Skip to content

chore: version packages - #27

Merged
cavewebs merged 1 commit into
mainfrom
changeset-release/main
Oct 5, 2026
Merged

cavewebs merged 1 commit into
mainfrom
changeset-release/main

Conversation

@github-actions

@github-actions github-actions Bot commented Sep 15, 2026 •

Copy link
Copy Markdown
Contributor

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@dashcommerce/core@0.2.1

Patch Changes

  • #34 55ca9fa Thanks @cavewebs! - Harden checkout and Stripe webhook payment integrity: verify variant ownership, re-resolve coupon/shipping amounts at checkout, require paid payment status (incl. async success), and reconcile PaymentIntent amounts; fix hosted Checkout Session tax/discount line items.

  • #26 bcdad21 Thanks @cavewebs! - Railway/reverse-proxy: use configured public site URL for Stripe success/cancel and portal return URLs instead of request.origin which can be localhost:PORT

@dashcommerce/starter@0.3.2

Patch Changes

@github-actions
github-actions Bot force-pushed the changeset-release/main branch 3 times, most recently from f5e9110 to 7c23048 Compare September 15, 2026 13:42
@github-actions
github-actions Bot force-pushed the changeset-release/main branch from 7c23048 to 75a26f9 Compare September 29, 2026 02:58
cavewebs added a commit that referenced this pull request Oct 5, 2026
## Summary

Harden checkout and Stripe webhook payment integrity so cart totals and
paid amounts stay consistent through checkout.

## Changes

- Verify product/variant ownership when pricing cart lines
- Re-resolve coupon and shipping amounts at checkout (do not trust stale
stored amounts)
- Require paid payment status before marking orders paid (including
async payment success)
- Reconcile PaymentIntent amounts against order totals
- Fix hosted Checkout Session tax/discount line items

## Test plan

- [x] `bun test` focused suites (payment-integrity, coupons,
cart-calculate, shipping-zones) — 42 pass
- [ ] CI green on this PR
- [ ] Stripe test-mode: one embedded + one hosted purchase
- [ ] Merge, then ship patch via Version Packages (`@dashcommerce/core`
0.2.1)

## Release

Includes a **patch** changeset for `@dashcommerce/core`. After merge,
Version Packages PR #27 should pick this up for npm publish.

Quiet PR — no public vulnerability detail.
@github-actions
github-actions Bot force-pushed the changeset-release/main branch from 75a26f9 to b80e371 Compare October 5, 2026 15:44
@cavewebs
cavewebs merged commit c0b1317 into main Oct 5, 2026
cavewebs added a commit that referenced this pull request Oct 6, 2026
<!-- CURSOR_AGENT_PR_BODY_BEGIN -->
## Summary

After Version Packages (#27), `@dashcommerce/core` is `0.2.1` in
`package.json` but `DASHCOMMERCE_VERSION` in
`packages/core/src/index.ts` was still `"0.2.0"`. That fails
`packages/core/test/version-constant.test.ts` on main.

Changesets only bumps `package.json`. The hardcoded constant did not
move with it.

## Fix

Source `DASHCOMMERCE_VERSION` from `package.json` (`import pkg from
"../package.json"`). tsdown inlines `version` into `dist/index.js` at
build time, so the published descriptor matches the package and future
Version Packages PRs cannot drift.

The existing version-constant CI step remains as the backstop.

No changeset, no publish, no EmDash peer / PaymentProvider / advisory
changes.

## Test

- `bun test packages/core/test/version-constant.test.ts` — pass
(`0.2.1`)
- Simulated `package.json` bump to `9.9.9` — test still passed without
touching the constant
- `bun run --cwd packages/core test` — 123 pass
- `bun run typecheck` — pass

<!-- CURSOR_AGENT_PR_BODY_END -->

<div><a
href="https://cursor.com/agents/bc-f7d5cee4-dd1b-5f1d-84e6-05423135efa2?cursor_ref=pr_footer&cursor_cta=open_in_web"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-web-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-web-light.png"><img
alt="Open in Web" width="114" height="28"
src="https://cursor.com/assets/images/open-in-web-dark.png"></picture></a>&nbsp;<a
href="https://cursor.com/background-agent?bcId=bc-f7d5cee4-dd1b-5f1d-84e6-05423135efa2&cursor_ref=pr_footer&cursor_cta=open_in_cursor"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-cursor-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-cursor-light.png"><img
alt="Open in Cursor" width="131" height="28"
src="https://cursor.com/assets/images/open-in-cursor-dark.png"></picture></a>&nbsp;</div>
cavewebs added a commit that referenced this pull request Oct 7, 2026
<!-- CURSOR_AGENT_PR_BODY_BEGIN -->
## Why

After Version Packages
[#37](#37)
(`@dashcommerce/core@0.2.2`), **CI is green** on `main` but **Release is
red**. npm is shipped locally (`npm publish --access public` from
`packages/core`); Actions is not a working publisher.

Verified on [Release run
37460919491](https://github.com/emdashCommerce/dashcommerce/actions/runs/37460919491)
(and the same pattern on
[#27](https://github.com/emdashCommerce/dashcommerce/actions/runs/37335940811)):

1. No pending changesets after the version PR merge.
2. `changesets/action` logs `No changesets found. Attempting to publish
any unpublished packages to npm`.
3. It writes `.npmrc` from `NPM_TOKEN` and runs `bun run release` →
`changeset publish`.
4. npm returns `E404 Not Found - PUT
https://registry.npmjs.org/@dashcommerce%2fcore` — the usual failure
when the token cannot publish the scope. The secret is **present but
unusable**, not missing (so an `if: secrets.NPM_TOKEN != ''` skip would
still run and fail).

Pushes that only open/update a Version Packages PR stay green. Merging
that PR is what turns `main` red.

## Change

Small, reversible cut of the broken Actions publish path:

- Keep `Release` on `push` to `main`.
- Keep `changesets/action` **without** `publish:`, so it still
opens/updates Version Packages PRs and exits 0 when there is nothing to
version.
- Drop `NPM_TOKEN`, `NPM_CONFIG_PROVENANCE`, `id-token: write`,
`registry-url`, and `createGithubReleases` (all publish-only).
- Document local publish in `.changeset/README.md`.

`bun run release` in root `package.json` is unchanged for anyone who
wants to publish from a logged-in machine.

## Not in this PR

- No `NPM_TOKEN` refresh/rotation.
- No changes to Sync starter token handling.
- Does not claim Actions published anything.

## Reverse

Restore `publish: bun run release`, `NPM_TOKEN`, and provenance on the
`changesets/action` step if Actions npm auth is ever wired up for real.

## After merge

The next `main` push runs Release without `changeset publish`, so the
default branch check should go green. Version Packages PRs keep working
the same way; npm still ships locally.
<!-- CURSOR_AGENT_PR_BODY_END -->

<div><a
href="https://cursor.com/agents/bc-e4a0b3cc-04c9-5fa5-95c0-4896db1713d4?cursor_ref=pr_footer&cursor_cta=open_in_web"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-web-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-web-light.png"><img
alt="Open in Web" width="114" height="28"
src="https://cursor.com/assets/images/open-in-web-dark.png"></picture></a>&nbsp;<a
href="https://cursor.com/background-agent?bcId=bc-e4a0b3cc-04c9-5fa5-95c0-4896db1713d4&cursor_ref=pr_footer&cursor_cta=open_in_cursor"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-cursor-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-cursor-light.png"><img
alt="Open in Cursor" width="131" height="28"
src="https://cursor.com/assets/images/open-in-cursor-dark.png"></picture></a>&nbsp;</div>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant