Skip to content

docs: record native release verification - #37

Merged
tannerlinsley merged 3 commits into
mainfrom
taren/native-release-verification
Aug 2, 2026
Merged

docs: record native release verification#37
tannerlinsley merged 3 commits into
mainfrom
taren/native-release-verification

Conversation

@tannerlinsley

@tannerlinsley tannerlinsley commented Aug 2, 2026

Copy link
Copy Markdown
Member

Summary

  • close F-174 after the native package bootstrap
  • record the 0.4.0 exception and verified 0.5.0 OIDC release
  • record credential cleanup

Verification

  • pnpm exec prettier --check API-FRICTION.md
  • git diff --check

Summary by CodeRabbit

  • Documentation
    • Documented the resolution of security finding F-174.
    • Recorded the initial publication and subsequent trusted releases of the React Native Charts package through version 0.5.1.
    • Confirmed registry integrity and release attestation verification.
    • Documented revocation of temporary publishing credentials and bootstrap secrets.
    • No exported or public interfaces were changed.

@coderabbitai

coderabbitai Bot commented Aug 2, 2026

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@tannerlinsley, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 42 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 13d05d26-e5c8-4487-ba9d-0cb7c43f055c

📥 Commits

Reviewing files that changed from the base of the PR and between 2f8b8c0 and f80d6b1.

📒 Files selected for processing (1)
  • API-FRICTION.md
📝 Walkthrough

Walkthrough

F-174 is marked resolved in API-FRICTION.md. The finding now records package publication, trusted OIDC releases, registry integrity and attestation verification, and removal of temporary credentials.

Changes

Release evidence resolution

Layer / File(s) Summary
Resolve F-174 release evidence
API-FRICTION.md
The finding status changes to resolved. The record documents completed publication, release verification, and temporary credential removal.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Possibly related PRs

  • TanStack/charts#6: Updates API-FRICTION.md with release evidence for another package.
  • TanStack/charts#7: Documents publication verification and resolution for another finding.
  • TanStack/charts#36: Documents the same protected bootstrap publication and release verification.

Suggested reviewers: gillkyle

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the documentation change that records native release verification.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch taren/native-release-verification

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@tannerlinsley
tannerlinsley force-pushed the taren/native-release-verification branch from 13b6812 to 2f8b8c0 Compare August 2, 2026 17:02

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@API-FRICTION.md`:
- Line 212: Align the F-174 objective and release evidence so they identify the
same OIDC-verified npm release: either add attestation evidence for 0.5.0, or
update the objective to 0.5.1 and explain how that release resolves F-174.
Update the related entries around the objective and release notes consistently
before retaining both statuses as resolved.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 4d2afbdf-736d-4fd5-8828-785a8afd08da

📥 Commits

Reviewing files that changed from the base of the PR and between 69a8244 and 2f8b8c0.

📒 Files selected for processing (1)
  • API-FRICTION.md

Comment thread API-FRICTION.md
@tannerlinsley
tannerlinsley force-pushed the taren/native-release-verification branch from 2f8b8c0 to f80d6b1 Compare August 2, 2026 17:18
@tannerlinsley
tannerlinsley merged commit d4b4dfe into main Aug 2, 2026
17 checks passed
@tannerlinsley
tannerlinsley deleted the taren/native-release-verification branch August 2, 2026 17:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant