From bfd21afdcae6c24f90448ca7c545eb26771aef50 Mon Sep 17 00:00:00 2001 From: Lindsay Holmwood Date: Sat, 3 Oct 2026 10:00:18 +1000 Subject: [PATCH] docs(skills): pin the 1.2.1 release in the stash-cli and stash-edge skills The skills ship inside the stash tarball and nothing rewrites their version literals, so release-train.test.ts requires the stash-cli skill to pin the stash version in the tree. Version Packages #1020 moved stash and @cipherstash/stack to 1.2.1 and left the pins at 1.2.0, because no CI ran on it. main has failed that test since. Move the stash-cli one-shot install and the two stash-edge @cipherstash/stack specifiers from 1.2.0 to 1.2.1, as #928 (1fcf7223) and #938 (4aaf7dca) did for their releases. No changeset: the pins move with the release they name, and a changeset here would start a 1.2.2 release only to correct them. Refs: CIP-4285 Co-Authored-By: Claude Opus 5.5 (1M context) Claude-Session: https://claude.ai/code/session_01PaY5xYydZUWhv8Nex9Sw8a --- skills/stash-cli/SKILL.md | 2 +- skills/stash-edge/SKILL.md | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/skills/stash-cli/SKILL.md b/skills/stash-cli/SKILL.md index c3435bfa8..d5dd7cf73 100644 --- a/skills/stash-cli/SKILL.md +++ b/skills/stash-cli/SKILL.md @@ -396,7 +396,7 @@ Gets a project from zero to a direct EQL v3 install. It loads an existing `stash The removed `--eql-version`, `--latest`, `--drizzle`, `--migration`, `--direct`, `--migrations-dir`, and `--exclude-operator-family` options fail clearly instead of being ignored. A request for EQL v2 points dump-recovery users to the upstream EQL 2.3.1 SQL release. New installs are EQL v3 only; its pinned bundle self-adapts when a database role cannot create the optional operator family. -**`--database-url` is a one-shot.** It installs against that database and leaves the project untouched — no config is loaded, and none is scaffolded, nor is an encryption client. This lets `npx --package=stash@1.2.0 stash eql install --database-url 'postgres://...'` run in a bare project with no CipherStash dependencies while pinning the CLI to this skill's release. It also means the flag always wins: loading a config could pick up a parent-directory `databaseUrl` literal and install against the wrong database. +**`--database-url` is a one-shot.** It installs against that database and leaves the project untouched — no config is loaded, and none is scaffolded, nor is an encryption client. This lets `npx --package=stash@1.2.1 stash eql install --database-url 'postgres://...'` run in a bare project with no CipherStash dependencies while pinning the CLI to this skill's release. It also means the flag always wins: loading a config could pick up a parent-directory `databaseUrl` literal and install against the wrong database. **The install verifies the bundle before it runs it.** Before connecting, `eql install` hashes the SQL it resolved from `@cipherstash/eql` and compares it against the `installSqlSha256` that release attests to. A mismatch refuses — naming both digests and the resolved path — rather than executing SQL the version number does not vouch for; nothing is opened and nothing is sent. In practice this only fires on a corrupt or tampered `node_modules`, since the bundle and its manifest are emitted by the same build. diff --git a/skills/stash-edge/SKILL.md b/skills/stash-edge/SKILL.md index 57ecf6a2f..acc83449f 100644 --- a/skills/stash-edge/SKILL.md +++ b/skills/stash-edge/SKILL.md @@ -76,7 +76,7 @@ build step. ```ts import { Encryption, encryptedTable, types, isEncrypted, -} from 'npm:@cipherstash/stack@1.2.0/wasm-inline' +} from 'npm:@cipherstash/stack@1.2.1/wasm-inline' ``` **Pin an exact version.** Deno caches by specifier, so an unpinned import @@ -91,7 +91,7 @@ name everywhere: ```jsonc { "imports": { - "@cipherstash/stack/wasm-inline": "npm:@cipherstash/stack@1.2.0/wasm-inline" + "@cipherstash/stack/wasm-inline": "npm:@cipherstash/stack@1.2.1/wasm-inline" } } ```