Skip to content

chore: move to ras-stack 0.39.0 and drop the adoption policy - #51

Merged
richardsolomou merged 2 commits into
mainfrom
chore/ras-stack-0.39
Aug 14, 2026
Merged

richardsolomou merged 2 commits into
mainfrom
chore/ras-stack-0.39

Conversation

@richardsolomou

@richardsolomou richardsolomou commented Aug 14, 2026 •

Copy link
Copy Markdown
Owner

Problem

ras-stack 0.39.0 removed the adoption policy feature. ras policy check now only covers the Changesets config, Dependabot config, and the pnpm cooldown, and it ignores an adoption block instead of rejecting it. Ours still declared a minimum ras-stack version, toolchain pins, and required config references that nothing reads any more — config that looks enforced but isn't.

Separately, CI still called the reusable workflows at @v0.35.0 while the package moved to 0.39.0. The release-changesets.yml pin is the one that bites: it predates the v0.38.1 fix where a release run superseded by a later merge stands down cleanly instead of failing the build. On main that shows up as a red build for a release that was simply overtaken, not broken.

Changes

  • Bump ras-stack to ^0.39.0 and refresh the lockfile.
  • Delete the adoption block from ras-stack.policy.json.
  • Roll the minimumReleaseAgeExclude entry from ras-stack@0.35.0 to ras-stack@0.39.0, since 0.39.0 is newer than the one-week cooldown.
  • Move all three reusable workflow pins in .github/workflows/ci.yml from @v0.35.0 to @v0.39.0: check-js.yml, check-browser.yml, and release-changesets.yml. Versions only — the job inputs and the rest of the YAML are untouched.

Risk

Low. Nothing in this repo calls ras policy ... adoption, and the removed block was already inert on 0.39.0. Rolling back is a revert; the exclusion only affects fresh resolution, not installs against the committed lockfile.

The workflow pins are the part CI actually exercises. check-js and check-browser run from this branch's ref, so this PR's own run is the proof they work at 0.39.0. The release job is gated on a push to main, so it won't have run before merge — that one lands on trust in the upstream tag plus the fact that the pin it replaces is four minor versions stale.

Verification

just check (format:check, lint, policy:check, typecheck, test, build) passes locally — 231 tests, clean ras policy check, successful build. pnpm install --frozen-lockfile passes the supply-chain policy check with only the 0.39.0 exclusion in place. After the pin bump I re-ran just check and confirmed no richardsolomou/ras-stack/...@v reference below v0.39.0 remains under .github/workflows/.

Checklist

  • Tests cover new or changed behavior where practical.
  • Geometry changes are checked against a real export, not just the preview.
  • User-facing behavior is documented in the README.

0.39.0 removes the adoption policy feature, so the adoption block in
ras-stack.policy.json is now inert config that nothing reads. Delete it
rather than leave dead weight that looks like it still enforces
something, and roll the release-age exclusion forward to the version we
actually install.
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Aug 14, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
basekit e743383 Commit Preview URL

Branch Preview URL
Aug 14 2026, 08:51 PM

The release-changesets pin was still on v0.35.0, which predates the
v0.38.1 fix where a release run superseded by a later merge stands down
cleanly instead of failing the build.
@richardsolomou
richardsolomou merged commit 7eb62a3 into main Aug 14, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant