalized the demo backend manifest and regenerated its lockfile metadata through npm.

Package verification now checks license metadata and actual LICENSE contents in source and installed tarballs. Added 10 regression tests covering root/workspace/installed packages, missing or mismatched license files, incorrect or absent metadata, and an incorrect canonical license. The README and existing changeset are updated. Historical release snapshots and third-party notices are unchanged.

Validation: lint, build, all 5,104 unit/type tests and packed-consumer checks pass. All four CI jobs are green, including coverage, PostgreSQL, S3, documentation builds and E2E.

@andrewzolotukhin
andrewzolotukhin merged commit 297866c into development Oct 4, 2026
4 checks passed
@andrewzolotukhin
andrewzolotukhin deleted the chore/v5-release-readiness branch October 4, 2026 07:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant